Official agent skill

Avm Tf Testing

by Azure in Azure/terraform-azurerm-avm-ptn-alz

A skill your agent uses for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior.

OfficialMITAuto-check passedTesting & QA

Install Avm Tf Testing

skills CLI
$ npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-testing -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Azure/terraform-azurerm-avm-ptn-alz avm-tf-testing --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Azure/terraform-azurerm-avm-ptn-alz.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/avm-tf-testing .claude/skills/avm-tf-testing && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
avm-tf-testing
GitHub stars
135
Token cost
~1.8k tokens
SKILL.md length
787 words
Files
3 (incl. references)
Skills in repo
13
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior.

  • Works in 5 steps: Terraform initialization; → deployment; → a no-change idempotency plan; → …
  • AVM Terraform validation
  • SKILL.md covers Test surfaces, Unit tests, Integration tests and E2E examples, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Avm Tf Testing is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization. Use for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/example-test.md` and `references/terraform-test.md`).

It sits in Testing & QA, covering Infrastructure as code, Integration testing and End-to-end testing. It works with Microsoft Azure, Terraform and PowerShell. The repository describes itself as: Terraform Azure Verified Pattern Module for Azure Landing Zone Management Groups and Policy. The licence is MIT.

When your agent uses it

  • AVM Terraform validation
  • Provider-mocked unit tests
  • Real-Azure integration tests
  • E2E example tests

Example prompts

  • “/avm-tf-testing”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Terraform initialization;
  2. deployment;
  3. a no-change idempotency plan;
  4. cleanup; and
  5. bounded retries for recognized capacity failures.

What it can do on your machine

Read from SKILL.md and the folder at commit e2a318c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are powershell and hcl).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Avm Tf Testing loads about 1.8k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 49 tokens; SKILL.md has 787 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~49
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Azure/terraform-azurerm-avm-ptn-alz at commit e2a318c, republished under its MIT licence (© Azure). 787 words, ~1,770 tokens.

Download SKILL.mdSave it as .claude/skills/avm-tf-testing/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
avm-tf-testing
description
Use for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior.

AVM Terraform Testing

Use PowerShell 7.4 or later with the Avm.Authoring module. The old repository launcher, Make targets, Porch flags, and container workflow are retired.

pwsh
Install-PSResource -Name Avm.Authoring -Repository PSGallery -TrustRepository
Import-Module Avm.Authoring
avm version

Test surfaces

SurfaceCommandPurpose
Terraform validationavm testRun Terraform initialization when needed and validate the module.
Unit testsavm test unitRun tests/unit/*.tftest.hcl with mocked providers.
Integration testsavm test integrationRun tests/integration/*.tftest.hcl against real Azure.
E2E examplesavm test e2eApply, idempotency-check, and destroy runnable examples/*.
Policyavm check policyBuild example plan JSON and evaluate APRL and AVMSEC through Conftest.
Full PR gateavm pr-checkRun the clean-worktree PR gauntlet; it does not replace standalone test tiers.

Always name the tier when tests are expected. Bare avm test validates Terraform; it does not run unit, integration, and E2E suites.

For Conftest findings or files under examples/<name>/exceptions, read avm-tf-conftest before changing Rego or suppressing a policy.

Unit tests

Place tests in tests/unit. Mock every provider declared by the module:

Every new resource-deploying module therefore mocks azapi. Declare or mock azurerm only when a test configures or exercises independently justified azurerm_* exception blocks.

hcl
mock_provider "azapi" {}
mock_provider "modtm" {}
mock_provider "random" {}

run "creates_the_resource" {
  command = apply

  variables {
    name      = "example"
    parent_id = "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/example"
  }

  assert {
    condition     = output.resource_id != null
    error_message = "The module should return the primary resource ID."
  }
}

Use mocked apply so computed values and resource creation paths can be asserted without Azure. Add focused tests for:

  • defaults and optional features;
  • validation failures with expect_failures;
  • conditional resources;
  • outputs;
  • parent-to-submodule propagation; and
  • resource_types, retry, timeouts, and ignore_body_changes wiring.

For detailed .tftest.hcl syntax, mocking, assertions, and troubleshooting patterns, see the Terraform test reference.

Integration tests

Place real-Azure Terraform tests in tests/integration. Do not mock providers. Keep each run focused, use unique names, and verify behaviors that cannot be proven from a mocked plan.

Test configurations, fixtures, and setup or teardown Terraform use AzAPI for every control-plane and ordinary supporting resource. If test scaffolding needs a direct Azure dependency that the module under test does not create, use an AzAPI resource, data source, or action and include Azure/azapi in that Terraform root's required_providers.

