Agent skill

Terraform Module Patterns

by revfactory in revfactory/harness-100

Detailed guide on Terraform module design patterns, directory structures, state management, and environment separation strategies.

Apache-2.0Auto-check passedDevOps & Cloud

Install Terraform Module Patterns

skills CLI
$ npx skills add revfactory/harness-100 --skill terraform-module-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install revfactory/harness-100 terraform-module-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/revfactory/harness-100.git skills-src && mkdir -p .claude/skills && cp -r skills-src/en/26-infra-as-code/.claude/skills/terraform-module-patterns .claude/skills/terraform-module-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
terraform-module-patterns
GitHub stars
1.3k
Token cost
~1.4k tokens
SKILL.md length
150 words
Files
1
Skills in repo
464
Repo updated
First seen
Licence
Apache-2.0

At a glance

Detailed guide on Terraform module design patterns, directory structures, state management, and environment separation strategies.

  • Works in 3 steps: Single Responsibility Module → Input/Output Design → Conditional Resources
  • Terraform modules
  • SKILL.md covers Directory Structure Patterns, Module Design Principles, State Management Patterns and Tagging Strategy, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Terraform Module Patterns is an agent skill from revfactory/harness-100. Detailed guide on Terraform module design patterns, directory structures, state management, and environment separation strategies. Use this skill for 'Terraform modules', 'module structure', 'state management', 'remote state', 'environment separation', 'workspace', 'terragrunt', 'module patterns', and other Terraform module design tasks. Enhances the IaC design capabilities of infra-architect and drift-detector. Note: actual terraform apply and infrastructure provisioning execution are outside the scope of this…

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Infrastructure as code. It works with Terraform. The licence is Apache-2.0.

When your agent uses it

  • Terraform modules
  • Module structure
  • State management
  • Environment separation

Example prompts

  • “Terraform modules”
  • “module structure”
  • “state management”
  • “/terraform-module-patterns”

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Single Responsibility Module
  2. Input/Output Design
  3. Conditional Resources

What it can do on your machine

Read from SKILL.md and the folder at commit 8e8d35c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are hcl).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Terraform Module Patterns loads about 1.4k tokens when it runs. Until then it costs about 137 tokens; SKILL.md has 150 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~137
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from revfactory/harness-100 at commit 8e8d35c, republished under its Apache-2.0 licence (© revfactory). 150 words, ~1,360 tokens.

Download SKILL.mdSave it as .claude/skills/terraform-module-patterns/SKILL.md (or your agent's skills folder).
name
terraform-module-patterns
description
Detailed guide on Terraform module design patterns, directory structures, state management, and environment separation strategies. Use this skill for 'Terraform modules', 'module structure', 'state management', 'remote state', 'environment separation', 'workspace', 'terragrunt', 'module patterns', and other Terraform module design tasks. Enhances the IaC design capabilities of infra-architect and drift-detector. Note: actual terraform apply and infrastructure provisioning execution are outside the scope of this skill.

Terraform Module Patterns — Terraform Module Design Pattern Guide

Patterns and best practices for designing reusable and maintainable Terraform modules.

Directory Structure Patterns

Pattern 1: Module Layer Separation
infrastructure/
├── modules/                    # Reusable modules
│   ├── networking/
│   │   ├── vpc/
│   │   │   ├── main.tf
│   │   │   ├── variables.tf
│   │   │   ├── outputs.tf
│   │   │   └── README.md
│   │   ├── security-group/
│   │   └── load-balancer/
│   ├── compute/
│   │   ├── ecs-service/
│   │   ├── lambda/
│   │   └── ec2-asg/
│   └── data/
│       ├── rds/
│       ├── elasticache/
│       └── s3/
├── environments/               # Per-environment configuration
│   ├── dev/
│   │   ├── main.tf            # Module invocations
│   │   ├── terraform.tfvars   # Environment variables
│   │   └── backend.tf         # State storage
│   ├── staging/
│   └── prod/
└── global/                    # Cross-environment (IAM, DNS)
    ├── iam/
    └── route53/
Pattern 2: Terragrunt-based DRY
infrastructure/
├── modules/                    # Same as above
├── terragrunt.hcl             # Root config (backend, provider)
└── environments/
    ├── terragrunt.hcl         # Common variables
    ├── dev/
    │   ├── terragrunt.hcl     # include root + env vars
    │   ├── vpc/
    │   │   └── terragrunt.hcl # module source + inputs
    │   ├── ecs/
    │   └── rds/
    └── prod/

