Official agent skill

Avm Tf Migration

by Azure in Azure/terraform-azurerm-avm-ptn-alz

A skill your agent uses for AVM Terraform AzureRM-to-AzAPI migrations, state preservation, moved blocks, provider state moves, submodule extraction, upgrade tests, and post-migration specification…

OfficialMITAuto-check passedDevOps & Cloud

Install Avm Tf Migration

skills CLI
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-migration -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-migration --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/avm-tf-migration .claude/skills/avm-tf-migration && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
avm-tf-migration
GitHub stars
135
Token cost
~1.7k tokens
SKILL.md length
764 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses for AVM Terraform AzureRM-to-AzAPI migrations, state preservation, moved blocks, provider state moves, submodule extraction, upgrade tests, and post-migration specification…

  • Works in 2 steps: Provider migration in place: azurerm_*… → Composition migration: moving a resource…
  • AVM Terraform AzureRM-to-AzAPI migrations
  • SKILL.md covers Separate two changes, Cardinality rule, Provider migration in place and Target implementation checklist, plus 2 more sections
  • Calls terraform

What it does

Avm Tf Migration is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization. Use for AVM Terraform AzureRM-to-AzAPI migrations, state preservation, moved blocks, provider state moves, submodule extraction, upgrade tests, and post-migration specification compliance.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Terraform and Microsoft Azure. The repository describes itself as: Terraform Azure Verified Pattern Module for Azure Landing Zone Management Groups and Policy. The licence is MIT.

When your agent uses it

  • AVM Terraform AzureRM-to-AzAPI migrations
  • State preservation
  • Provider state moves
  • Submodule extraction

Example prompts

  • “/avm-tf-migration”

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Provider migration in place: azurerm_* to an AzAPI resource at the same module/cardinality boundary.
  2. Composition migration: moving a resource across a module boundary, such as extracting a root collection into…

What it can do on your machine

Read from SKILL.md and the folder at commit e2a318c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • terraform

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • azure.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Avm Tf Migration loads about 1.7k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 764 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/terraform-azurerm-avm-ptn-alz at commit e2a318c, republished under its MIT licence (© Azure). 764 words, ~1,692 tokens.

Download SKILL.mdSave it as .claude/skills/avm-tf-migration/SKILL.md (or your agent's skills folder).
name
avm-tf-migration
description
Use for AVM Terraform AzureRM-to-AzAPI migrations, state preservation, moved blocks, provider state moves, submodule extraction, upgrade tests, and post-migration specification compliance.

AVM Terraform Migration

An AzureRM-to-AzAPI migration is complete only when the implementation satisfies the current AVM specifications and existing consumers have a documented, tested state path.

Migration guidance applies to existing modules only. AzureRM may be read, analyzed, and referenced as source input being migrated, including legacy azurerm_* state addresses. Generated target code uses AzAPI for every control-plane and supported Azure operation.

The target rule includes implementation, submodules, upgrade examples, E2E configurations, Terraform tests, fixtures, setup or teardown Terraform, documentation examples, and generated snippets. Supporting control-plane resources use AzAPI, and each standalone target Terraform root includes Azure/azapi in required_providers. Retain an azurerm_* resource or data-source block only when that block independently implements one specific unsupported data-plane/non-ARM operation. Document the exact block and why AzAPI cannot implement it with an upstream AzAPI issue or pull request, and replace the block when support ships. One valid block does not authorize another.

Read TFFR3-TFFR8, TFRMFR1, TFRMNFR1, TFRMNFR2, TFNFR38, and TFNFR39 through https://azure.github.io/Azure-Verified-Modules/llms.txt before choosing the migration shape.

Separate two changes

Treat these as different graph migrations:

  1. Provider migration in place: azurerm_* to an AzAPI resource at the same module/cardinality boundary.
  2. Composition migration: moving a resource across a module boundary, such as extracting a root collection into module.child[each.key].azapi_resource.this.

Combining them makes state preservation harder and can make a reusable moved block impossible. Prefer migrating the provider in place first, releasing that state path, and extracting to a submodule in a later breaking release when needed.

