Terraform and OpenTofu Guide
agentscope-ai/QwenPaw
Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.
Operate Terraform and OpenTofu across the whole infrastructure lifecycle: module structure, state backends and locking, plan/apply workflow, drift detection, remote state, upgrade and refactor…
$ npx skills add magnus919/agent-skills --skill terraform -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install magnus919/agent-skills terraform --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/terraform .claude/skills/terraform && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "terraform" agent skill from https://github.com/magnus919/agent-skills/tree/main/terraform into .claude/skills/terraform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/magnus919/agent-skills/tree/main/terraformType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add magnus919/agent-skills --skill terraform -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install magnus919/agent-skills terraform --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/terraform .agents/skills/terraform && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "terraform" agent skill from https://github.com/magnus919/agent-skills/tree/main/terraform into .agents/skills/terraform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add magnus919/agent-skills --skill terraform -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install magnus919/agent-skills terraform --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/terraform .cursor/skills/terraform && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "terraform" agent skill from https://github.com/magnus919/agent-skills/tree/main/terraform into .cursor/skills/terraform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/magnus919/agent-skills.git --path terraform--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add magnus919/agent-skills --skill terraform -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install magnus919/agent-skills terraform --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/terraform .gemini/skills/terraform && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "terraform" agent skill from https://github.com/magnus919/agent-skills/tree/main/terraform into .gemini/skills/terraform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install magnus919/agent-skills terraformInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add magnus919/agent-skills --skill terraform -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/terraform .github/skills/terraform && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "terraform" agent skill from https://github.com/magnus919/agent-skills/tree/main/terraform into .github/skills/terraform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add magnus919/agent-skills --skill terraform -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install magnus919/agent-skills terraform --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/magnus919/agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/terraform .opencode/skills/terraform && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "terraform" agent skill from https://github.com/magnus919/agent-skills/tree/main/terraform into .opencode/skills/terraform/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "terraform", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
terraformOperate Terraform and OpenTofu across the whole infrastructure lifecycle: module structure, state backends and locking, plan/apply workflow, drift detection, remote state, upgrade and refactor…
Terraform is an agent skill from magnus919/agent-skills. Operate Terraform and OpenTofu across the whole infrastructure lifecycle: module structure, state backends and locking, plan/apply workflow, drift detection, remote state, upgrade and refactor flows, and evidence-based diagnostics. Use when running or inspecting terraform plans, applies, state files, imports, or state surgery, or when the bundled tfops script should handle the task. Do not use for IaC methodology or cloud design decisions - those route up to platform-engineering.
Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 20 other files, including scripts and reference files (for example `README.md`, `evals/evals.json` and `references/00-source-index.md`). Compatibility notes: Terraform CLI 1.5+ or OpenTofu CLI 1.6+ for delegated commands; the bundled tfops script runs on Python 3.8+ and its --help and state-file analysis need no…
It sits in DevOps & Cloud, covering Infrastructure as code. It works with Terraform. The repository describes itself as: Curated collection of AI agent skills for Hermes and other agent frameworks. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 22b4723. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
terraformtofuFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Terraform CLI 1.5+ or OpenTofu CLI 1.6+ for delegated commands; the bundled tfops script runs on Python 3.8+ and its --help and state-file analysis need no terraform binary.
From compatibility in the SKILL.md frontmatter.
Terraform loads about 3.1k tokens when it runs, and up to ~9k if it reads all its reference files. Until then it costs about 124 tokens; SKILL.md has 1,364 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from magnus919/agent-skills at commit 22b4723, republished under its MIT licence (© magnus919). 1,364 words, ~3,102 tokens.
.claude/skills/terraform/SKILL.md (or your agent's skills folder). This skill also uses 15 other files; get the full folder from GitHub.Use this skill to run, inspect, and repair Terraform and OpenTofu infrastructure safely: understand a module graph, verify state backends and locking, review plans before applies, find and fix drift, work with remote state, plan version upgrades and refactors, and diagnose failures with evidence. This is a tool skill for one named tool (Terraform and its drop-in OpenTofu fork share one agent workflow and one trigger). Design decisions and IaC methodology belong to platform-engineering and its references/infrastructure-as-code.md; this skill owns execution.
terraform.lock.hcl, and CI invocation before running anything. Never infer state from a config file — the state file is the source of truth for what exists.tfops dry-run) and an explicit confirmation. Never run apply with unreviewed changes.state mv, state rm, state push) is a reviewed, scoped operation with a backup.apply is not proof of success: verify the external boundary (DNS, load balancer, API response) that the resource was supposed to satisfy, and check for drift on the next plan.tfops redacts nothing by itself but all outputs should be bounded summaries.scripts/tfops is an agent-first wrapper around the terraform/tofu CLI. It works without a terraform binary for --help, doctor, and direct --state analysis, so an agent can inventory a state file anywhere.
scripts/tfops doctor --json # binary, config, backend, state availability
scripts/tfops state --state state.json --json # inspect a local state file directly
scripts/tfops plan --state state.json --json # state-level plan summary (no binary needed)
scripts/tfops plan --json # full plan via terraform plan -json
scripts/tfops apply --dry-run --json # preview only, never mutates
scripts/tfops plan --save-plan reviewed.tfplan --json
# Review reviewed.tfplan, then apply that same file
scripts/tfops apply --yes --plan reviewed.tfplan --json
scripts/tfops apply --yes --plan reviewed.tfplan --force --json # bypass findings only after review
scripts/tfops import aws_instance.web i-0abc --dry-runMutation gate: apply and import refuse to run without --yes (exit 2). apply also requires a plan created through tfops plan --save-plan FILE, which explicitly enables provider refresh and writes a SHA-256 sidecar. tfops verifies the sidecar, copies the reviewed plan to a private temporary snapshot, runs terraform show -json on that snapshot, checks format/success evidence and validates prior state when present, blocks tainted resources and detected drift by default, and applies the same snapshot. Empty change collections may be omitted by supported plan JSON formats; errored must be false, and applyable/complete must be true when the engine reports them. --force bypasses only findings from valid plan evidence; it cannot bypass missing or invalid evidence, an absent sidecar, a hash mismatch, or a plan created without the wrapper's explicit refresh. The sidecar is local provenance for accidental mix-ups, not a cryptographic signature. --dry-run previews without mutating. A --state summary is not evidence of live drift and cannot satisfy the apply guard. TERRAFORM env var overrides binary selection (terraform then tofu are auto-detected otherwise). Exit codes: 0 ok, 1 analysis/runtime error, 2 gate refusal, 127 binary missing, 124 timeout.
terraform validate, tfops plan --json (or a state-file summary when the backend is unreachable).required_providers) and module versions; commit terraform.lock.hcl.for_each/count for repetition, not code generation; use templatefile for config injection, and treat provisioners as a last resort.references/01-modules-and-structure.md.local backend stores state on disk; remote backends (S3+DynamoDB, GCS, Azure Storage, Terraform Cloud/OpenTofu Cloud, Consul) keep state off disk and enable collaboration.force-unlock only after verifying no other run is active).sensitive = true.terraform init -migrate-state / -reconfigure), and lock troubleshooting: references/02-state-and-backends.md.plan reads config + state + provider data and proposes a diff; apply realizes it. Treat plan output as the contract the apply will fulfill.prevent_destroy and create_before_destroy lifecycle rules where recreation is dangerous.-target only for emergencies, never as a habit; -auto-approve only inside a reviewed CI/CD gate.-json), and review checklists: references/03-plan-apply-workflow.md.plan + reviewed apply (reconcile), or import when the resource was never managed; never delete-and-recreate as a default reflex.tfops inspects the reviewed saved plan for tainted resources and provider-detected drift, refuses when findings exist unless --force is deliberate, and applies that exact plan. Direct state analysis can flag taint but cannot establish live drift. Methods and cadence: references/04-drift-detection.md.data "terraform_remote_state" — reference by workspace/environment, never hand-copy outputs.references/05-remote-state-and-collaboration.md.terraform validate/tofu validate, run a plan, apply in a non-production environment first, and use terraform state replace-provider / state mv for provider-version or address changes.moved blocks (plan-safe, no state surgery), or reviewed state mv when moved does not fit; never delete state to force recreation.references/06-upgrades-and-refactors.md.Diagnose in evidence order: binary/version → config validation → backend + lock status → state serial/lineage → plan diff → apply error → boundary check.
force-unlock.state pull/state push only with a backup and reviewed scope.tfops doctor gathers the first layer of evidence; failure patterns and their probes live in references/07-diagnostics.md.| Load when | Reference |
|---|---|
| Module design, composition, or structure conventions | references/01-modules-and-structure.md |
| Backend choice, migration, or locking problems | references/02-state-and-backends.md |
| Planning, applying, or reviewing a change | references/03-plan-apply-workflow.md |
| Unexpected config-vs-reality differences | references/04-drift-detection.md |
| Shared or cross-stack state | references/05-remote-state-and-collaboration.md |
| Version bumps, provider migrations, or module refactors | references/06-upgrades-and-refactors.md |
| A failed apply, lock, or state error | references/07-diagnostics.md |
| Sources, version observations, and refresh procedure | references/00-source-index.md |
scripts/tfops: agent-first wrapper (state analysis, plan/apply, gated mutations, JSON output).tests/test_tfops.py + tests/fixtures/fixture-state.json: deterministic tests against a bundled state fixture.references/: eight dated, source-indexed references covering the operational topics above.| Claim | Minimum evidence |
|---|---|
| Config is valid | terraform validate (or tofu validate) exit 0 |
| State is readable | tfops state --state FILE --json parses and inventories it |
| Plan is safe | Reviewed plan diff with counts of create/update/destroy/replace and no tainted resources applied blind |
| Apply succeeded | Apply exit 0 plus the external boundary the resource serves responds correctly |
| No drift | A clean re-plan immediately after apply and on the declared cadence |
sensitive output values.apply, import, state push, or force-unlock without the mutation gate (--yes after a reviewed plan, or an explicit human directive).required_providers and version pins.platform-engineering; this skill owns the Terraform/OpenTofu tool itself.platform-engineering methodology, then execute with this skill.© magnus919, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 15 other files (scripts, references) in terraform of magnus919/agent-skills.
