All skills
acedergren avatar

/infrastructure-as-code

@d0e87b8

Use when the user asks to "Terraform state on OCI", "native OCI backend", "Terraform import OCI", "Terraform apply 403", "Terraform ZPR", or "Terraform Bastion".

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/infrastructure-as-code

This session only. Nothing lands on disk.

referencesoci-terraform-import-drift.md

≈645 tokens on demand. Your agent reads this file only when SKILL.md points to it.

OCI Terraform Import, Drift, and Adoption

Use this reference when adopting existing OCI resources, repairing state, or diagnosing provider drift.

Official Sources

Adoption Flow

  1. Pin Terraform and oracle/oci provider versions before import.
  2. Back up current state or confirm remote state versioning.
  3. Write the intended HCL first, matching the real resource shape.
  4. Get the official import ID format from the exact provider resource documentation.
  5. Import one resource at a time.
  6. Run terraform plan after each import and reconcile computed/default fields.
  7. Use moved blocks for address changes after adoption.
  8. Use ignore_changes only for explicitly console-owned fields, commonly tags, and document the owner.

OCI-Specific Drift Patterns

  • Eventual consistency can make freshly created IAM, networking, and database resources appear missing. Prefer provider timeouts/retries and staged applies over blind retries.
  • Some resource IDs are simple OCIDs; others are composite IDs. Always check the provider resource page.
  • Identity resources often live at tenancy/root scope even when the workload lives in a compartment.
  • Tags, defined tags, default security lists, route rules, and generated names often create noisy drift.
  • Provider upgrades can change computed fields; read changelogs before relaxing lifecycle rules.

Resource Manager Adoption

Use Resource Manager import-state jobs when moving a local Terraform environment into Resource Manager. Do not copy .terraform/, local state files, or local backend credentials into a Resource Manager stack zip.

Pressure Scenarios

  • "Import this existing VCN": get the provider import ID, write matching HCL, import, then plan.
  • "Terraform wants to replace a subnet": check immutable fields, route/security-list associations, provider version drift, and moved blocks before accepting replacement.
  • "Provider schema validation fails locally on darwin_arm64": treat known OCI provider plugin startup failures as environment blockers until confirmed, not as HCL proof.

Source: SKILL.md on GitHub

No alerts5mo4 checks · Risk SAFE
  • Gen Agent Trust Hub6mo

    The skill provides technical guidance and HCL code snippets for managing Oracle Cloud Infrastructure (OCI) using Terraform. It covers best practices for resource lifecycle management, authentication methods, and state file recovery while referencing official OCI modules.

  • Socket6mo

    No alerts

  • Snyk6mo

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d0e87b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 4 months ago
version
2.0.0
aliases
[
  "oci-terraform",
  "oci-iac",
  "terraform-oci"
]
domains
[
  "oci",
  "iac"
]
Other metadata
keywords
[
  "OCI",
  "Oracle Cloud",
  "Terraform",
  "terraform-provider-oci",
  "native OCI backend",
  "Terraform state",
  "Resource Manager",
  "Terraform import",
  "moved block",
  "provider pinning",
  "government cloud Terraform",
  "OCI Terraform auth",
  "OCI module quality",
  "Terraform ZPR",
  "Terraform Bastion"
]

README badge

README badge for acedergren/agentic-tools/infrastructure-as-code