Terravision Cloud Diagrams
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
Keep Terraform and CDK infrastructure in sync. An agent skill from agentic-community/mcp-gateway-registry.
$ npx skills add agentic-community/mcp-gateway-registry --skill infra-sync -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install agentic-community/mcp-gateway-registry infra-sync --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/agentic-community/mcp-gateway-registry.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/infra-sync .claude/skills/infra-sync && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "infra-sync" agent skill from https://github.com/agentic-community/mcp-gateway-registry/tree/main/.claude/skills/infra-sync into .claude/skills/infra-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "infra-sync", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/agentic-community/mcp-gateway-registry/tree/main/.claude/skills/infra-syncType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add agentic-community/mcp-gateway-registry --skill infra-sync -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install agentic-community/mcp-gateway-registry infra-sync --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agentic-community/mcp-gateway-registry.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/infra-sync .agents/skills/infra-sync && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "infra-sync" agent skill from https://github.com/agentic-community/mcp-gateway-registry/tree/main/.claude/skills/infra-sync into .agents/skills/infra-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "infra-sync", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add agentic-community/mcp-gateway-registry --skill infra-sync -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install agentic-community/mcp-gateway-registry infra-sync --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agentic-community/mcp-gateway-registry.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/infra-sync .cursor/skills/infra-sync && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "infra-sync" agent skill from https://github.com/agentic-community/mcp-gateway-registry/tree/main/.claude/skills/infra-sync into .cursor/skills/infra-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "infra-sync", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/agentic-community/mcp-gateway-registry.git --path .claude/skills/infra-sync--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add agentic-community/mcp-gateway-registry --skill infra-sync -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install agentic-community/mcp-gateway-registry infra-sync --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agentic-community/mcp-gateway-registry.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/infra-sync .gemini/skills/infra-sync && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "infra-sync" agent skill from https://github.com/agentic-community/mcp-gateway-registry/tree/main/.claude/skills/infra-sync into .gemini/skills/infra-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "infra-sync", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install agentic-community/mcp-gateway-registry infra-syncInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add agentic-community/mcp-gateway-registry --skill infra-sync -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/agentic-community/mcp-gateway-registry.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/infra-sync .github/skills/infra-sync && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "infra-sync" agent skill from https://github.com/agentic-community/mcp-gateway-registry/tree/main/.claude/skills/infra-sync into .github/skills/infra-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "infra-sync", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add agentic-community/mcp-gateway-registry --skill infra-sync -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install agentic-community/mcp-gateway-registry infra-sync --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/agentic-community/mcp-gateway-registry.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/infra-sync .opencode/skills/infra-sync && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "infra-sync" agent skill from https://github.com/agentic-community/mcp-gateway-registry/tree/main/.claude/skills/infra-sync into .opencode/skills/infra-sync/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "infra-sync", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
infra-syncKeep Terraform and CDK infrastructure in sync. An agent skill from agentic-community/mcp-gateway-registry.
Infra Sync is an agent skill from agentic-community/mcp-gateway-registry. Keep Terraform and CDK infrastructure in sync. Compares terraform/aws-ecs/ and infra/ to identify discrepancies in ECS services, networking, storage, secrets, IAM, and configuration. Reports parity gaps and generates fixes for the target IaC tool. Use when changes are made to either Terraform or CDK infrastructure.
Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Infrastructure as code. It works with Terraform, Amazon Web Services and Model Context Protocol. The repository describes itself as: Enterprise-ready MCP Gateway & Registry that centralizes AI development tools with secure OAuth authentication, dynamic tool discovery, and unified access for both autonomous AI… The licence is Apache-2.0.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit ec3a197. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
terraformnpxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Infra Sync loads about 2.7k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 912 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from agentic-community/mcp-gateway-registry at commit ec3a197, republished under its Apache-2.0 licence (© agentic-community). 912 words, ~2,702 tokens.
.claude/skills/infra-sync/SKILL.md (or your agent's skills folder).Use this skill when changes are made to either the Terraform (terraform/aws-ecs/) or CDK (infra/) infrastructure and the other needs to be updated to maintain parity.
terraform/aws-ecs/infra/lib/registry/Ask the user (or determine from context):
Read the relevant files from both Terraform and CDK based on the comparison area.
