Official agent skill

Avm Tf Interfaces

by Azure in Azure/terraform-azurerm-avm-ptn-alz

A skill your agent uses for AVM Terraform diagnostic settings, role assignments, locks, managed identities, private endpoints, customer-managed keys, tags, and AzAPI control interfaces.

OfficialMITAuto-check passedDevOps & Cloud

Install Avm Tf Interfaces

skills CLI
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-interfaces -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-interfaces --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/avm-tf-interfaces .claude/skills/avm-tf-interfaces && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
avm-tf-interfaces
GitHub stars
135
Token cost
~1.8k tokens
SKILL.md length
655 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses for AVM Terraform diagnostic settings, role assignments, locks, managed identities, private endpoints, customer-managed keys, tags, and AzAPI control interfaces.

  • AVM Terraform diagnostic settings
  • SKILL.md covers Canonical utility module, Resource-feature interfaces, Diagnostic settings v2 and AzAPI control interfaces, plus 2 more sections
  • Reaches raw.githubusercontent.com
  • Role assignments

What it does

Avm Tf Interfaces is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization. Use for AVM Terraform diagnostic settings, role assignments, locks, managed identities, private endpoints, customer-managed keys, tags, and AzAPI control interfaces.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Microsoft Azure and Terraform. The repository describes itself as: Terraform Azure Verified Pattern Module for Azure Landing Zone Management Groups and Policy. The licence is MIT.

When your agent uses it

  • AVM Terraform diagnostic settings
  • Role assignments
  • Managed identities
  • Private endpoints

Example prompts

  • “/avm-tf-interfaces”

What it can do on your machine

Read from SKILL.md and the folder at commit e2a318c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are hcl).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • raw.githubusercontent.com

    Also links to:

    • azure.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Avm Tf Interfaces loads about 1.8k tokens when it runs. Until then it costs about 46 tokens; SKILL.md has 655 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~46
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/terraform-azurerm-avm-ptn-alz at commit e2a318c, republished under its MIT licence (© Azure). 655 words, ~1,845 tokens.

Download SKILL.mdSave it as .claude/skills/avm-tf-interfaces/SKILL.md (or your agent's skills folder).
name
avm-tf-interfaces
description
Use for AVM Terraform diagnostic settings, role assignments, locks, managed identities, private endpoints, customer-managed keys, tags, and AzAPI control interfaces.

AVM Terraform Interfaces

Read the current RMFR4, RMFR5, TFFR6, TFFR7, TFFR8, and TFNFR38 pages through https://azure.github.io/Azure-Verified-Modules/llms.txt.

Every new module MUST use AzAPI for its primary resource and every directly authored standard-interface or supporting control-plane Azure resource. Do not use AzureRM for convenience in implementation, examples, tests, fixtures, E2E setup, or generated snippets. Each permitted azurerm_* resource or data-source block must independently implement one specific unsupported data-plane/non-ARM operation, document the exact block and AzAPI gap with an upstream AzAPI issue or pull request, and be replaced when support ships. One valid block does not authorize another.

Canonical utility module

For every RMFR4 or RMFR5 interface migration, fetch both current sources from Azure/Azure-Verified-Modules:

  • https://raw.githubusercontent.com/Azure/Azure-Verified-Modules/refs/heads/main/docs/content/specs-defs/specs/terraform/interfaces.md
  • the matching https://raw.githubusercontent.com/Azure/Azure-Verified-Modules/refs/heads/main/docs/static/includes/interfaces/tf/int.<interface>.schema.tf

Treat the entire canonical variable declaration as atomic. Copy it in full and replace only documented placeholders; preserve attribute ordering, types, defaults, nullability, descriptions, validations, and error messages exactly. Lint notices are migration hints, not complete implementation instructions.

The resource module declares the exact consumer-facing schema. Azure/avm-utl-interfaces/azure provides the implementation and composition:

hcl
module "avm_interfaces" {
  source  = "Azure/avm-utl-interfaces/azure"
  version = "~> 0.6"

  diagnostic_settings_v2 = var.diagnostic_settings
  managed_identities     = var.managed_identities
}

Only pass inputs supported by the resource. Keep the utility version constraint current with the specification and Registry release.

Resource-feature interfaces

Expose an interface only when the Azure resource supports the capability:

InterfaceConsumer variablePurpose
Diagnostic settingsdiagnostic_settingsRoute logs and metrics to supported destinations.
Role assignmentsrole_assignmentsCreate RBAC assignments scoped to the resource.
LockslockApply an optional CanNotDelete or ReadOnly management lock.
Managed identitiesmanaged_identitiesConfigure system-assigned and user-assigned identities.
Private endpointsprivate_endpointsCreate private endpoints and optional DNS-zone integration.
Customer-managed keycustomer_managed_keyConfigure supported CMK encryption.
TagstagsApply tags to resources that support them.