AzureRM may be configured or exercised only when required by permitted azurerm_* resource or data-source blocks. Each block must independently implement one specific unsupported data-plane/non-ARM operation, document the exact block and why no applicable AzAPI resource or action can implement it, link the upstream AzAPI issue or pull request, and be replaced when support ships. One valid block does not authorize another.

Authenticate without committed secrets. Local runs can use an authenticated Azure CLI session or supported ARM_* environment variables. CI uses OIDC with least-privilege identities and protected environments.

E2E examples

Each direct child of examples/ is a standalone Terraform root. Discover and target examples with:

pwsh
avm test e2e --list
avm test e2e --example default

Without --example, runnable examples execute sequentially. A .e2eignore marker excludes an example from discovery. E2E performs:

  1. Terraform initialization;
  2. deployment;
  3. a no-change idempotency plan;
  4. cleanup; and
  5. bounded retries for recognized capacity failures.

An idempotency diff is a failure and is never hidden by a retry.

Every runnable example and E2E configuration uses AzAPI for direct Azure setup and control-plane resources, and its required_providers includes Azure/azapi. It may include AzureRM only to configure or exercise independently justified unsupported data-plane/non-ARM blocks. A legacy /azurerm suffix in a published AVM module source is a Registry namespace and is not an AzureRM provider declaration.

For exceptional manual workflows such as distributing examples across subscriptions or retaining deployments for inspection, see the manual example-testing reference.

Show full SKILL.md (245 more words)Show less

PowerShell hooks

Supported hooks run in isolated pwsh processes:

  • tests/unit/setup.ps1;
  • tests/integration/setup.ps1;
  • examples/<name>/pre.ps1;
  • examples/<name>/post.ps1; and
  • examples/<name>/tflint-pre.ps1.

Shell equivalents such as setup.sh, pre.sh, post.sh, or tflint-pre.sh are rejected as configuration errors. Port all hooks to PowerShell.

Use hooks only for required environment preparation or cleanup. Keep Terraform assertions in Terraform tests.

Authoring gates

Before committing:

pwsh
avm pre-commit

For Terraform this applies sync, fixable convention rules, transforms, formatting, and docs. It is not a substitute for unit or real-Azure tests.

After reviewing and committing all changes:

pwsh
avm pr-check

The worktree must be clean. PR check runs sync, format, transform, lint, policy, convention, validation, and docs. Unit tests are deliberately a separate reusable-workflow job rather than repeated inside PR check.

CI expectations

  • Use the governance-managed reusable Terraform workflow.
  • Use OIDC and a user-assigned identity or equivalent secretless federation.
  • Keep test environments least privilege and isolate subscriptions where practical.
  • Treat skipped as different from pass. If the change requires a test tier, an undiscovered or skipped tier is not evidence.
  • Preserve logs for failed Terraform run blocks, plans, policy findings, and cleanup failures.

Debugging

Run the smallest command that reproduces the issue:

pwsh
avm test unit
avm test integration
avm test e2e --example default
avm lint
avm check policy

Use -Path <module-directory> when testing a module outside the current directory and -Ecosystem terraform when context detection is ambiguous. Use --passthru for structured results in automation. Command failures throw; do not rely on $LASTEXITCODE or parse friendly console output.

When direct Terraform debugging is necessary, keep its flags consistent with the authoring engine and return to the avm command for final validation.

© Azure, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in .github/skills/avm-tf-testing of Azure/terraform-azurerm-avm-ptn-alz.

  • SKILL.md
  • references/example-test.md
  • references/terraform-test.md

Open the folder on GitHubat commit e2a318c

Compare with similar skills

Avm Tf Testing next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Avm Tf Testing compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Avm Tf Testing this skillAzure/terraform-azurerm-avm-ptn-alz135—~1.8kAutomated safety check: PassMIT
Review Testshashicorp/terraform-provider-aws11k—~908Automated safety check: PassMPL-2.0
Review Tests Helpershashicorp/terraform-provider-aws11k—~994Automated safety check: PassMPL-2.0
Atmos Migrationcloudposse/atmos1.4k—~5.1kAutomated safety check: WarnApache-2.0
Oma Tf Infrafirst-fluke/oh-my-agent1.3k—~2.8kAutomated safety check: PassMIT
Terraform Mock Testaztfmod/terraform-provider-azurecaf188—~553Automated safety check: PassMIT

Similar skills

  • Review Tests

    hashicorp/terraform-provider-aws

    Official

    Review Terraform AWS Provider acceptance and unit test basics: required basic and disappears tests, TestAcc naming, TestCase essentials (PreCheck/ErrorCheck/ProtoV5ProviderFactories/CheckDestroy)…

    11k GitHub stars~908 tokensUpdated today
    Testing & QAAuto-check passed
  • Review Tests Helpers

    hashicorp/terraform-provider-aws

    Official

    Review Terraform AWS Provider test helpers: Exists/Destroy check functions, exportstest.go wiring, create.Error wrapping, data source tests, list resource tests (querycheck + Terraform version…

    11k GitHub stars~994 tokensUpdated today
    Testing & QAAuto-check passed
  • Atmos Migration

    cloudposse/atmos

    Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…

    1.4k GitHub stars~5.1k tokensUpdated today
    DevOps & CloudAuto-check: warnings
  • Oma Tf Infra

    first-fluke/oh-my-agent

    Infrastructure-as-code specialist for multi-cloud provisioning using Terraform across any provider (AWS, GCP, Azure, Oracle Cloud).

