Agent skill

Atmos Stacks

by cloudposse in cloudposse/atmos

Stack configuration: local and remote imports, inheritance, deep merging, locals, vars, settings, metadata, overrides, dependencies, and modernization

Apache-2.0Auto-check: notesDevOps & Cloud

Install Atmos Stacks

skills CLI
$ npx skills add cloudposse/atmos --skill atmos-stacks -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cloudposse/atmos atmos-stacks --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agent-skills/skills/atmos-stacks .claude/skills/atmos-stacks && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
atmos-stacks
GitHub stars
1.4k
Token cost
~3k tokens
SKILL.md length
944 words
Files
3 (incl. references)
Skills in repo
70
Repo updated
First seen
Licence
Apache-2.0

At a glance

Stack configuration: local and remote imports, inheritance, deep merging, locals, vars, settings, metadata, overrides, dependencies, and modernization

  • Works in 4 steps: name field in the stack manifest… → name_template in atmos.yaml (Go template). → Legacy name_pattern in atmos.yaml… → …
  • Tasks that involve Legacy modernization
  • SKILL.md covers What Stacks Are, Related Skills, Stack Discovery and Stack Manifest Structure, plus 7 more sections
  • Calls jq and terraform

What it does

Atmos Stacks is an agent skill from cloudposse/atmos. Stack configuration: local and remote imports, inheritance, deep merging, locals, vars, settings, metadata, overrides, dependencies, and modernization

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/import-patterns.md` and `references/inheritance-deep-merge.md`).

It sits in DevOps & Cloud, covering Legacy modernization. It works with Terraform. The repository describes itself as: Atmos is the open-source runtime for infrastructure — it builds, authenticates, and ships Terraform, OpenTofu, Packer, Ansible, Kubernetes, Helm, and containers the same way on… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Legacy modernization

Example prompts

  • “/atmos-stacks”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. name field in the stack manifest (explicit override).
  2. name_template in atmos.yaml (Go template).
  3. Legacy name_pattern in atmos.yaml (migration-only; recommend name_template or explicit name).
  4. File basename (e.g., prod.yaml becomes prod).

What it can do on your machine

Read from SKILL.md and the folder at commit 36726ae. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • jq
    • terraform

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Atmos Stacks loads about 3k tokens when it runs, and up to ~7.9k if it reads all its reference files. Until then it costs about 41 tokens; SKILL.md has 944 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:142
    ings.key }}`, `{{ .vars.key }}`, and `{{ .env.KEY }}`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cloudposse/atmos at commit 36726ae, republished under its Apache-2.0 licence (© cloudposse). 944 words, ~3,050 tokens.

Download SKILL.mdSave it as .claude/skills/atmos-stacks/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
atmos-stacks
description
Stack configuration: local and remote imports, inheritance, deep merging, locals, vars, settings, metadata, overrides, dependencies, and modernization
metadata.copyright
Copyright Cloud Posse, LLC 2026
metadata.version
1.0.0
metadata.category
core-config

Atmos Stack Configuration

Stacks are YAML configuration files that define which components to deploy, with what settings, and how they relate to each other. They separate configuration from infrastructure code, enabling the same Terraform root modules to be deployed across many environments with different settings.

What Stacks Are

A stack manifest is a YAML file that declares components and their configuration for a specific combination of organization, tenant, account, region, and stage. Atmos discovers stack manifests based on included_paths and excluded_paths in atmos.yaml, then deep-merges all imported configurations to produce the final resolved state for each component.

Stacks are not Terraform workspaces, although Atmos derives workspace names from stack names. A single stack manifest can configure multiple components, and a single component can appear across many stacks with different variable values.

NeedLoad
Local and remote import mechanicsatmos-imports
Modernizing legacy stack patternsatmos-modernization
YAML function inventoryatmos-yaml-functions
Component source provisioningatmos-components

Stack Discovery

Atmos discovers stack manifests based on included_paths and excluded_paths configured in the stacks section of atmos.yaml. For root config discovery and routing, see the atmos-config skill; for path layout and base_path behavior, see atmos-project-layout.

Stack Name Precedence

Atmos resolves the stack name using this priority (highest first):

  1. name field in the stack manifest (explicit override).
  2. name_template in atmos.yaml (Go template).
  3. Legacy name_pattern in atmos.yaml (migration-only; recommend name_template or explicit name).
  4. File basename (e.g., prod.yaml becomes prod).

Stack Manifest Structure

A stack manifest can contain the following top-level sections:

yaml
# Optional: explicit stack name override
name: "plat-ue2-prod"

# Import other configurations
import:
  - catalog/vpc/defaults
  - mixins/region/us-east-2
  - orgs/acme/plat/prod/_defaults
  # Remote imports are supported, but they import stack config only:
  # - github://acme/config/main/stacks/catalog/vpc.yaml

# Global-scope sections (apply to all components)
vars: {}
locals: {}
env: {}
settings: {}
hooks: {}
overrides: {}

# Component-type scope (apply to all components of that type)
terraform:
  vars: {}
  env: {}
  settings: {}
  hooks: {}
  backend_type: s3
  backend: {}
  providers: {}
  command: terraform
  overrides: {}

helmfile:
  vars: {}
  env: {}
  settings: {}
  hooks: {}
  command: helmfile
  overrides: {}

# Component definitions
components:
  terraform:
    vpc:
      metadata: {}
      vars: {}
      env: {}
      settings: {}
      hooks: {}
      backend_type: s3
      backend: {}
      providers: {}
      command: terraform
      auth: {}
  helmfile:
    echo-server:
      vars: {}
      env: {}
      settings: {}

Configuration Sections Reference

vars

Variables passed as inputs to Terraform, Helmfile, or Packer components. Defined at global, component-type, or component level. Deep-merged across all levels with component-level values taking precedence.

yaml
vars:
  environment: prod
  region: us-east-1
  tags:
    Environment: Production
    ManagedBy: Atmos

Maps are recursively merged; lists are replaced (not appended).

locals

File-scoped temporary variables for reducing repetition within a single YAML file. Locals do NOT inherit across file imports. They can reference each other using {{ .locals.name }} syntax with automatic dependency resolution.

yaml
locals:
  namespace: acme
  name_prefix: "{{ .locals.namespace }}-{{ .vars.stage }}"

components:
  terraform:
    vpc:
      vars:
        name: "{{ .locals.name_prefix }}-vpc"

Locals can also access settings, vars, and env defined in the same file using {{ .settings.key }}, {{ .vars.key }}, and {{ .env.KEY }}.

env

Environment variables set when executing components. Simple key-value pairs merged shallowly across levels.

yaml
env:
  AWS_PROFILE: acme-prod
  TF_IN_AUTOMATION: "true"
settings

Integration metadata and configuration not passed to Terraform. Used for Atlantis, validation, and other Atmos integrations.

yaml
settings:
  validation:
    check-cidr:
      schema_type: jsonschema
      schema_path: schemas/vpc.json
dependencies:
  components:
    - component: vpc
    - component: dns-zone
      stack: plat-ue2-prod
    - kind: file
      path: configs/service.yaml
metadata

Component-only section that controls Atmos behavior for that component. Cannot be used at global or component-type level.

yaml
components:
  terraform:
    vpc:
      metadata:
        component: vpc           # Terraform root module path
        inherits:
          - vpc/defaults         # Inheritance chain
        type: abstract           # abstract or real (default)
        enabled: true            # Enable/disable component
        locked: false            # Prevent modifications
        terraform_workspace: "custom-ws"
        custom:
          owner: platform-team
hooks

Lifecycle event handlers that execute actions at specific points (e.g., after terraform apply).

yaml
hooks:
  store-outputs:
    events:
      - after-terraform-apply
    command: store
    name: prod/ssm
    outputs:
      vpc_id: .vpc_id
command

Override the executable for a component type or specific component. Useful for OpenTofu, custom wrappers, or version-pinned binaries.

yaml
terraform:
  command: tofu
flags

Default values for terraform CLI execution flags (lock_timeout, lock, parallelism, refresh, compact_warnings). Settable in atmos.yaml (components.terraform.flags), at the stack level (root-level terraform: block), and per component — merged field-by-field, lowest to highest precedence. An explicit CLI-typed flag (-- -lock-timeout=30s) always wins over all three. Terraform-only; not every flag applies to every subcommand.

yaml
terraform:
  flags:
    lock_timeout: "5m"

components:
  terraform:
    vpc:
      flags:
        parallelism: 4
backend

Terraform backend configuration. Atmos generates backend.tf.json automatically.

yaml
terraform:
  backend_type: s3
  backend:
    s3:
      bucket: acme-ue1-root-tfstate
      region: us-east-1
      encrypt: true
      use_lockfile: true
providers

Terraform provider configuration. Atmos generates providers_override.tf.json automatically.

yaml
terraform:
  providers:
    aws:
      region: us-east-1
      assume_role:
        role_arn: "arn:aws:iam::{{ .vars.account_id }}:role/TerraformRole"
auth

Authentication configuration for cloud providers. Primarily defined in atmos.yaml but can be referenced at component level.

yaml
components:
  terraform:
    vpc:
      auth:
        identity: prod-admin
overrides

Scoped overrides that apply only to components defined in the current manifest and its imports (not to all components in the top-level stack). This is different from regular vars/env/settings which affect all components.

yaml
overrides:
  env:
    TEST_ENV_VAR: "overridden-value"
  vars:
    custom_tag: override
  settings:
    validation:
      check-cidr:
        schema_path: schemas/vpc-override.json
Show full SKILL.md (408 more words)Show less

Deep-Merge Behavior and Override Precedence

Atmos deep-merges configuration from multiple levels. The precedence order (lowest to highest priority):

  1. Global scope (vars:, env:, settings:)
  2. Component-type scope (terraform.vars:, helmfile.env:)
  3. Base component defaults (via metadata.inherits, in list order)
  4. Component-level scope (components.terraform.<name>.vars:)
  5. Overrides (overrides:, terraform.overrides:)

For maps, keys are recursively merged with higher-priority values overriding lower-priority ones. For lists, the entire list at higher priority replaces the lower-priority list (lists are not appended).

The _defaults.yaml Pattern

A common convention is to use _defaults.yaml files at each level of the directory hierarchy:

text
stacks/
  orgs/
    acme/
      _defaults.yaml            # Organization-wide defaults
      plat/
        _defaults.yaml          # Tenant defaults
        dev/
          _defaults.yaml        # Stage defaults
          us-east-2.yaml        # Top-level stack (deployable)
          us-west-2.yaml
        prod/
          _defaults.yaml
          us-east-2.yaml
          us-west-2.yaml

The underscore prefix ensures these files sort to the top of directory listings. They are excluded from stack discovery via excluded_paths and must be explicitly imported. Atmos has no special handling for _defaults.yaml -- it is purely a naming convention.

Each level imports the parent _defaults.yaml and adds its own defaults:

yaml
# stacks/orgs/acme/plat/prod/_defaults.yaml
import:
  - orgs/acme/plat/_defaults

vars:
  stage: prod
  tags:
    Environment: Production

Describing Stacks

Use atmos describe stacks to view the fully resolved configuration after all imports, inheritance, and overrides:

bash
# View all stacks
atmos describe stacks

# Filter by stack
atmos describe stacks --stack plat-ue2-prod

# Filter by component and section
atmos describe stacks --components vpc --sections vars

# Output as JSON
atmos describe stacks --format json | jq '.["plat-ue2-prod"]'

Use atmos describe component for a single component:

bash
atmos describe component vpc -s plat-ue2-prod

YAML Functions

Atmos provides YAML functions for dynamic value resolution at runtime:

  • !terraform.output <component> <output> -- Read Terraform outputs from another component.
  • !terraform.state <component> <path> -- Access Terraform state values.
  • !store <store-name> <component> <key> -- Read from external key-value stores (SSM, Vault, etc.).
  • !env <VAR_NAME> -- Read environment variables with optional defaults.
  • !exec <command> -- Execute shell commands and use output.
  • !include <path> -- Load content from external files.
  • !secret <name> -- Resolve declared secrets.
  • !append and !unset -- Control inherited list/key merge behavior.

For the full current function inventory, load atmos-yaml-functions.

Common Patterns and Best Practices

  1. Organize by org/tenant/stage/region: Structure stacks hierarchically so defaults cascade naturally through imports.
  2. Use catalog for component defaults: Place reusable component configurations in stacks/catalog/ and import them.
  3. Keep inheritance shallow: Limit to 2-3 levels of metadata.inherits to maintain readability.
  4. Use _defaults.yaml at every level: Define shared vars, env, and settings at the appropriate organizational level.
  5. Exclude non-deployable files: Configure excluded_paths to prevent catalog, mixin, and defaults files from being treated as top-level stacks.
  6. Use name or name_template for stack naming: If legacy name_pattern is present, migrate it.
  7. Use atmos describe stacks liberally: Always verify the resolved configuration before applying changes.
  8. Treat remote imports as config only: use component source: or atmos vendor pull when imported config references component code that is not already local.

References

© cloudposse, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in agent-skills/skills/atmos-stacks of cloudposse/atmos.

  • SKILL.md
  • references/import-patterns.md
  • references/inheritance-deep-merge.md

Open the folder on GitHubat commit 36726ae

Compare with similar skills

Atmos Stacks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Atmos Stacks compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Atmos Stacks this skillcloudposse/atmos1.4k—~3kAutomated safety check: NotesApache-2.0
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
Itemgen Command Buildermicrosoft/terraform-provider-fabric128—~1.5kAutomated safety check: PassMPL-2.0
Nx Plugin For AWSawslabs/nx-plugin-for-aws151—~3.6kAutomated safety check: PassApache-2.0
Resource Designermicrosoft/terraform-provider-fabric128—~6kAutomated safety check: PassMPL-2.0
Smarterrhashicorp/terraform-provider-aws11k—~722Automated safety check: PassMPL-2.0

Similar skills

  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Itemgen Command Builder

    microsoft/terraform-provider-fabric

    Official

    Given SDK analysis results, automatically determine the correct itemgen archetype and build the full go run tools/itemgen/main.go command.

    128 GitHub stars~1.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Nx Plugin For AWS

    awslabs/nx-plugin-for-aws

    Official

    Scaffold and build cloud-native applications on AWS using @aws/nx-plugin generators.

    151 GitHub stars~3.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Resource Designer

    microsoft/terraform-provider-fabric

    Official

    Research SDK contracts, design Terraform schema approach, and compose a GitHub issue for a new resource, data source, ephemeral resource, or enhancement to an existing resource.

    128 GitHub stars~6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Smarterr

    hashicorp/terraform-provider-aws

    Official

    Refactor error handling to use smarterr. An agent skill from hashicorp/terraform-provider-aws.

    11k GitHub stars~722 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Avm Tf Lifecycle

    Azure/terraform-azurerm-avm-ptn-alz

    Official

    A skill your agent uses whenever an Azure Verified Module (AVM) is being proposed, approved, published, handed over to a new owner, orphaned, or deprecated — and whenever a contributor is choosing a…

    135 GitHub stars~1.9k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from cloudposse/atmos

All 70 skills in this repo
  • Fix Log

    cloudposse/atmos

    A skill your agent uses when implementing, finishing, documenting, or reviewing a fix, repair, remediation, bug fix, debug-and-fix task, workflow fix, infrastructure fix, or any change that should…

    1.4k GitHub stars~685 tokensUpdated today
    Auto-check passed
  • Atmos Lint

    cloudposse/atmos

    Atmos Terraform linting with TFLint: standalone atmos terraform lint, component-aware config discovery and toolchain versions, TFLint rule configuration, and lifecycle hooks/CI findings.

    1.4k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Changelog

    cloudposse/atmos

    Blog post authoring for Atmos: MDX template, frontmatter, website/blog/tags.yml and authors.yml rules, problem-first framing, backtick-opening ban, optional cast embeds, and no-Go-internals leakage.

    1.4k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Editions

    cloudposse/atmos

    Decide whether a PR's new or changed default needs edition-journal handling (pkg/edition, docs/prd/editions.md), and do the mechanical work if so: journal entries, the four-layer default check…

    1.4k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Atmos Migration

    cloudposse/atmos

    Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…

    1.4k GitHub stars~5.1k tokensUpdated today
    Auto-check: warnings
  • PR Maintenance Loop

    cloudposse/atmos

    Start an hourly background loop that keeps the current branch's PR rebased, its addressed CodeRabbit threads resolved, its CI checks passing, its lint clean, its tests passing with adequate patch…

    1.4k GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Works with

Questions about Atmos Stacks

What does Atmos Stacks do?

Stack configuration: local and remote imports, inheritance, deep merging, locals, vars, settings, metadata, overrides, dependencies, and modernization. Atmos Stacks is an agent skill from cloudposse/atmos.

When should I use Atmos Stacks?

Atmos Stacks fits situations like: tasks that involve Legacy modernization.

How do I install Atmos Stacks in Claude Code?

Run `npx skills add cloudposse/atmos --skill atmos-stacks -a claude-code`. Or copy the skill folder (agent-skills/skills/atmos-stacks in cloudposse/atmos) into .claude/skills/atmos-stacks in your project. Claude Code loads it when a task matches its description.

How do I install Atmos Stacks in Codex?

Run `npx skills add cloudposse/atmos --skill atmos-stacks -a codex`. Or copy the skill folder (agent-skills/skills/atmos-stacks in cloudposse/atmos) into .agents/skills/atmos-stacks in your project. Codex loads it when a task matches its description.

Can I use Atmos Stacks in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cloudposse/atmos --skill atmos-stacks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/atmos-stacks, .gemini/skills/atmos-stacks, .github/skills/atmos-stacks and .opencode/skills/atmos-stacks in your project.

What does Atmos Stacks need to run?

Going by SKILL.md and its folder, Atmos Stacks needs the command-line tools its instructions call (jq and terraform).

Does Atmos Stacks access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Atmos Stacks safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Atmos Stacks use?

Atmos Stacks is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Atmos Stacks use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.8k tokens, read only when the agent opens those files.

What are the alternatives to Atmos Stacks?

Skills that share tags, products or a category with Atmos Stacks: Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars), Itemgen Command Builder (microsoft/terraform-provider-fabric, 128 stars), Nx Plugin For AWS (awslabs/nx-plugin-for-aws, 151 stars) and Resource Designer (microsoft/terraform-provider-fabric, 128 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Atmos Stacks?

cloudposse (a GitHub organization) maintains it in cloudposse/atmos, which has 1,396 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on October 8, 2026.

Source: cloudposse/atmos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.