Apex GitHub Operations
jonathan-vella/apex
WORKFLOW SKILL — Full GitHub contribution lifecycle: branches, conventional commits, issues, PRs, Actions, releases.
A skill your agent uses whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module /…
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-classifications -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-classifications --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/avm-tf-classifications .claude/skills/avm-tf-classifications && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "avm-tf-classifications" agent skill from https://github.com/Azure/terraform-azurerm-avm-ptn-alz/tree/main/.github/skills/avm-tf-classifications into .claude/skills/avm-tf-classifications/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avm-tf-classifications", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Azure/terraform-azurerm-avm-ptn-alz/tree/main/.github/skills/avm-tf-classificationsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-classifications -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-classifications --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/avm-tf-classifications .agents/skills/avm-tf-classifications && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "avm-tf-classifications" agent skill from https://github.com/Azure/terraform-azurerm-avm-ptn-alz/tree/main/.github/skills/avm-tf-classifications into .agents/skills/avm-tf-classifications/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avm-tf-classifications", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-classifications -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-classifications --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/avm-tf-classifications .cursor/skills/avm-tf-classifications && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "avm-tf-classifications" agent skill from https://github.com/Azure/terraform-azurerm-avm-ptn-alz/tree/main/.github/skills/avm-tf-classifications into .cursor/skills/avm-tf-classifications/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avm-tf-classifications", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git --path .github/skills/avm-tf-classifications--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-classifications -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-classifications --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/avm-tf-classifications .gemini/skills/avm-tf-classifications && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "avm-tf-classifications" agent skill from https://github.com/Azure/terraform-azurerm-avm-ptn-alz/tree/main/.github/skills/avm-tf-classifications into .gemini/skills/avm-tf-classifications/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avm-tf-classifications", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-classificationsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-classifications -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/avm-tf-classifications .github/skills/avm-tf-classifications && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "avm-tf-classifications" agent skill from https://github.com/Azure/terraform-azurerm-avm-ptn-alz/tree/main/.github/skills/avm-tf-classifications into .github/skills/avm-tf-classifications/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avm-tf-classifications", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-classifications -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-classifications --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/avm-tf-classifications .opencode/skills/avm-tf-classifications && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "avm-tf-classifications" agent skill from https://github.com/Azure/terraform-azurerm-avm-ptn-alz/tree/main/.github/skills/avm-tf-classifications into .opencode/skills/avm-tf-classifications/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "avm-tf-classifications", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
avm-tf-classificationsA skill your agent uses whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module /…
Avm Tf Classifications is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization. Use this skill whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module / GitHub repo / Terraform Registry entry. Covers the three module classes, the criteria that separate them ("single resource only" vs "opinionated multi-resource solution" vs "shared logic"), the naming conventions per class (avm-res-, avm-ptn-, avm-utl-), and the corresponding GitHub repo name (terraform-azure-avm-<class-<name for…
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Infrastructure as code. It works with Microsoft Azure, Terraform and GitHub. The repository describes itself as: Terraform Azure Verified Pattern Module for Azure Landing Zone Management Groups and Policy. The licence is MIT.
Read from SKILL.md and the folder at commit e2a318c. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are hcl).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
raw.githubusercontent.comazure.github.ioregistry.terraform.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Avm Tf Classifications loads about 2.9k tokens when it runs. Until then it costs about 211 tokens; SKILL.md has 932 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Azure/terraform-azurerm-avm-ptn-alz at commit e2a318c, republished under its MIT licence (© Azure). 932 words, ~2,884 tokens.
.claude/skills/avm-tf-classifications/SKILL.md (or your agent's skills folder).Every AVM module is exactly one of three classes. The class drives the naming convention, the repo name, the spec set that applies, and the review process.
Classification does not change the provider rule. Every new resource, pattern, or utility module repository that deploys Azure resources MUST use AzAPI for every control-plane and supported direct Azure operation. Each permitted azurerm_* resource or data-source block must independently implement one specific unsupported data-plane/non-ARM operation, document the exact block and AzAPI gap with an upstream AzAPI issue or pull request, and be replaced when support ships. One valid block does not authorize another.
Fetch https://azure.github.io/Azure-Verified-Modules/llms.txt and confirm the current versions of these sources:
avm-res-)Deploys a single instance of one primary Azure resource (RMFR1) — e.g. one Key Vault, one Storage Account, one Search Service — plus the standard cross-cutting interfaces (lock, RBAC, diagnostic settings, private endpoints, etc. — see avm-tf-interfaces) and child resources that don't add value as standalone modules.
The primary resource MUST be implemented with AzAPI. Do not create a new AzureRM-based resource module.
If a consumer needs N instances of the resource, they call the module N times. The module itself never loops over the primary resource.
