All skills
acedergren avatar

/infrastructure-as-code

@d0e87b8

Use when the user asks to "Terraform state on OCI", "native OCI backend", "Terraform import OCI", "Terraform apply 403", "Terraform ZPR", or "Terraform Bastion".

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/infrastructure-as-code

This session only. Nothing lands on disk.

referencesoci-terraform-state-backends.md

≈762 tokens on demand. Your agent reads this file only when SKILL.md points to it.

OCI Terraform State Backends

Use this reference when deciding where Terraform state lives for OCI work.

Official Sources

Decision Tree

Situation Backend choice
Terraform v1.12+ and OCI Object Storage allowed Prefer native backend "oci"
OCI Resource Manager stack Let Resource Manager manage stack state
Terraform older than v1.12 or incompatible runtime S3-compatible Object Storage fallback, explicitly marked legacy
One-person disposable experiment Local state is acceptable only if no team or production resources are managed
HCP Terraform/Terraform Enterprise is the chosen control plane Use that product's remote state model, not OCI Object Storage by default

Native OCI Backend Baseline

terraform {
  backend "oci" {
    bucket    = "terraform-state"
    namespace = "object-storage-namespace"
    key       = "prod/network/terraform.tfstate"
    region    = "us-ashburn-1"
  }
}

Add optional workspace_key_prefix for workspace separation and kms_key_id when a specific OCI KMS key is required. Prefer partial backend configuration and environment/config-file credentials rather than embedding secrets in HCL.

Safety Rules

  • Enable Object Storage bucket versioning for state recovery.
  • Grant the state principal only the bucket/object operations needed for state and lock objects.
  • Treat state, lock files, plan files, and .terraform/ as sensitive.
  • Do not pass plaintext credentials through -backend-config; Terraform can persist backend configuration under .terraform/ and in saved plans.
  • Do not use customer secret keys for new Terraform v1.12+ state unless a legacy fallback is explicitly required and documented.
  • Separate state by environment and blast radius: tenancy/bootstrap, networking, security, workloads, and databases should not all share one state file.

Legacy S3-Compatible Fallback

Use only when the runtime cannot use native backend "oci". Document:

  1. Terraform/OpenTofu version and why native OCI backend is unavailable.
  2. Customer secret key owner and rotation procedure.
  3. Bucket versioning, encryption, and lifecycle policy.
  4. Locking limitations and concurrent apply control.
  5. Migration path back to native backend "oci".

Pressure Scenario

User asks: "Set up Terraform state in OCI Object Storage for Terraform 1.12."

Passing answer: choose native backend "oci", enable bucket versioning, avoid hardcoded credentials, and mention S3-compatible Object Storage only as a legacy fallback.

Source: SKILL.md on GitHub

No alerts5mo4 checks · Risk SAFE
  • Gen Agent Trust Hub6mo

    The skill provides technical guidance and HCL code snippets for managing Oracle Cloud Infrastructure (OCI) using Terraform. It covers best practices for resource lifecycle management, authentication methods, and state file recovery while referencing official OCI modules.

  • Socket6mo

    No alerts

  • Snyk6mo

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d0e87b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 4 months ago
version
2.0.0
aliases
[
  "oci-terraform",
  "oci-iac",
  "terraform-oci"
]
domains
[
  "oci",
  "iac"
]
Other metadata
keywords
[
  "OCI",
  "Oracle Cloud",
  "Terraform",
  "terraform-provider-oci",
  "native OCI backend",
  "Terraform state",
  "Resource Manager",
  "Terraform import",
  "moved block",
  "provider pinning",
  "government cloud Terraform",
  "OCI Terraform auth",
  "OCI module quality",
  "Terraform ZPR",
  "Terraform Bastion"
]

README badge

README badge for acedergren/agentic-tools/infrastructure-as-code