All skills
acedergren avatar

/infrastructure-as-code

@d0e87b8

Use when the user asks to "Terraform state on OCI", "native OCI backend", "Terraform import OCI", "Terraform apply 403", "Terraform ZPR", or "Terraform Bastion".

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/infrastructure-as-code

This session only. Nothing lands on disk.

referencesoci-terraform-auth-matrix.md

≈944 tokens on demand. Your agent reads this file only when SKILL.md points to it.

OCI Terraform Auth Matrix

Use this reference when Terraform auth is the real problem, especially for 401, 403, NotAuthorizedOrNotFound, or environment-specific failures.

Official Sources

Context Matrix

Execution context Prefer Avoid
Local laptop API key config profile for durable work; SecurityToken profile for short interactive work Committing private keys, OCIDs, or credentials in provider blocks
Cloud Shell Use current Oracle Cloud Shell/provider guidance and short-lived profile behavior Assuming a laptop ~/.oci/config exists unchanged
GitHub Actions or external CI Organization-approved OIDC/federation if configured; otherwise scoped API key secret Long-lived administrator API keys or unscoped tenancy policies
OCI DevOps build pipeline Resource principal/dynamic group policies for the pipeline resource User credentials copied into build specs
OCI Compute instance auth = "InstancePrincipal" plus dynamic group and IAM policy API key files on the instance
OCI Functions or supported service auth = "ResourcePrincipal" plus required resource principal env and policies Instance principal syntax
OKE workload auth = "OKEWorkloadIdentity" when the provider/resource supports it Node instance principal for app workload identity
OCI Resource Manager Provider block normally needs only region; Resource Manager supplies execution context Local API key provider blocks inside Resource Manager configs

Provider Auth Methods

OCI Terraform provider auth methods to check in current docs:

  • APIKey
  • InstancePrincipal
  • ResourcePrincipal
  • SecurityToken
  • OKEWorkloadIdentity

When parameters are set in multiple supported provider locations, Oracle documents precedence among environment variables, non-default OCI config profiles, and the DEFAULT profile. Also inspect explicit provider arguments in HCL because they can lock a configuration to the wrong user, tenancy, region, or auth method.

403 Triage

  1. Identify the caller: user, group, identity-domain group, dynamic group, CI principal, Resource Manager user/job, instance principal, resource principal, or OKE workload identity.
  2. Identify target resource family and compartment.
  3. Check policy location is at or above the target resource compartment.
  4. Check verb is high enough: inspect < read < use < manage.
  5. Check resource family is correct: virtual-network-family, instance-family, volume-family, object-family, orm-family, etc.
  6. Check condition clauses and dynamic-group matching rules.
  7. Allow for IAM propagation lag before rerunning.

Pressure Scenarios

  • "Terraform apply gets 403 creating a VCN": verify caller and manage virtual-network-family scope before changing HCL.
  • "Compute instance Terraform cannot list buckets": use instance principal dynamic-group membership and object-family policy.
  • "Resource Manager cannot create a stack from Git": check orm-config-source-providers, orm-stacks, and source provider permissions.
  • "IDCS group can log in but Terraform fails": map identity-domain/IDCS group membership to the OCI IAM policy subject and compartment scope.

Source: SKILL.md on GitHub

No alerts5mo4 checks · Risk SAFE
  • Gen Agent Trust Hub6mo

    The skill provides technical guidance and HCL code snippets for managing Oracle Cloud Infrastructure (OCI) using Terraform. It covers best practices for resource lifecycle management, authentication methods, and state file recovery while referencing official OCI modules.

  • Socket6mo

    No alerts

  • Snyk6mo

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d0e87b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 4 months ago
version
2.0.0
aliases
[
  "oci-terraform",
  "oci-iac",
  "terraform-oci"
]
domains
[
  "oci",
  "iac"
]
Other metadata
keywords
[
  "OCI",
  "Oracle Cloud",
  "Terraform",
  "terraform-provider-oci",
  "native OCI backend",
  "Terraform state",
  "Resource Manager",
  "Terraform import",
  "moved block",
  "provider pinning",
  "government cloud Terraform",
  "OCI Terraform auth",
  "OCI module quality",
  "Terraform ZPR",
  "Terraform Bastion"
]

README badge

README badge for acedergren/agentic-tools/infrastructure-as-code