Agent skill

Infra As Code

by revfactory in revfactory/harness-100

A full Infrastructure as Code design and implementation pipeline.

Apache-2.0Auto-check passedDevOps & Cloud

Install Infra As Code

skills CLI
$ npx skills add revfactory/harness-100 --skill infra-as-code -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install revfactory/harness-100 infra-as-code --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/revfactory/harness-100.git skills-src && mkdir -p .claude/skills && cp -r skills-src/en/26-infra-as-code/.claude/skills/infra-as-code .claude/skills/infra-as-code && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
infra-as-code
GitHub stars
1.3k
Token cost
~1.8k tokens
SKILL.md length
683 words
Files
1
Skills in repo
464
Repo updated
First seen
Licence
Apache-2.0

At a glance

A full Infrastructure as Code design and implementation pipeline.

  • Works in 3 steps: Preparation (Performed directly by… → Team Assembly and Execution → Integration and Final Deliverables
  • Requests like design IaC
  • SKILL.md covers Execution Mode, Agent Composition, Workflow and Modes by Task Scale, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Infra As Code is an agent skill from revfactory/harness-100. A full Infrastructure as Code design and implementation pipeline. An agent team collaborates to perform Terraform/Pulumi-based infrastructure design, security policies, cost optimization, and drift detection. Use this skill for requests like 'design IaC', 'write Terraform code', 'create infrastructure code', 'Pulumi project design', 'cloud infrastructure design', 'infrastructure security design', 'infrastructure cost optimization', 'drift detection setup', and other IaC tasks. Also supports codifying existing…

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Terraform and Pulumi. The licence is Apache-2.0.

When your agent uses it

  • Requests like design IaC
  • Write Terraform code
  • Create infrastructure code
  • Pulumi project design

Example prompts

  • “design IaC”
  • “write Terraform code”
  • “create infrastructure code”
  • “/infra-as-code”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Preparation (Performed directly by Orchestrator)
  2. Team Assembly and Execution
  3. Integration and Final Deliverables

What it can do on your machine

Read from SKILL.md and the folder at commit 8e8d35c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Infra As Code loads about 1.8k tokens when it runs. Until then it costs about 171 tokens; SKILL.md has 683 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~171
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from revfactory/harness-100 at commit 8e8d35c, republished under its Apache-2.0 licence (© revfactory). 683 words, ~1,793 tokens.

Download SKILL.mdSave it as .claude/skills/infra-as-code/SKILL.md (or your agent's skills folder).
name
infra-as-code
description
A full Infrastructure as Code design and implementation pipeline. An agent team collaborates to perform Terraform/Pulumi-based infrastructure design, security policies, cost optimization, and drift detection. Use this skill for requests like 'design IaC', 'write Terraform code', 'create infrastructure code', 'Pulumi project design', 'cloud infrastructure design', 'infrastructure security design', 'infrastructure cost optimization', 'drift detection setup', and other IaC tasks. Also supports codifying existing infrastructure (import). Note: actual terraform apply execution, cloud console operations, and production deployment are outside the scope of this skill.

Infra as Code — IaC Design Pipeline

An agent team collaborates to perform Terraform/Pulumi-based infrastructure design -> security -> cost optimization -> drift detection.

Execution Mode

Agent Team — 5 members communicate directly via SendMessage and cross-validate each other.

Agent Composition

AgentFileRoleType
infra-architect.claude/agents/infra-architect.mdArchitecture, module structure, environment separationgeneral-purpose
security-engineer.claude/agents/security-engineer.mdIAM, networking, encryption, compliancegeneral-purpose
cost-optimizer.claude/agents/cost-optimizer.mdResource sizing, reservations, FinOpsgeneral-purpose
drift-detector.claude/agents/drift-detector.mdState verification, policy compliance, auto-remediationgeneral-purpose
iac-reviewer.claude/agents/iac-reviewer.mdCross-validation, IaC best practicesgeneral-purpose

