Official agent skill

Avm Tf Submodules

by Azure in Azure/terraform-azurerm-avm-ptn-alz

A skill your agent uses for AVM Terraform ARM subresources implemented as local submodules, including cardinality, parentid, resourcetypes, retry, timeouts, ignorebodychanges, outputs, files, and…

OfficialMITAuto-check passedDevOps & Cloud

Install Avm Tf Submodules

skills CLI
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-submodules -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-submodules --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/avm-tf-submodules .claude/skills/avm-tf-submodules && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
avm-tf-submodules
GitHub stars
135
Token cost
~2k tokens
SKILL.md length
464 words
Files
1
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses for AVM Terraform ARM subresources implemented as local submodules, including cardinality, parentid, resourcetypes, retry, timeouts, ignorebodychanges, outputs, files, and…

  • AVM Terraform ARM subresources implemented as local submodules
  • SKILL.md covers Cardinality, Required files, Parent ID and resource_types, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Including cardinality

What it does

Avm Tf Submodules is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization. Use for AVM Terraform ARM subresources implemented as local submodules, including cardinality, parentid, resourcetypes, retry, timeouts, ignorebodychanges, outputs, files, and tests.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Terraform and Microsoft Azure. The repository describes itself as: Terraform Azure Verified Pattern Module for Azure Landing Zone Management Groups and Policy. The licence is MIT.

When your agent uses it

  • AVM Terraform ARM subresources implemented as local submodules
  • Including cardinality
  • Ignorebodychanges

Example prompts

  • “/avm-tf-submodules”

What it can do on your machine

Read from SKILL.md and the folder at commit e2a318c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are hcl).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • azure.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Avm Tf Submodules loads about 2k tokens when it runs. Until then it costs about 51 tokens; SKILL.md has 464 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~51
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/terraform-azurerm-avm-ptn-alz at commit e2a318c, republished under its MIT licence (© Azure). 464 words, ~1,993 tokens.

Download SKILL.mdSave it as .claude/skills/avm-tf-submodules/SKILL.md (or your agent's skills folder).
name
avm-tf-submodules
description
Use for AVM Terraform ARM subresources implemented as local submodules, including cardinality, parent_id, resource_types, retry, timeouts, ignore_body_changes, outputs, files, and tests.

AVM Terraform Submodules

TFRMNFR1 requires each ARM subresource to be implemented as a full local submodule under modules/<singular-name>/. Read TFRMNFR1 together with TFRMFR1, TFRMNFR2, TFFR6-TFFR8, TFNFR38, and TFNFR39 through https://azure.github.io/Azure-Verified-Modules/llms.txt.

Every new submodule that deploys an Azure resource MUST use AzAPI for every control-plane and supported direct Azure operation. Do not declare or configure hashicorp/azurerm, and do not create any azurerm_* resource or data source for convenience or supporting infrastructure in a submodule or its examples, tests, fixtures, or setup Terraform.

Cardinality

The parent owns for_each or count; the child primary resource owns one instance:

hcl
module "part" {
  source   = "./modules/part"
  for_each = var.parts

  name                = each.value.name
  parent_id           = azapi_resource.this.id
  resource_types      = var.resource_types.example_widgets_parts
  retry               = var.retry
  timeouts            = var.timeouts
  ignore_body_changes = var.ignore_body_changes.example_widgets_parts
}
hcl
# modules/part/main.tf
resource "azapi_resource" "this" {
  type      = var.resource_types.example_widgets_parts
  name      = var.name
  parent_id = var.parent_id

  body = {
    properties = var.properties
  }

  ignore_body_changes    = length(var.ignore_body_changes.example_widgets_parts) > 0 ? var.ignore_body_changes.example_widgets_parts : null
  response_export_values = []
  retry                  = var.retry

  dynamic "timeouts" {
    for_each = var.timeouts == null ? [] : [var.timeouts]
    content {
      create = timeouts.value.create
      read   = timeouts.value.read
      update = timeouts.value.update
      delete = timeouts.value.delete
    }
  }
}

Do not add count or for_each to the child's primary resource.

Required files

Every submodule follows TFNFR39 and the applicable documentation, telemetry, and testing requirements:

text
modules/part/
  _footer.md
  _header.md
  main.tf
  main.telemetry.tf
  outputs.tf
  README.md          # generated
  terraform.tf
  variables.tf
  locals.tf        # when locals exist
  tests/
    unit/
    integration/

Additional files use canonical prefixes such as main.role_assignments.tf. The submodule declares every provider it consumes in its own terraform.tf; AzAPI is required. Each permitted azurerm_* resource or data-source block must independently implement one specific unsupported data-plane/non-ARM operation, document the exact block and AzAPI gap with an upstream AzAPI issue or pull request, and be replaced when support ships. One valid block does not authorize another.

