knowre-dev/run-digger

Manage terraform collaboration

View on GitHub

Trust Signals

Scorecard Score
not yet scored
Maintenance Recency
Maintainedlast commit Apr 7, 2025
License
Apache 2.0

Pinned Snippet

workflow.ymlSHA-pinned
uses: knowre-dev/digger@c7328a0f2803986c8e40ef26f541334c81402443 # no releases — HEAD as of 2026-07-11

tags can be moved; commit SHAs can't. why a SHA?

namedescriptionrequireddefault
eeuse ee cli?nofalse
setup-awsSetup AWSnofalse
aws-access-key-idAWS access key idno
aws-secret-access-keyAWS secret access keyno
aws-role-to-assumeARN of AWS IAM role to assume using OIDCno
aws-regionAWS regionnous-east-1
setup-google-cloudSetup google cloudnofalse
google-auth-credentialsService account key used got Google auth (mutually exclusive with 'google-workload-identity-provider' input)no
google-workload-identity-providerWorkload identity provider to be used for Google OIDC auth (mutually exclusive with 'google-auth-credentials' input)no
google-workload-identity-provider-audience'audience' parameter configured in Google's Workload Identity Provider (if specified). To be used when the 'google-workload-identity-provider' input is specifiedno
google-service-accountService account to be used when the 'google-workload-identity-provider' input is specified)no
google-lock-bucketThe GCP bucket to use for locksno
setup-azureSetup Azurenofalse
azure-client-idAzure Client ID to be used for Azure OIDC authno
azure-tenant-idAzureAD ID of the organization you are usingno
azure-subscription-idSubscription ID of you are usingno
setup-terragruntSetup terragruntnofalse
setup-opentofuSetup OpenToFunofalse
setup-pulumiSetup Puluminofalse
terragrunt-versionTerragrunt versionnov0.73.7
opentofu-versionOpenTofu versionnov1.6.1
pulumi-versionPulumi versionnov3.3.0
setup-terraformSetup terraformnofalse
terraform-versionTerraform versionnov1.5.5
configure-checkoutConfigure checkout. Beware that this will overwrite any changes in the working directorynotrue
upload-plan-destinationDestination to upload the plan to. azure, gcp, github and aws are currently supported.no
upload-plan-destination-s3-bucketName of the destination bucket for AWS S3. Should be provided if destination == awsno
upload-plan-destination-s3-encryption-enabledIf encryption is to be enabled for s3 bucketnofalse
upload-plan-destination-s3-encryption-typethe type of encryption to use for the S3 bucket, either AES256 or KMSnoAES256
upload-plan-destination-s3-encryption-kms-key-idfor encryption of type KMS you need to specify the KMS key ID to useno
upload-plan-destination-azure-containerName of the destination storage account container for Azure blob storage. Should be provided if destination == azureno
upload-plan-destination-azure-storage-accountName of the destination storage account for Azure blob storage. Should be provided if destination == azureno
upload-plan-destination-gcp-bucketName of the destination bucket for a GCP bucket. Should be provided if destination == gcpno
setup-checkovSetup Checkovnofalse
checkov-versionCheckov versionno3.2.22
disable-lockingDisable locking (deprecated, use pr_locks on digger.yml instead)nofalse
digger-filenameAlternative Digger configuration file nameno
digger-private-keyDigger private key (for digger team and next only)no
digger-tokenDigger tokenno
digger-hostnameDigger hostnamenohttps://cloud.digger.dev
digger-organisationThe name of your digger organisationno
setup-tfenvSetup tfenvnofalse
post-plans-as-one-commentPost plans as one commentnofalse
reporting-strategycomments_per_run or latest_run_comment, anything else will default to original behavior of multiple commentsnocomments_per_run
modemanual, drift-detection or otherwiseno""
no-backendrun cli-only, without an orchestrator backendnofalse
commanddigger plan or digger apply in case of manual modeno""
projectproject name for digger to run in case of manual modeno""
drift-detection-slack-notification-urldrift-detection slack drift urlno""
cache-dependenciesLeverage actions/cache to cache dependencies to speed up executionnofalse
terraform-cache-dirallows overriding of the terraform cache dir which defaults to ${github.workspace}/cacheno""
digger-spec(orchestrator only) the spec to pass onto digger clino""
namedescription
outputThe terraform output