Must add value over raw azapi_resource (RMFR2) — usually via the standard interfaces, validation, and sensible WAF-aligned defaults. If your module is a thin wrapper that just passes inputs through to a single azapi_resource, you don't have a resource module — you have a useless module.
avm-ptn-)Deploys an opinionated multi-resource solution to a recurring problem — e.g. "hub-and-spoke landing zone", "AKS baseline", "AI Foundry workspace with all dependencies". Pattern modules compose resource modules (TFFR1 — Cross-Referencing Modules requires them to consume AVM resource modules where available rather than re-implementing).
If a resource module doesn't exist for a resource the pattern needs, the pattern owner MUST log an issue on the central AVM repo requesting it (PMNFR4).
Any control-plane resource implemented directly in a pattern module MUST use AzAPI. The absence of an AVM resource module is not permission to use AzureRM.
avm-utl-)Provides shared logic with no resource deployments of its own, or rarely with a single supporting resource (e.g. a deployment script). Today the canonical example is avm-utl-interfaces — the variable schemas for the standard cross-cutting interfaces. Utility modules are introduced gradually and the specifications around them are still maturing.
If a utility module deploys a supporting control-plane Azure resource, that resource MUST use AzAPI.
If a utility module deploys no resources, telemetry collection MUST NOT be added (SFR3).
Are you deploying Azure resources?
├─ No → utility module (avm-utl-)
└─ Yes
├─ Exactly one primary resource (+ standard interfaces + child resources)?
│ └─ Yes → resource module (avm-res-)
└─ Multiple primary resources composed into a solution?
└─ Yes → pattern module (avm-ptn-)If you find yourself wanting to deploy "a Key Vault AND a Storage Account" as one module, that's a pattern module composing two resource modules — not a single resource module.
| Class | Format | Example |
|---|---|---|
| Resource | avm-res-<resource provider>-<ARM resource type> | avm-res-keyvault-vault, avm-res-search-searchservice, avm-res-compute-virtualmachine |
| Pattern | avm-ptn-<short pattern name> | avm-ptn-aks-production, avm-ptn-alz-management |
| Utility | avm-utl-<utility name> | avm-utl-interfaces, avm-utl-types |
Notes on the resource segment:
<resource provider> is the lowercased and trimmed ARM provider name — Microsoft.KeyVault → keyvault, Microsoft.Storage → storage, Microsoft.Search → search.<ARM resource type> is the lowercased and singular-ish resource type — vaults → vault, storageAccounts → storageaccount, searchServices → searchservice, virtualMachines → virtualmachine.avm-res-keyvault-vault-key, avm-res-storage-storageaccount-blob. But sub-resources within a single resource module live under modules/ (TFRMNFR1) — not every child resource becomes its own AVM module.Azure org)The repo name prefixes the module name with terraform-azure- (RMNFR1). The <provider> segment is a legacy Terraform Registry requirement; the spec now fixes it to azure for new modules — even though AVM Terraform modules use AzAPI:
| Class | Repo |
|---|---|
| Resource | terraform-azure-avm-res-<rp>-<type> — e.g. terraform-azure-avm-res-storage-storageaccount |
| Pattern | terraform-azure-avm-ptn-<name> — e.g. terraform-azure-avm-ptn-aks-production |
| Utility | terraform-azure-avm-utl-<name> — e.g. terraform-azure-avm-utl-interfaces |
This expands to the Terraform Registry source string Azure/avm-res-<rp>-<type>/azure (the /azure suffix is the Registry's "provider" namespace, fixed by convention even though the module's code uses AzAPI).
Legacy note. Most existing repos are still named
terraform-azurerm-avm-*with anAzure/avm-res-.../azurermRegistry source — RMNFR1 changed the required<provider>segment fromazurermtoazure, and the bulk of published modules pre-date the change. Keep an existing module's published name/source as-is; useazureonly for new modules. The template repo itself remainsterraform-azurerm-avm-template.
Inside a new module, the primary azapi_resource MUST be named this (TFRMNFR2):
resource "azapi_resource" "this" {
type = var.resource_types.search_search_services
parent_id = var.parent_id
name = var.name
location = var.location
body = { properties = { ... } }
ignore_body_changes = length(var.ignore_body_changes.search_search_services) > 0 ? var.ignore_body_changes.search_search_services : null
response_export_values = []
retry = var.retry
dynamic "timeouts" {
for_each = var.timeouts == null ? [] : [var.timeouts]
content {
create = timeouts.value.create
read = timeouts.value.read
update = timeouts.value.update
delete = timeouts.value.delete
}
}
}When maintaining a pre-existing AzureRM module, keep its existing primary resource label this until migration. Do not copy that legacy implementation into a new module.
avm-res-compute-virtualmachine module 5 times, or write a pattern module if there's reusable orchestration.terraform-azure-avm-... is mechanical — don't substitute terraform-azapi-avm-... "because we're using AzAPI now". The Registry-side convention is fixed./azurerm Registry source identifies an existing published module; it does not allow a new module to use AzureRM as its primary provider.name default. Resource modules MUST NOT default the primary resource's name (RMNFR2 / SNFR25) — the consumer must always supply it. Defaults are permitted (and required) for the standard-interface child resources like pep-<name>.avm-res-keyvault-vault violates TFFR1.© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/avm-tf-classifications of Azure/terraform-azurerm-avm-ptn-alz.
