Skip to content

Use rootform-dev/action/analyze@v1 when you need a Form and architecture reports without comparison or a Policy gate. It installs and verifies Rootform and prepares required project content itself; setup and init are optional.

Analyze a completed plan export YAML
- uses: rootform-dev/action/analyze@v1
id: analysis
with:
version: 0.1.0
input: ${{ runner.temp }}/plan.json
plan-file: ${{ runner.temp }}/plan.tfplan

input is required and accepts plan JSON, state JSON, a Form or a Comparison Form. Pair a raw plan with its matching saved plan; supplied pairing must verify. Omit plan-file for state and saved Forms. A saved Form is reused with its original path and bytes; it is not analyzed again. stage selects an available architecture stage where applicable; Rootform supplies the default.

form, report and html are file paths for later steps in this job. The form output preserves the supplied Form or exposes the generated Form. Summary and artifact upload default to on. Artifacts contain the Form and derived reports, never raw inputs. This primitive never comments on a PR.

See the integrated reference for installation, version and project content and permissions, artifact retention and publication. Use compare for two operands or check for Policies.

Inputs

Type describes accepted values. GitHub passes all inputs as strings. bool accepts true or false. int accepts a whole number. An empty default leaves the input unset.

InputTypeDefaultDescription
versionstring""Exact published version; omit to reuse a verified version in this job
github-tokenstring${{ github.token }}GitHub token for release API requests
inputstring""Path to plan JSON, state JSON, Form or Comparison Form
plan-filestring""Matching saved plan for input; pairing must verify
stagestring""Architecture stage: planned, refreshed or recorded
projectstring""Project directory for raw evidence or Policy selection; defaults to workspace
lockedboolfalseRequire and preserve existing rootform.lock
offlineboolfalsePrepare selected external content without network access
cachebooltrueCache verified external sources selected by rootform.lock
summarybooltrueAppend CLI Markdown to GitHub Job Summary
upload-artifactbooltrueUpload Form and derived reports as one artifact; never raw inputs
artifact-namestring""Artifact name; defaults to a unique name per invocation, including matrix jobs
retention-daysint7Artifact retention: 1–90 days, capped by repository limit

Outputs

OutputDescription
versionVerified Rootform CLI version
formPath to the supplied or generated Form
reportPath to the complete CLI Markdown report
htmlPath to the self-contained HTML Explorer
artifact-idUploaded artifact ID for cross-job download
artifact-urlUploaded artifact URL

Exact fields and defaults: Action metadata.