About this project

tf-via-pr is a GitHub Action for automating Terraform and OpenTofu workflows through pull requests. It runs plan on pull_request events and apply on push or merge events, while automatically handling init, format, validate, and workspace selection. The action posts plan or apply results as an up-to-date PR comment with a diff summary and workflow status, and can update an existing comment to preserve revision history. Security features include optional encryption of plan file artifacts using OpenSSL AES-256-CTR with salt and PBKDF2, configurable artifact retention, and the ability to hide sensitive CLI arguments from displayed commands. A plan-parity option helps prevent stale applies in merge queues. The action supports many Terraform/OpenTofu CLI arguments such as backend-config, var-file, target, replace, destroy, refresh-only, and parallelism, and can run format and validate checks. It is intended for DevOps and platform engineers who want self-service infrastructure provisioning without managing containers or VMs. Example workflows cover AWS authentication, matrix strategies, linting, conditional jobs, manual triggers on self-hosted runners, and scheduled drift detection. Outputs include plan artifact IDs and URLs, command results, exit codes, diffs, check IDs, and PR comment identifiers.