tflint - a pluggable linter for Terraform configurations
tflint [--init] [--recursive] [--format=default|compact|json] [--minimum-failure-severity=error|warning|notice] [--force] [--chdir=DIR]
Options you will use
--init- install the plugins declared in .tflint.hcl (e.g. the azurerm ruleset)
--recursive- lint every directory below the current one
--format=compact- one issue per line: file:line:col: Severity - message (rule)
--minimum-failure-severity=LEVEL- only issues at or above LEVEL make the exit status non-zero
--force- exit 0 even if issues were found
--chdir=DIR- run as if started in DIR
--init- Install the plugins declared in .tflint.hcl (e.g. the azurerm ruleset).
--recursive- Run command in each directory recursively.
-f, --format FORMAT- Output format: default, json, checkstyle, junit, compact, sarif.
-c, --config FILE- Config file name (default .tflint.hcl).
--chdir=DIR- Switch to a different working directory before executing the command.
--var-file=FILE- Terraform variable file name (repeatable).
--var KEY=VALUE- Set a Terraform variable (repeatable).
--enable-rule=RULE- Enable rules from the command line.
--disable-rule=RULE- Disable rules from the command line.
--only=RULE- Enable only this rule, disabling all other defaults (repeatable).
--enable-plugin=PLUGIN- Enable plugins from the command line.
--call-module-type=TYPE- Types of module to call: all, local (default), none.
--minimum-failure-severity=LEVEL- Sets minimum severity level for exiting with a non-zero error code: error, warning, notice.
--force- Return zero exit status even if issues found.
--fix- Fix issues automatically (rules that support autofix).
--no-color- Disable colorized output.
--filter=FILE- Filter issues by file names or globs.
-v, --version- Print TFLint version.
Examples
$ tflint --init && tflintinstall plugins, then lint the current module
$ tflint --recursive --format=compactevery directory, one line per issue (CI logs)
Gotchas
- Exit status: 0 no issues, 1 tflint failed, 2 issues found.
- Configuration lives in .tflint.hcl: plugin "terraform" { preset = "recommended" }, plugin "azurerm" { enabled = true, version = "...", source = "github.com/terraform-linters/tflint-ruleset-azurerm" }, rule "<name>" { enabled = false }.
- tflint catches what terraform validate cannot: unused declarations, missing version constraints, unpinned module sources, and (with the azurerm ruleset) values Azure would reject at apply time, such as an invalid VM size.
Taught in
Try tflint in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.