{"product_id":"terraform-pr-security-gate-github-gpt-4-1-slack","title":"Terraform PR Security Gate: GitHub, GPT-4.1 \u0026 Slack","description":"\u003ch3\u003eAutomatically secure your Terraform pull requests—with GitHub, OpenAI, and Slack sign-off\u003c\/h3\u003e\n\u003cp\u003eThis n8n workflow reviews \u003cstrong\u003eTerraform PRs on GitHub\u003c\/strong\u003e using an OpenAI tool-calling agent that can run plan, security, cost, and standards checks, then records results in \u003cstrong\u003ePostgres\u003c\/strong\u003e, comments on the PR, and either \u003cstrong\u003eauto-approves\u003c\/strong\u003e clean changes or routes flagged issues to \u003cstrong\u003eSlack for human review\u003c\/strong\u003e.\u003c\/p\u003e\n\n\u003ch3\u003eWhat this workflow does\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003eTriggers on GitHub pull request events\u003c\/strong\u003e for your selected repository.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eExtracts PR metadata\u003c\/strong\u003e (repo, branch, author, title, PR number) and fetches full PR details from GitHub for review context.\u003c\/li\u003e\n  \u003cli\u003eRuns an \u003cstrong\u003eOpenAI agent with session memory\u003c\/strong\u003e to produce a structured JSON review. When required, it can call HTTP tools to:\n    \u003cul\u003e\n      \u003cli\u003eRun a \u003cstrong\u003eTerraform plan\u003c\/strong\u003e\n\u003c\/li\u003e\n      \u003cli\u003eExecute a \u003cstrong\u003eTerraform security scan\u003c\/strong\u003e\n\u003c\/li\u003e\n      \u003cli\u003e\u003cstrong\u003eEstimate cost impact\u003c\/strong\u003e\u003c\/li\u003e\n      \u003cli\u003eQuery a \u003cstrong\u003evector store of internal IaC standards\u003c\/strong\u003e\n\u003c\/li\u003e\n    \u003c\/ul\u003e\n  \u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eParses the agent’s JSON output\u003c\/strong\u003e into findings, overall risk, verdict, blocking issues, and a cost impact summary.\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eLogs the review\u003c\/strong\u003e into a Postgres table named \u003ccode\u003eterraform_pr_reviews\u003c\/code\u003e and posts a \u003cstrong\u003eformatted comment\u003c\/strong\u003e back to the GitHub PR.\u003c\/li\u003e\n  \u003cli\u003eIf the verdict is \u003cstrong\u003epass\u003c\/strong\u003e, the workflow \u003cstrong\u003esubmits a GitHub PR approval\u003c\/strong\u003e. Otherwise, it \u003cstrong\u003esends findings to Slack\u003c\/strong\u003e, waits for a human security decision, and then either approves or requests changes in GitHub.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eUse cases\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003eEnforce Terraform security and standards on every GitHub PR before merge.\u003c\/li\u003e\n  \u003cli\u003eGive security engineers a Slack hand-off for risky changes requiring approval.\u003c\/li\u003e\n  \u003cli\u003eMaintain an audit trail of Terraform PR reviews via Postgres for reporting and compliance.\u003c\/li\u003e\n  \u003cli\u003ePrevent unexpected spend by surfacing cost impact directly in PR comments.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eTechnical details\u003c\/h3\u003e\n\u003cul\u003e\n  \u003cli\u003e\n\u003cstrong\u003en8n nodes:\u003c\/strong\u003e if, set, wait, Slack, GitHub, Postgres\u003c\/li\u003e\n  \u003cli\u003e\n\u003cstrong\u003eIntegrations:\u003c\/strong\u003e GitHub (read PRs, post comments, approve\/request changes), Slack (human decision routing), Postgres (store review records), OpenAI (tool-calling review agent)\u003c\/li\u003e\n\u003c\/ul\u003e","brand":"N8N Commerce","offers":[{"title":"Default Title","offer_id":45950010228915,"sku":"N8N-19175","price":22.99,"currency_code":"GBP","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0749\/6279\/6723\/files\/7NEghGtkfQ6dlxNgzyte9_d2zgxi8Y.png?v=1788512858","url":"https:\/\/buyflowscripts.com\/products\/terraform-pr-security-gate-github-gpt-4-1-slack","provider":"N8N Commerce","version":"1.0","type":"link"}