All skills
hashicorp avatar

/terraform-stacks

@4451cec official
by hashicorphashicorp/agent-skills880 stars
130

Comprehensive guide for working with HashiCorp Terraform Stacks. Use when creating, modifying, or validating Terraform Stack configurations (.tfcomponent.hcl, .tfdeploy.hcl files), working with stack components and deployments from local modules, public registry, or private registry sources, managing multi-region or multi-environment infrastructure, or troubleshooting Terraform Stacks syntax and structure.

Use this Skill: https://skilld.dev/gh/hashicorp/agent-skills/terraform-stacks

This session only. Nothing lands on disk.

referenceslinked-stacks.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Linked Stacks Reference

Complete reference for linking Terraform Stacks together using published outputs and upstream inputs.

Publish Output Block

Exports outputs from a Stack for consumption by other Stacks (linked Stacks).

###Syntax

publish_output "<output_name>" {
  type  = <type>
  value = <expression>
}

Arguments

  • output_name (label, required): Unique identifier for this published output
  • type (required): Data type of the output
  • value (required): Expression to export

Accessing Deployment Outputs

Reference deployment outputs using: deployment.<deployment_name>.<output_name>

Important Notes

  • Must apply the Stack's deployment configuration before downstream Stacks can reference outputs
  • Published outputs create a snapshot that other Stacks can read
  • Changes to published outputs automatically trigger runs in downstream Stacks

Examples

Basic Published Output:

publish_output "vpc_id" {
  type  = string
  value = deployment.network.vpc_id
}

publish_output "subnet_ids" {
  type  = list(string)
  value = deployment.network.private_subnet_ids
}

Multiple Deployment Outputs:

publish_output "regional_vpc_ids" {
  type = map(string)
  value = {
    us_east = deployment.us_east.vpc_id
    us_west = deployment.us_west.vpc_id
    eu_west = deployment.eu_west.vpc_id
  }
}

Complex Output:

publish_output "database_config" {
  type = object({
    endpoint = string
    port     = number
    name     = string
  })
  value = {
    endpoint = deployment.production.db_endpoint
    port     = deployment.production.db_port
    name     = deployment.production.db_name
  }
}

Regional Endpoints:

publish_output "api_endpoints" {
  type = map(object({
    url    = string
    region = string
  }))
  value = {
    for env in ["dev", "staging", "prod"] : env => {
      url    = deployment[env].api_url
      region = deployment[env].region
    }
  }
}

Upstream Input Block

References published outputs from another Stack (linked Stacks).

Syntax

upstream_input "<input_name>" {
  type   = "stack"
  source = "<stack_address>"
}

Arguments

  • input_name (label, required): Local name for this upstream input
  • type (required): Must be "stack"
  • source (required): Full Stack address in format: app.terraform.io/<org>/<project>/<stack-name>

Accessing Upstream Outputs

Reference upstream outputs using: upstream_input.<input_name>.<output_name>

Important Notes

  • Creates a dependency on the upstream Stack
  • Upstream Stack must have applied its deployment configuration
  • Changes in upstream Stack automatically trigger downstream Stack runs
  • Only works with Stacks in the same HCP Terraform project

Examples

Basic Upstream Reference:

upstream_input "network" {
  type   = "stack"
  source = "app.terraform.io/my-org/my-project/networking-stack"
}

deployment "application" {
  inputs = {
    vpc_id     = upstream_input.network.vpc_id
    subnet_ids = upstream_input.network.subnet_ids
  }
}

Multiple Upstream Stacks:

upstream_input "network" {
  type   = "stack"
  source = "app.terraform.io/my-org/my-project/network-stack"
}

upstream_input "database" {
  type   = "stack"
  source = "app.terraform.io/my-org/my-project/database-stack"
}

deployment "application" {
  inputs = {
    vpc_id              = upstream_input.network.vpc_id
    subnet_ids          = upstream_input.network.private_subnet_ids
    database_endpoint   = upstream_input.database.endpoint
    database_credentials = upstream_input.database.credentials
  }
}

Regional Upstream Dependencies:

upstream_input "regional_network" {
  type   = "stack"
  source = "app.terraform.io/my-org/my-project/regional-networks"
}

deployment "us_east_app" {
  inputs = {
    region     = "us-east-1"
    vpc_id     = upstream_input.regional_network.regional_vpc_ids["us_east"]
    subnet_ids = upstream_input.regional_network.regional_subnet_ids["us_east"]
  }
}

Complete Working Example

For a complete example showing full Stack configurations with all files (variables, providers, components, outputs, deployments) for both upstream and downstream Stacks, see the "Linked Stacks (Cross-Stack Dependencies)" section in examples.md.

Source: SKILL.md on GitHub

1 warning17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill serves as a technical reference guide and documentation suite for managing infrastructure deployments using stack configurations. It provides structural examples, CLI usage guidelines, and API monitoring practices that follow industry-standard workflows. No security concerns were identified.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    5/7 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 4451cec. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 days ago.

Activeupdated 2 months ago
Other metadata
metadata
{
  "lifecycle-status": "active",
  "copyright": "Copyright IBM Corp. 2026",
  "version": "0.0.1"
}
  • terraform
  • hcl
  • infrastructure-as-code
  • stacks
  • multi-environment
  • deployment
  • hcp-terraform
  • orchestration
  • components
  • oidc

README badge

README badge for hashicorp/agent-skills/terraform-stacks

Provides configuration and deployment patterns for Terraform Stacks, HashiCorp's declarative infrastructure orchestration layer. Covers component definitions, provider configuration with OIDC workload identity, deployment instances across environments, and HCP Terraform integration including variable sets and linked Stacks. Requires Terraform v1.13 or later.

Generated from the current SKILL.md.

What Terraform version is required?
Terraform v1.13.x or later is required to use Terraform Stacks and the CLI plugin. Specify the exact version in a .terraform-version file at the root of your Stack repository.
What file extensions do Stacks use?
Component configuration uses .tfcomponent.hcl and deployment configuration uses .tfdeploy.hcl. Both must be at the root level of the Stack repository.
How do I reference module sources?
Components can reference modules from local paths (./modules/vpc), the public registry (terraform-aws-modules/vpc/aws), private registry (app.terraform.io/org-name/vpc/aws), or Git sources (git::https://...). A modules/ directory is only required when using local module sources.
What authentication method does this skill recommend?
Use workload identity (OIDC) with identity_token blocks and assume_role_with_web_identity in provider configuration. This avoids long-lived static credentials and provides temporary, scoped credentials per deployment run.
How do I destroy a deployment?
Set destroy = true in the deployment block, upload the configuration, approve the destroy run, then remove the deployment block entirely.

Generated from the current SKILL.md. These answers refresh after source changes.