All skills
acedergren avatar

/infrastructure-as-code

@d0e87b8

Use when the user asks to "Terraform state on OCI", "native OCI backend", "Terraform import OCI", "Terraform apply 403", "Terraform ZPR", or "Terraform Bastion".

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/infrastructure-as-code

This session only. Nothing lands on disk.

referencesoci-terraform-bastion.md

≈640 tokens on demand. Your agent reads this file only when SKILL.md points to it.

OCI Terraform Bastion Automation

Use this reference when Terraform manages OCI Bastion resources, sessions, allowlists, IAM, or private-access guardrails.

Official Sources

Behavioral Rules

  • Prefer OCI Bastion or private connectivity over public SSH for private instance access.
  • Treat client CIDR allowlists as sensitive operational controls. Avoid permanent 0.0.0.0/0.
  • Do not store private keys in Terraform state. Use external key generation and controlled distribution.
  • Use Managed SSH only when the target supports Oracle Cloud Agent and Bastion plugin requirements.
  • Use port forwarding for unsupported targets, database listeners, RDP, ADB private endpoints, or Managed SSH plugin gaps.
  • Treat sessions as ephemeral access objects; clean them up unless the operating model explicitly keeps them.

Terraform Review Checklist

  • Does the plan create or widen a client CIDR allowlist?
  • Does the plan create public IPs or public SSH rules as a shortcut?
  • Are session TTLs within Oracle's current 30-to-180-minute bounds?
  • Are target-side NSGs/security lists scoped to the bastion path and target port?
  • Are IAM policies scoped to bastion/session operations and target resource needs?
  • Are SSH public keys inputs and private keys kept out of state?
  • Does the target image/shape require port forwarding instead of Managed SSH?

Allowlist Safety

For Terraform-managed allowlists, do not make ad hoc Console changes without reconciling state. For emergency access, prefer a short-lived, reviewed variable change with cleanup, or use CLI/Console with an explicit post-incident import/state reconciliation step.

Pressure Scenario

"Terraform should create a Bastion for private instance access."

Passing answer: create OCI Bastion with narrow allowlists, target-side network rules, scoped IAM, no public SSH fallback, no private keys in state, and explicit session cleanup behavior.

Source: SKILL.md on GitHub

No alerts5mo4 checks · Risk SAFE
  • Gen Agent Trust Hub6mo

    The skill provides technical guidance and HCL code snippets for managing Oracle Cloud Infrastructure (OCI) using Terraform. It covers best practices for resource lifecycle management, authentication methods, and state file recovery while referencing official OCI modules.

  • Socket6mo

    No alerts

  • Snyk6mo

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d0e87b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 34 minutes ago.

Activeupdated 4 months ago
version
2.0.0
aliases
[
  "oci-terraform",
  "oci-iac",
  "terraform-oci"
]
domains
[
  "oci",
  "iac"
]
Other metadata
keywords
[
  "OCI",
  "Oracle Cloud",
  "Terraform",
  "terraform-provider-oci",
  "native OCI backend",
  "Terraform state",
  "Resource Manager",
  "Terraform import",
  "moved block",
  "provider pinning",
  "government cloud Terraform",
  "OCI Terraform auth",
  "OCI module quality",
  "Terraform ZPR",
  "Terraform Bastion"
]

README badge

README badge for acedergren/agentic-tools/infrastructure-as-code