Skip to content

Use rootform-dev/action/check@v1 to evaluate Policies and gate a job. It can produce the Form from a raw plan or state before checking; no analyze step is required. A supplied Form or Comparison Form is reused without new analysis.

Check a plan directly YAML
- uses: rootform-dev/action/check@v1
id: checks
with:
version: 0.1.0
input: ${{ runner.temp }}/plan.json
plan-file: ${{ runner.temp }}/plan.tfplan
policy-pack: ./policies/team

input is required. Pair a raw plan with its matching saved plan; omit plan-file for state and saved Forms. The example assumes a Policy Pack at ./policies/team. policy-pack accepts source directories or compiled files, one path per line. policy accepts selectors, one per line, and can narrow explicitly selected Packs. Without these overrides, check evaluates the project-selected Policies. No Pack is selected implicitly.

For a Comparison Form, side accepts before, after or both; the CLI default is both. stage selects an architecture stage where applicable. Rootform validates these combinations and owns every verdict. See Policy selection and Policy outcomes.

form exposes the reused or produced Form path. result, report and sarif are the Policy result, Markdown and SARIF file paths; exit-code is the exact CLI check exit code. Available outputs, Summary and artifacts are published before a negative gate fails the step. Use GitHub's continue-on-error when later workflow steps should continue; it does not change the verdict. Summary and upload default to on. This primitive never comments on a PR.

See installation, version and project content and permissions, artifact retention and publication.

Inputs

Type describes accepted values. GitHub passes all inputs as strings. bool accepts true or false. int accepts a whole number. An empty default leaves the input unset.

InputTypeDefaultDescription
versionstring""Exact published version; omit to reuse a verified version in this job
github-tokenstring${{ github.token }}GitHub token for release API requests
inputstring""Path to plan JSON, state JSON, Form or Comparison Form
plan-filestring""Matching saved plan for input; pairing must verify
policystring""Policy selectors, one per line, within selected Packs
policy-packstring""Policy Pack source directories or compiled files, one per line
sidestring""Comparison sides: before, after or both; defaults to both
stagestring""Architecture stage: planned, refreshed or recorded
projectstring""Project directory for raw evidence or Policy selection; defaults to workspace
lockedboolfalseRequire and preserve existing rootform.lock
offlineboolfalsePrepare selected external content without network access
cachebooltrueCache verified external sources selected by rootform.lock
summarybooltrueAppend CLI Markdown to GitHub Job Summary
upload-artifactbooltrueUpload Form and derived reports as one artifact; never raw inputs
artifact-namestring""Artifact name; defaults to a unique name per invocation, including matrix jobs
retention-daysint7Artifact retention: 1–90 days, capped by repository limit

Outputs

OutputDescription
versionVerified Rootform CLI version
formPath to the supplied or generated Form
resultPath to Policy result JSON
reportPath to the complete CLI Markdown report
sarifPath to Policy result SARIF
exit-codeRootform check exit code, exposed before the gate
artifact-idUploaded artifact ID for cross-job download
artifact-urlUploaded artifact URL

Exact fields and defaults: Action metadata.