All skills
jeffallan avatar

/terraform-engineer

@d0e7f4e
by jeffallanjeffallan/claude-skills12k stars
1,124

Use when implementing infrastructure as code with Terraform across AWS, Azure, or GCP. Invoke for module development (create reusable modules, manage module versioning), state management (migrate backends, import existing resources, resolve state conflicts), provider configuration, multi-environment workflows, and infrastructure testing.

Use this Skill: https://skilld.dev/gh/jeffallan/claude-skills/terraform-engineer

This session only. Nothing lands on disk.

SKILL.md

≈90 tokens always: the name and description. ≈1.2k when used: this file. ≈11k more on demand in 5 files.

Terraform Engineer

Senior Terraform engineer specializing in infrastructure as code across AWS, Azure, and GCP with expertise in modular design, state management, and production-grade patterns.

Core Workflow

  1. Analyze infrastructure — Review requirements, existing code, cloud platforms
  2. Design modules — Create composable, validated modules with clear interfaces
  3. Implement state — Configure remote backends with locking and encryption
  4. Secure infrastructure — Apply security policies, least privilege, encryption
  5. Validate — Run terraform fmt and terraform validate, then tflint; if any errors are reported, fix them and re-run until all checks pass cleanly before proceeding
  6. Plan and review — Run terraform plan -out=tfplan and extract a summarized plan highlighting creates, updates, deletes, and especially any destructive actions (recreations or deletions); if the plan fails, see error recovery below
  7. Approve and apply — Present the plan summary to the user and ask for explicit approval. Only execute terraform apply tfplan after receiving confirmation. Refuse to apply the plan if approval is withheld, or if destructive changes are present and the user has not explicitly accepted them

Error Recovery

Validation failures (step 5): Fix reported errors → re-run terraform validate → repeat until clean. For tflint warnings, address rule violations before proceeding.

Plan failures (step 6):

  • State drift — Run terraform refresh to reconcile state with real resources, or use terraform state rm / terraform import to realign specific resources, then re-plan.
  • Provider auth errors — Verify credentials, environment variables, and provider configuration blocks; re-run terraform init if provider plugins are stale, then re-plan.
  • Dependency / ordering errors — Add explicit depends_on references or restructure module outputs to resolve unknown values, then re-plan.

After any fix, return to step 5 to re-validate before re-running the plan.

Reference Guide

Load detailed guidance based on context:

Topic Reference Load When
Modules references/module-patterns.md Creating modules, inputs/outputs, versioning
State references/state-management.md Remote backends, locking, workspaces, migrations
Providers references/providers.md AWS/Azure/GCP configuration, authentication
Testing references/testing.md terraform plan, terratest, policy as code
Best Practices references/best-practices.md DRY patterns, naming, security, cost tracking

Constraints

MUST DO

  • Use semantic versioning and pin provider versions
  • Enable remote state with locking and encryption
  • Validate inputs with validation blocks
  • Use consistent naming conventions and tag all resources
  • Document module interfaces
  • Run terraform fmt and terraform validate

MUST NOT DO

  • Store secrets in plain text or hardcode environment-specific values
  • Use local state for production or skip state locking
  • Mix provider versions without constraints
  • Create circular module dependencies or skip input validation
  • Commit .terraform directories

Code Examples

Minimal Module Structure

main.tf

resource "aws_s3_bucket" "this" {
  bucket = var.bucket_name
  tags   = var.tags
}

variables.tf

variable "bucket_name" {
  description = "Name of the S3 bucket"
  type        = string

  validation {
    condition     = length(var.bucket_name) > 3
    error_message = "bucket_name must be longer than 3 characters."
  }
}

variable "tags" {
  description = "Tags to apply to all resources"
  type        = map(string)
  default     = {}
}

outputs.tf

output "bucket_id" {
  description = "ID of the created S3 bucket"
  value       = aws_s3_bucket.this.id
}

Remote Backend Configuration (S3 + DynamoDB)

terraform {
  backend "s3" {
    bucket         = "my-tf-state"
    key            = "env/prod/terraform.tfstate"
    region         = "us-east-1"
    encrypt        = true
    dynamodb_table = "terraform-lock"
  }
}

Provider Version Pinning

terraform {
  required_version = ">= 1.5.0"

  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 5.0"
    }
    azurerm = {
      source  = "hashicorp/azurerm"
      version = "~> 3.0"
    }
  }
}

Output Format

When implementing Terraform solutions, provide: module structure (main.tf, variables.tf, outputs.tf), backend and provider configuration, example usage with tfvars, and a brief explanation of design decisions.

Documentation

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk CRITICAL
  • Gen Agent Trust Hub16d

    This skill is flagged as highly risky due to multiple confirmed detections by automated security scanners. The main skill definition file is classified as malware by file reputation services, and an included documentation link is blacklisted as malicious. Additionally, the skill's workflow involving the execution of Terraform commands on user-supplied code introduces an indirect prompt injection surface.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    4/6 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at d0e7f4e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 2 months ago
Other metadata
metadata
{
  "author": "https://github.com/Jeffallan",
  "version": "1.1.0",
  "domain": "infrastructure",
  "triggers": "Terraform, infrastructure as code, IaC, terraform module, terraform state, AWS provider, Azure provider, GCP provider, terraform plan, terraform apply",
  "role": "specialist",
  "scope": "implementation",
  "output-format": "code",
  "related-skills": "cloud-architect, devops-engineer, kubernetes-specialist"
}
  • Infrastructure
  • terraform
  • aws
  • azure
  • gcp
  • iac
  • modules
  • state-management
  • providers

README badge

README badge for jeffallan/claude-skills/terraform-engineer

Writes Terraform modules and state configurations for AWS, Azure, and GCP infrastructure. Handles module design, remote backend setup with locking, provider version pinning, and validation workflows using terraform fmt, terraform validate, and tflint.

Generated from the current SKILL.md.

Does this skill support AWS, Azure, and GCP?
Yes. The skill covers provider configuration and patterns for all three cloud platforms, with examples for AWS S3 and references to provider-specific guidance.
What does this skill do if terraform plan fails?
The skill includes error recovery steps for state drift, provider auth errors, and dependency issues. It guides you through terraform refresh, terraform import, credential verification, and explicit depends_on fixes before re-planning.
Does this skill handle state management?
Yes. It covers remote backend setup with locking and encryption (S3 + DynamoDB example included), workspace management, state migrations, and resource import workflows.
Will this skill create modules for me?
Yes. The skill designs and implements reusable modules with input validation, clear outputs, semantic versioning, and documentation. It enforces module interface patterns and prevents circular dependencies.
Does this skill test Terraform code?
The skill runs terraform fmt and terraform validate before every plan, plus tflint for linting. It references detailed testing and policy-as-code guidance in bundled documentation.

Generated from the current SKILL.md. These answers refresh after source changes.