Skip to main content

tflint

The tflint step type lints a Terraform component in a stack and reports findings through the shared scanner engine. Use it in workflows and custom commands to check a component before deployment.

workflows:
lint:
steps:
- name: lint-vpc
type: tflint
component: vpc
stack: dev

Fields​

component
Required Terraform component name, resolved using the selected stack.
stack
Stack name. When omitted, Atmos checks the command's stack flag and then ATMOS_STACK; execution fails if no stack is available.
args
Additional tflint arguments appended to the scanner defaults. The scanner captures SARIF output for reporting.
env
Environment variables passed to the scanner. Values support step template resolution.

These fields can also be placed under with; non-empty top-level values take precedence. The component name, stack, arguments, and environment values support step templates.

Execution Context​

The step uses a failure policy of fail: lint findings can fail the step. This differs from the default warn policy of the dedicated kind: tflint lifecycle hook, which also documents tool installation and ruleset configuration.

The result includes the component and stack in its metadata. When a scanner summary is available, it also includes status, title, counts, and the number of findings.