All skills
acedergren avatar

/infrastructure-as-code

@d0e87b8

Use when the user asks to "Terraform state on OCI", "native OCI backend", "Terraform import OCI", "Terraform apply 403", "Terraform ZPR", or "Terraform Bastion".

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/infrastructure-as-code

This session only. Nothing lands on disk.

referencesoci-terraform-secrets-state.md

≈798 tokens on demand. Your agent reads this file only when SKILL.md points to it.

OCI Terraform Secrets and State Safety

Use this reference when Terraform interacts with OCI Vault, passwords, wallets, private keys, generated secrets, stack variables, or sensitive outputs.

Official Sources

Core Rule

Terraform state and plan files can contain sensitive values. sensitive = true hides values in CLI/UI output but still stores values in state unless Terraform ephemeral/write-only behavior is supported in that exact context.

High-Risk Values

Avoid putting these in Terraform state:

  • Database admin passwords and generated passwords.
  • ADB wallets, wallet passwords, and connection strings with credentials.
  • Private keys, SSH keys, API signing keys, and customer secret keys.
  • Secret contents read from OCI Vault or supplied as variables.
  • User data or cloud-init that embeds credentials.
  • Sensitive root-module outputs consumed by terraform_remote_state.

Safer Patterns

  • Store and rotate secret material in OCI Vault; Terraform should usually manage vault/key/secret metadata and pass secret OCIDs, not secret contents.
  • Let applications retrieve secrets at runtime through instance principals, resource principals, or workload identity.
  • Use generated secret/password features outside Terraform state when supported by OCI service workflows.
  • Use sensitive = true to reduce accidental display, but still protect backend state as secret material.
  • Use Terraform ephemeral variables or write-only arguments only after verifying Terraform version and OCI provider/resource support.
  • For Resource Manager, do not put user credentials or confidential values in Terraform configuration files. Treat stack variables, job logs, config zips, plans, and state as sensitive review surfaces.

State Review Checklist

Before approving Terraform that touches secrets:

  1. Run terraform plan and inspect which attributes are written.
  2. Search for random_password, tls_private_key, oci_vault_secret, wallet files, private_key, password, and sensitive outputs.
  3. Check whether any data source reads actual secret content.
  4. Confirm state backend access is least-privilege and versioned.
  5. Confirm outputs do not expose values to terraform_remote_state consumers.
  6. Document any unavoidable state exposure and the rotation/remediation plan.

Pressure Scenario

User asks: "Use Vault for the DB password in Terraform."

Passing answer: explain that Vault alone does not prevent Terraform state capture, prefer runtime retrieval or secret OCID references, and only use Terraform-managed secret content if state exposure is explicitly accepted and protected.

Source: SKILL.md on GitHub

No alerts5mo4 checks · Risk SAFE
  • Gen Agent Trust Hub6mo

    The skill provides technical guidance and HCL code snippets for managing Oracle Cloud Infrastructure (OCI) using Terraform. It covers best practices for resource lifecycle management, authentication methods, and state file recovery while referencing official OCI modules.

  • Socket6mo

    No alerts

  • Snyk6mo

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d0e87b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 hours ago.

Activeupdated 4 months ago
version
2.0.0
aliases
[
  "oci-terraform",
  "oci-iac",
  "terraform-oci"
]
domains
[
  "oci",
  "iac"
]
Other metadata
keywords
[
  "OCI",
  "Oracle Cloud",
  "Terraform",
  "terraform-provider-oci",
  "native OCI backend",
  "Terraform state",
  "Resource Manager",
  "Terraform import",
  "moved block",
  "provider pinning",
  "government cloud Terraform",
  "OCI Terraform auth",
  "OCI module quality",
  "Terraform ZPR",
  "Terraform Bastion"
]

README badge

README badge for acedergren/agentic-tools/infrastructure-as-code