Do not expose a no-op interface or rename a standard variable.

Diagnostic settings v2

New modules use:

  • utility input diagnostic_settings_v2; and
  • utility output diagnostic_settings_azapi_v2.

The v2 shape supports log category or category group, metrics, enabled flags, and retention policy objects. Do not restrict category values because Azure can add categories.

The owning module supplies scope and all TFFR4-TFFR8 controls:

hcl
resource "azapi_resource" "diagnostic_settings" {
  for_each = module.avm_interfaces.diagnostic_settings_azapi_v2

  type      = var.resource_types.insights_diagnostic_settings
  name      = each.value.name
  parent_id = azapi_resource.this.id
  body      = each.value.body

  ignore_body_changes    = length(var.ignore_body_changes.insights_diagnostic_settings) > 0 ? var.ignore_body_changes.insights_diagnostic_settings : null
  response_export_values = []
  retry                  = var.retry

  dynamic "timeouts" {
    for_each = var.timeouts == null ? [] : [var.timeouts]
    content {
      create = timeouts.value.create
      read   = timeouts.value.read
      update = timeouts.value.update
      delete = timeouts.value.delete
    }
  }
}

Do not use the utility module's legacy diagnostic-settings input or output in new code.

AzAPI control interfaces

These apply to every AzAPI resource, independently of optional resource features:

resource_types

The object contains one deterministic key per AzAPI resource and nested objects matching submodules. Each owning module defines its own tested API-version defaults. Parent slots do not repeat child string defaults.

Show full SKILL.md (269 more words)Show less
retry and timeouts

Expose the TFFR7 object shapes. Apply both to every AzAPI resource and cascade them unchanged to every submodule:

hcl
retry = var.retry

dynamic "timeouts" {
  for_each = var.timeouts == null ? [] : [var.timeouts]
  content {
    create = timeouts.value.create
    read   = timeouts.value.read
    update = timeouts.value.update
    delete = timeouts.value.delete
  }
}
ignore_body_changes

Expose one optional(list(string), []) field per owned AzAPI resource and one nested child-shaped object per submodule. Apply the matching field and collapse an empty list to null:

hcl
ignore_body_changes = length(var.ignore_body_changes.example_widgets) > 0 ? var.ignore_body_changes.example_widgets : null

Pass only the matching nested slot to a child. Do not cascade the parent's path list unchanged because paths are specific to one resource body.

Paths use body-relative dot notation. Individual list indices cannot be targeted. Ignored configuration is not sent to Azure until the path is removed, and interface changes take effect only after apply.

Resource ID validation

Validate standard interface resource IDs with TFNFR38 where each field has one expected resource type:

hcl
validation {
  condition = alltrue([
    for endpoint in values(var.private_endpoints) :
    can(provider::azapi::parse_resource_id("Microsoft.Network/virtualNetworks/subnets", endpoint.subnet_resource_id))
  ])
  error_message = "Each subnet_resource_id must be a valid subnet resource ID."
}

Handle nullable values and collections explicitly. If a field legitimately accepts unrelated resource types, do not validate it against one arbitrary type.

Composition rules

  • Implement locks, role assignments, diagnostic settings, private endpoints, and other child or extension resources as distinct, descriptively named resources or required submodules.
  • Keep the primary resource label this.
  • Source every AzAPI type from var.resource_types.
  • Apply response_export_values, retry, timeouts, and ignore_body_changes to every applicable AzAPI resource. Omit replace_triggers_refs when no replacement paths exist; otherwise use a non-empty static list of unique, valid JMESPath body paths.
  • Use unquoted lifecycle references such as ignore_changes = [name].
  • Do not create destination workspaces, virtual networks, subnets, key vaults, or other consumer-owned dependencies inside a resource module.
  • Keep standard collection inputs non-null with empty defaults.

Consult the canonical schema files for exact consumer-facing declarations and the Azure/avm-utl-interfaces/azure release documentation for implementation inputs and outputs. Do not reconstruct either from memory.

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/avm-tf-interfaces of Azure/terraform-azurerm-avm-ptn-alz.