Module Design Principles

1. Single Responsibility Module
hcl
# Good: VPC module handles only VPC
module "vpc" {
  source = "./modules/networking/vpc"
  cidr_block = "10.0.0.0/16"
  az_count   = 3
}

# Bad: One module for all infrastructure
module "everything" {  # Anti-pattern!
  source = "./modules/full-stack"
}
2. Input/Output Design
hcl
# variables.tf — Validation required
variable "instance_type" {
  type        = string
  description = "EC2 instance type"
  default     = "t3.medium"
  validation {
    condition     = can(regex("^t3\\.", var.instance_type))
    error_message = "Only t3 family is allowed."
  }
}

variable "environment" {
  type = string
  validation {
    condition     = contains(["dev", "staging", "prod"], var.environment)
    error_message = "Must be one of dev, staging, prod."
  }
}

# outputs.tf — Expose only values needed by other modules
output "vpc_id" {
  value       = aws_vpc.main.id
  description = "ID of the created VPC"
}
3. Conditional Resources
hcl
variable "enable_monitoring" {
  type    = bool
  default = true
}

resource "aws_cloudwatch_metric_alarm" "cpu" {
  count = var.enable_monitoring ? 1 : 0
  # ...
}

State Management Patterns

Remote State Configuration
hcl
# backend.tf
terraform {
  backend "s3" {
    bucket         = "company-terraform-state"
    key            = "environments/prod/vpc/terraform.tfstate"
    region         = "ap-northeast-2"
    dynamodb_table = "terraform-locks"
    encrypt        = true
  }
}
State Separation Strategies
StrategySeparation BasisProsCons
Per-environmentdev/staging/prodEnvironment isolation, independent deploymentNeed data source for cross-env references
Per-layernetwork/compute/dataReduced blast radiusComplex reference management
Per-teamTeam-owned resourcesAutonomyShared resource management difficulty
Per-lifecycleChange frequencyStable resource protectionBoundary definition difficulty
Cross-State References
hcl
# Read VPC ID from network state
data "terraform_remote_state" "network" {
  backend = "s3"
  config = {
    bucket = "company-terraform-state"
    key    = "environments/prod/network/terraform.tfstate"
    region = "ap-northeast-2"
  }
}

# Usage
resource "aws_ecs_service" "app" {
  network_configuration {
    subnets = data.terraform_remote_state.network.outputs.private_subnet_ids
  }
}

Tagging Strategy

hcl
locals {
  common_tags = {
    Environment = var.environment
    Project     = var.project_name
    ManagedBy   = "terraform"
    Team        = var.team_name
    CostCenter  = var.cost_center
  }
}

resource "aws_instance" "app" {
  tags = merge(local.common_tags, {
    Name = "${var.project_name}-${var.environment}-app"
    Role = "application"
  })
}

Anti-patterns and Solutions

Anti-patternProblemSolution
Giant state fileSlow plan/apply, large blast radiusSplit by layer
Hardcoded valuesCannot reuse across environmentsvariables + tfvars
Provider inside moduleLost flexibilityProvider only at root
Complex conditions with countResource recreation on index changesUse for_each
Plaintext secretsSecurity violationSSM/Vault references

© revfactory, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in en/26-infra-as-code/.claude/skills/terraform-module-patterns of revfactory/harness-100.