| Comparison Area | Terraform Files | CDK Files |
|---|---|---|
| ECS Services | terraform/aws-ecs/modules/mcp-gateway/ecs-services.tf | infra/lib/registry/registry-service-stack.ts |
| Networking | terraform/aws-ecs/modules/mcp-gateway/networking.tf, terraform/aws-ecs/vpc.tf | infra/lib/registry/registry-network-stack.ts, infra/lib/registry/registry-service-stack.ts (ALB section) |
| Storage (EFS) | terraform/aws-ecs/modules/mcp-gateway/storage.tf | infra/lib/registry/registry-service-stack.ts (EFS section) |
| Storage (DocumentDB) | terraform/aws-ecs/documentdb.tf | infra/lib/registry/registry-data-stack.ts, infra/lib/registry/constructs/documentdb-cluster.ts |
| Secrets | terraform/aws-ecs/modules/mcp-gateway/secrets.tf | infra/lib/registry/registry-service-stack.ts (secrets section) |
| IAM | terraform/aws-ecs/modules/mcp-gateway/iam.tf | infra/lib/registry/constructs/registry-ecs-service.ts (task roles) |
| Keycloak | terraform/aws-ecs/keycloak-ecs.tf, terraform/aws-ecs/keycloak-*.tf | infra/lib/registry/registry-auth-stack.ts, infra/lib/registry/constructs/keycloak-service.ts |
| Observability | terraform/aws-ecs/modules/mcp-gateway/observability.tf | infra/lib/registry/constructs/observability-pipeline.ts |
| CloudFront/WAF | terraform/aws-ecs/cloudfront.tf, terraform/aws-ecs/waf.tf | infra/lib/registry/registry-cdn-stack.ts, infra/lib/registry/constructs/cloudfront-distribution.ts, infra/lib/registry/constructs/waf-rules.ts |
| Secret Rotation | terraform/aws-ecs/secret-rotation.tf | infra/lib/registry/registry-ops-stack.ts, infra/lib/registry/constructs/secret-rotation.ts |
| CI/CD | terraform/aws-ecs/codebuild.tf | infra/lib/registry/registry-build-stack.ts, infra/lib/registry/constructs/codebuild-pipeline.ts |
| Variables/Config | terraform/aws-ecs/variables.tf, terraform/aws-ecs/modules/mcp-gateway/variables.tf | infra/lib/registry/registry-config.ts, infra/config.yaml |
| Monitoring | terraform/aws-ecs/cloudwatch-alarms.tf, terraform/aws-ecs/modules/mcp-gateway/monitoring.tf | infra/lib/registry/registry-service-stack.ts (monitoring section) |
For each comparison area, check the following attributes:
For each service (registry, auth-server, MCP servers, A2A agents):
:username::, :password::)Present findings in this format:
## Infrastructure Parity Report
**Date:** {date}
**Source of Truth:** {Terraform|CDK}
**Scope:** {Full|Targeted area}
### Summary
| Area | Status | Discrepancies |
|------|--------|---------------|
| ECS Services | {In Sync / Diverged} | {count} |
| Networking | {In Sync / Diverged} | {count} |
| Storage | {In Sync / Diverged} | {count} |
| Secrets | {In Sync / Diverged} | {count} |
| IAM | {In Sync / Diverged} | {count} |
| Observability | {In Sync / Diverged} | {count} |
### Discrepancies
#### {Area}: {Description}
| Attribute | Terraform | CDK | Action Required |
|-----------|-----------|-----|-----------------|
| {attr} | {tf value} | {cdk value} | {Fix in TF / Fix in CDK / Intentional} |
### Intentional Differences
These differences are by design and should NOT be synced:
| Feature | CDK | Terraform | Rationale |
|---------|-----|-----------|-----------|
| Circuit Breaker | Enabled | Not configured | Faster failure detection (~4 min vs ~3 hours) |
| HOME=/tmp | Set on registry | Not set | Fixes Path.home() PermissionError in container |
| DocumentDB credentials | Always passed when cluster exists | Gated on storage_backend | Skills repository always uses DocumentDB |
| Keycloak URL fallback | Falls back to http://{alb-dns} | Always https:// | Deployment without Route53/certs |
### Recommendations
1. **Must Fix:** {Critical parity gaps}
2. **Should Fix:** {Important but non-breaking gaps}
3. **Consider:** {Nice-to-have improvements}If the user wants fixes applied:
cd infra && npx tsc --noEmit to verify TypeScript compilescd terraform/aws-ecs && terraform validate if availableThis is the most common source of drift. For each ECS service, extract and compare every environment variable:
Terraform location: Look for environment = [{ name = "...", value = "..." }] blocks in ecs-services.tf
CDK location: Look for environment: { KEY: "value" } objects in registry-service-stack.ts
Compare line by line. Pay special attention to:
Terraform: Look for secrets = [{ name = "...", valueFrom = "..." }] blocks
CDK: Look for secrets: { KEY: ecs.Secret.fromSecretsManager(...) } objects
Compare the JSON key extraction syntax carefully:
"${aws_secretsmanager_secret.x.arn}:username::"ecs.Secret.fromSecretsManager(secret, 'username')Terraform: Check mount_points and volume blocks in each service definition
CDK: Check efsVolumes property in RegistryEcsService constructor calls
Important: The registry service should have NO EFS mounts in both tools. Only auth-server and specific MCP servers mount EFS.
