Official agent skill

Avm Tf Codestyle

by Azure in Azure/terraform-azurerm-avm-ptn-alz

A skill your agent uses for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting.

OfficialMITAuto-check passedDevOps & Cloud

Install Avm Tf Codestyle

skills CLI
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-codestyle -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-codestyle --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/avm-tf-codestyle .claude/skills/avm-tf-codestyle && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
avm-tf-codestyle
GitHub stars
135
Token cost
~1.6k tokens
SKILL.md length
650 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting.

  • AVM Terraform file layout
  • SKILL.md covers Standard file layout, Provider requirements, Naming and declarations and AzAPI block requirements, plus 3 more sections
  • Calls terraform
  • Lifecycle syntax

What it does

Avm Tf Codestyle is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization. Use for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Terraform and Microsoft Azure. The repository describes itself as: Terraform Azure Verified Pattern Module for Azure Landing Zone Management Groups and Policy. The licence is MIT.

When your agent uses it

  • AVM Terraform file layout
  • Lifecycle syntax
  • Provider requirements
  • Avm.Authoring formatting

Example prompts

  • “/avm-tf-codestyle”

What it can do on your machine

Read from SKILL.md and the folder at commit e2a318c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • terraform

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • azure.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Avm Tf Codestyle loads about 1.6k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 650 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/terraform-azurerm-avm-ptn-alz at commit e2a318c, republished under its MIT licence (© Azure). 650 words, ~1,598 tokens.

Download SKILL.mdSave it as .claude/skills/avm-tf-codestyle/SKILL.md (or your agent's skills folder).
name
avm-tf-codestyle
description
Use for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting.

AVM Terraform Code Style

Fetch the current Terraform non-functional specifications through https://azure.github.io/Azure-Verified-Modules/llms.txt. Current module examples can lag the specification and are not authoritative.

Standard file layout

TFNFR39 applies to the root module and every submodule:

FileRequirementContents
terraform.tfMUSTThe single terraform {} block with required Terraform and provider versions.
variables.tfMUSTVariable blocks.
outputs.tfMUSTOutput blocks.
main.tfMUSTPrimary resource, data, and module blocks.
locals.tfRequired when locals existLocal values only.

Large modules may use main.<topic>.tf, variables.<topic>.tf, outputs.<topic>.tf, and locals.<topic>.tf. Topic names are snake case and each file contains only the block kind indicated by its prefix.

Do not add root-level providers.tf, module.tf, or everything.tf. Reusable AVM modules declare provider requirements but never provider configurations.

Each module and submodule also includes _header.md and _footer.md; README.md is generated.

Provider requirements

Every new module repository that deploys Azure resources MUST use AzAPI for every control-plane and supported direct Azure operation. Do not declare or configure hashicorp/azurerm, and do not create any azurerm_* resource or data source for convenience or ordinary supporting infrastructure in implementation, submodules, examples, E2E configurations, Terraform tests, fixtures, setup or teardown Terraform, migration examples, documentation examples, or generated snippets.

TFNFR25 requires a minimum and maximum Terraform CLI constraint, while TFFR3 requires the AzAPI provider range. Use the governance-managed baseline; a compliant current shape is:

hcl
terraform {
  required_version = ">= 1.9, < 2.0"

  required_providers {
    azapi = {
      source  = "Azure/azapi"
      version = "~> 2.12"
    }
  }
}

Apply this Azure/azapi requirement to every standalone Terraform root that directly creates, reads, or acts on Azure resources. Supporting resources outside the module under test use AzAPI. Each permitted azurerm_* resource or data-source block must independently implement one specific unsupported data-plane/non-ARM operation, document the exact block and why AzAPI cannot implement it with an upstream AzAPI issue or pull request, and be replaced when support ships. One valid block does not authorize another.

Do not raise required_version only because non-empty ignore_body_changes needs Terraform 1.11. Emit null when that interface is unused so earlier supported Terraform versions remain compatible.

