Agent skill

Atmos Hooks

by cloudposse in cloudposse/atmos

Atmos hooks: lifecycle events, hook kinds, command/store/git/security hooks, step/steps hooks, when: conditions, scoping and overrides, toolchain integration, --skip-hooks, and Atmos Pro/local output

Apache-2.0Auto-check passedDevOps & Cloud

Install Atmos Hooks

skills CLI
$ npx skills add cloudposse/atmos --skill atmos-hooks -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cloudposse/atmos atmos-hooks --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agent-skills/skills/atmos-hooks .claude/skills/atmos-hooks && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
atmos-hooks
GitHub stars
1.4k
Token cost
~2.3k tokens
SKILL.md length
1,018 words
Files
1
Skills in repo
70
Repo updated
First seen
Licence
Apache-2.0

At a glance

Atmos hooks: lifecycle events, hook kinds, command/store/git/security hooks, step/steps hooks, when: conditions, scoping and overrides, toolchain integration, --skip-hooks, and Atmos Pro/local output

  • Tasks that involve Infrastructure as code
  • SKILL.md covers Related Skills, Hook Shape, Lifecycle Events and Conditional Execution with when, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Atmos Hooks is an agent skill from cloudposse/atmos. Atmos hooks: lifecycle events, hook kinds, command/store/git/security hooks, step/steps hooks, when: conditions, scoping and overrides, toolchain integration, --skip-hooks, and Atmos Pro/local output

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Git and Terraform. The repository describes itself as: Atmos is the open-source runtime for infrastructure — it builds, authenticates, and ships Terraform, OpenTofu, Packer, Ansible, Kubernetes, Helm, and containers the same way on… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Infrastructure as code

Example prompts

  • “Use the atmos-hooks skill to atmo hooks: lifecycle events, hook kinds, command/store/git/security hooks, step/steps hooks, when: conditions, scoping…”
  • “/atmos-hooks”

What it can do on your machine

Read from SKILL.md and the folder at commit fbae93f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Atmos Hooks loads about 2.3k tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 1,018 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cloudposse/atmos at commit fbae93f, republished under its Apache-2.0 licence (© cloudposse). 1,018 words, ~2,329 tokens.

Download SKILL.mdSave it as .claude/skills/atmos-hooks/SKILL.md (or your agent's skills folder).
name
atmos-hooks
description
Atmos hooks: lifecycle events, hook kinds, command/store/git/security hooks, step/steps hooks, when: conditions, scoping and overrides, toolchain integration, --skip-hooks, and Atmos Pro/local output
metadata.copyright
Copyright Cloud Posse, LLC 2026
metadata.version
1.0.0
metadata.category
ci-automation

Atmos Hooks

Use this skill for lifecycle hooks that run before or after component operations, or for generation hooks declared in a scaffold template.

Hooks can run scanners, policy checks, store writes, Git actions, custom commands, or other toolchain-aware automation around Terraform, Helm, Kubernetes, and other component commands.

NeedLoad
Store output hooksatmos-stores
Shared step fields and kind: step payloadsatmos-steps
Post-deployment smoke tests and integration checksatmos-tests
Git hooks and GitOps repositoriesatmos-git
Tool installation for hook commandsatmos-toolchain
TFLint hooks, standalone linting, and rule configurationatmos-lint
CI summaries and Atmos Pro uploadatmos-ci and atmos-pro

Hook Shape

Hooks are configured in stack manifests at global, component-type, or component scope.

yaml
hooks:
  store-vpc-outputs:
    events:
      - after.terraform.apply
    kind: store
    name: prod/ssm
    outputs:
      vpc_id: .vpc_id

components:
  terraform:
    vpc:
      hooks:
        scan-plan:
          events:
            - after.terraform.plan
          kind: trivy

Modern dotted event names such as after.terraform.plan are preferred. Legacy hyphenated event names may appear in older stacks; modernize them when editing nearby config.

Lifecycle Events

Use before/after events for component operations, for example:

  • before.terraform.init, after.terraform.init
  • before.terraform.plan, after.terraform.plan
  • before.terraform.apply, after.terraform.apply
  • before.terraform.deploy, after.terraform.deploy
  • before.terraform.test, after.terraform.test
  • before.terraform.output, after.terraform.output — fires for atmos terraform output, useful for backfilling a store from already-deployed infrastructure without an apply
  • before.terraform.refresh, after.terraform.refresh

Kubernetes provides before/after events for render, diff/plan, apply/deploy, delete, and validate. Native Helm provides template, diff, apply/deploy, and delete; Helmfile provides template, diff, apply/sync/deploy, and destroy. Use the canonical dotted events and remember that command aliases normalize to their execution event (deploy to apply, Kubernetes plan to diff, and Helmfile sync to apply).

Scaffold templates use the separate before.scaffold.generate and after.scaffold.generate events. They reuse the condition vocabulary but can run only kind: step and kind: steps; do not configure stack-only kinds in spec.hooks.

Multi-component DAG runs (e.g. --affected, --query, or workflows that fan out across several components) also fire aggregate events once for the whole run, in addition to the per-component events fired for each individual component: after.terraform.plan.aggregate, after.terraform.apply.aggregate, and after.terraform.destroy.aggregate. Use a per-component event for component-specific behavior (scans, store writes) and an aggregate event for run-level summaries or notifications that should fire only once.

Conditional Execution with when

Hooks share the same when: condition engine as workflow steps: predicate keywords (ci, local, always, never, success, failure) or a CEL expression built from runtime facts such as stack and component. For example, restrict a hook to CI runs against the prod stack:

yaml
hooks:
  prod-ci-scan:
    events:
      - after.terraform.plan
    kind: trivy
    when: stack == "prod" && ci

See atmos-workflows for the full when:/CEL syntax reference.

Hook Kinds

Stack lifecycle hooks support command, store, git, tflint, infracost, trivy, checkov, kics, and the step bridge. The legacy ci.* hook kinds still parse but are deprecated no-ops; use the current CI provider bindings instead. Use a named kind when Atmos has one; use command for a project-specific binary. The legacy command: discriminator and hyphenated events remain compatibility input only; author new configuration with kind: and dotted events.

Hooks can use dependencies.tools so required scanners or CLIs are installed and placed on PATH for the hook execution context.

When the hook declares the required binary in dependencies.tools, do not add a separate atmos toolchain install step. Atmos resolves, installs, and injects the tool before the hook fires.

Step-Backed Hook Kinds

Hooks can also delegate to the same step-type registry that workflows, custom commands, and cast recordings use, instead of one of the named kinds above:

  • kind: step runs one registered step type. Set the step type with the hook's type: field and configure it with with:, exactly like a workflow step.
  • kind: steps runs an ordered list of registered step types, provided as a YAML list under with:.

Hook step lists run in order. A type: test group can contain parallel or matrix checks; see atmos-tests.

The hook envelope owns events, when, env, retry, and on_failure; with: is decoded and validated as the step's own configuration. kind: step supplies the one step type through the hook's type:; kind: steps supplies type-bearing objects in its ordered with: list.

yaml
hooks:
  check-prereqs:
    events:
      - before.terraform.plan
    kind: step
    type: require
    with:
      tools:
        - kubectl
        - helm

  bring-up-and-plan:
    events:
      - before.terraform.plan
    kind: steps
    with:
      - type: emulator
        command: up
      - type: atmos
        command: terraform plan vpc

Use kind: step/kind: steps when you need a registered step type (container, emulator, require, atmos, shell, and other types workflows support) inside a hook; use the older named kinds (trivy, checkov, kics, infracost) when Atmos already ships a purpose-built scanner integration for the job.

Show full SKILL.md (348 more words)Show less
Working directory in kind: step/kind: steps

A step's relative paths (source, destination, path, files, context, and other step-specific fields) resolve against with: { working_directory: ... } when set, or the component's own working directory when unset. This is the only surface where working_directory is ever component-relative -- workflows and custom commands always resolve relative values against the current working directory, since neither is scoped to a single component.

An explicit working_directory: value resolves differently depending on its shape:

ValueResolves against
Not setThe component's working directory (a provisioned/vendored working copy when one exists, otherwise the in-repo source directory)
., .., ./foo, ../fooThe directory Atmos was run from
foo, foo/barThe component's working directory + foo (or foo/bar)
/absolute/pathUsed as-is

A plain relative value (foo) behaves like the unset default -- component-relative. A ./- or ../-prefixed value is an explicit signal to anchor to the directory Atmos was run from instead.

Scaffold hooks (before.scaffold.generate/after.scaffold.generate) follow the same shape, but anchor to the scaffold's target/output directory (atmos scaffold generate <template> <target>'s target) instead of a component's working directory -- there is no component in a scaffold run. An unset or bare-relative working_directory: defaults to/anchors under target; the target directory is also exposed to hook templates as {{ .TargetPath }}. Use working_directory: "." to opt back into running the hook in the directory Atmos was launched from. This default excludes type: atmos steps: a nested atmos invocation must keep resolving its own atmos.yaml/stacks against the directory Atmos was launched from, so it keeps the ambient cwd unless working_directory: is set explicitly.

Operational Guidance

  • Use hooks for repeatable lifecycle behavior, not one-off local scripts.
  • Scope hooks as narrowly as possible: component hooks for component-specific behavior, shared mixins/defaults for organization-wide checks.
  • Use --skip-hooks to bypass all hooks for a diagnostic run, or --skip-hooks=name1,name2 to skip specific hooks by name. This flag is registered on the terraform command only today; there is no helmfile or packer equivalent yet.
  • Treat hook output as part of CI evidence. When Atmos Pro is connected and the hook kind supports upload, prefer structured upload; otherwise rely on local/CI summaries.
  • Keep destructive hooks opt-in and visible in stack config.

© cloudposse, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in agent-skills/skills/atmos-hooks of cloudposse/atmos.

Open the folder on GitHubat commit fbae93f

Compare with similar skills

Atmos Hooks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Atmos Hooks compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Atmos Hooks this skillcloudposse/atmos1.4k—~2.3kAutomated safety check: PassApache-2.0
Datadog Data Source GeneratorDataDog/terraform-provider-datadog468—~2.7kAutomated safety check: PassMPL-2.0
Carefulyonatangross/orchestkit290—~1.2kAutomated safety check: PassMIT
Review Docshashicorp/terraform-provider-aws11k—~1.3kAutomated safety check: PassMPL-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT

Similar skills

  • Datadog Data Source Generator

    DataDog/terraform-provider-datadog

    Official

    Generates a Datadog Terraform provider data source from an OpenAPI operation with tfgen and opens a review-ready GitHub PR with a risk scan and testing guide.

    468 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Careful

    yonatangross/orchestkit

    Blocks destructive shell commands once invoked: a PreToolUse Bash guard denies rm -rf outside temp dirs, force pushes and remote branch deletes, git reset --hard, DROP TABLE / DROP DATABASE /…

    290 GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Review Docs

    hashicorp/terraform-provider-aws

    Official

    Review a Terraform AWS Provider PR's end-user documentation (website/docs//.markdown): whether docs are needed, description openings, argument/attribute style, section structure, tags wording, code…

    11k GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes

More from cloudposse/atmos

All 70 skills in this repo
  • Fix Log

    cloudposse/atmos

    A skill your agent uses when implementing, finishing, documenting, or reviewing a fix, repair, remediation, bug fix, debug-and-fix task, workflow fix, infrastructure fix, or any change that should…

    1.4k GitHub stars~685 tokensUpdated today
    Auto-check passed
  • Atmos Lint

    cloudposse/atmos

    Atmos Terraform linting with TFLint: standalone atmos terraform lint, component-aware config discovery and toolchain versions, TFLint rule configuration, and lifecycle hooks/CI findings.

    1.4k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Changelog

    cloudposse/atmos

    Blog post authoring for Atmos: MDX template, frontmatter, website/blog/tags.yml and authors.yml rules, problem-first framing, backtick-opening ban, optional cast embeds, and no-Go-internals leakage.

    1.4k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Editions

    cloudposse/atmos

    Decide whether a PR's new or changed default needs edition-journal handling (pkg/edition, docs/prd/editions.md), and do the mechanical work if so: journal entries, the four-layer default check…

    1.4k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Atmos Migration

    cloudposse/atmos

    Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…

    1.4k GitHub stars~5.1k tokensUpdated today
    Auto-check: warnings
  • PR Maintenance Loop

    cloudposse/atmos

    Start an hourly background loop that keeps the current branch's PR rebased, its addressed CodeRabbit threads resolved, its CI checks passing, its lint clean, its tests passing with adequate patch…

    1.4k GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Atmos Hooks

What does Atmos Hooks do?

Atmos hooks: lifecycle events, hook kinds, command/store/git/security hooks, step/steps hooks, when: conditions, scoping and overrides, toolchain integration, --skip-hooks, and Atmos Pro/local output. Atmos Hooks is an agent skill from cloudposse/atmos.

When should I use Atmos Hooks?

Atmos Hooks fits situations like: tasks that involve Infrastructure as code.

How do I install Atmos Hooks in Claude Code?

Run `npx skills add cloudposse/atmos --skill atmos-hooks -a claude-code`. Or copy the skill folder (agent-skills/skills/atmos-hooks in cloudposse/atmos) into .claude/skills/atmos-hooks in your project. Claude Code loads it when a task matches its description.

How do I install Atmos Hooks in Codex?

Run `npx skills add cloudposse/atmos --skill atmos-hooks -a codex`. Or copy the skill folder (agent-skills/skills/atmos-hooks in cloudposse/atmos) into .agents/skills/atmos-hooks in your project. Codex loads it when a task matches its description.

Can I use Atmos Hooks in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cloudposse/atmos --skill atmos-hooks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/atmos-hooks, .gemini/skills/atmos-hooks, .github/skills/atmos-hooks and .opencode/skills/atmos-hooks in your project.

What does Atmos Hooks need to run?

SKILL.md names no scripts, command-line tools or credentials: Atmos Hooks is instructions for the agent only.

Does Atmos Hooks access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Atmos Hooks safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Atmos Hooks use?

Atmos Hooks is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Atmos Hooks use?

About 2.3k tokens (SKILL.md is roughly 9.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Atmos Hooks?

Skills that share tags, products or a category with Atmos Hooks: Datadog Data Source Generator (DataDog/terraform-provider-datadog, 468 stars), Careful (yonatangross/orchestkit, 290 stars), Review Docs (hashicorp/terraform-provider-aws, 11k stars) and Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Atmos Hooks?

cloudposse (a GitHub organization) maintains it in cloudposse/atmos, which has 1,398 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on October 9, 2026.

Source: cloudposse/atmos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.