All skills

Use when the user asks to "find OCI skills", "route Oracle Cloud work", "install the OCI skill pack", "review OCI skill ownership", or "separate Oracle skills".

Use this Skill: https://skilld.dev/gh/acedergren/agentic-tools/oci

This session only. Nothing lands on disk.

infrastructure-as-codereferencesoci-terraform-state-backends.md

≈762 tokens on demand. Your agent reads this file only when SKILL.md points to it.

OCI Terraform State Backends

Use this reference when deciding where Terraform state lives for OCI work.

Official Sources

Decision Tree

Situation Backend choice
Terraform v1.12+ and OCI Object Storage allowed Prefer native backend "oci"
OCI Resource Manager stack Let Resource Manager manage stack state
Terraform older than v1.12 or incompatible runtime S3-compatible Object Storage fallback, explicitly marked legacy
One-person disposable experiment Local state is acceptable only if no team or production resources are managed
HCP Terraform/Terraform Enterprise is the chosen control plane Use that product's remote state model, not OCI Object Storage by default

Native OCI Backend Baseline

terraform {
  backend "oci" {
    bucket    = "terraform-state"
    namespace = "object-storage-namespace"
    key       = "prod/network/terraform.tfstate"
    region    = "us-ashburn-1"
  }
}

Add optional workspace_key_prefix for workspace separation and kms_key_id when a specific OCI KMS key is required. Prefer partial backend configuration and environment/config-file credentials rather than embedding secrets in HCL.

Safety Rules

  • Enable Object Storage bucket versioning for state recovery.
  • Grant the state principal only the bucket/object operations needed for state and lock objects.
  • Treat state, lock files, plan files, and .terraform/ as sensitive.
  • Do not pass plaintext credentials through -backend-config; Terraform can persist backend configuration under .terraform/ and in saved plans.
  • Do not use customer secret keys for new Terraform v1.12+ state unless a legacy fallback is explicitly required and documented.
  • Separate state by environment and blast radius: tenancy/bootstrap, networking, security, workloads, and databases should not all share one state file.

Legacy S3-Compatible Fallback

Use only when the runtime cannot use native backend "oci". Document:

  1. Terraform/OpenTofu version and why native OCI backend is unavailable.
  2. Customer secret key owner and rotation procedure.
  3. Bucket versioning, encryption, and lifecycle policy.
  4. Locking limitations and concurrent apply control.
  5. Migration path back to native backend "oci".

Pressure Scenario

User asks: "Set up Terraform state in OCI Object Storage for Terraform 1.12."

Passing answer: choose native backend "oci", enable bucket versioning, avoid hardcoded credentials, and mention S3-compatible Object Storage only as a legacy fallback.

Source: SKILL.md on GitHub

1 warning3mo3 checks · Risk MEDIUM
  • Gen Agent Trust Hub3mo

    An expert-level OCI utility pack that includes advanced scripts for presentation management and database administration. Security concerns include runtime compilation of C shims for system call interception and a powerful SQL script for tenancy-wide security remediation. The skill also ingests untrusted data from document archives and web headers, creating a surface for indirect prompt injection.

  • Socket3mo

    No alerts

  • Snyk3mo

    Risk: LOW · No issues

Signed by skilld at d0e87b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 4 months ago
version
1.0.0
aliases
[
  "oci-skills",
  "oracle-skills",
  "oci-skill-pack"
]
domains
[
  "oci",
  "oracle",
  "skill-pack"
]
Other metadata
keywords
[
  "OCI",
  "Oracle Cloud",
  "Oracle",
  "skill pack",
  "skill routing",
  "separation of duties",
  "ownership",
  "architecture",
  "operations",
  "manifest"
]

README badge

README badge for acedergren/agentic-tools/oci