Use rootform-dev/action/check@v1 to evaluate Policies and gate a job. It can
produce the Form from a raw plan or state before checking; no analyze step is
required. A supplied Form or Comparison Form is reused without new analysis.
- uses: rootform-dev/action/check@v1 id: checks with: version: 0.1.0 input: ${{ runner.temp }}/plan.json plan-file: ${{ runner.temp }}/plan.tfplan policy-pack: ./policies/teaminput is required. Pair a raw plan with its matching saved plan; omit
plan-file for state and saved Forms. The example assumes a Policy Pack at
./policies/team. policy-pack accepts source directories or compiled files,
one path per line. policy accepts selectors, one per line, and can narrow
explicitly selected Packs. Without these overrides, check evaluates the
project-selected Policies. No Pack is selected implicitly.
For a Comparison Form, side accepts before, after or both; the CLI
default is both. stage selects an architecture stage where applicable.
Rootform validates these combinations and owns every verdict. See
Policy selection and
Policy outcomes.
form exposes the reused or produced Form path. result, report and sarif
are the Policy result, Markdown and SARIF file paths; exit-code is the exact
CLI check exit code. Available outputs, Summary and artifacts are published
before a negative gate fails the step. Use GitHub's continue-on-error when
later workflow steps should continue; it does not change the verdict.
Summary and upload default to on. This primitive never comments on a PR.
See installation, version and project content and permissions, artifact retention and publication.
Type describes accepted values. GitHub passes all inputs as strings. bool accepts true or false. int accepts a whole number. An empty default leaves the input unset.
Exact fields and defaults: Action metadata.