Workflow

Phase 1: Preparation (Performed directly by Orchestrator)
  1. Extract from user input:
    • Infrastructure Requirements: What service the infrastructure is for
    • Cloud Provider (optional): AWS / GCP / Azure
    • IaC Tool (optional): Terraform / Pulumi / OpenTofu
    • Constraints (optional): Budget, compliance, existing infrastructure
    • Existing Code (optional): Existing IaC code, architecture documents
  2. Create _workspace/ directory at the project root
  3. Organize input and save to _workspace/00_input.md
  4. If existing files are available, copy them to _workspace/ and skip the corresponding Phase
  5. Determine execution mode based on the scope of the request (see "Modes by Task Scale" below)
Phase 2: Team Assembly and Execution
OrderTaskAssigneeDependenciesDeliverable
1Infrastructure DesignarchitectNone_workspace/01_infra_design.md
2aSecurity DesignsecurityTask 1_workspace/02_security_design.md
2bCost AnalysiscostTask 1_workspace/03_cost_analysis.md
3Drift PolicydriftTasks 1, 2a_workspace/04_drift_policy.md
4Final ReviewreviewerTasks 1-3_workspace/05_review_report.md

Tasks 2a (security) and 2b (cost) can be executed in parallel.

Inter-team Communication Flow:

  • architect completes -> delivers network, IAM, data stores to security; delivers resource specs and scaling to cost; delivers module structure and core resources to drift
  • security completes -> delivers security policies and compliance checks to drift; delivers security cost items to cost
  • cost completes -> delivers cost anomaly detection criteria to drift
  • reviewer cross-validates all deliverables. Requests fixes for RED Must Fix items (up to 2 times)
Phase 3: Integration and Final Deliverables
  1. Check all files in _workspace/
  2. Verify all RED Must Fix items have been addressed
  3. Report the final summary to the user

Modes by Task Scale

User Request PatternExecution ModeDeployed Agents
"Design infrastructure code", "Full IaC"Full PipelineAll 5 agents
"Design infrastructure architecture only"Design Modearchitect + reviewer
"Review infrastructure security"Security Modesecurity + reviewer
"Analyze infrastructure costs"Cost Modecost + reviewer
"Set up drift detection"Drift Modedrift + reviewer
"Codify existing infrastructure"Import Modearchitect + drift + reviewer

Leveraging Existing Files: If the user provides existing IaC code, architecture documents, etc., copy the files to the appropriate location in _workspace/ and skip the corresponding agent's step.

Show full SKILL.md (271 more words)Show less

Data Transfer Protocol

StrategyMethodPurpose
File-based_workspace/ directoryStore and share main deliverables
Message-basedSendMessageReal-time delivery of key information, fix requests
Task-basedTaskCreate/TaskUpdateProgress tracking, dependency management

Error Handling

Error TypeStrategy
Provider undecidedDesign with AWS as default, note multi-cloud considerations
Scale unestimableStart small + Auto Scaling for elastic response
Agent failureRetry once -> if fails, proceed without that deliverable, note omission in review
RED found in reviewRequest fix from relevant agent -> rework -> re-verify (up to 2 times)
Existing infrastructure conflictInclude terraform import strategy, establish gradual migration plan

Test Scenarios

Normal Flow

Prompt: "Design Terraform infrastructure on AWS for running a NestJS API server. Use ECS Fargate + RDS PostgreSQL + ElastiCache Redis, with dev/staging/prod environment separation." Expected Result:

  • Design: VPC/subnet design, ECS/RDS/ElastiCache configuration, 3-environment module structure
  • Security: Security group matrix, IAM roles, KMS encryption, Checkov policies
  • Cost: Per-environment monthly cost estimates, Savings Plan suggestions, dev environment scheduling
  • Drift: Security group/IAM immediate remediation, config drift alerts
  • Review: Full consistency verification across all items
Existing Infrastructure Codification Flow

Prompt: "I want to convert infrastructure currently managed manually in the AWS console to Terraform" Expected Result:

  • Import mode: Establish terraform import strategy
  • Resource inventory, import command generation, state verification plan
  • Include gradual migration roadmap
Error Flow

Prompt: "Create simple web server infrastructure" (no detailed requirements) Expected Result:

  • Start design with basic configuration (VPC + EC2/ECS + ALB + RDS)
  • Ask additional requirement questions (scale, DB, domain, etc.)
  • Provide minimum configuration + expansion guide

Agent Extension Skills

SkillPathEnhanced AgentRole
terraform-module-patterns.claude/skills/terraform-module-patterns/skill.mdinfra-architect, drift-detectorModule structure, state management, environment separation, tagging strategy
cloud-cost-models.claude/skills/cloud-cost-models/skill.mdcost-optimizerAWS/GCP cost models, sizing, Savings Plan, FinOps maturity

© revfactory, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in en/26-infra-as-code/.claude/skills/infra-as-code of revfactory/harness-100.

