All skills
acedergren avatar

/infrastructure-as-code

@d0e87b8

Use when the user asks to "Terraform state on OCI", "native OCI backend", "Terraform import OCI", "Terraform apply 403", "Terraform ZPR", or "Terraform Bastion".

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/infrastructure-as-code

This session only. Nothing lands on disk.

referencesoci-terraform-zpr.md

≈641 tokens on demand. Your agent reads this file only when SKILL.md points to it.

OCI Terraform ZPR Automation

Use this reference when Terraform manages Zero Trust Packet Routing (ZPR) enablement, security attributes, ZPR policy, or protected-resource rollout.

Official Sources

Behavioral Rules

  • Check current provider support before writing ZPR resources; ZPR support is newer than many examples and modules.
  • Sequence policy before attributes. Applying attributes before allow policy can block production flows.
  • Treat resource import/adoption as a first-class step for existing namespaces, policies, VCNs, VNICs, databases, and private endpoints.
  • Review the plan for large attribute fan-out. A single attribute change can affect multiple flows.
  • Keep rollback simple: remove the attribute or correct the ZPL policy before broad network rewrites.
  • Do not assume ZPR replaces route tables, NSGs, or security lists.

Lockout-Safe Apply Sequence

  1. Pin Terraform and OCI provider versions.
  2. Import or data-source existing namespaces, attributes, policies, and target resources.
  3. Add ZPL policy that permits known-good source-to-target flows.
  4. Plan and peer-review the policy diff.
  5. Apply policy only.
  6. Apply attributes to a non-production or canary resource.
  7. Validate connectivity and observability.
  8. Expand attributes in small batches.

Plan Review Checklist

  • Does the provider version support every ZPR resource or attribute field used?
  • Does the plan create policy before assigning attributes?
  • Does the plan touch production resources, VNICs, databases, private endpoints, or VCN attributes?
  • Are route tables, NSGs, security lists, and DNS unchanged unless intentionally reviewed?
  • Are imports and moved blocks used instead of delete/recreate for brownfield ZPR?
  • Is there a rollback command or targeted revert path?

Pressure Scenario

"Terraform should add ZPR attributes to production resources."

Passing answer: stop and require policy-first sequencing, provider support check, import/adoption review, canary rollout, and rollback before applying attributes broadly.

Source: SKILL.md on GitHub

No alerts5mo4 checks · Risk SAFE
  • Gen Agent Trust Hub6mo

    The skill provides technical guidance and HCL code snippets for managing Oracle Cloud Infrastructure (OCI) using Terraform. It covers best practices for resource lifecycle management, authentication methods, and state file recovery while referencing official OCI modules.

  • Socket6mo

    No alerts

  • Snyk6mo

    Risk: LOW · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d0e87b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 hours ago.

Activeupdated 4 months ago
version
2.0.0
aliases
[
  "oci-terraform",
  "oci-iac",
  "terraform-oci"
]
domains
[
  "oci",
  "iac"
]
Other metadata
keywords
[
  "OCI",
  "Oracle Cloud",
  "Terraform",
  "terraform-provider-oci",
  "native OCI backend",
  "Terraform state",
  "Resource Manager",
  "Terraform import",
  "moved block",
  "provider pinning",
  "government cloud Terraform",
  "OCI Terraform auth",
  "OCI module quality",
  "Terraform ZPR",
  "Terraform Bastion"
]

README badge

README badge for acedergren/agentic-tools/infrastructure-as-code