Open the folder on GitHubat commit 22b4723
Terraform next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Terraform this skillmagnus919/agent-skills | 115 | — | ~3.1k | Automated safety check: Pass | MIT | |
| Terraform and OpenTofu Guideagentscope-ai/QwenPaw | 36k | 6 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Terraform Skillantonbabenko/terraform-skill | 2.4k | 1 repos | ~5.1k | Automated safety check: Pass | Apache-2.0 | |
| Review Docshashicorp/terraform-provider-aws | 11k | — | ~1.3k | Automated safety check: Pass | MPL-2.0 | |
| Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit | 260 | 6 repos | ~1.1k | Automated safety check: Notes | Custom licence | |
| Cloudflarehodgef/apiker | 127 | 7 repos | ~2.2k | Automated safety check: Pass | MIT |
agentscope-ai/QwenPaw
Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.
antonbabenko/terraform-skill
A skill your agent uses when writing, reviewing, or debugging Terraform/OpenTofu modules, tests, CI, scans, or state ops - diagnoses failure mode (identity churn, secrets, blast radius, CI drift…
hashicorp/terraform-provider-aws
Review a Terraform AWS Provider PR's end-user documentation (website/docs//.markdown): whether docs are needed, description openings, argument/attribute style, section structure, tags wording, code…
maslennikov-ig/claude-code-orchestrator-kit
Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…
hodgef/apiker
Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…
patrickchugh/terravision
Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.
magnus919/agent-skills
Organize durable agent research outputs as summaries, analysis, and evidence dossiers.
magnus919/agent-skills
Build portable, first-person colored ASCII city engines and small GIS-derived city packs.
magnus919/agent-skills
Manage color workflows with ICC profiles, working spaces, gamut mapping, and color science.
magnus919/agent-skills
A skill your agent uses for PhD-level expertise in data science, statistics, and machine learning: rigorous statistical analysis, experimental design, causal inference, advanced modeling, research…
magnus919/agent-skills
Use Docker Compose to define, run, debug, and harden multi-container applications.
magnus919/agent-skills
Design, review, simulate, and verify FPGA logic using explicit RTL contracts, clock and reset models, CDC analysis, timing constraints, and reproducible implementation evidence.
Works with
Categories
Operate Terraform and OpenTofu across the whole infrastructure lifecycle: module structure, state backends and locking, plan/apply workflow, drift detection, remote state, upgrade and refactor…. Terraform is an agent skill from magnus919/agent-skills. Operate Terraform and OpenTofu across the whole infrastructure lifecycle: module structure, state backends and locking, plan/apply workflow, drift detection, remote state, upgrade and refactor flows, and evidence-based diagnostics.
Terraform fits situations like: inspecting terraform plans; the bundled tfops script should handle the task; iaC methodology; cloud design decisions - those route up to platform-engineering.
Run `npx skills add magnus919/agent-skills --skill terraform -a claude-code`. Or copy the skill folder (terraform in magnus919/agent-skills) into .claude/skills/terraform in your project. Claude Code loads it when a task matches its description.
Run `npx skills add magnus919/agent-skills --skill terraform -a codex`. Or copy the skill folder (terraform in magnus919/agent-skills) into .agents/skills/terraform in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add magnus919/agent-skills --skill terraform -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/terraform, .gemini/skills/terraform, .github/skills/terraform and .opencode/skills/terraform in your project.
Going by SKILL.md and its folder, Terraform needs Python for the scripts in its folder and the command-line tools its instructions call (terraform and tofu). Our summary lists: Python 3. Compatibility (from SKILL.md): Terraform CLI 1.5+ or OpenTofu CLI 1.6+ for delegated commands; the bundled tfops script runs on Python 3.8+ and its --help and state-file analysis need no terraform binary..
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Terraform is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.9k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Terraform: Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 36k stars), Terraform Skill (antonbabenko/terraform-skill, 2.4k stars), Review Docs (hashicorp/terraform-provider-aws, 11k stars) and Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
magnus919 (a GitHub user) maintains it in magnus919/agent-skills, which has 115 GitHub stars. The repository holds 131 skills in this directory. The repository was last updated on October 10, 2026.
Source: magnus919/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.