Cardinality rule

TFRMNFR1 requires the parent module to own count or for_each. A submodule's primary resource manages one instance:

hcl
module "part" {
  source   = "./modules/part"
  for_each = var.parts
}
hcl
# modules/part/main.tf
resource "azapi_resource" "this" {
  # No count or for_each here.
}

Do not move for_each inside the submodule to make state addresses easier. That violates the target design.

A root collection address such as:

text
azurerm_example_part.this["a"]

becomes:

text
module.part["a"].azapi_resource.this

Terraform cannot express a generic key-preserving resource-to-module move for every unknown consumer key. Options are:

  • migrate the provider at the existing boundary first;
  • migrate a resource already inside an existing for_each module call;
  • publish explicit consumer terraform state mv instructions for known keys; or
  • accept and document a breaking state migration when extraction itself is required.

Never hide a state-breaking extraction behind a claim that a wildcard moved block preserves it.

Provider migration in place

When the providers support the state move, use a declarative block:

hcl
moved {
  from = azurerm_example_widget.this
  to   = azapi_resource.this
}

For a same-level collection, moving the resource address can preserve its instances. Verify this against applied state; do not assume provider state conversion supports every resource.

Keep migration blocks for the documented compatibility window and release them with clear upgrade notes. Use direct terraform state mv only when no reusable declarative move exists, and provide PowerShell-friendly instructions:

pwsh
terraform state list
terraform state mv 'azurerm_example_part.this["a"]' 'module.part["a"].azapi_resource.this'

Back up state before imperative changes.

Show full SKILL.md (329 more words)Show less

Target implementation checklist

The AzAPI target must include:

  • Azure/azapi ~> 2.12;
  • primary resource label this;
  • required parent_id and TFNFR38 resource ID validation;
  • standard TFNFR39 files in root and submodules;
  • type from the deterministic resource_types object;
  • response_export_values, including an explicit empty value;
  • replace_triggers_refs only when replacement paths exist, using a non-empty static list of unique, valid JMESPath body paths;
  • consumer-configurable retry and dynamic timeouts;
  • per-resource ignore_body_changes with empty lists collapsed to null;
  • nested resource_types and ignore_body_changes slots for submodules;
  • discrete outputs mapped from azapi_resource.this.output; and
  • standard interfaces composed through Azure/avm-utl-interfaces/azure ~> 0.6.

Do not retain AzureRM as a convenience fallback or copy it into target examples and tests. Existing AzureRM configuration is migration input only, except when the target still requires the narrowly documented unsupported data-plane/non-ARM operation.

Ignore semantics during migration

Static Terraform lifecycle references remain expressions:

hcl
lifecycle {
  ignore_changes = [name]
}

Use this for compile-time-static resource attributes, including a migration case where an imported server-assigned role-assignment name must remain stable.

Use TFFR8 ignore_body_changes for consumer-selected body paths:

hcl
ignore_body_changes = length(var.ignore_body_changes.example_widgets) > 0 ? var.ignore_body_changes.example_widgets : null

Paths are body-relative dot notation, cannot target list indices, and prevent ignored configuration from being sent to Azure. A change to the provider-private value takes effect only after apply.

Upgrade-path validation

Test against real state:

  1. deploy a representative example with the latest published pre-migration module;
  2. capture terraform state list and a state backup;
  3. switch the example to the local migrated module;
  4. run terraform init -upgrade;
  5. run terraform plan and require zero unintended destroys or replacements;
  6. apply the migration;
  7. run a second plan and require no changes;
  8. verify discrete outputs and all supported interfaces; and
  9. destroy through the migrated implementation.

Use avm test integration for real-Azure Terraform tests and avm test e2e --example <name> for an example deployment. Run avm pre-commit, commit all results, and then run avm pr-check on a clean worktree.

If state cannot be preserved, classify the change correctly under the current breaking-change and semantic-versioning specifications. Document exact consumer commands and expected effects rather than silently accepting recreation.

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/avm-tf-migration of Azure/terraform-azurerm-avm-ptn-alz.

