Reading a compliance report

Understand the compliance score, the findings, the auto-fixes, and what to do with warnings.

What the score means

After the Terraform is generated, the Compliance check runs the Workmates rule set over the whole file set. The rules are organized into around ten sections covering areas such as naming and tagging, security-group and port scoping, encryption at rest and in transit, and resource dependencies. The result is a pass or fail and a score out of 100.

The score is a summary; the findings are what you act on. Each rule section reports as pass or fail with a short detail, so you can see exactly which area lowered the score.

Rule of thumb

A passing score with zero critical findings is safe to proceed. Any critical finding blocks the run regardless of the number.

Findings

Every report groups its results into three kinds of finding.

KindMeaning
CriticalBlocks the run. Must be fixed and the Terraform regenerated before the run can continue.
WarningAdvisory. Reviewed at the tech-lead gate, then you proceed or regenerate.
Auto-fixA safe correction already applied for you, shown as a before/after diff to confirm.

Auto-fixes

Common, unambiguous issues are corrected automatically and surfaced as a diff so you can confirm the change matches your intent. Typical examples are enabling encryption or adding required tags. The block below shows an auto-fix that turns on encryption in transit and adds the required tags.

hclcompliance auto-fix (diff)
300/90">"text-rose-300">resource 300/90">"aws_elasticache_replication_group" 300/90">"cache" {
- 300/90">"text-white/35"># transit encryption left at provider 300/90">"text-rose-300">default (off)
+ transit_encryption_enabled = true
at_rest_encryption_enabled = true
+ tags = {
+ Environment = 300/90">"text-rose-300">var.environment
+ ManagedBy = 300/90">"updp"
+ }
}

Auto-fixes are already applied

You do not need to reapply an auto-fix. Read the diff, confirm it matches intent, and continue.

What to do with warnings

Use the finding kind to decide the next action.

  • Critical findings block the run. Fix the underlying requirement and regenerate the Terraform.
  • Warnings are advisory. Review them at the tech-lead gate, then proceed or regenerate.
  • Auto-fixed items are already in the file set. Confirm each diff matches your intent.

Proceeding past the gate

Once criticals are clear and warnings are reviewed, the run continues to the tech-lead review of the combined Terraform, and from there to the deploy pull request.

Was this page helpful?View as llms.txt