Install the "terragrunt-generator" agent skill from https://github.com/akin-ozer/cc-devops-skills/tree/main/devops-skills-plugin/skills/terragrunt-generator into .claude/skills/terragrunt-generator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terragrunt-generator", then confirm the skill loads.
Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
skills CLI
$ npx skills add akin-ozer/cc-devops-skills --skill terragrunt-generator -a codex
Project install goes to .agents/skills/; add -g for ~/.codex/skills/.
Install the "terragrunt-generator" agent skill from https://github.com/akin-ozer/cc-devops-skills/tree/main/devops-skills-plugin/skills/terragrunt-generator into .agents/skills/terragrunt-generator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terragrunt-generator", then confirm the skill loads.
Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add akin-ozer/cc-devops-skills --skill terragrunt-generator -a cursor
Project install goes to .agents/skills/; add -g for ~/.cursor/skills/.
Install the "terragrunt-generator" agent skill from https://github.com/akin-ozer/cc-devops-skills/tree/main/devops-skills-plugin/skills/terragrunt-generator into .cursor/skills/terragrunt-generator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terragrunt-generator", then confirm the skill loads.
Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
skills CLI
$ npx skills add akin-ozer/cc-devops-skills --skill terragrunt-generator -a gemini-cli
Project install goes to .agents/skills/; add -g for ~/.gemini/skills/.
Install the "terragrunt-generator" agent skill from https://github.com/akin-ozer/cc-devops-skills/tree/main/devops-skills-plugin/skills/terragrunt-generator into .gemini/skills/terragrunt-generator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terragrunt-generator", then confirm the skill loads.
Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
skills CLI
$ npx skills add akin-ozer/cc-devops-skills --skill terragrunt-generator -a github-copilot
Project install goes to .agents/skills/; add -g for ~/.copilot/skills/.
Install the "terragrunt-generator" agent skill from https://github.com/akin-ozer/cc-devops-skills/tree/main/devops-skills-plugin/skills/terragrunt-generator into .github/skills/terragrunt-generator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terragrunt-generator", then confirm the skill loads.
GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
skills CLI
$ npx skills add akin-ozer/cc-devops-skills --skill terragrunt-generator -a opencode
OpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
Install the "terragrunt-generator" agent skill from https://github.com/akin-ozer/cc-devops-skills/tree/main/devops-skills-plugin/skills/terragrunt-generator into .opencode/skills/terragrunt-generator/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terragrunt-generator", then confirm the skill loads.
OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
Works in 12 steps: Generate Root Configuration → Generate Child Module Configuration → Generate Standalone Module → …
Tasks that involve Software architecture
SKILL.md covers Overview, Trigger Phrases, Root Configuration Naming and Architecture Patterns, plus 4 more sections
Runs Python scripts from its folder; reaches github.com
What it does
Terragrunt Generator is an agent skill from akin-ozer/cc-devops-skills. Generate/create/scaffold Terragrunt HCL files — root.hcl, terragrunt.hcl, child modules, stacks, multi-env layouts.
Its SKILL.md is about 7.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files, including reference files and assets (for example `references/common-patterns.md` and `test/test_templates.py`).
It sits in Development, covering Software architecture. The repository describes itself as: DevOps skills for Claude Code and Codex. The licence is Apache-2.0.
When your agent uses it
Tasks that involve Software architecture
Example prompts
“/terragrunt-generator”
Requirements
Python 3
Workflow steps
12 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 276af75. It shows what the files ask for, not the result of running them.
Tool permissions
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Runs code
Ships script files (Python), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
Network
Hosts in commands or code, which the agent is likely to contact:
github.com
Also links to:
terragrunt.gruntwork.io
From URLs in SKILL.md, links to its own repository left out.
Credentials
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Context cost
Terragrunt Generator loads about 7.9k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 34 tokens; SKILL.md has 2,215 words of instructions outside code blocks.
