Skip to content

ci: add placeholder bucket to terraform-validate backend config#5

Closed
nickelghost with Copilot wants to merge 6 commits into
mainfrom
copilot/fix-terraform-validate-backend-config
Closed

ci: add placeholder bucket to terraform-validate backend config#5
nickelghost with Copilot wants to merge 6 commits into
mainfrom
copilot/fix-terraform-validate-backend-config

Conversation

Copilot AI commented Apr 30, 2026

Copy link
Copy Markdown
Contributor
  • Investigate CI failure: terraform validate in Terraform 1.15 validates backend blocks and requires bucket, even when passed via backend_config
  • Replace dflook/terraform-validate@v1 steps with hashicorp/setup-terraform@v3 + terraform init -backend=false && terraform validate to skip backend validation entirely
Original prompt

Problem

The dflook/terraform-validate@v1 action in .github/workflows/lint.yml started failing because a recent version of the action now runs terraform init before validate. The S3 backend in both terraform/app/main.tf and terraform/app_building/main.tf only specifies key, with bucket and region supplied via environment variables at apply time. This is valid for real runs but causes terraform init to fail during CI validation because bucket is required.

Fix

Add a backend_config input with a placeholder bucket value to both dflook/terraform-validate steps in .github/workflows/lint.yml. This satisfies the backend initialization requirement without affecting real deployments.

Update the two validate steps like this:

      - name: Validate app_building
        uses: dflook/terraform-validate@v1
        with:
          path: terraform/app_building
          backend_config: |
            bucket="placeholder"
      - name: Validate app
        uses: dflook/terraform-validate@v1
        with:
          path: terraform/app
          backend_config: |
            bucket="placeholder"

The file to update is .github/workflows/lint.yml.

The following is the prior conversation context from the user's chat exploration (may be truncated):

User: terraform validate suddenly started requiring the bucket for s3 backend. when it's actually applied, it's configured via an environment variable. this was not required for a long time and now validate complains about it out of nowhere

Assistant: This is a breaking change in dflook/terraform-validate@v1. Starting from dflook/terraform-github-actions v1.45.0, the action runs terraform init before validate, and the S3 backend initialization now requires bucket (and typically region) to be present — it no longer tolerates a partial backend config during init.

Your backend configs only have key, relying on env vars (AWS_* / TF_VAR_* / -backend-config) at apply time — which is fine for real runs, but dflook/terraform-validate now fails during the init phase in CI.

The fix is to pass backend_config to the action with a dummy/placeholder bucket, or — the cleaner approach — tell the action to skip backend initialization entirely using backend_config: false. That's supported by the action and is exactly the right thing to do for a pure syntax/semantic validation:

      - name: Validate app_building
        uses: dflook/terraform-validate@v1
        with:
          path: terraform/app_building
          backend_config: |
            bucket="placeholder"
      - name: Validate app
        uses: dflook/terraform-validate@v1
        with:
          path: terraform/app
          backend_config: |
            bucket="placeholder"

Or alternatively, pin to an older version of the action that didn't require this (e.g. dflook/terraform-validate@v1.44.0) to buy time while you decide on the right approach.

Would you like me to open a PR with the backend_config fix applied to your workflow file?

User: yes please

Assistant: We're waiting for your response on the tool call confirmation dialog to continue — please approve it to let the coding agent create the PR.

This pull request was created from Copilot chat.

Copilot AI changed the title [WIP] Fix terraform validate action by adding backend config ci: add placeholder bucket to terraform-validate backend config Apr 30, 2026
Copilot AI requested a review from nickelghost April 30, 2026 21:56
…ckend=false && validate

Agent-Logs-Url: https://github.com/nickelghost/pufferfish/sessions/5138f2e9-a1b7-4220-b85c-f6953919fdf7

Co-authored-by: nickelghost <16365643+nickelghost@users.noreply.github.com>
Copilot stopped work on behalf of nickelghost due to an error April 30, 2026 22:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants