Agent skill

Atmos Terraform State Migrations

by cloudposse in cloudposse/atmos

Terraform state migration workflow with tfmigrate in Atmos: writing migration HCL, running atmos terraform migrate plan/apply/list, wiring kind: tfmigrate hooks, configuring history mode, and…

Apache-2.0Auto-check passedDevOps & Cloud

Install Atmos Terraform State Migrations

skills CLI
$ npx skills add cloudposse/atmos --skill atmos-terraform-state-migrations -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cloudposse/atmos atmos-terraform-state-migrations --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cloudposse/atmos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/agent-skills/skills/atmos-terraform-state-migrations .claude/skills/atmos-terraform-state-migrations && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
atmos-terraform-state-migrations
GitHub stars
1.4k
Token cost
~1.7k tokens
SKILL.md length
591 words
Files
2 (incl. references)
Skills in repo
70
Repo updated
First seen
Licence
Apache-2.0

At a glance

Terraform state migration workflow with tfmigrate in Atmos: writing migration HCL, running atmos terraform migrate plan/apply/list, wiring kind: tfmigrate hooks, configuring history mode, and…

  • Works in 6 steps: Confirm the migration addresses come… → Confirm the migration file targets the… → Run atmos terraform migrate plan and… → …
  • Tasks that involve Infrastructure as code
  • SKILL.md covers Start With Resolved Context, One-Off CLI Workflow, Migration Files and Hook Wiring, plus 2 more sections
  • Needs ATMOS_TFMIGRATE_HISTORY_KEY

What it does

Atmos Terraform State Migrations is an agent skill from cloudposse/atmos. Terraform state migration workflow with tfmigrate in Atmos: writing migration HCL, running atmos terraform migrate plan/apply/list, wiring kind: tfmigrate hooks, configuring history mode, and handling state refactors, rerun safety, workspace context, backend history variables, and CI-safe migrations.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/tfmigrate-migration-patterns.md`).

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Terraform. The repository describes itself as: Atmos is the open-source runtime for infrastructure — it builds, authenticates, and ships Terraform, OpenTofu, Packer, Ansible, Kubernetes, Helm, and containers the same way on… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Infrastructure as code

Example prompts

  • “/atmos-terraform-state-migrations”

Requirements

  • A credential in ATMOS_TFMIGRATE_HISTORY_KEY

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Confirm the migration addresses come from atmos terraform state list, not from code names alone.
  2. Confirm the migration file targets the resolved component working directory and workspace.
  3. Run atmos terraform migrate plan and inspect the post-migration Terraform plan.
  4. Use history mode for hooks or CI workflows that may rerun.
  5. Keep migration files and hook wiring in the same PR as the Terraform refactor they support.
  6. Remove or disable one-shot hook wiring after the migration has safely run everywhere it is intended to run.

What it can do on your machine

Read from SKILL.md and the folder at commit 110e139. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash, hcl and yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ATMOS_TFMIGRATE_HISTORY_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Atmos Terraform State Migrations loads about 1.7k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 84 tokens; SKILL.md has 591 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cloudposse/atmos at commit 110e139, republished under its Apache-2.0 licence (© cloudposse). 591 words, ~1,666 tokens.

Download SKILL.mdSave it as .claude/skills/atmos-terraform-state-migrations/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
atmos-terraform-state-migrations
description
Terraform state migration workflow with tfmigrate in Atmos: writing migration HCL, running atmos terraform migrate plan/apply/list, wiring kind: tfmigrate hooks, configuring history mode, and handling state refactors, rerun safety, workspace context, backend history variables, and CI-safe migrations.
metadata.copyright
Copyright Cloud Posse, LLC 2026
metadata.version
1.0.0
metadata.category
state-versioning
references
references/tfmigrate-migration-patterns.md

Atmos Terraform State Migrations

Use this skill when creating or reviewing Terraform state migrations for Atmos components. Atmos delegates state migrations to tfmigrate. It runs tfmigrate in the same component context as atmos terraform plan and apply. Before tfmigrate runs, Atmos performs auth identity setup, source and workdir provisioning, backend and varfile generation, Terraform init, workspace selection, toolchain resolution, and TFMIGRATE_EXEC_PATH setup.

For migration HCL syntax and examples, load references/tfmigrate-migration-patterns.md.

Start With Resolved Context

Never guess stack names, component names, workspaces, backend paths, or state addresses.

bash
atmos describe component <component> -s <stack>
atmos terraform migrate list <component> -s <stack>
atmos terraform state list <component> -s <stack>

Use the resolved component output to confirm:

  • the final Terraform component and component path
  • Terraform workspace name
  • backend type and backend settings
  • whether a kind: tfmigrate hook already exists
  • history key and history bucket from atmos terraform migrate list

Use atmos terraform state show <component> -s <stack> <address> when resource identity or import IDs are unclear. If a refactor can be handled with Terraform moved blocks and stays in the same state, prefer that unless the user specifically needs tfmigrate automation or multi-state moves.

One-Off CLI Workflow

Create a migration file in a project-owned migrations directory, then preview it before applying. tfmigrate resolves --migration relative to the migration_dir in its config. The Atmos-generated default config points migration_dir at the component's migrations/ directory when one exists. Pass just the filename, not a migrations/-prefixed path.

bash
atmos terraform migrate plan <component> -s <stack> --migration 20260527090000_refactor_vpc.hcl
atmos terraform migrate apply <component> -s <stack> --migration 20260527090000_refactor_vpc.hcl

For multiple selected component instances:

bash
atmos terraform migrate plan --components vpc,eks -s <stack> --migration 20260527090000_refactor.hcl
atmos terraform migrate plan --query '.settings.requires_migration == true' --tfmigrate-config .tfmigrate.hcl
atmos terraform migrate plan --affected --migration 20260527090000_refactor.hcl

Do not run apply until plan succeeds and the Terraform plan after migration does not show unintended destroy/create changes. --affected does not support --include-dependents for migrate.

Migration Files

Use tfmigrate HCL for state operations that need reviewable, repeatable files. A migration file contains exactly one migration block.

hcl
migration "state" "rename_subnet" {
  actions = [
    "mv aws_subnet.private aws_subnet.private_primary",
  ]
}

Common actions:

  • mv <source> <destination> for renames and module/address moves in one state.
  • rm <addresses>... for removing state bindings without destroying infrastructure.
  • import <address> <id> for binding existing infrastructure.
  • replace-provider <from> <to> for provider address migrations.
  • xmv <source-pattern> <destination-pattern> for wildcard moves.
  • migration "multi_state" for moving resources between component directories or state files.

Keep migration filenames sortable, usually with a timestamp prefix. In history mode, unapplied migrations are processed in filename order.

Show full SKILL.md (248 more words)Show less

Hook Wiring

Use hooks when the migration should run as part of normal plan, apply, or deploy workflows.

yaml
components:
  terraform:
    s3-bucket:
      dependencies:
        tools:
          tfmigrate: "0.4.x"

      hooks:
        state-migration:
          events:
            - before.terraform.plan
            - before.terraform.apply
          kind: tfmigrate
          migration: 20260527090000_remove_template_provider.hcl
          mode: dynamic

mode: dynamic is the default. before.terraform.plan runs tfmigrate plan. before.terraform.apply and before.terraform.deploy run tfmigrate apply. Use mode: plan or mode: apply only when the hook must always run one action.

Hook fields:

  • migration: path to one migration file.
  • config: path to .tfmigrate.hcl; omit migration when using history mode.
  • backend_config: entries passed as repeated tfmigrate --backend-config flags for the Terraform state backend.
  • mode: dynamic, plan, or apply.

History Mode

Single-file tfmigrate apply path.hcl is not idempotent. A rerun can fail if a source address already moved, or an address was already removed. For CI-safe reruns, use tfmigrate history mode with durable storage.

yaml
hooks:
  state-migration:
    events:
      - before.terraform.plan
      - before.terraform.apply
    kind: tfmigrate
    config: .tfmigrate.hcl
    mode: dynamic

Atmos exposes helper variables for .tfmigrate.hcl:

hcl
tfmigrate {
  migration_dir = "./tfmigrate"

  history {
    storage "s3" {
      bucket   = env.ATMOS_TFMIGRATE_HISTORY_BUCKET
      key      = env.ATMOS_TFMIGRATE_HISTORY_KEY
      region   = env.ATMOS_TFMIGRATE_HISTORY_REGION
      role_arn = env.ATMOS_TFMIGRATE_HISTORY_ROLE_ARN
    }
  }
}

The default history key is tfmigrate/<stack>/<component>/<workspace>/history.json. Atmos passes history settings to tfmigrate, but does not persist or repair history itself. Configure durable S3, GCS, or CI-persisted local storage.

Safety Checklist

Before committing migration work:

  1. Confirm the migration addresses come from atmos terraform state list, not from code names alone.
  2. Confirm the migration file targets the resolved component working directory and workspace.
  3. Run atmos terraform migrate plan and inspect the post-migration Terraform plan.
  4. Use history mode for hooks or CI workflows that may rerun.
  5. Keep migration files and hook wiring in the same PR as the Terraform refactor they support.
  6. Remove or disable one-shot hook wiring after the migration has safely run everywhere it is intended to run.

© cloudposse, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in agent-skills/skills/atmos-terraform-state-migrations of cloudposse/atmos.

  • SKILL.md
  • references/tfmigrate-migration-patterns.md

Open the folder on GitHubat commit 110e139

Compare with similar skills

Atmos Terraform State Migrations next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Atmos Terraform State Migrations compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Atmos Terraform State Migrations this skillcloudposse/atmos1.4k—~1.7kAutomated safety check: PassApache-2.0
Terraform and OpenTofu Guideagentscope-ai/QwenPaw36k6 repos~4.2kAutomated safety check: PassApache-2.0
Terraform Skillantonbabenko/terraform-skill2.4k1 repos~5.1kAutomated safety check: PassApache-2.0
Review Docshashicorp/terraform-provider-aws11k—~1.3kAutomated safety check: PassMPL-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT

Similar skills

  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    36k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Terraform Skill

    antonbabenko/terraform-skill

    A skill your agent uses when writing, reviewing, or debugging Terraform/OpenTofu modules, tests, CI, scans, or state ops - diagnoses failure mode (identity churn, secrets, blast radius, CI drift…

    2.4k GitHub starsUsed in 1 repo~5.1k tokens
    DevOps & CloudAuto-check passed
  • Review Docs

    hashicorp/terraform-provider-aws

    Official

    Review a Terraform AWS Provider PR's end-user documentation (website/docs//.markdown): whether docs are needed, description openings, argument/attribute style, section structure, tags wording, code…

    11k GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes

More from cloudposse/atmos

All 70 skills in this repo
  • Fix Log

    cloudposse/atmos

    A skill your agent uses when implementing, finishing, documenting, or reviewing a fix, repair, remediation, bug fix, debug-and-fix task, workflow fix, infrastructure fix, or any change that should…

    1.4k GitHub stars~685 tokensUpdated today
    Auto-check passed
  • Atmos Lint

    cloudposse/atmos

    Atmos Terraform linting with TFLint: standalone atmos terraform lint, component-aware config discovery and toolchain versions, TFLint rule configuration, and lifecycle hooks/CI findings.

    1.4k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Changelog

    cloudposse/atmos

    Blog post authoring for Atmos: MDX template, frontmatter, website/blog/tags.yml and authors.yml rules, problem-first framing, backtick-opening ban, optional cast embeds, and no-Go-internals leakage.

    1.4k GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Editions

    cloudposse/atmos

    Decide whether a PR's new or changed default needs edition-journal handling (pkg/edition, docs/prd/editions.md), and do the mechanical work if so: journal entries, the four-layer default check…

    1.4k GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Atmos Migration

    cloudposse/atmos

    Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp…

    1.4k GitHub stars~5.1k tokensUpdated today
    Auto-check: warnings
  • PR Maintenance Loop

    cloudposse/atmos

    Start an hourly background loop that keeps the current branch's PR rebased, its addressed CodeRabbit threads resolved, its CI checks passing, its lint clean, its tests passing with adequate patch…

    1.4k GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Atmos Terraform State Migrations

What does Atmos Terraform State Migrations do?

Terraform state migration workflow with tfmigrate in Atmos: writing migration HCL, running atmos terraform migrate plan/apply/list, wiring kind: tfmigrate hooks, configuring history mode, and…. Atmos Terraform State Migrations is an agent skill from cloudposse/atmos. Terraform state migration workflow with tfmigrate in Atmos: writing migration HCL, running atmos terraform migrate plan/apply/list, wiring kind: tfmigrate hooks, configuring history mode, and handling state refactors, rerun safety, workspace context, backend history variables, and CI-safe migrations.

When should I use Atmos Terraform State Migrations?

Atmos Terraform State Migrations fits situations like: tasks that involve Infrastructure as code.

How do I install Atmos Terraform State Migrations in Claude Code?

Run `npx skills add cloudposse/atmos --skill atmos-terraform-state-migrations -a claude-code`. Or copy the skill folder (agent-skills/skills/atmos-terraform-state-migrations in cloudposse/atmos) into .claude/skills/atmos-terraform-state-migrations in your project. Claude Code loads it when a task matches its description.

How do I install Atmos Terraform State Migrations in Codex?

Run `npx skills add cloudposse/atmos --skill atmos-terraform-state-migrations -a codex`. Or copy the skill folder (agent-skills/skills/atmos-terraform-state-migrations in cloudposse/atmos) into .agents/skills/atmos-terraform-state-migrations in your project. Codex loads it when a task matches its description.

Can I use Atmos Terraform State Migrations in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cloudposse/atmos --skill atmos-terraform-state-migrations -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/atmos-terraform-state-migrations, .gemini/skills/atmos-terraform-state-migrations, .github/skills/atmos-terraform-state-migrations and .opencode/skills/atmos-terraform-state-migrations in your project.

What does Atmos Terraform State Migrations need to run?

Going by SKILL.md and its folder, Atmos Terraform State Migrations needs credentials named ATMOS_TFMIGRATE_HISTORY_KEY. Our summary lists: A credential in ATMOS_TFMIGRATE_HISTORY_KEY.

Does Atmos Terraform State Migrations access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Atmos Terraform State Migrations safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Atmos Terraform State Migrations use?

Atmos Terraform State Migrations is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Atmos Terraform State Migrations use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Atmos Terraform State Migrations?

Skills that share tags, products or a category with Atmos Terraform State Migrations: Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 36k stars), Terraform Skill (antonbabenko/terraform-skill, 2.4k stars), Review Docs (hashicorp/terraform-provider-aws, 11k stars) and Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Atmos Terraform State Migrations?

cloudposse (a GitHub organization) maintains it in cloudposse/atmos, which has 1,398 GitHub stars. The repository holds 70 skills in this directory. The repository was last updated on October 10, 2026.

Source: cloudposse/atmos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.