Agent skill

Render Env

by polarsource in polarsource/polar

Add a new Terraform Cloud variable for the Render-hosted backend across production, sandbox, and test.

Apache-2.0Auto-check: notesDevOps & Cloud

Install Render Env

skills CLI
$ npx skills add polarsource/polar --skill render-env -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install polarsource/polar render-env --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/polarsource/polar.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/render-env .claude/skills/render-env && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
render-env
GitHub stars
10k
Token cost
~1.9k tokens
SKILL.md length
904 words
Files
1
Skills in repo
18
Repo updated
First seen
Licence
Apache-2.0

At a glance

Add a new Terraform Cloud variable for the Render-hosted backend across production, sandbox, and test.

  • Works in 4 steps: Add the tfe_variable to each… → Add the variable {} block to each… → Format → …
  • Tasks that involve Infrastructure as code
  • SKILL.md covers Inputs, Naming convention, Step 1: Add the tfe_variable… and Step 2: Add the variable {}…, plus 3 more sections
  • Calls terraform, stripe and git; needs POLAR_PLAIN_TOKEN

What it does

Render Env is an agent skill from polarsource/polar. Add a new Terraform Cloud variable for the Render-hosted backend across production, sandbox, and test. Declares the tfevariable in terraform/global/{production,sandbox,test}.tf and the matching variable {} block in terraform/{production,sandbox,test}/variables.tf, then reminds the user to wire it into render.tf / the renderservice module.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Terraform. The repository describes itself as: Polar — A billing platform for the intelligence era. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Infrastructure as code

Example prompts

  • “/render-env”

Requirements

  • A credential in POLAR_PLAIN_TOKEN
  • Pre-approved tools (allowed-tools): Read, Edit, Write, Bash, Grep, Glob

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Add the tfe_variable to each global/{env}.tf
  2. Add the variable {} block to each {env}/variables.tf
  3. Format
  4. Hand off

What it can do on your machine

Read from SKILL.md and the folder at commit 599c727. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Edit
    • Write
    • Bash
    • Grep
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • terraform
    • stripe
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • POLAR_PLAIN_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Render Env loads about 1.9k tokens when it runs. Until then it costs about 88 tokens; SKILL.md has 904 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Edit, Write, Bash, Grep, Glob

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from polarsource/polar at commit 599c727, republished under its Apache-2.0 licence (© polarsource). 904 words, ~1,891 tokens.

Download SKILL.mdSave it as .claude/skills/render-env/SKILL.md (or your agent's skills folder).
name
render-env
description
Add a new Terraform Cloud variable for the Render-hosted backend across production, sandbox, and test. Declares the tfe_variable in terraform/global/{production,sandbox,test}.tf and the matching variable {} block in terraform/{production,sandbox,test}/variables.tf, then reminds the user to wire it into render.tf / the render_service module.
allowed-tools
Read, Edit, Write, Bash, Grep, Glob
user-invocable
true

Add a Render env variable to Terraform

This skill declares a new Terraform Cloud variable so a value can be set via the TFC UI and consumed by the Render backend services. It only does the plumbing — it does not wire the variable into a Render env group. Wiring requires picking the right *_config / *_secrets object in terraform/modules/render_service/, which is task-specific and the user should drive.

Inputs

The skill takes two positional args from the invocation: /render-env <name> <description>.

  • ${name} — the Terraform variable name in snake_case. Used verbatim as the TFC variable key, the tfe_variable resource suffix, and the variable block name. Example: stripe_climate_api_key.
  • ${description} — a short human-readable description. Used in the description attribute and (with the env appended) in the per-env tfe_variable description. Example: Stripe Climate API key.

If either arg is missing, ask the user before doing anything. Also ask:

  • Sensitive? Default to true (almost everything in these files is sensitive). Only set false for non-secret config strings (cf. slo_report_slack_channel, customer_portal_url_overrides).
  • Which environments? Default to all three (production, sandbox, test). The user may want to skip one — test in particular often omits variables that aren't exercised there.

Do not ask about lifecycle { ignore_changes = [value] }. New variables here have no value baked into the Terraform code, so there's nothing for Terraform to overwrite — TFC just holds whatever's typed into the UI, and ignore_changes would be a no-op. The handful of existing blocks that include it (e.g. polar_organization_id, customer_portal_url_overrides) seed a default value in code and want UI overrides to stick; that's a different shape from a fresh secret and the user will tell you up-front if they want it.