Terraform: Check aws_lb_listener and aws_lb_target_group resources in networking.tf
CDK: Check listener and target group creation in registry-service-stack.ts
Compare:
Maintain this list of differences that should NOT trigger sync warnings:
Circuit Breaker - CDK enables circuitBreaker: { enable: true, rollback: true } on ECS services. Terraform does not. This is intentional for faster failure detection.
HOME=/tmp - CDK sets HOME=/tmp on the registry container. Terraform does not. This fixes a Path.home() PermissionError that occurs when the container runs as a non-root user without a home directory.
DocumentDB Credential Passing - CDK passes DocumentDB credentials whenever dataStack.documentDbSecretArn exists. Terraform gates on var.storage_backend == "documentdb". CDK's approach is correct because the skills repository always uses DocumentDB regardless of the storage backend setting.
Keycloak URL Fallback - CDK falls back to http://{alb-dns-name} when Route53 is disabled. Terraform always uses https://. CDK's approach allows deployment without DNS/certificates.
grep -n "ENV_VAR_NAME" to quickly find where a variable is defined in both codebasescd infra && npx tsc --noEmit to verify compilationterraform fmt and terraform validateinfra/docs/CDK-INFRASTRUCTURE.md for the latest CDK documentation and parity notes© agentic-community, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/infra-sync of agentic-community/mcp-gateway-registry.
Open the folder on GitHubat commit ec3a197
Infra Sync next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Infra Sync this skillagentic-community/mcp-gateway-registry | 962 | — | ~2.7k | Automated safety check: Pass | Apache-2.0 | |
| Terravision Cloud Diagramspatrickchugh/terravision | 1.6k | — | ~5.6k | Automated safety check: Notes | AGPL-3.0-only | |
| Eks Best Practicesaws-samples/appmod-blueprints | 113 | — | ~5k | Automated safety check: Pass | MIT-0 | |
| AWS Sst Developmentzxkane/aws-skills | 367 | — | ~2.7k | Automated safety check: Warn | MIT | |
| AWS Cdk Developmentzxkane/aws-skills | 367 | 2 repos | ~2.5k | Automated safety check: Pass | MIT | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 259 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence |
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
aws-samples/appmod-blueprints
Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.
zxkane/aws-skills
SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework.
zxkane/aws-skills
AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
LukasNiessen/terrashark
Prevent Terraform/OpenTofu hallucinations by diagnosing and fixing failure modes: identity churn, secret exposure, blast-radius mistakes, CI drift, and compliance gate gaps.
agentic-community/mcp-gateway-registry
Explain a GitHub issue or pull request at 100, 200, and 300 level.
agentic-community/mcp-gateway-registry
Debug issues in the MCP Gateway Registry using first-principles thinking.
agentic-community/mcp-gateway-registry
Generate a search quality benchmark for the AI Registry. An agent skill from agentic-community/mcp-gateway-registry.
agentic-community/mcp-gateway-registry
Write prose people will actually read. An agent skill from agentic-community/mcp-gateway-registry.
agentic-community/mcp-gateway-registry
Given an MCP server URL, probe the server via curl to discover its metadata and tools, then generate a markdown file with copy-pasteable content for each field in the Amazon Bedrock AgentCore…
agentic-community/mcp-gateway-registry
Generate a benchmark report from stress test results (registration, API performance, search concurrency).
Categories
Keep Terraform and CDK infrastructure in sync. An agent skill from agentic-community/mcp-gateway-registry. Infra Sync is an agent skill from agentic-community/mcp-gateway-registry. Keep Terraform and CDK infrastructure in sync.
Infra Sync fits situations like: changes are made to either Terraform; CDK infrastructure.
Run `npx skills add agentic-community/mcp-gateway-registry --skill infra-sync -a claude-code`. Or copy the skill folder (.claude/skills/infra-sync in agentic-community/mcp-gateway-registry) into .claude/skills/infra-sync in your project. Claude Code loads it when a task matches its description.
Run `npx skills add agentic-community/mcp-gateway-registry --skill infra-sync -a codex`. Or copy the skill folder (.claude/skills/infra-sync in agentic-community/mcp-gateway-registry) into .agents/skills/infra-sync in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add agentic-community/mcp-gateway-registry --skill infra-sync -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/infra-sync, .gemini/skills/infra-sync, .github/skills/infra-sync and .opencode/skills/infra-sync in your project.
Going by SKILL.md and its folder, Infra Sync needs the command-line tools its instructions call (terraform and npx). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Infra Sync is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Infra Sync: Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Eks Best Practices (aws-samples/appmod-blueprints, 113 stars), AWS Sst Development (zxkane/aws-skills, 367 stars) and AWS Cdk Development (zxkane/aws-skills, 367 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
agentic-community (a GitHub organization) maintains it in agentic-community/mcp-gateway-registry, which has 962 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 6, 2026.
Source: agentic-community/mcp-gateway-registry on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.