Skip to content
Back to skills

Terraform

ASecurity

Provision infrastructure as code with Terraform: resources, modules, state, workspaces, and remote backends. Use for cloud resource management.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 1, 2026
ai-agentsgobashawsgcpazureterraformbackenddevops

Works with

  • cli

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned October 1, 2026

npx -y skills add ssrjkk/agent-skills --skill terraform --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Terraform?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Terraform
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/ssrjkk-terraform-agent-skills/badge)](https://www.skillsdirectory.com/skills/ssrjkk-terraform-agent-skills)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: terraform
description: "Provision infrastructure as code with Terraform: resources, modules, state, workspaces, and remote backends. Use for cloud resource management."
category: devops
tags: [terraform, iac, infrastructure, cloud, modules, state, aws]
models: [sonnet, opus, gpt-6, gemini-3, glm-5]
version: 1.0.0
created: 2026-09-26
updated: 2026-09-28
author: ssrjkk
---
# Terraform

> Provisioning cloud infrastructure as code with Terraform.

## Quick Start
```bash
terraform init
terraform plan
terraform apply
terraform destroy  # when done
```

## When to Use
- Reproducible cloud infrastructure
- Managing AWS/GCP/Azure resources as code
- Environments that must be identical
- Team-wide infrastructure changes with review

## Best Practices

### Configuration
- Organize by environment and component
- Use variables for config; locals for derived values
- Define outputs for inter-module references
- Pin provider and module versions

### Modules
- Extract reusable units into modules
- Keep modules small and focused
- Validate inputs with variables
- Document inputs/outputs

### State
- Use a remote backend (S3/OSS/Terraform Cloud)
- Enable state locking to prevent conflicts
- Never edit state by hand; use `terraform state`
- Protect state with permissions and versioning

### Workflow
- Plan before apply; review the diff
- Use workspaces or separate dirs per environment
- Run in CI with approval for production
- Clean up unused resources with destroy

## Dependencies
```bash
# Terraform CLI
terraform version
# providers configured in code
```

## Examples
```hcl
# Provider + resource
terraform {
  required_version = ">= 1.5"
  backend "s3" {
    bucket = "my-tf-state"
    key    = "prod/terraform.tfstate"
    region = "us-east-1"
  }
}

provider "aws" {
  region = var.region
}

resource "aws_s3_bucket" "app" {
  bucket = "my-app-bucket"
  tags   = { Environment = var.environment }
}
```
```hcl
# Variable + output
variable "region" {
  type    = string
  default = "us-east-1"
}

variable "environment" {
  type        = string
  description = "Deployment environment"
}

output "bucket_id" {
  value = aws_s3_bucket.app.id
}
```
```hcl
# Simple module usage
module "vpc" {
  source = "./modules/vpc"
  cidr   = "10.0.0.0/16"
  name   = var.environment
}
```
```bash
# Standard workflow
terraform init
terraform fmt
terraform validate
terraform plan -out=plan.tfplan
terraform apply plan.tfplan
```

## Step-by-Step
1. Initialize the project and configure the provider.
2. Set up a remote backend with locking.
3. Write resources for the core infrastructure.
4. Extract repeated logic into modules.
5. Parameterize with variables; define outputs.
6. Run `fmt`, `validate`, and `plan` before apply.
7. Apply in CI with approval for prod environments.
8. Keep state secure and reviewed.

## Validation
1. `terraform validate` passes
2. `terraform plan` shows the intended changes only
3. State is consistent with real resources (`refresh`)
4. Destroy removes all created resources
5. Plan diff is reviewed before apply

## Troubleshooting
- State lock: release stale locks via the backend or force-unlock.
- Drift: run `terraform plan` to detect and reconcile.
- "Provider not found": run `terraform init` to fetch providers.

Files in this skill

  • SKILL.md3.2 KB
  • SKILL.ru.md4.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…