Always· name and description, kept in context so the agent knows when to use it
~34
When it runs· the whole SKILL.md, loaded when a task matches
~7.9k
With references· SKILL.md plus every file in references/, read only if the agent opens them
~14k
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
Safety
Auto-check passed
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Download SKILL.mdSave it as .claude/skills/terragrunt-generator/SKILL.md (or your agent's skills folder). This skill also uses 8 other files; get the full folder from GitHub.
Generate production-ready Terragrunt configurations following current best practices, naming conventions, and security standards. All generated configurations are automatically validated.
Trigger Phrases
Use this skill when the user asks for:
A new root.hcl, terragrunt.hcl, or terragrunt.stack.hcl
RECOMMENDED: Use root.hcl instead of terragrunt.hcl for root files per migration guide.
Approach
Root File
Include Syntax
Modern
root.hcl
find_in_parent_folders("root.hcl")
Legacy
terragrunt.hcl
find_in_parent_folders()
Include standard: Default to find_in_parent_folders("root.hcl") in all new examples and generated configs. Use find_in_parent_folders() only when explicitly targeting a legacy root file named terragrunt.hcl.
Architecture Patterns
CRITICAL: Before generating ANY configuration, you MUST determine the architecture pattern and understand its constraints.
Pattern A: Multi-Environment with Environment-Agnostic Root
Use when: Managing multiple environments (dev/staging/prod) with shared root configuration.
Key principle:root.hcl is environment-agnostic - it does NOT read environment-specific files.
Stack path rule: Keep no_dot_terragrunt_stack mode consistent across dependent units. Do not mix direct-path and .terragrunt-stack generation in the same dependency chain.
Commands:
bash
terragrunt stack generate # Generate unit configurations
terragrunt stack run plan # Plan all units
terragrunt stack run apply # Apply all units
terragrunt stack output # Get aggregated outputs
terragrunt stack clean # Clean generated directories
CRITICAL: Feature flag default values MUST be static (boolean, string, number).
They CANNOT reference local.* values. Use static defaults and override via CLI/env vars.
Correct:
hcl
feature "enable_monitoring" {
default = false # Static value - OK
}
Production Recommendation: For critical production resources, add exclude blocks to prevent accidental destruction:
hcl
# Protect production databases from accidental destroy
exclude {
if = true
actions = ["destroy"]
exclude_dependencies = false
}
# Also use prevent_destroy for critical resources
prevent_destroy = true
Report that runtime Terragrunt validation is pending.
If validator skill execution is unavailable:
Run direct Terragrunt checks instead:bash
terragrunt hcl fmt --check
terragrunt dag graph
If tree is unavailable for presentation:
Use:bash
find . -maxdepth 4 -type f | sort
Presentation Requirements
MANDATORY: After successful validation, you MUST present ALL of the following sections. Incomplete presentation is not acceptable. Copy and fill in the templates below.
1. Directory Structure Summary (MANDATORY)
bash
# Show the generated structure
tree <infrastructure-directory>
2. Files Generated (MANDATORY)
Output this table with all generated files:
markdown
| File | Purpose |
|------|---------|
| root.hcl | Shared configuration for all child modules (state backend, provider) |
| dev/env.hcl | Development environment variables |
| prod/env.hcl | Production environment variables |
| dev/vpc/terragrunt.hcl | VPC module for development |
| ... | ... |
3. Usage Instructions (MANDATORY)
You MUST include this section. Copy the template below and fill in the actual values:
markdown
## Usage Instructions
### Prerequisites
Before running Terragrunt commands, ensure:
1. AWS credentials are configured (`aws configure` or environment variables)
2. S3 bucket `<BUCKET_NAME>` exists for state storage
3. DynamoDB table `<TABLE_NAME>` exists for state locking
### Commands
# Navigate to infrastructure directory
cd <INFRASTRUCTURE_DIR>
# Initialize all modules
terragrunt run --all init
