Agent skill

Terraform Engineer

by Jeffallan in Jeffallan/claude-skills

Writes reusable Terraform modules and manages state, providers and environments across AWS, Azure and GCP, with validation, plan review and explicit apply approval.

MITAuto-check passedDevOps & Cloud

Install Terraform Engineer

skills CLI
$ npx skills add Jeffallan/claude-skills --skill terraform-engineer -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Jeffallan/claude-skills terraform-engineer --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Jeffallan/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/terraform-engineer .claude/skills/terraform-engineer && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
terraform-engineer
GitHub stars
12k
Token cost
~1.4k tokens
SKILL.md length
448 words
Files
6 (incl. references)
Skills in repo
58
Repo updated
First seen
Licence
MIT

At a glance

Writes reusable Terraform modules and manages state, providers and environments across AWS, Azure and GCP, with validation, plan review and explicit apply approval.

  • Works in 7 steps: Analyze infrastructure — Review… → Design modules — Create composable,… → Implement state — Configure remote… → …
  • Creating reusable Terraform modules with inputs, outputs and versioning
  • SKILL.md covers Core Workflow, Reference Guide, Constraints and Code Examples, plus 1 more section
  • Calls terraform

What it does

The agent reviews requirements and existing code, designs composable modules with clear interfaces, configures remote backends with locking and encryption, applies least-privilege security, then validates with terraform fmt, terraform validate and tflint. It creates a plan with terraform plan -out=tfplan, summarizes creates, updates and deletes with destructive actions highlighted, and presents that to you. terraform apply runs only after explicit confirmation, and the agent refuses to apply if approval is withheld or destructive changes have not been accepted.

An error recovery section covers state drift with refresh, state rm and import, provider authentication problems, and dependency ordering with depends_on, always returning to validation before planning again. Reference files cover module patterns, state management with remote backends, workspaces and migrations, provider setup for AWS, Azure and GCP, best practices and testing.

When your agent uses it

  • Creating reusable Terraform modules with inputs, outputs and versioning
  • Migrating state to a remote backend or importing existing resources
  • Resolving state drift or state conflicts
  • Running the same configuration across several environments
  • Reviewing a plan for destructive changes before applying it

Example prompts

  • “Turn our VPC resources into a reusable module with variables, outputs and a version tag.”
  • “Move the Terraform state from local files to a remote backend with locking.”
  • “Import the existing S3 bucket into state and write the matching resource block.”
  • “Run a plan for the staging workspace and tell me which resources would be destroyed.”

Requirements

  • The Terraform CLI and `tflint`
  • Credentials for the target cloud provider

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Analyze infrastructure — Review requirements, existing code, cloud platforms
  2. Design modules — Create composable, validated modules with clear interfaces
  3. Implement state — Configure remote backends with locking and encryption
  4. Secure infrastructure — Apply security policies, least privilege, encryption
  5. Validate — Run terraform fmt and terraform validate, then tflint; if any errors are reported, fix them and re-run until all checks pass…
  6. Plan and review — Run terraform plan -out=tfplan and extract a summarized plan highlighting creates, updates, deletes, and especially any…
  7. Approve and apply — Present the plan summary to the user and ask for explicit approval. Only execute terraform apply tfplan after…

What it can do on your machine

Read from SKILL.md and the folder at commit 1be15d8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • terraform

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • synergetic.solutions
    • jeffallan.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Terraform Engineer loads about 1.4k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 90 tokens; SKILL.md has 448 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~13k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Jeffallan/claude-skills at commit 1be15d8, republished under its MIT licence (© Jeffallan). 448 words, ~1,439 tokens.

Download SKILL.mdSave it as .claude/skills/terraform-engineer/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
terraform-engineer
description
Use when implementing infrastructure as code with Terraform across AWS, Azure, or GCP. Invoke for module development (create reusable modules, manage module versioning), state management (migrate backends, import existing resources, resolve state conflicts), provider configuration, multi-environment workflows, and infrastructure testing.
license
MIT
metadata.author
https://github.com/Jeffallan
metadata.company
https://synergetic.solutions
metadata.version
1.1.0
metadata.domain
infrastructure
metadata.triggers
Terraform, infrastructure as code, IaC, terraform module, terraform state, AWS provider, Azure provider, GCP provider, terraform plan, terraform apply
metadata.role
specialist
metadata.scope
implementation
metadata.output-format
code
metadata.related-skills
cloud-architect, devops-engineer, kubernetes-specialist

Terraform Engineer

Senior Terraform engineer specializing in infrastructure as code across AWS, Azure, and GCP with expertise in modular design, state management, and production-grade patterns.

Core Workflow

  1. Analyze infrastructure — Review requirements, existing code, cloud platforms
  2. Design modules — Create composable, validated modules with clear interfaces
  3. Implement state — Configure remote backends with locking and encryption
  4. Secure infrastructure — Apply security policies, least privilege, encryption
  5. Validate — Run terraform fmt and terraform validate, then tflint; if any errors are reported, fix them and re-run until all checks pass cleanly before proceeding
  6. Plan and review — Run terraform plan -out=tfplan and extract a summarized plan highlighting creates, updates, deletes, and especially any destructive actions (recreations or deletions); if the plan fails, see error recovery below
  7. Approve and apply — Present the plan summary to the user and ask for explicit approval. Only execute terraform apply tfplan after receiving confirmation. Refuse to apply the plan if approval is withheld, or if destructive changes are present and the user has not explicitly accepted them
Error Recovery

Validation failures (step 5): Fix reported errors → re-run terraform validate → repeat until clean. For tflint warnings, address rule violations before proceeding.

Plan failures (step 6):

  • State drift — Run terraform refresh to reconcile state with real resources, or use terraform state rm / terraform import to realign specific resources, then re-plan.
  • Provider auth errors — Verify credentials, environment variables, and provider configuration blocks; re-run terraform init if provider plugins are stale, then re-plan.
  • Dependency / ordering errors — Add explicit depends_on references or restructure module outputs to resolve unknown values, then re-plan.

After any fix, return to step 5 to re-validate before re-running the plan.

Show full SKILL.md (175 more words)Show less

Reference Guide

Load detailed guidance based on context:

TopicReferenceLoad When
Modulesreferences/module-patterns.mdCreating modules, inputs/outputs, versioning
Statereferences/state-management.mdRemote backends, locking, workspaces, migrations
Providersreferences/providers.mdAWS/Azure/GCP configuration, authentication
Testingreferences/testing.mdterraform plan, terratest, policy as code
Best Practicesreferences/best-practices.mdDRY patterns, naming, security, cost tracking

Constraints

MUST DO
  • Use semantic versioning and pin provider versions
  • Enable remote state with locking and encryption
  • Validate inputs with validation blocks
  • Use consistent naming conventions and tag all resources
  • Document module interfaces
  • Run terraform fmt and terraform validate
MUST NOT DO
  • Store secrets in plain text or hardcode environment-specific values
  • Use local state for production or skip state locking
  • Mix provider versions without constraints
  • Create circular module dependencies or skip input validation
  • Commit .terraform directories

Code Examples

Minimal Module Structure

main.tf

hcl
resource "aws_s3_bucket" "this" {
  bucket = var.bucket_name
  tags   = var.tags
}

variables.tf

hcl
variable "bucket_name" {
  description = "Name of the S3 bucket"
  type        = string

  validation {
    condition     = length(var.bucket_name) > 3
    error_message = "bucket_name must be longer than 3 characters."
  }
}

variable "tags" {
  description = "Tags to apply to all resources"
  type        = map(string)
  default     = {}
}

outputs.tf

hcl
output "bucket_id" {
  description = "ID of the created S3 bucket"
  value       = aws_s3_bucket.this.id
}
Remote Backend Configuration (S3 + DynamoDB)
hcl
terraform {
  backend "s3" {
    bucket         = "my-tf-state"
    key            = "env/prod/terraform.tfstate"
    region         = "us-east-1"
    encrypt        = true
    dynamodb_table = "terraform-lock"
  }
}
Provider Version Pinning
hcl
terraform {
  required_version = ">= 1.5.0"

  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 5.0"
    }
    azurerm = {
      source  = "hashicorp/azurerm"
      version = "~> 3.0"
    }
  }
}

Output Format

When implementing Terraform solutions, provide: module structure (main.tf, variables.tf, outputs.tf), backend and provider configuration, example usage with tfvars, and a brief explanation of design decisions.

Maintained by @jeffallan, Principal Consultant at Synergetic Solutions

Documentation

© Jeffallan, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (references) in skills/terraform-engineer of Jeffallan/claude-skills.

  • SKILL.md
  • references/best-practices.md
  • references/module-patterns.md
  • references/providers.md
  • references/state-management.md
  • references/testing.md

Open the folder on GitHubat commit 1be15d8

Compare with similar skills

Terraform Engineer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Terraform Engineer compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Terraform Engineer this skillJeffallan/claude-skills12k—~1.4kAutomated safety check: PassMIT
Terraform Module Librarywshobson/agents40k11 repos~1.3kAutomated safety check: PassMIT
Cloud Architectdavila7/claude-code-templates32k8 repos~1.9kAutomated safety check: PassMIT
Oma Tf Infrafirst-fluke/oh-my-agent1.3k—~2.8kAutomated safety check: PassMIT
Heroku To AWSaws/agent-toolkit-for-aws2.8k—~7.2kAutomated safety check: PassApache-2.0
Azure To AWSaws/agent-toolkit-for-aws2.8k—~4.6kAutomated safety check: PassApache-2.0

Similar skills

  • Build reusable, tested Terraform modules for AWS, Azure, GCP and OCI, with a standard file layout, an AWS VPC example, versioning rules and Terratest checks.

    40k GitHub starsUsed in 11 repos~1.3k tokens
    DevOps & CloudAuto-check passed
  • Cloud Architect

    davila7/claude-code-templates

    Expert cloud architect specializing in AWS/Azure/GCP multi-cloud infrastructure design, advanced IaC (Terraform/OpenTofu/CDK), FinOps cost optimization, and modern architectural patterns.

