TFLint Integration with DefectDojo
TFLint Integration with DefectDojo
TFLint is an open source, pluggable linter for Terraform, maintained by the terraform-linters project on GitHub. Its core ruleset checks Terraform language usage, such as deprecated syntax, unused declarations, and naming conventions, while provider plugins (for AWS, Azure, and Google Cloud) add rules that catch provider-specific problems like invalid instance types before terraform plan ever runs. TFLint can write several output formats, including JSON, SARIF, JUnit, and Checkstyle; DefectDojo imports its JSON output.
TFLint Integration with DefectDojo
TFLint is the first check our Terraform hits in CI, and sending its JSON to DefectDojo means those results are tracked instead of scrolling past in a job log. Each issue becomes a Finding on the Asset that owns the module, with TFLint's own rule severity mapped to High, Medium, or Info, the file and line it points at, and a link to the rule documentation when the plugin publishes one. Reimporting each run closes the issues a change fixed and flags anything new, so reviewers see the delta rather than the whole list.
Why TFLint Matters
Terraform's own validate command checks syntax and internal consistency, but it does not know that an instance type does not exist or that a variable is declared and never used. TFLint fills that gap.
- Provider rulesets catch values the cloud API would reject, which turns a failed apply into a failed lint step minutes earlier.
- The core ruleset enforces Terraform best practices such as typed variables, pinned module sources, and removing unused declarations.
- Each rule carries a severity (error, warning, or notice), so teams can separate broken configuration from style advice.
- Many issues are fixable automatically with
tflint --fix, and the report says which ones. - It runs locally with no service to host, so the same check works on a laptop and in CI.
Advantages of This Integration
- Severity mapping that follows TFLint. TFLint's error, warning, and notice levels map to High, Medium, and Info, so lint errors can carry an SLA while notices stay informational.
- Deduplication by rule and location. DefectDojo hashes TFLint findings on the rule name, file path, and line, so rescanning unchanged code does not create duplicates.
- Reimport lifecycle. Reimporting into the same Test mitigates issues that were fixed, adds new ones, and reactivates any that came back.
- Rule documentation on the Finding. When a rule has a published page, its link is stored in References, so the engineer who picks up the Finding can read why the rule exists.
- Module context. When TFLint reports an issue through a module call, the caller locations are listed in the description, which shows where to make the change.
- Shared workflow. TFLint findings get the same assignment, Jira push, notes, and reporting as every other infrastructure finding on the Asset.
How This Integration Works
DefectDojo imports TFLint output with the TFLint Scan scan type.
1. Produce a JSON report. From the Terraform root module, after installing any plugins declared in .tflint.hcl with tflint --init, write the JSON report:
tflint --format json > tflint.json
The parser reads the issues array. The report's errors array holds problems TFLint hit while running, such as an unparseable file or a missing plugin, and is not imported, so check the job log for those.
2. Import it. In the UI, open the Engagement, choose Import Scan Results, select TFLint Scan, and upload the file. For automation, use the API in Community Edition or DefectDojo Pro:
curl "https://YOUR_INSTANCE/api/v2/import-scan/"
-H "Authorization: Token $DD_API_TOKEN"
-F "scan_type=TFLint Scan"
-F "file=@tflint.json"
-F "product_name=network-infra"
-F "engagement_name=Terraform CI"
-F "auto_create_context=true"
DefectDojo Pro users can use Universal Importer:
universal-importer import
--defectdojo-url "https://YOUR_INSTANCE.cloud.defectdojo.com/"
--scan-type "TFLint Scan"
--report-path "./tflint.json"
--product-name "network-infra"
--engagement-name "Terraform CI"
--auto-create-context
3. Reimport on each change. Send later reports for the same module to /api/v2/reimport-scan/ against the same Test so history is kept in one place.
Data Granularity: What Gets Imported
| DefectDojo Field | Source in TFLint Report | Notes |
|---|---|---|
| Title | rule.name and message |
Formatted as rule_name: message |
| Severity | rule.severity |
error is High, warning is Medium, notice is Info; unknown values are Medium |
| Description | message plus context |
Adds location, a note when the issue is fixable with --fix, and each caller |
| File Path | range.filename |
File containing the issue |
| Line | range.start.line |
Start line of the issue |
| Vulnerability ID from tool | rule.name |
For example aws_instance_invalid_type |
| References | rule.link |
Left empty when the plugin publishes no rule page |
| Runtime errors | errors array |
Not imported |
| Finding type | Static | All findings are static |
| Deduplication | Hashcode | Vulnerability ID from tool, file path, line |
Use Cases
In a pull request pipeline: Every Terraform change runs TFLint and reimports into a Test per root module. A merge gate can check DefectDojo for active High findings, which correspond to TFLint errors, while warnings and notices are tracked without blocking.
Standardizing many modules: A platform team maintaining 60 shared modules imports each into its own Test under one Asset. Rule-level filtering shows which conventions are widely broken and which modules need attention first.
Before a provider upgrade: Running TFLint with the current provider ruleset across all workspaces and importing the results shows where deprecated or invalid arguments are used, so the upgrade work can be assigned and tracked.
Next to policy and misconfiguration scanners: TFLint catches invalid and unconventional code, while tools such as Checkov, tfsec, or terraform-compliance check security policy. Importing all of them into the same Asset gives reviewers one list for the module.
Operational Tips
- Check the TFLint
errorsarray or exit status in CI. A missing plugin produces a run with few or no issues, and DefectDojo cannot tell that apart from clean code. - Deduplication includes the line number, so moving a block can mitigate a finding and open a matching one on a new line. Reimporting into the same Test keeps this easy to follow.
- Use
minimum_severity=Mediumon import if notices are noise for your team. You can lower the threshold later. - Enable and disable rules in
.tflint.hcl, not by filtering in DefectDojo, so local runs and imported results agree. - Tag imports with the workspace or environment name so production code can be filtered and held to tighter SLAs.
- Findings marked fixable can often be cleared in bulk with
tflint --fix, followed by a reimport to mitigate them.