# Preview changes for a specific environment
cd <ENV>/vpc && terragrunt plan
# Preview all changes
terragrunt run --all plan
# Apply changes (requires approval)
terragrunt run --all apply
# Destroy (use with extreme caution)
terragrunt run --all destroy
4. Placeholder Replacement and Secrets Check (MANDATORY)
You MUST include this section. Copy the template below and fill in the actual values:
markdown
## Placeholder and Secrets Check
### Placeholder Replacement
- [ ] All placeholders (`[AWS_REGION]`, `[BUCKET_NAME]`, `[DYNAMODB_TABLE]`, etc.) replaced with real values
- [ ] No legacy placeholder aliases left (for example `[REGION]`)
- [ ] `terraform.source` values point to real module sources and pinned versions
### Secrets Safety
- [ ] No plaintext credentials or access keys in `terragrunt.hcl`, `root.hcl`, `env.hcl`, `account.hcl`, or `region.hcl`
- [ ] Sensitive values sourced via environment variables, secret managers, or CI variables
- [ ] Example values kept non-sensitive and clearly marked as placeholders
5. Environment-Specific Notes (MANDATORY)
You MUST include this section. Copy the template below and fill in the actual values:
markdown
## Environment Notes
### Required Environment Variables
| Variable | Description | Example |
|----------|-------------|---------|
| AWS_PROFILE | AWS CLI profile to use | `my-profile` |
| AWS_REGION | AWS region (or set in provider) | `us-east-1` |
### Prerequisites
- [ ] S3 bucket `<BUCKET_NAME>` must exist before first run
- [ ] DynamoDB table `<TABLE_NAME>` must exist for state locking
- [ ] IAM permissions for Terraform state management
### Production-Specific Protections
| Module | Protection | Description |
|--------|------------|-------------|
| prod/rds | `prevent_destroy = true` | Prevents accidental database deletion |
| prod/rds | `exclude { actions = ["destroy"] }` | Blocks destroy commands |
6. Next Steps (Optional)
Suggest what the user might want to do next (add more modules, customize configurations, etc.)
Best Practices
Reference ../terragrunt-validator/references/best_practices.md for comprehensive guidelines.
Key principles:
Use include blocks to inherit root configuration (DRY)
Always provide mock outputs for dependencies
Enable state encryption (encrypt = true)
Use generate blocks for provider configuration
Specify bounded version constraints (~> 5.0, not >= 5.0) for local/Git modules
Never hardcode credentials or secrets
Configure retry logic for transient errors
Note on Version Constraints with Registry Modules: When using Terraform Registry modules (e.g., tfr:///terraform-aws-modules/vpc/aws?version=5.1.0), they typically define their own required_providers. In this case, you may omit generating required_providers in root.hcl to avoid conflicts. The module's pinned version (?version=X.X.X) provides the version constraint. See "Common Issues → Provider Conflict with Registry Modules" for details.
Anti-patterns to avoid:
Hardcoded account IDs, regions, or environment names
Missing mock outputs for dependencies
Duplicated configuration across modules
Unencrypted state storage
Missing or loose version constraints (except when using registry modules that define their own)
Root.hcl trying to read env.hcl that doesn't exist at root level
Error: Attempt to get attribute from null value
on ./root.hcl line X:
This value is null, so it does not have any attributes.
Cause: Root.hcl is trying to read env.hcl via find_in_parent_folders("env.hcl"), but env.hcl doesn't exist at the root level.
Solution: Make root.hcl environment-agnostic:
hcl
# DON'T do this in root.hcl for multi-environment setups:
locals {
env_vars = read_terragrunt_config(find_in_parent_folders("env.hcl")) # FAILS
}
# DO use static values or get_env():
generate "provider" {
path = "provider.tf"
if_exists = "overwrite_terragrunt"
contents = <<EOF
provider "aws" {
region = "us-east-1" # Static value, or use get_env("AWS_REGION", "us-east-1")
}
EOF
}
Provider Conflict with Registry Modules
When using Terraform Registry modules (e.g., tfr:///terraform-aws-modules/vpc/aws), they may define their own required_providers block. This can conflict with provider configuration generated by root.hcl.
