Use rootform-dev/action@v1 for the complete review: a Form, architecture
Markdown, Explorer HTML, Job Summary and downloadable evidence. Add Policies
for a gate and opt in to a PR comment when reviewers need the report there.
Start with the GitHub quick start.
Provide either input or both before and after, never both modes.
input accepts plan JSON, state JSON, a Form or a Comparison Form.
Each comparison operand accepts plan JSON, state JSON or a single-input Form;
a Comparison Form cannot be an operand. Saved Forms are reopened without
reinterpreting the original exports.
- uses: rootform-dev/action@v1 id: rootform with: version: 0.1.0 input: ${{ runner.temp }}/plan.json plan-file: ${{ runner.temp }}/plan.tfplan policy-pack: ./policies/teamThe example assumes your planning step has exported the saved plan and
./policies/team contains a Policy Pack. Rootform verifies the plan pairing.
For comparison, replace the input pair with before and after, pairing
each raw plan with before-plan-file or after-plan-file.
check: true evaluates project-selected Policies; policy narrows an explicit
selection and policy-pack supplies local Packs. Selectors and Pack paths
accept one value per line. No Pack is selected implicitly. stage selects a
single architecture; before-stage and after-stage select comparison stages.
side applies to a Comparison Form check and defaults to both.
See Policy selection.
Set an exact published version; latest and version ranges are not accepted.
Omit it only after an earlier Rootform Action step in the same job installed
and verified a version. An unrelated executable on PATH is not reused.
Release archive checksum and executable version are verified. Public releases
need no separate token; github-token can increase GitHub API rate limits.
It is not passed to Rootform. All entrypoints use Node 24 and require Actions
Runner 2.327.1 or newer.
project locates Rootform configuration for raw evidence or Policy selection;
it defaults to the workspace. Reopening a Form preserves its evidence and
selection. locked: true requires and preserves an existing rootform.lock.
The Action never creates or edits that lock.
The job shares ROOTFORM_HOME between Rootform steps. The default cache retains
only external Dialect and Policy Pack sources selected by the lock; restored
content is verified again. offline: true prepares verified local content
without network access. It does not prevent installation from downloading
the CLI when no earlier verified Rootform step is available.
Rootform never runs Terraform/OpenTofu, providers, clouds or backends.
form, report and html are paths usable by later steps in the same job.
form contains a Comparison Form when comparing. When a check runs, result,
sarif and exit-code are also available. Unproduced outputs are empty.
version and exit-code are values; no Form or report body enters step outputs.
Summary and artifact upload default to on. Artifacts persist the Form and
derived reports for download or another job; raw plans, states and saved binary
plans are never uploaded. artifact-id and artifact-url exist only after
upload. Retention defaults to seven days, accepts 1–90 days, and is capped by
the repository limit. Default names avoid matrix collisions; a custom
artifact-name must be unique per invocation. On GitHub Enterprise Server,
disable this artifact transport with upload-artifact: false.
Available evidence is published before applying a nonzero check exit code.
Use step-level continue-on-error if later workflow steps should continue.
SARIF is a retained result file; this Action does not upload code-scanning results.
Normal use needs contents: read. A PR comment needs comment: true,
pull-requests: write, actions: read, and shared job-level concurrency keyed
by PR number with cancellation disabled. Only same-repository pull_request
events comment; forks keep Summary/artifacts and skip comments. On GitHub
Enterprise Server, leave comment off. The analyze,
compare, and check Actions, along with the init Action, reject
pull_request_target. Follow the
comment example and choose an audience
that may see the topology in Forms and reports.
Type describes accepted values. GitHub passes all inputs as strings. bool accepts true or false. int accepts a whole number. An empty default leaves the input unset.
Exact fields and defaults: Action metadata.