Open the folder on GitHubat commit e2a318c

Compare with similar skills

Avm Tf Interfaces next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Avm Tf Interfaces compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Avm Tf Interfaces this skillAzure/terraform-azurerm-avm-ptn-alz135—~1.8kAutomated safety check: PassMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
TerrasharkLukasNiessen/terrashark714—~843Automated safety check: PassMIT
Provider Verificationmondoohq/mql411—~3.7kAutomated safety check: PassCustom licence
Tirith MigrateStackGuardian/tirith170—~1.7kAutomated safety check: PassApache-2.0
Terraform Azurerm Set Diff Analyzergithub/awesome-copilot40k1 repos~547Automated safety check: PassMIT

Similar skills

  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Terrashark

    LukasNiessen/terrashark

    Prevent Terraform/OpenTofu hallucinations by diagnosing and fixing failure modes: identity churn, secret exposure, blast-radius mistakes, CI drift, and compliance gate gaps.

    714 GitHub stars~843 tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Verify mql provider resource/field changes against real cloud infrastructure.

    411 GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Tirith Migrate

    StackGuardian/tirith

    Translate existing policy-as-code into Tirith policies. An agent skill from StackGuardian/tirith.

    170 GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Official

    Analyze Terraform plan JSON output for AzureRM Provider to distinguish between false-positive diffs (order-only changes in Set-type attributes) and actual resource changes.

    40k GitHub starsUsed in 1 repo~547 tokens
    DevOps & CloudAuto-check passed
  • Tirith Standards

    StackGuardian/tirith

    Generate a Tirith policy set for an existing Terraform or OpenTofu repository, covering organization standards such as required tags, naming conventions, allowed regions, permitted resource types…

    170 GitHub stars~2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from Azure/terraform-azurerm-avm-ptn-alz

All 13 skills in this repo
  • Avm Tf Azapi

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform AzAPI resources, provider constraints, ARM schemas, parent IDs, resource types, retries, timeouts, response exports, replacement triggers, and…

    135 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Testing

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior.

    135 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Classifications

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module /…

    135 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Codestyle

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting.

    135 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Conftest

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory.

    135 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Documentation

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform generated README content, header.md, footer.md, examples documentation, terraform-docs inputs, and Avm.Authoring documentation checks.

    135 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Avm Tf Interfaces

What does Avm Tf Interfaces do?

A skill your agent uses for AVM Terraform diagnostic settings, role assignments, locks, managed identities, private endpoints, customer-managed keys, tags, and AzAPI control interfaces. Avm Tf Interfaces is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization. Use for AVM Terraform diagnostic settings, role assignments, locks, managed identities, private endpoints, customer-managed keys, tags, and AzAPI control interfaces.

When should I use Avm Tf Interfaces?

Avm Tf Interfaces fits situations like: AVM Terraform diagnostic settings; role assignments; managed identities; private endpoints.

How do I install Avm Tf Interfaces in Claude Code?

Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-interfaces -a claude-code`. Or copy the skill folder (.github/skills/avm-tf-interfaces in Azure/terraform-azurerm-avm-ptn-alz) into .claude/skills/avm-tf-interfaces in your project. Claude Code loads it when a task matches its description.

How do I install Avm Tf Interfaces in Codex?

Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-interfaces -a codex`. Or copy the skill folder (.github/skills/avm-tf-interfaces in Azure/terraform-azurerm-avm-ptn-alz) into .agents/skills/avm-tf-interfaces in your project. Codex loads it when a task matches its description.

Can I use Avm Tf Interfaces in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-interfaces -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/avm-tf-interfaces, .gemini/skills/avm-tf-interfaces, .github/skills/avm-tf-interfaces and .opencode/skills/avm-tf-interfaces in your project.

What does Avm Tf Interfaces need to run?

SKILL.md names no scripts, command-line tools or credentials: Avm Tf Interfaces is instructions for the agent only.

Does Avm Tf Interfaces access the network?

SKILL.md names 2 domains. In commands or code: raw.githubusercontent.com; the agent is likely to contact it when it follows the instructions. As links in the text: azure.github.io. This is read from the text; nothing was executed.

Is Avm Tf Interfaces safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Avm Tf Interfaces use?

Avm Tf Interfaces is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Avm Tf Interfaces use?

About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Avm Tf Interfaces?

Skills that share tags, products or a category with Avm Tf Interfaces: Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Terrashark (LukasNiessen/terrashark, 714 stars), Provider Verification (mondoohq/mql, 411 stars) and Tirith Migrate (StackGuardian/tirith, 170 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Avm Tf Interfaces?

Azure (a GitHub organization, an official publisher) maintains it in Azure/terraform-azurerm-avm-ptn-alz, which has 135 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 6, 2026.

Source: Azure/terraform-azurerm-avm-ptn-alz on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.