Symptoms:
Error: Duplicate required providers configuration
Solutions:
Remove conflicting generate block - If using registry modules that manage their own providers, avoid generating duplicate required_providers:
hcl
# In root.hcl - only generate provider config, not required_providers
generate "provider" {
path = "provider.tf"
if_exists = "overwrite_terragrunt"
contents = <<EOF
provider "aws" {
region = "us-east-1"
}
EOF
}
Use if_exists = "skip" - Skip generation if file already exists:
If you see Unknown variable; There is no variable named "local" in feature blocks, ensure defaults are static values (see Feature Flags section above).
Child Module Cannot Find env.hcl
Symptom:
Error: Attempt to get attribute from null value
on ./dev/vpc/terragrunt.hcl line X:
Terragrunt Generator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
Terragrunt Generator compared with similar skills
Skill
Stars
Used in
Tokens
Auto-check
Licence
Repo updated
Terragrunt Generator this skillakin-ozer/cc-devops-skills
Creates interactive architecture, workflow, sequence, data-flow and lifecycle diagrams as standalone HTML with inline SVG, themes and image or video export.
Tells the agent where new code belongs in an Electron multi-process project and which APIs each process may use, with rules for new bridges, services, agents and workers.
Reviews backend code under api/ for concrete, reproducible defects, routes to rule packs for architecture, schema, repositories and SQLAlchemy, and ranks findings from P0 to P3.
Generate/create/scaffold Terragrunt HCL files — root.hcl, terragrunt.hcl, child modules, stacks, multi-env layouts. Terragrunt Generator is an agent skill from akin-ozer/cc-devops-skills.hcl, child modules, stacks, multi-env layouts.
When should I use Terragrunt Generator?
Terragrunt Generator fits situations like: tasks that involve Software architecture.
How do I install Terragrunt Generator in Claude Code?
Run `npx skills add akin-ozer/cc-devops-skills --skill terragrunt-generator -a claude-code`. Or copy the skill folder (devops-skills-plugin/skills/terragrunt-generator in akin-ozer/cc-devops-skills) into .claude/skills/terragrunt-generator in your project. Claude Code loads it when a task matches its description.
How do I install Terragrunt Generator in Codex?
Run `npx skills add akin-ozer/cc-devops-skills --skill terragrunt-generator -a codex`. Or copy the skill folder (devops-skills-plugin/skills/terragrunt-generator in akin-ozer/cc-devops-skills) into .agents/skills/terragrunt-generator in your project. Codex loads it when a task matches its description.
Can I use Terragrunt Generator in Cursor, Gemini CLI or GitHub Copilot?
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add akin-ozer/cc-devops-skills --skill terragrunt-generator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/terragrunt-generator, .gemini/skills/terragrunt-generator, .github/skills/terragrunt-generator and .opencode/skills/terragrunt-generator in your project.
What does Terragrunt Generator need to run?
Going by SKILL.md and its folder, Terragrunt Generator needs Python for the scripts in its folder. Our summary lists: Python 3.
Does Terragrunt Generator access the network?
SKILL.md names 2 domains. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. As links in the text: terragrunt.gruntwork.io. This is read from the text; nothing was executed.
Is Terragrunt Generator safe to install?
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
What licence does Terragrunt Generator use?
Terragrunt Generator is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
How many tokens does Terragrunt Generator use?
About 7.9k tokens (SKILL.md is roughly 32k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.5k tokens, read only when the agent opens those files.
What are the alternatives to Terragrunt Generator?
Skills that share tags, products or a category with Terragrunt Generator: Archify Diagrams (tt-a1i/archify, 82k stars), Electron Multi-Process Architecture (iOfficeAI/AionUi, 33k stars), Backend Code Review (langgenius/dify, 158k stars) and Dark Architecture Diagram Builder (Cocoon-AI/architecture-diagram-generator, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Who maintains Terragrunt Generator?
akin-ozer (a GitHub user) maintains it in akin-ozer/cc-devops-skills, which has 320 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on July 26, 2026.
Source: akin-ozer/cc-devops-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.