Open the folder on GitHubat commit e2a318c

Compare with similar skills

Avm Tf Migration next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Avm Tf Migration compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Avm Tf Migration this skillAzure/terraform-azurerm-avm-ptn-alz135—~1.7kAutomated safety check: PassMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
TerrasharkLukasNiessen/terrashark714—~843Automated safety check: PassMIT
Provider Verificationmondoohq/mql411—~3.7kAutomated safety check: PassCustom licence
Tirith MigrateStackGuardian/tirith170—~1.7kAutomated safety check: PassApache-2.0
Terraform Azurerm Set Diff Analyzergithub/awesome-copilot40k1 repos~547Automated safety check: PassMIT

Similar skills

  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Terrashark

    LukasNiessen/terrashark

    Prevent Terraform/OpenTofu hallucinations by diagnosing and fixing failure modes: identity churn, secret exposure, blast-radius mistakes, CI drift, and compliance gate gaps.

    714 GitHub stars~843 tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Verify mql provider resource/field changes against real cloud infrastructure.

    411 GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Tirith Migrate

    StackGuardian/tirith

    Translate existing policy-as-code into Tirith policies. An agent skill from StackGuardian/tirith.

    170 GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Official

    Analyze Terraform plan JSON output for AzureRM Provider to distinguish between false-positive diffs (order-only changes in Set-type attributes) and actual resource changes.

    40k GitHub starsUsed in 1 repo~547 tokens
    DevOps & CloudAuto-check passed
  • Tirith Standards

    StackGuardian/tirith

    Generate a Tirith policy set for an existing Terraform or OpenTofu repository, covering organization standards such as required tags, naming conventions, allowed regions, permitted resource types…

    170 GitHub stars~2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from Azure/terraform-azurerm-avm-ptn-alz

All 13 skills in this repo
  • Avm Tf Azapi

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform AzAPI resources, provider constraints, ARM schemas, parent IDs, resource types, retries, timeouts, response exports, replacement triggers, and…

    135 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Testing

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior.

    135 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Classifications

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module /…

    135 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Codestyle

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting.

    135 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Conftest

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory.

    135 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Documentation

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform generated README content, header.md, footer.md, examples documentation, terraform-docs inputs, and Avm.Authoring documentation checks.

    135 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Avm Tf Migration

What does Avm Tf Migration do?

A skill your agent uses for AVM Terraform AzureRM-to-AzAPI migrations, state preservation, moved blocks, provider state moves, submodule extraction, upgrade tests, and post-migration specification…. Avm Tf Migration is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization. Use for AVM Terraform AzureRM-to-AzAPI migrations, state preservation, moved blocks, provider state moves, submodule extraction, upgrade tests, and post-migration specification compliance.

When should I use Avm Tf Migration?

Avm Tf Migration fits situations like: AVM Terraform AzureRM-to-AzAPI migrations; state preservation; provider state moves; submodule extraction.

How do I install Avm Tf Migration in Claude Code?

Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-migration -a claude-code`. Or copy the skill folder (.github/skills/avm-tf-migration in Azure/terraform-azurerm-avm-ptn-alz) into .claude/skills/avm-tf-migration in your project. Claude Code loads it when a task matches its description.

How do I install Avm Tf Migration in Codex?

Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-migration -a codex`. Or copy the skill folder (.github/skills/avm-tf-migration in Azure/terraform-azurerm-avm-ptn-alz) into .agents/skills/avm-tf-migration in your project. Codex loads it when a task matches its description.

Can I use Avm Tf Migration in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-migration -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/avm-tf-migration, .gemini/skills/avm-tf-migration, .github/skills/avm-tf-migration and .opencode/skills/avm-tf-migration in your project.

What does Avm Tf Migration need to run?

Going by SKILL.md and its folder, Avm Tf Migration needs the command-line tools its instructions call (terraform).

Does Avm Tf Migration access the network?

SKILL.md names 1 domain. As links in the text: azure.github.io. This is read from the text; nothing was executed.

Is Avm Tf Migration safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Avm Tf Migration use?

Avm Tf Migration is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Avm Tf Migration use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Avm Tf Migration?

Skills that share tags, products or a category with Avm Tf Migration: Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Terrashark (LukasNiessen/terrashark, 714 stars), Provider Verification (mondoohq/mql, 411 stars) and Tirith Migrate (StackGuardian/tirith, 170 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Avm Tf Migration?

Azure (a GitHub organization, an official publisher) maintains it in Azure/terraform-azurerm-avm-ptn-alz, which has 135 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 6, 2026.

Source: Azure/terraform-azurerm-avm-ptn-alz on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.