All skills
hashicorp avatar

/terraform-policy

@516354c official
by hashicorphashicorp/agent-skills880 stars
130

Write, test, or convert Terraform Policy files (.policy.hcl, .policytest.hcl, Sentinel→tfpolicy). Triggers: policy.hcl, policytest, convert sentinel, tfpolicy, write a policy.

Use this Skill: https://skilld.dev/gh/hashicorp/agent-skills/terraform-policy

This session only. Nothing lands on disk.

examplesREADME.md

≈648 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Sentinel to tfpolicy Conversion Examples

This folder packages representative Sentinel-to-tfpolicy conversion examples for sharing with teammates.

Each example subfolder contains:

  • <sentinel-policy-name>.sentinel - the actual Sentinel policy file included for comparison
  • <sentinel-policy-name>.policy.hcl - the tfpolicy version or best approximation
  • README.md - explanation of the conversion quality, what changed, and any limitations

Converted tfpolicy examples in this bundle prefer remediation-focused diagnostics over repeating Terraform addresses from Sentinel summary {} output. Terraform Policy diagnostics already identify the failing object and point to the relevant location, so converted examples avoid ${meta.address} in error messages.

Included examples:

  • dms-endpoints-should-use-ssl - direct attribute conversion (Perfect)
  • elasticsearch-https-required - nested block conversion (Good)
  • eventbridge-custom-event-bus-should-have-attached-policy - cross-resource conversion via core::getresources() (Limited)
  • cloudfront-associated-with-waf - approximation only due to missing reference metadata (Not convertible as an exact translation)
  • efs-access-point-should-enforce-user-identity - direct presence check (Perfect)
  • elasticsearch-encrypted-at-rest - nested encryption block check (Good)
  • dms-endpoint-should-be-ssl-configured - config-derived certificate check (Good)
  • ec2-network-acl-should-have-subnet-ids - association-aware approximation (Limited)
  • secretsmanager-auto-rotation-enabled-check - secret-to-rotation relationship via core::getresources() (Good)
  • s3-bucket-should-have-object-lock-enabled - object lock association approximation (Limited)
  • ec2-vpc-default-security-group-no-traffic - inline-only approximation of a broader graph check (Not convertible as an exact translation)
  • elasticsearch-in-vpc-only - config-to-end-state VPC placement approximation (Limited)
  • cloudtrail-server-side-encryption-enabled - config-to-end-state encryption check (Good)
  • step-functions-state-machine-logging-enabled - nested logging block conversion (Good)
  • elasticache-redis-replication-group-encryption-at-transit-enabled - direct boolean check (Perfect)
  • s3-block-public-access-bucket-level - variable and association heavy approximation (Not convertible as an exact translation)

Note: The Sentinel policy files in this bundle come from the locally cloned policy library so reviewers can inspect the original Sentinel and converted tfpolicy side by side in one place.

Source: SKILL.md on GitHub

No alerts3d3 checks · Risk SAFE
  • Gen Agent Trust Hub3d

    This skill is safe and provides a comprehensive framework for authoring, testing, and converting Terraform Policies. It includes detailed security best practices, such as safe attribute handling and proper IAM policy enforcement, to help users create robust policies.

  • Socket3d

    No alerts

  • Snyk3d

    Risk: LOW · No issues

Signed by skilld at 516354c. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated last week
Other metadata
metadata
{
  "lifecycle-status": "active",
  "copyright": "Copyright IBM Corp. 2026",
  "version": "0.1.0"
}

README badge

README badge for hashicorp/agent-skills/terraform-policy