Skip to content

Use rootform-dev/action/compare@v1 to review architectural differences between two sets of evidence. It installs Rootform and prepares required content; setup, init and separate analyze steps are optional.

Compare two completed plans YAML
- uses: rootform-dev/action/compare@v1
id: comparison
with:
version: 0.1.0
before: ${{ runner.temp }}/before/plan.json
before-plan-file: ${{ runner.temp }}/before/plan.tfplan
after: ${{ runner.temp }}/after/plan.json
after-plan-file: ${{ runner.temp }}/after/plan.tfplan

Both before and after are required. Each accepts plan JSON, state JSON or a single-input Form; a Comparison Form cannot be an operand. Each supplied saved plan must verify against its own JSON export. Omit the saved-plan input on a state or Form side. before-stage and after-stage choose available stages; Rootform supplies their defaults.

form is the Comparison Form, which embeds both architectures. There are no separate before/after Form outputs. report and html present that same Form; all three outputs are same-job paths. Reopen it with analyze or evaluate its Policies with check. Summary and artifact upload default to on; the primitive never comments on a PR.

See installation, version and project content and permissions, artifact retention and publication.

Inputs

Type describes accepted values. GitHub passes all inputs as strings. bool accepts true or false. int accepts a whole number. An empty default leaves the input unset.

InputTypeDefaultDescription
versionstring""Exact published version; omit to reuse a verified version in this job
github-tokenstring${{ github.token }}GitHub token for release API requests
beforestring""Before plan JSON, state JSON or single-input Form
afterstring""After plan JSON, state JSON or single-input Form
before-plan-filestring""Matching saved plan for before; pairing must verify
after-plan-filestring""Matching saved plan for after; pairing must verify
before-stagestring""Before stage: planned, refreshed or recorded
after-stagestring""After stage: planned, refreshed or recorded
projectstring""Project directory for raw evidence or Policy selection; defaults to workspace
lockedboolfalseRequire and preserve existing rootform.lock
offlineboolfalsePrepare selected external content without network access
cachebooltrueCache verified external sources selected by rootform.lock
summarybooltrueAppend CLI Markdown to GitHub Job Summary
upload-artifactbooltrueUpload Form and derived reports as one artifact; never raw inputs
artifact-namestring""Artifact name; defaults to a unique name per invocation, including matrix jobs
retention-daysint7Artifact retention: 1–90 days, capped by repository limit

Outputs

OutputDescription
versionVerified Rootform CLI version
formPath to the generated Comparison Form
reportPath to the complete CLI Markdown report
htmlPath to the self-contained HTML Explorer
artifact-idUploaded artifact ID for cross-job download
artifact-urlUploaded artifact URL

Exact fields and defaults: Action metadata.