Skip to content
Back to skills

075 Agents B8da2eb7

ASecurity

Agent instructions specific to the `infra/terraform/` subtree.

  • 9 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 11, 2026
devopsgobashsqlazureterraformbackendsecurity

Security analysis

A100/100

Scanned October 11, 2026

npx -y skills add tools-only/X-Skills --skill 075-agents_b8da2eb7 --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of 075 Agents B8da2eb7?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for 075 Agents B8da2eb7
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/tools-only-075-agents-b8da2eb7/badge)](https://www.skillsdirectory.com/skills/tools-only-075-agents-b8da2eb7)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

SKILL.md
# Terraform Infrastructure

Agent instructions specific to the `infra/terraform/` subtree.

## Build Commands

```bash
# Format check
terraform fmt -check -recursive infra/terraform/

# Per-project validation
cd infra/terraform/{project}
terraform init -backend=false
terraform validate

# Full suite (all projects)
npm run validate:terraform

# Deploy (plan preview first)
cd infra/terraform/{project}
terraform plan -out=tfplan
terraform apply tfplan
```

## Module Structure

Each project follows this layout:

```text
infra/terraform/{project}/
  main.tf              # Root module — providers, module calls
  variables.tf         # Input variables with descriptions and validations
  outputs.tf           # Output values
  terraform.tf         # Required providers and backend configuration
  locals.tf            # Local values (naming, tags, computed values)
  terraform.tfvars     # Variable values (not committed for sensitive data)
  modules/
    */                 # One module per resource or logical group
      main.tf
      variables.tf
      outputs.tf
```

## Conventions

- **AVM-first**: Use AVM-TF modules from `registry.terraform.io/Azure/avm-res-{provider}-{resource}/azurerm`
- **Provider pin**: `~> 4.0` for AzureRM
- **Backend**: Azure Storage Account
- **Unique suffix**: `random_string` resource (4 chars, lowercase, `special = false`, `upper = false`)
- **Tags**: Every resource gets the 4 required tags (`Environment`, `ManagedBy = "Terraform"`, `Project`, `Owner`)
- **Variables**: Every variable must have a `description` and a `type`; use `validation` blocks where appropriate
- **Security**: TLS 1.2, HTTPS-only, managed identity, no public blob access, Azure AD-only SQL auth
- **No hardcoded secrets**: Use Key Vault data sources or `sensitive = true` variables
- **State**: Never commit `.tfstate` files; use remote backend

## Governance

Before generating configurations, always check `agent-output/{project}/04-governance-constraints.md`
for subscription-level Azure Policy requirements that may impose additional rules.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…