    1.3k GitHub stars~2.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Terraform Mock Test

    aztfmod/terraform-provider-azurecaf

    Validate a resource definition end-to-end using terraform test with mockprovider azurerm.

    188 GitHub stars~553 tokensUpdated 17 days ago
    DevOps & CloudAuto-check passed
  • Azure Firmware Analysis

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Firmware Analysis development including best practices, security, integrations & coding patterns, and deployment.

    777 GitHub stars~1.2k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from Azure/terraform-azurerm-avm-ptn-alz

All 13 skills in this repo
  • Avm Tf Azapi

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform AzAPI resources, provider constraints, ARM schemas, parent IDs, resource types, retries, timeouts, response exports, replacement triggers, and…

    135 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Classifications

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses whenever a contributor is deciding what KIND of Azure Verified Module to build in Terraform — resource module, pattern module, or utility module — or is naming a module /…

    135 GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Codestyle

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform file layout, HCL style, variables, outputs, validation, lifecycle syntax, provider requirements, and Avm.Authoring formatting.

    135 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Conftest

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses whenever an AVM Terraform task involves Conftest, OPA, Rego, APRL, AVMSEC, policy findings, policy exceptions, or files under an example exceptions directory.

    135 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Documentation

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform generated README content, header.md, footer.md, examples documentation, terraform-docs inputs, and Avm.Authoring documentation checks.

    135 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed
  • Avm Tf Interfaces

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses for AVM Terraform diagnostic settings, role assignments, locks, managed identities, private endpoints, customer-managed keys, tags, and AzAPI control interfaces.

    135 GitHub stars~1.8k tokensUpdated 2 days ago
    Auto-check passed

Questions about Avm Tf Testing

What does Avm Tf Testing do?

A skill your agent uses for AVM Terraform validation, provider-mocked unit tests, real-Azure integration tests, E2E example tests, PowerShell hooks, OIDC, policy checks, and Avm.Authoring CI behavior. Avm Tf Testing is an agent skill from Azure/terraform-azurerm-avm-ptn-alz, published by the product's own GitHub organization.Authoring CI behavior.

When should I use Avm Tf Testing?

Avm Tf Testing fits situations like: AVM Terraform validation; provider-mocked unit tests; real-Azure integration tests; E2E example tests.

How do I install Avm Tf Testing in Claude Code?

Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-testing -a claude-code`. Or copy the skill folder (.github/skills/avm-tf-testing in Azure/terraform-azurerm-avm-ptn-alz) into .claude/skills/avm-tf-testing in your project. Claude Code loads it when a task matches its description.

How do I install Avm Tf Testing in Codex?

Run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-testing -a codex`. Or copy the skill folder (.github/skills/avm-tf-testing in Azure/terraform-azurerm-avm-ptn-alz) into .agents/skills/avm-tf-testing in your project. Codex loads it when a task matches its description.

Can I use Avm Tf Testing in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Azure/terraform-azurerm-avm-ptn-alz --skill avm-tf-testing -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/avm-tf-testing, .gemini/skills/avm-tf-testing, .github/skills/avm-tf-testing and .opencode/skills/avm-tf-testing in your project.

What does Avm Tf Testing need to run?

SKILL.md names no scripts, command-line tools or credentials: Avm Tf Testing is instructions for the agent only.

Does Avm Tf Testing access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Avm Tf Testing safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Avm Tf Testing use?

Avm Tf Testing is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Avm Tf Testing use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4k tokens, read only when the agent opens those files.

What are the alternatives to Avm Tf Testing?

Skills that share tags, products or a category with Avm Tf Testing: Review Tests (hashicorp/terraform-provider-aws, 11k stars), Review Tests Helpers (hashicorp/terraform-provider-aws, 11k stars), Atmos Migration (cloudposse/atmos, 1.4k stars) and Oma Tf Infra (first-fluke/oh-my-agent, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Avm Tf Testing?

Azure (a GitHub organization, an official publisher) maintains it in Azure/terraform-azurerm-avm-ptn-alz, which has 135 GitHub stars. The repository holds 13 skills in this directory. The repository was last updated on October 6, 2026.

Source: Azure/terraform-azurerm-avm-ptn-alz on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.