Terraform HCL Formatter
Format Terraform HCL with terraform fmt-style indentation and aligned equals, and lint for hardcoded secrets, 0.0.0.0/0 rules and undeclared vars.
Terraform HCL Formatter
terraform {
required_version = ">= 1.5.0"
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 5.0"
}
}
}
provider "aws" {
region = var.region
}
variable "region" {
description = "AWS region"
type = string
default = "us-east-1"
}
variable "instance_type" {
description = "EC2 instance type"
type = string
}
resource "aws_security_group" "web" {
name = "web-sg"
description = "web sg"
ingress {
from_port = 22
to_port = 22
protocol = "tcp"
cidr_blocks = ["0.0.0.0/0"]
}
}
resource "aws_db_instance" "main" {
identifier = "main-db"
engine = "postgres"
instance_class = "db.t3.micro"
username = "admin"
password = "supersecret123"
skip_final_snapshot = true
publicly_accessible = true
}
output "db_endpoint" {
value = aws_db_instance.main.endpoint
sensitive = false
}
1 errors, 3 warnings, 2 info findings
- WarningL34Wildcard CIDR 0.0.0.0/0 in security group — locks open the rule
- WarningL34Security group allows traffic from 0.0.0.0/0
- ErrorL43Hardcoded password literal — use a variable with sensitive=true
- InfoL44skip_final_snapshot=true — recovery becomes harder if DB is destroyed
- WarningL45Resource is publicly_accessible — confirm this is intentional
- InfoL21variable "instance_type" has no default — caller must provide it (terraform.tfvars or -var)
- terraformL1
- provider "aws"L11
- variable "region"L15
- variable "instance_type"L21
- resource "aws_security_group" "web"L26
- resource "aws_db_instance" "main"L38
- output "db_endpoint"L48
Updated . Provided as is. Check the output before you rely on it in production.
How to use Terraform HCL Formatter
- 1
Paste your HCL
Drop any Terraform configuration into the input pane: a single resource, a full module, or several files concatenated. The formatter handles HCL2 syntax, heredocs, and string interpolations.
- 2
Read the formatted output
The right pane shows terraform fmt-equivalent output: 2-space indentation, aligned equals signs within blocks, and normalized blank lines. Click Copy to lift the cleaned text back into your editor.
- 3
Triage findings
Errors flag hardcoded AWS keys, inline private keys, and dangerous patterns. Warnings cover 0.0.0.0/0 CIDRs, public flags, and missing safeguards. Info findings note declared variables without defaults.
- 4
Inspect block structure
The Structure panel lists every top-level block with its labels and line number, so you can quickly count resources, spot mistyped block types, or find a stray locals block buried in a long file.
- 5
Re-run after edits
Both formatting and linting recompute as you type. Iterate until findings are clean, then copy the output to your repo. The tool catches the issues that cause noisy code review feedback before you push.
Questions and answers
What is Terraform HCL Formatter?
Is the formatting identical to terraform fmt?
Does it send my data to a server?
What lint rules are included?
Does it execute or plan my Terraform?
For AI agents: how to call this tool
Machine-readable contract, endpoints and examples. Humans can ignore this section.
Best Path For Builders
Browser workflow
Runs instantly in the browser with private local processing and copy/export-ready output.
Browser Workflow
This tool is optimized for instant in-browser execution with local data handling. Run it here and copy/export the output directly.
/terraform-hcl-formatter/
For automation planning, fetch the canonical contract at /api/tool/terraform-hcl-formatter.json.