Naming and declarations

  • Use snake case for Terraform identifiers.
  • Name the primary AzAPI resource this; name satellite resources after their purpose.
  • Give every variable and output a precise type and description.
  • Mark secret variables and outputs sensitive and follow the current ephemeral-value requirements.
  • Default collections to {} or [] with nullable = false.
  • Use optional(...) for non-required object attributes and give defaults that match the documentation.
  • Keep variable, local, resource, module, and output ordering consistent with the transforms applied by avm transform.
  • Prefer discrete computed outputs over whole-resource outputs.

Example:

hcl
variable "private_endpoints" {
  type = map(object({
    name               = optional(string)
    subnet_resource_id = string
  }))
  default  = {}
  nullable = false

  validation {
    condition = alltrue([
      for endpoint in values(var.private_endpoints) :
      can(provider::azapi::parse_resource_id("Microsoft.Network/virtualNetworks/subnets", endpoint.subnet_resource_id))
    ])
    error_message = "Each private endpoint subnet must be a valid subnet resource ID."
  }

  description = "A map of private endpoints to create."
}

TFNFR38 requires provider::azapi::parse_resource_id with a literal expected resource type for ARM resource IDs. Short-circuit optional values and iterate collections or nested attributes. Do not use regex, startswith, length, or split as substitutes, except for the prescribed generic check on an extension-resource module's polymorphic parent_id under TFRMFR1.

Show full SKILL.md (201 more words)Show less

AzAPI block requirements

Every AzAPI resource must:

  • source type from the deterministic field in var.resource_types;
  • declare response_export_values;
  • omit replace_triggers_refs when no replacement paths exist; otherwise declare a non-empty static list of unique, valid JMESPath body paths;
  • assign retry = var.retry;
  • emit timeouts through a dynamic block; and
  • assign the per-resource ignore_body_changes list, collapsing empty to null.
  • set tags = var.tags exactly on resource types supported by the current AVM TFLint capability snapshot and omit tags on unsupported types.

See avm-tf-azapi for the complete pattern.

Lifecycle syntax

Terraform lifecycle references are expressions, not strings:

hcl
lifecycle {
  ignore_changes = [tags]
}

Use static lifecycle.ignore_changes for compile-time-static references. Use the consumer-configurable AzAPI ignore_body_changes interface when body paths are dynamic. Body paths are strings because they are passed to the provider:

hcl
ignore_body_changes = length(var.ignore_body_changes.example_widgets) > 0 ? var.ignore_body_changes.example_widgets : null

Generated and managed files

  • Edit _header.md or _footer.md, not README.md.
  • Do not hand-edit managed telemetry or provider-version content that avm sync or avm transform owns.
  • Keep comments rare and limited to non-obvious constraints or documented exceptions.

Formatting and validation

Use the PowerShell module rather than individual binaries:

pwsh
avm transform
avm format
avm docs
avm pre-commit

Review and commit all resulting changes, then run:

pwsh
avm pr-check

avm pr-check requires a clean Git worktree. Do not use Make, the old repository launcher, a container, Porch, or a separately installed formatter to approximate these checks.

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/avm-tf-codestyle of Azure/terraform-azurerm-avm-ptn-alz.

Open the folder on GitHubat commit e2a318c

Compare with similar skills

Avm Tf Codestyle next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Avm Tf Codestyle compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Avm Tf Codestyle this skillAzure/terraform-azurerm-avm-ptn-alz135—~1.6kAutomated safety check: PassMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
TerrasharkLukasNiessen/terrashark714—~843Automated safety check: PassMIT
Provider Verificationmondoohq/mql411—~3.7kAutomated safety check: PassCustom licence
Tirith MigrateStackGuardian/tirith170—~1.7kAutomated safety check: PassApache-2.0
Terraform Azurerm Set Diff Analyzergithub/awesome-copilot40k1 repos~547Automated safety check: PassMIT

Similar skills

  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Terrashark

    LukasNiessen/terrashark

    Prevent Terraform/OpenTofu hallucinations by diagnosing and fixing failure modes: identity churn, secret exposure, blast-radius mistakes, CI drift, and compliance gate gaps.