    32k GitHub starsUsed in 8 repos~1.9k tokens
    DevOps & CloudAuto-check passed
  • Oma Tf Infra

    first-fluke/oh-my-agent

    Infrastructure-as-code specialist for multi-cloud provisioning using Terraform across any provider (AWS, GCP, Azure, Oracle Cloud).

    1.3k GitHub stars~2.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Heroku To AWS

    aws/agent-toolkit-for-aws

    Official

    Migrate workloads from Heroku to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~7.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Azure To AWS

    aws/agent-toolkit-for-aws

    Official

    Migrate workloads from Microsoft Azure to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~4.6k tokensUpdated today
    DevOps & CloudAuto-check passed
  • GCP To AWS

    aws/agent-toolkit-for-aws

    Official

    Migrate workloads from Google Cloud Platform to AWS — plus AI and agentic workloads from any provider.

    2.8k GitHub stars~15k tokensUpdated today
    DevOps & CloudAuto-check passed

More from Jeffallan/claude-skills

All 58 skills in this repo
  • API Designer

    Jeffallan/claude-skills

    Designs REST and GraphQL APIs from resource modeling to an OpenAPI 3.1 contract, with versioning, pagination and RFC 7807 error handling.

    12k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • CLI Developer

    Jeffallan/claude-skills

    Walks through designing, building and polishing a command-line tool: user workflow and command hierarchy, implementation in commander, click, typer or cobra, completions and cross-platform testing.

    12k GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed
  • Kubernetes Specialist

    Jeffallan/claude-skills

    Creates and checks Kubernetes manifests, Helm charts, RBAC and network policies, and helps debug pod problems, with kubectl checks and rollback steps.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Laravel Specialist

    Jeffallan/claude-skills

    Builds Laravel 10+ applications with Eloquent models, Sanctum authentication, Horizon queues, API resources and Livewire components, tested with Pest or PHPUnit.

    12k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Pandas Pro

    Jeffallan/claude-skills

    Handles pandas DataFrame work: cleaning, merging, groupby aggregation, pivots, time-series resampling and memory tuning, with checks on dtypes, shapes and nulls.

    12k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Apache Spark Engineer

    Jeffallan/claude-skills

    Guides writing and tuning Apache Spark jobs: DataFrame and RDD code, Spark SQL, partitioning, caching, shuffle tuning and structured streaming.

    12k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed

Categories

Questions about Terraform Engineer

What does Terraform Engineer do?

Writes reusable Terraform modules and manages state, providers and environments across AWS, Azure and GCP, with validation, plan review and explicit apply approval. The agent reviews requirements and existing code, designs composable modules with clear interfaces, configures remote backends with locking and encryption, applies least-privilege security, then validates with terraform fmt, terraform validate and tflint. It creates a plan with terraform plan -out=tfplan, summarizes creates, updates and deletes with destructive actions highlighted, and presents that to you.

When should I use Terraform Engineer?

Terraform Engineer fits situations like: creating reusable Terraform modules with inputs, outputs and versioning; migrating state to a remote backend or importing existing resources; resolving state drift or state conflicts; running the same configuration across several environments.

How do I install Terraform Engineer in Claude Code?

Run `npx skills add Jeffallan/claude-skills --skill terraform-engineer -a claude-code`. Or copy the skill folder (skills/terraform-engineer in Jeffallan/claude-skills) into .claude/skills/terraform-engineer in your project. Claude Code loads it when a task matches its description.

How do I install Terraform Engineer in Codex?

Run `npx skills add Jeffallan/claude-skills --skill terraform-engineer -a codex`. Or copy the skill folder (skills/terraform-engineer in Jeffallan/claude-skills) into .agents/skills/terraform-engineer in your project. Codex loads it when a task matches its description.

Can I use Terraform Engineer in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Jeffallan/claude-skills --skill terraform-engineer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/terraform-engineer, .gemini/skills/terraform-engineer, .github/skills/terraform-engineer and .opencode/skills/terraform-engineer in your project.

What does Terraform Engineer need to run?

Going by SKILL.md and its folder, Terraform Engineer needs the command-line tools its instructions call (terraform). Our summary lists: The Terraform CLI and `tflint`; Credentials for the target cloud provider.

Does Terraform Engineer access the network?

SKILL.md names 3 domains. As links in the text: github.com, synergetic.solutions and jeffallan.github.io. This is read from the text; nothing was executed.

Is Terraform Engineer safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Terraform Engineer use?

Terraform Engineer is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Terraform Engineer use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.

What are the alternatives to Terraform Engineer?

Skills that share tags, products or a category with Terraform Engineer: Terraform Module Library (wshobson/agents, 40k stars), Cloud Architect (davila7/claude-code-templates, 32k stars), Oma Tf Infra (first-fluke/oh-my-agent, 1.3k stars) and Heroku To AWS (aws/agent-toolkit-for-aws, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Terraform Engineer?

Jeffallan (a GitHub user) maintains it in Jeffallan/claude-skills, which has 11,788 GitHub stars. The repository holds 58 skills in this directory. The repository was last updated on October 3, 2026.

Source: Jeffallan/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.