tflint
The tflint step type lints a Terraform component in a stack and reports findings through the shared scanner engine. Use it in workflows and custom commands to check a component before deployment.
workflows:
lint:
steps:
- name: lint-vpc
type: tflint
component: vpc
stack: dev
Fields
component- Required Terraform component name, resolved using the selected stack.
stack- Stack name. When omitted, Atmos checks the command's
stackflag and thenATMOS_STACK; execution fails if no stack is available. args- Additional tflint arguments appended to the scanner defaults. The scanner captures SARIF output for reporting.
env- Environment variables passed to the scanner. Values support step template resolution.
These fields can also be placed under with; non-empty top-level values take precedence. The component name, stack, arguments, and environment values support step templates.
Execution Context
The step uses a failure policy of fail: lint findings can fail the step. This differs from the default warn policy of the dedicated kind: tflint lifecycle hook, which also documents tool installation and ruleset configuration.
The result includes the component and stack in its metadata. When a scanner summary is available, it also includes status, title, counts, and the number of findings.