    714 GitHub stars~843 tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Verify mql provider resource/field changes against real cloud infrastructure.

    411 GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Tirith Migrate

    StackGuardian/tirith

    Translate existing policy-as-code into Tirith policies. An agent skill from StackGuardian/tirith.

    170 GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Analyze Terraform plan JSON output for AzureRM Provider to distinguish between false-positive diffs (order-only changes in Set-type attributes) and actual resource changes.

    40k GitHub starsUsed in 1 repo~547 tokens
    DevOps & CloudAuto-check passed
  • Tirith Standards

    StackGuardian/tirith

    Generate a Tirith policy set for an existing Terraform or OpenTofu repository, covering organization standards such as required tags, naming conventions, allowed regions, permitted resource types…

    170 GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from Azure/terraform-azurerm-avm-ptn-alz

All 13 skills in this repo
  • Avm Tf Azapi

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform AzAPI resources, provider constraints, ARM schemas, parent IDs, resource types, retries, timeouts, response exports, replacement triggers, and…

    135 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Testing

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior.

    135 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Classifications

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module /…

    135 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Conftest

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory.

    135 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Documentation

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform generated README content, header.md, footer.md, examples documentation, terraform-docs inputs, and Avm.Authoring documentation checks.

    135 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Interfaces

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform diagnostic settings, role assignments, locks, managed identities, private endpoints, customer-managed keys, tags, and AzAPI control interfaces.

    135 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Avm Tf Codestyle

What does Avm Tf Codestyle do?

A skill your agent uses for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting. Avm Tf Codestyle is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization.Authoring formatting.

When should I use Avm Tf Codestyle?

Avm Tf Codestyle fits situations like: AVM Terraform file layout; lifecycle syntax; provider requirements; avm.Authoring formatting.

How do I install Avm Tf Codestyle in Claude Code?

Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-codestyle -a claude-code`. Or copy the skill folder (.github/skills/avm-tf-codestyle in Azure/terraform-azurerm-avm-ptn-alz) into .claude/skills/avm-tf-codestyle in your project. Claude Code loads it when a task matches its description.

How do I install Avm Tf Codestyle in Codex?

Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-codestyle -a codex`. Or copy the skill folder (.github/skills/avm-tf-codestyle in Azure/terraform-azurerm-avm-ptn-alz) into .agents/skills/avm-tf-codestyle in your project. Codex loads it when a task matches its description.

Can I use Avm Tf Codestyle in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-codestyle -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/avm-tf-codestyle, .gemini/skills/avm-tf-codestyle, .github/skills/avm-tf-codestyle and .opencode/skills/avm-tf-codestyle in your project.

What does Avm Tf Codestyle need to run?

Going by SKILL.md and its folder, Avm Tf Codestyle needs the command-line tools its instructions call (terraform).

Does Avm Tf Codestyle access the network?

SKILL.md names 1 domain. As links in the text: azure.github.io. This is read from the text; nothing was executed.

Is Avm Tf Codestyle safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Avm Tf Codestyle use?

Avm Tf Codestyle is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Avm Tf Codestyle use?

About 1.6k tokens (SKILL.md is roughly 6.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Avm Tf Codestyle?

Skills that share tags, products or a category with Avm Tf Codestyle: Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Terrashark (LukasNiessen/terrashark, 714 stars), Provider Verification (mondoohq/mql, 411 stars) and Tirith Migrate (StackGuardian/tirith, 170 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Avm Tf Codestyle?

Azure (a GitHub organization, an official publisher) maintains it in Azure/terraform-azurerm-avm-ptn-alz, which has 135 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 6, 2026.

Source: Azure/terraform-azurerm-avm-ptn-alz on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.