Open the folder on GitHubat commit e2a318c
Avm Tf Classifications next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Avm Tf Classifications this skillAzure/terraform-azurerm-avm-ptn-alz | 135 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Apex GitHub Operationsjonathan-vella/apex | 217 | — | ~1.5k | Automated safety check: Pass | MIT | |
| Terravision Cloud Diagramspatrickchugh/terravision | 1.6k | — | ~5.6k | Automated safety check: Notes | AGPL-3.0-only | |
| TerrasharkLukasNiessen/terrashark | 714 | — | ~843 | Automated safety check: Pass | MIT | |
| Datadog Data Source GeneratorDataDog/terraform-provider-datadog | 468 | — | ~2.7k | Automated safety check: Pass | MPL-2.0 | |
| Provider Verificationmondoohq/mql | 411 | — | ~3.7k | Automated safety check: Pass | Custom licence |
jonathan-vella/apex
WORKFLOW SKILL — Full GitHub contribution lifecycle: branches, conventional commits, issues, PRs, Actions, releases.
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
LukasNiessen/terrashark
Prevent Terraform/OpenTofu hallucinations by diagnosing and fixing failure modes: identity churn, secret exposure, blast-radius mistakes, CI drift, and compliance gate gaps.
DataDog/terraform-provider-datadog
Generates a Datadog Terraform provider data source from an OpenAPI operation with tfgen and opens a review-ready GitHub PR with a risk scan and testing guide.
mondoohq/mql
Verify mql provider resource/field changes against real cloud infrastructure.
StackGuardian/tirith
Translate existing policy-as-code into Tirith policies. An agent skill from StackGuardian/tirith.
Azure/terraform-azurerm-avm-ptn-alz
A skill your agent uses for AVM Terraform AzAPI resources, provider constraints, ARM schemas, parent IDs, resource types, retries, timeouts, response exports, replacement triggers, and…
Azure/terraform-azurerm-avm-ptn-alz
A skill your agent uses for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior.
Azure/terraform-azurerm-avm-ptn-alz
A skill your agent uses for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting.
Azure/terraform-azurerm-avm-ptn-alz
A skill your agent uses whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory.
Azure/terraform-azurerm-avm-ptn-alz
A skill your agent uses for AVM Terraform generated README content, header.md, footer.md, examples documentation, terraform-docs inputs, and Avm.Authoring documentation checks.
Azure/terraform-azurerm-avm-ptn-alz
A skill your agent uses for AVM Terraform diagnostic settings, role assignments, locks, managed identities, private endpoints, customer-managed keys, tags, and AzAPI control interfaces.
Works with
Categories
A skill your agent uses whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module /…. Avm Tf Classifications is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization. Use this skill whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module / GitHub repo / Terraform Registry entry.
Avm Tf Classifications fits situations like: A contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module; utility module —; is naming a module / GitHub repo / Terraform Registry entry; phrases like resource module vs pattern module.
Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-classifications -a claude-code`. Or copy the skill folder (.github/skills/avm-tf-classifications in Azure/terraform-azurerm-avm-ptn-alz) into .claude/skills/avm-tf-classifications in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-classifications -a codex`. Or copy the skill folder (.github/skills/avm-tf-classifications in Azure/terraform-azurerm-avm-ptn-alz) into .agents/skills/avm-tf-classifications in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-classifications -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/avm-tf-classifications, .gemini/skills/avm-tf-classifications, .github/skills/avm-tf-classifications and .opencode/skills/avm-tf-classifications in your project.
SKILL.md names no scripts, command-line tools or credentials: Avm Tf Classifications is instructions for the agent only.
SKILL.md names 3 domains. As links in the text: raw.githubusercontent.com, azure.github.io and registry.terraform.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Avm Tf Classifications is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Avm Tf Classifications: Apex GitHub Operations (jonathan-vella/apex, 217 stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Terrashark (LukasNiessen/terrashark, 714 stars) and Datadog Data Source Generator (DataDog/terraform-provider-datadog, 468 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Azure (a GitHub organization, an official publisher) maintains it in Azure/terraform-azurerm-avm-ptn-alz, which has 135 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 6, 2026.
Source: Azure/terraform-azurerm-avm-ptn-alz on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.