Open the folder on GitHubat commit 8e8d35c

Compare with similar skills

Infra As Code next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Infra As Code compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Infra As Code this skillrevfactory/harness-1001.3k—~1.8kAutomated safety check: PassApache-2.0
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT
Cloudflaredmmulroy/cloudflare-skill728—~1.6kAutomated safety check: PassMIT
Spacectlspacelift-io/spacectl173—~2.3kAutomated safety check: PassMIT
Audit Infrastructure As Codecyberful/cyberful134—~649Automated safety check: PassAGPL-3.0
AWS Sst Developmentzxkane/aws-skills367—~2.7kAutomated safety check: WarnMIT

Similar skills

  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Cloudflare

    dmmulroy/cloudflare-skill

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and…

    728 GitHub stars~1.6k tokensUpdated 8 mo ago
    DevOps & CloudAuto-check passed
  • Spacectl

    spacelift-io/spacectl

    Manage Spacelift stacks, runs, modules, policies, and infrastructure via CLI.

    173 GitHub stars~2.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Audit infrastructure-as-code artifacts for unsafe defaults, policy gaps, privilege exposure, control drift, and deployment-impact evidence.

    134 GitHub stars~649 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • AWS Sst Development

    zxkane/aws-skills

    SST v4 (Ion) expert for managing AWS resources as code with the Pulumi-backed framework.

    367 GitHub stars~2.7k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check: warnings
  • Deploying Applications

    ancoleman/ai-design-components

    Deployment patterns from Kubernetes to serverless and edge functions.

    526 GitHub stars~3.1k tokensUpdated 10 mo ago
    DevOps & CloudAuto-check passed

More from revfactory/harness-100

All 464 skills in this repo
  • Anti Bot Analyzer

    revfactory/harness-100

    A skill for analyzing website anti-bot defense mechanisms and developing legitimate evasion strategies.

    1.3k GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • API Error Design Patterns

    revfactory/harness-100

    Reference for designing how an API reports failures: structured error codes, response shapes, client-friendly messages, an error catalog and retry or fallback advice.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Arg Parser Generator

    revfactory/harness-100

    Methodology for systematically designing and generating CLI tool argument parser structures.

    1.3k GitHub stars~1.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Audience Segmentation

    revfactory/harness-100

    Audience segmentation skill used by the analyst and curator agents.

    1.3k GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Audio Storytelling

    revfactory/harness-100

    Audio storytelling skill used by the podcast scriptwriter and show note editor.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed

Works with

Categories

Questions about Infra As Code

What does Infra As Code do?

A full Infrastructure as Code design and implementation pipeline. Infra As Code is an agent skill from revfactory/harness-100. A full Infrastructure as Code design and implementation pipeline.

When should I use Infra As Code?

Infra As Code fits situations like: requests like design IaC; write Terraform code; create infrastructure code; pulumi project design.

How do I install Infra As Code in Claude Code?

Run `npx skills add revfactory/harness-100 --skill infra-as-code -a claude-code`. Or copy the skill folder (en/26-infra-as-code/.claude/skills/infra-as-code in revfactory/harness-100) into .claude/skills/infra-as-code in your project. Claude Code loads it when a task matches its description.

How do I install Infra As Code in Codex?

Run `npx skills add revfactory/harness-100 --skill infra-as-code -a codex`. Or copy the skill folder (en/26-infra-as-code/.claude/skills/infra-as-code in revfactory/harness-100) into .agents/skills/infra-as-code in your project. Codex loads it when a task matches its description.

Can I use Infra As Code in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add revfactory/harness-100 --skill infra-as-code -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/infra-as-code, .gemini/skills/infra-as-code, .github/skills/infra-as-code and .opencode/skills/infra-as-code in your project.

What does Infra As Code need to run?

SKILL.md names no scripts, command-line tools or credentials: Infra As Code is instructions for the agent only.

Does Infra As Code access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Infra As Code safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Infra As Code use?

Infra As Code is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Infra As Code use?

About 1.8k tokens (SKILL.md is roughly 7.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Infra As Code?

Skills that share tags, products or a category with Infra As Code: Cloudflare (hodgef/apiker, 127 stars), Cloudflare (dmmulroy/cloudflare-skill, 728 stars), Spacectl (spacelift-io/spacectl, 173 stars) and Audit Infrastructure As Code (cyberful/cyberful, 134 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Infra As Code?

revfactory (a GitHub user) maintains it in revfactory/harness-100, which has 1,290 GitHub stars. The repository holds 464 skills in this directory. The repository was last updated on March 22, 2026.

Source: revfactory/harness-100 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.