Parent ID

Each submodule exposes required, non-null parent_id and assigns it to its primary resource:

hcl
variable "parent_id" {
  type        = string
  nullable    = false
  description = "The fully-qualified ARM resource ID of the existing widget that will contain the part."

  validation {
    condition     = can(provider::azapi::parse_resource_id("Microsoft.Example/widgets", var.parent_id))
    error_message = "`parent_id` must be a valid widget resource ID."
  }
}

The parent normally passes azapi_resource.this.id. Do not replace this contract with resource_group_name, subscription IDs, or data-source reconstruction.

resource_types

The child owns its tested API-version default:

hcl
# modules/part/variables.tf
variable "resource_types" {
  type = object({
    example_widgets_parts = optional(string, "Microsoft.Example/widgets/parts@2024-01-01")
  })
  default  = {}
  nullable = false
  description = <<DESCRIPTION
AzAPI resource types and API versions used by the part submodule.

- `example_widgets_parts` - Resource type and API version for the part.
DESCRIPTION
}

The parent mirrors the complete child shape but does not repeat child string defaults:

hcl
variable "resource_types" {
  type = object({
    example_widgets = optional(string, "Microsoft.Example/widgets@2024-01-01")

    example_widgets_parts = optional(object({
      example_widgets_parts = optional(string)
    }), {})
  })
  default  = {}
  nullable = false
  description = <<DESCRIPTION
AzAPI resource types and API versions used by the module.

- `example_widgets` - Resource type and API version for the widget.
- `example_widgets_parts` - Resource-type overrides passed to the part submodule.
- `example_widgets_parts.example_widgets_parts` - Resource type and API-version override for the part.
DESCRIPTION
}

Pass var.resource_types.example_widgets_parts unchanged to the child. Document every owned-resource field and every nested submodule field in each variable description.

retry and timeouts

The parent cascades these resource-agnostic TFFR7 values unchanged. The child declares the same schemas and applies them to every AzAPI resource it owns.

Do not hard-code retry or timeout values that consumers cannot override.

Show full SKILL.md (169 more words)Show less

ignore_body_changes

Paths are specific to one resource body, so the parent exposes a child-shaped nested slot:

hcl
variable "ignore_body_changes" {
  type = object({
    example_widgets = optional(list(string), [])

    example_widgets_parts = optional(object({
      example_widgets_parts = optional(list(string), [])
    }), {})
  })
  default  = {}
  nullable = false
  description = <<DESCRIPTION
Body-relative paths ignored for root and part resources. Paths use dot notation.
Changes take effect only after apply. Ignored configuration is not sent to Azure.

- `example_widgets` - Paths ignored on the widget resource.
- `example_widgets_parts` - Paths passed to the part submodule.
- `example_widgets_parts.example_widgets_parts` - Paths ignored on the part resource.
DESCRIPTION
}

The child's variable contains its own field:

hcl
variable "ignore_body_changes" {
  type = object({
    example_widgets_parts = optional(list(string), [])
  })
  default  = {}
  nullable = false
  description = <<DESCRIPTION
Body-relative paths ignored on the part resource. Paths use dot notation.
Changes take effect only after apply. Ignored configuration is not sent to Azure.

- `example_widgets_parts` - Paths ignored on the part resource.
DESCRIPTION
}

Pass the nested slot unchanged. Do not pass the parent's example_widgets list to the child.

Outputs

The single-instance child exposes a scalar resource ID:

hcl
output "resource_id" {
  value       = azapi_resource.this.id
  description = "The resource ID of the part."
}

The parent aggregates naturally from the for_each module call:

hcl
output "part_resource_ids" {
  value       = { for key, part in module.part : key => part.resource_id }
  description = "A map of part resource IDs keyed by the input map."
}

Prefer discrete outputs over whole-resource output objects.

Documentation and tests

  • Author _header.md and _footer.md; generate each README.md with avm docs or avm pre-commit.
  • Add provider-mocked unit tests for child logic and parent aggregation.
  • Add real-Azure integration coverage where ARM behavior matters.
  • Exercise representative child instances through an E2E example.
  • Verify parent and child resource IDs, nested interface propagation, and idempotency.

Migration warning

Extracting an existing root collection into a for_each submodule changes addresses from resource.type["key"] to module.child["key"].resource.this. A generic reusable moved block cannot preserve arbitrary consumer keys across that resource-to-module boundary.

Prefer an in-place provider migration first, or publish explicit state migration steps and classify the extraction as breaking when required. See avm-tf-migration.

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/avm-tf-submodules of Azure/terraform-azurerm-avm-ptn-alz.