Naming convention

Follow the modern bare-key pattern that recent additions use (e.g. polar_access_token, tinybird_api_token, customer_portal_url_overrides):

  • The TFC key is the bare name: key = "${name}" — no _production / _sandbox / _test suffix on the key. Each variable set is per-workspace so the key doesn't need to be globally unique.
  • The tfe_variable resource label does get the env suffix: resource "tfe_variable" "${name}_${env}".
  • The matching variable block in terraform/${env}/variables.tf uses the bare name: variable "${name}". This lets render.tf reference it uniformly as var.${name} across all envs.

A handful of older variables (e.g. google_client_id_production, backend_secret_production) use a _production/_sandbox-suffixed key and matching variable. Don't replicate that pattern for new additions — it's legacy.

Step 1: Add the tfe_variable to each global/{env}.tf

For each selected ${env} in production, sandbox, test, append a block to terraform/global/${env}.tf (after the existing tfe_variable resources, before the file ends):

hcl
resource "tfe_variable" "${name}_${env}" {
  key             = "${name}"
  category        = "terraform"
  description     = "${description} for ${env}"
  sensitive       = ${sensitive}
  variable_set_id = tfe_variable_set.${env}.id
}

Only add a lifecycle { ignore_changes = [value] } block or a value = "..." line if the user explicitly asks for one (rare — usually let TFC hold the value).

Use Edit with enough surrounding context that the insertion lands at the correct spot. Prefer appending after the last existing tfe_variable resource in the file rather than rewriting the file.

Step 2: Add the variable {} block to each {env}/variables.tf

For each selected ${env}, append a block to terraform/${env}/variables.tf:

hcl
variable "${name}" {
  description = "${description}"
  type        = string
  sensitive   = ${sensitive}
}

Drop the sensitive = true line when ${sensitive} is false. Drop nothing else.

Step 3: Format

Run:

bash
terraform fmt -recursive terraform

from the repo root. If terraform isn't on PATH, note it and skip — the formatting is a nicety, not required.

Show full SKILL.md (390 more words)Show less

Step 4: Hand off

Report to the user:

  • The six files touched (or fewer if they skipped an env).
  • That the variable is now declared but not yet consumed. To consume it, they need to:
    1. Add a field to the relevant config/secrets object in terraform/modules/render_service/variables.tf. Pick by purpose:
      • backend_config — non-sensitive backend env vars (URLs, flags, log level, tax processor list).
      • backend_secrets — sensitive backend env vars (API keys, tokens, signing secrets).
      • Themed render_env_group blocks (stripe, github, logfire, tinybird, aws_s3, worker_sqs, apple, prometheus, slo_report, google, etc.) each have their own object — use the matching one when the var belongs to a clear bucket.
      • Use optional(string, "<default>") if you want a module-level default; otherwise plain string.
    2. Wire the field into the matching render_env_group block in terraform/modules/render_service/main.tf as POLAR_${NAME_UPPER} = { value = var.<object>.<field> }. Two backend groups exist:
      • render_env_group "backend" — applied to every environment.
      • render_env_group "backend_production" — production-only values (e.g. POLAR_PLAIN_TOKEN, ...). Put a var here when sandbox/test should not see it.
    3. Pass the value in from each terraform/${env}/render.tf module call, e.g. backend_secrets = { ... ${field} = var.${name} ... }. Sandbox and test won't have this line if the var is production-only.
    4. Set the actual value in TFC under the matching variable set (Production / Sandbox / Test).
    5. If this is a POLAR_* env var, also add the field to the Settings class in server/polar/config.py (Pydantic BaseSettings with env_prefix="polar_"; the env var name is POLAR_<FIELD_NAME>).
Hardcoded string vs tfe_variable

Choose the right shape up-front:

  • Hardcoded in render.tf (e.g. tax_processors = "[\"stripe\"]"): use when the value is static and you're fine editing + PR'ing terraform to change it.
  • tfe_variable via this skill: use when the value is a secret or needs to be editable from the TFC UI without a code deploy. Don't hardcode a "{}" / "" default in render.tf for something that's supposed to be UI-tunable — it defeats the point.

Don't

  • Don't write the variable into terraform/global/main.tf (the cross-org "Global Settings" set). Per-env sets in global/{env}.tf shadow it, so an entry in main.tf is dead weight when there's already a per-env one.
  • Don't hardcode a value = "..." unless the user asks. The point of a tfe_variable is that it can be set in the TFC UI.
  • Don't try to wire the variable into render.tf or the render_service module yourself — that's a structural decision (which secrets object? new object?) the user should make.
  • Don't git add or commit. Leave the changes staged for the user to review.

