All skills
acedergren avatar

/infrastructure-as-code

@d0e87b8

Use when the user asks to "Terraform state on OCI", "native OCI backend", "Terraform import OCI", "Terraform apply 403", "Terraform ZPR", or "Terraform Bastion".

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/infrastructure-as-code

This session only. Nothing lands on disk.

referencesoci-terraform-module-quality.md

≈692 tokens on demand. Your agent reads this file only when SKILL.md points to it.

OCI Terraform Module Quality Checklist

Use this reference before recommending official or community Terraform modules for OCI.

Official Sources

Checklist

Review every module, including Oracle-branded modules, against these criteria:

Check Passing signal
Release freshness Recent release or commit compatible with current OCI provider behavior
Provider constraints Explicit oracle/oci provider source and version range that fits the target Terraform version
Terraform version Compatible with the target CLI and Resource Manager supported versions
Examples Examples cover the target use case, not only a toy happy path
Issues and PRs Open issues do not show unresolved provider drift or broken resources
Supported resources Module supports required OCI features, regions, realms, and new service options
State shape Outputs are stable, sensitive outputs are minimized, and module addresses are acceptable
Brownfield adoption Module can import/adopt existing resources without replacement surprises
Security Least-privilege IAM, no broad admin defaults, no secret content outputs
Upgrade path Changelog explains breaking changes and migration steps

When to Avoid a Module

  • The module pins an old provider or references deprecated provider source addresses.
  • The module hides resource addresses that need precise import or moved-block control.
  • The module creates broad IAM, networking, or tagging defaults that conflict with tenant governance.
  • The module has no clear support for the target realm, region, identity-domain model, or Resource Manager runtime.
  • The module adds more abstraction than the workload needs.

Recommendation Pattern

When recommending a module, include:

  1. Module name and exact version/ref.
  2. Provider and Terraform version constraints.
  3. Last release or commit date checked.
  4. Known gaps and resources still written directly.
  5. Import and state migration impact.
  6. A minimal plan-review gate before apply.

Pressure Scenario

User asks: "Can we use the official OCI landing zone module?"

Passing answer: do not answer yes because it is official. Check release recency, provider constraints, brownfield risk, examples, issue activity, generated plan, and whether oci/landing-zones should own the architecture decision.

Source: SKILL.md on GitHub

No alerts5mo4 checks · Risk SAFE
  • Gen Agent Trust Hub6mo

    The skill provides technical guidance and HCL code snippets for managing Oracle Cloud Infrastructure (OCI) using Terraform. It covers best practices for resource lifecycle management, authentication methods, and state file recovery while referencing official OCI modules.

  • Socket6mo

    No alerts

  • Snyk6mo

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d0e87b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 hours ago.

Activeupdated 4 months ago
version
2.0.0
aliases
[
  "oci-terraform",
  "oci-iac",
  "terraform-oci"
]
domains
[
  "oci",
  "iac"
]
Other metadata
keywords
[
  "OCI",
  "Oracle Cloud",
  "Terraform",
  "terraform-provider-oci",
  "native OCI backend",
  "Terraform state",
  "Resource Manager",
  "Terraform import",
  "moved block",
  "provider pinning",
  "government cloud Terraform",
  "OCI Terraform auth",
  "OCI module quality",
  "Terraform ZPR",
  "Terraform Bastion"
]

README badge

README badge for acedergren/agentic-tools/infrastructure-as-code