Open the folder on GitHubat commit e2a318c

Compare with similar skills

Avm Tf Submodules next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Avm Tf Submodules compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Avm Tf Submodules this skillAzure/terraform-azurerm-avm-ptn-alz135—~2kAutomated safety check: PassMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
TerrasharkLukasNiessen/terrashark714—~843Automated safety check: PassMIT
Provider Verificationmondoohq/mql411—~3.7kAutomated safety check: PassCustom licence
Tirith MigrateStackGuardian/tirith170—~1.7kAutomated safety check: PassApache-2.0
Terraform Azurerm Set Diff Analyzergithub/awesome-copilot40k1 repos~547Automated safety check: PassMIT

Similar skills

  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Terrashark

    LukasNiessen/terrashark

    Prevent Terraform/OpenTofu hallucinations by diagnosing and fixing failure modes: identity churn, secret exposure, blast-radius mistakes, CI drift, and compliance gate gaps.

    714 GitHub stars~843 tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Verify mql provider resource/field changes against real cloud infrastructure.

    411 GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Tirith Migrate

    StackGuardian/tirith

    Translate existing policy-as-code into Tirith policies. An agent skill from StackGuardian/tirith.

    170 GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Official

    Analyze Terraform plan JSON output for AzureRM Provider to distinguish between false-positive diffs (order-only changes in Set-type attributes) and actual resource changes.

    40k GitHub starsUsed in 1 repo~547 tokens
    DevOps & CloudAuto-check passed
  • Tirith Standards

    StackGuardian/tirith

    Generate a Tirith policy set for an existing Terraform or OpenTofu repository, covering organization standards such as required tags, naming conventions, allowed regions, permitted resource types…

    170 GitHub stars~2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from Azure/terraform-azurerm-avm-ptn-alz

All 13 skills in this repo
  • Avm Tf Azapi

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform AzAPI resources, provider constraints, ARM schemas, parent IDs, resource types, retries, timeouts, response exports, replacement triggers, and…

    135 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Testing

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior.

    135 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Classifications

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module /…

    135 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Codestyle

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting.

    135 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Conftest

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory.

    135 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Documentation

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform generated README content, header.md, footer.md, examples documentation, terraform-docs inputs, and Avm.Authoring documentation checks.

    135 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Avm Tf Submodules

What does Avm Tf Submodules do?

A skill your agent uses for AVM Terraform ARM subresources implemented as local submodules, including cardinality, parentid, resourcetypes, retry, timeouts, ignorebodychanges, outputs, files, and…. Avm Tf Submodules is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization. Use for AVM Terraform ARM subresources implemented as local submodules, including cardinality, parentid, resourcetypes, retry, timeouts, ignorebodychanges, outputs, files, and tests.

When should I use Avm Tf Submodules?

Avm Tf Submodules fits situations like: AVM Terraform ARM subresources implemented as local submodules; including cardinality; ignorebodychanges.

How do I install Avm Tf Submodules in Claude Code?

Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-submodules -a claude-code`. Or copy the skill folder (.github/skills/avm-tf-submodules in Azure/terraform-azurerm-avm-ptn-alz) into .claude/skills/avm-tf-submodules in your project. Claude Code loads it when a task matches its description.

How do I install Avm Tf Submodules in Codex?

Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-submodules -a codex`. Or copy the skill folder (.github/skills/avm-tf-submodules in Azure/terraform-azurerm-avm-ptn-alz) into .agents/skills/avm-tf-submodules in your project. Codex loads it when a task matches its description.

Can I use Avm Tf Submodules in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-submodules -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/avm-tf-submodules, .gemini/skills/avm-tf-submodules, .github/skills/avm-tf-submodules and .opencode/skills/avm-tf-submodules in your project.

What does Avm Tf Submodules need to run?

SKILL.md names no scripts, command-line tools or credentials: Avm Tf Submodules is instructions for the agent only.

Does Avm Tf Submodules access the network?

SKILL.md names 1 domain. As links in the text: azure.github.io. This is read from the text; nothing was executed.

Is Avm Tf Submodules safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Avm Tf Submodules use?

Avm Tf Submodules is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Avm Tf Submodules use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Avm Tf Submodules?

Skills that share tags, products or a category with Avm Tf Submodules: Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Terrashark (LukasNiessen/terrashark, 714 stars), Provider Verification (mondoohq/mql, 411 stars) and Tirith Migrate (StackGuardian/tirith, 170 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Avm Tf Submodules?

Azure (a GitHub organization, an official publisher) maintains it in Azure/terraform-azurerm-avm-ptn-alz, which has 135 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 6, 2026.

Source: Azure/terraform-azurerm-avm-ptn-alz on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.