© polarsource, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/render-env of polarsource/polar.

Open the folder on GitHubat commit 599c727

Compare with similar skills

Render Env next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Render Env compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Render Env this skillpolarsource/polar10k—~1.9kAutomated safety check: NotesApache-2.0
Terraform and OpenTofu Guideagentscope-ai/QwenPaw35k6 repos~4.2kAutomated safety check: PassApache-2.0
Terraform Skillantonbabenko/terraform-skill2.4k1 repos~5.1kAutomated safety check: PassApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2596 repos~1.1kAutomated safety check: NotesCustom licence
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only

Similar skills

  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    35k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Terraform Skill

    antonbabenko/terraform-skill

    A skill your agent uses when writing, reviewing, or debugging Terraform/OpenTofu modules, tests, CI, scans, or state ops - diagnoses failure mode (identity churn, secrets, blast radius, CI drift…

    2.4k GitHub starsUsed in 1 repo~5.1k tokens
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    259 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Cloudflare

    dmmulroy/cloudflare-skill

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and…

    728 GitHub stars~1.6k tokensUpdated 8 mo ago
    DevOps & CloudAuto-check passed

More from polarsource/polar

All 18 skills in this repo
  • Polar Python SDK

    polarsource/polar

    Integrate Polar billing in server-side Python applications using the versioned Polar and PolarAsync clients.

    10k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Polar Typescript SDK

    polarsource/polar

    Integrate Polar billing in server-side TypeScript applications using the versioned createPolar and createPolarCore clients.

    10k GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Adr Check

    polarsource/polar

    Check a code change against the repo's Accepted Architecture Decision Records (ADRs) in handbook/engineering/decisions/ and report violations with citations.

    10k GitHub stars~771 tokensUpdated today
    Auto-check passed
  • API Surface Review

    polarsource/polar

    Review changes to Polar's API contract — Pydantic schemas, FastAPI endpoints, OpenAPI output and the generated SDKs.

    10k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Billing Review

    polarsource/polar

    Review a diff that touches Polar's billing domain — subscriptions, cycles and crons, orders, billing entries, meters and usage, discounts, checkout, payments and dunning, refunds, disputes, payouts…

    10k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Interview Task

    polarsource/polar

    Prepare an interview task for a candidate, as part of our hiring process.

    10k GitHub stars~933 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Render Env

What does Render Env do?

Add a new Terraform Cloud variable for the Render-hosted backend across production, sandbox, and test. Render Env is an agent skill from polarsource/polar. Add a new Terraform Cloud variable for the Render-hosted backend across production, sandbox, and test.

When should I use Render Env?

Render Env fits situations like: tasks that involve Infrastructure as code.

How do I install Render Env in Claude Code?

Run `npx skills add polarsource/polar --skill render-env -a claude-code`. Or copy the skill folder (.agents/skills/render-env in polarsource/polar) into .claude/skills/render-env in your project. Claude Code loads it when a task matches its description.

How do I install Render Env in Codex?

Run `npx skills add polarsource/polar --skill render-env -a codex`. Or copy the skill folder (.agents/skills/render-env in polarsource/polar) into .agents/skills/render-env in your project. Codex loads it when a task matches its description.

Can I use Render Env in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add polarsource/polar --skill render-env -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/render-env, .gemini/skills/render-env, .github/skills/render-env and .opencode/skills/render-env in your project.

What does Render Env need to run?

Going by SKILL.md and its folder, Render Env needs the command-line tools its instructions call (terraform, stripe and git) and credentials named POLAR_PLAIN_TOKEN. Our summary lists: A credential in POLAR_PLAIN_TOKEN. Its frontmatter pre-approves these tools: Read, Edit, Write, Bash, Grep, Glob.

Does Render Env access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Render Env safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Render Env use?

Render Env is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Render Env use?

About 1.9k tokens (SKILL.md is roughly 7.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Render Env?

Skills that share tags, products or a category with Render Env: Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 35k stars), Terraform Skill (antonbabenko/terraform-skill, 2.4k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 259 stars) and Cloudflare (hodgef/apiker, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Render Env?

polarsource (a GitHub organization) maintains it in polarsource/polar, which has 10,336 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 7, 2026.

Source: polarsource/polar on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.