Open the folder on GitHubat commit 8e8d35c

Compare with similar skills

Terraform Module Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Terraform Module Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Terraform Module Patterns this skillrevfactory/harness-1001.3k—~1.4kAutomated safety check: PassApache-2.0
Terraform and OpenTofu Guideagentscope-ai/QwenPaw35k6 repos~4.2kAutomated safety check: PassApache-2.0
Terraform Skillantonbabenko/terraform-skill2.4k1 repos~5.1kAutomated safety check: PassApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2596 repos~1.1kAutomated safety check: NotesCustom licence
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only

Similar skills

  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    35k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Terraform Skill

    antonbabenko/terraform-skill

    A skill your agent uses when writing, reviewing, or debugging Terraform/OpenTofu modules, tests, CI, scans, or state ops - diagnoses failure mode (identity churn, secrets, blast radius, CI drift…

    2.4k GitHub starsUsed in 1 repo~5.1k tokens
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    259 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Cloudflare

    dmmulroy/cloudflare-skill

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and…

    728 GitHub stars~1.6k tokensUpdated 8 mo ago
    DevOps & CloudAuto-check passed

More from revfactory/harness-100

All 464 skills in this repo
  • Anti Bot Analyzer

    revfactory/harness-100

    A skill for analyzing website anti-bot defense mechanisms and developing legitimate evasion strategies.

    1.3k GitHub stars~1.1k tokensUpdated 6 mo ago
    Auto-check passed
  • API Error Design Patterns

    revfactory/harness-100

    Reference for designing how an API reports failures: structured error codes, response shapes, client-friendly messages, an error catalog and retry or fallback advice.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed
  • API Security Checklist

    revfactory/harness-100

    Walks a backend-dev agent through OWASP API Top 10 checks, authentication and authorization patterns, and defense code during API design.

    1.3k GitHub stars~1.7k tokensUpdated 6 mo ago
    Auto-check passed
  • Arg Parser Generator

    revfactory/harness-100

    Methodology for systematically designing and generating CLI tool argument parser structures.

    1.3k GitHub stars~1.2k tokensUpdated 6 mo ago
    Auto-check passed
  • Audience Segmentation

    revfactory/harness-100

    Audience segmentation skill used by the analyst and curator agents.

    1.3k GitHub stars~1.3k tokensUpdated 6 mo ago
    Auto-check passed
  • Audio Storytelling

    revfactory/harness-100

    Audio storytelling skill used by the podcast scriptwriter and show note editor.

    1.3k GitHub stars~1.6k tokensUpdated 6 mo ago
    Auto-check passed

Works with

Categories

Questions about Terraform Module Patterns

What does Terraform Module Patterns do?

Detailed guide on Terraform module design patterns, directory structures, state management, and environment separation strategies. Terraform Module Patterns is an agent skill from revfactory/harness-100. Detailed guide on Terraform module design patterns, directory structures, state management, and environment separation strategies.

When should I use Terraform Module Patterns?

Terraform Module Patterns fits situations like: terraform modules; module structure; state management; environment separation.

How do I install Terraform Module Patterns in Claude Code?

Run `npx skills add revfactory/harness-100 --skill terraform-module-patterns -a claude-code`. Or copy the skill folder (en/26-infra-as-code/.claude/skills/terraform-module-patterns in revfactory/harness-100) into .claude/skills/terraform-module-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Terraform Module Patterns in Codex?

Run `npx skills add revfactory/harness-100 --skill terraform-module-patterns -a codex`. Or copy the skill folder (en/26-infra-as-code/.claude/skills/terraform-module-patterns in revfactory/harness-100) into .agents/skills/terraform-module-patterns in your project. Codex loads it when a task matches its description.

Can I use Terraform Module Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add revfactory/harness-100 --skill terraform-module-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/terraform-module-patterns, .gemini/skills/terraform-module-patterns, .github/skills/terraform-module-patterns and .opencode/skills/terraform-module-patterns in your project.

What does Terraform Module Patterns need to run?

SKILL.md names no scripts, command-line tools or credentials: Terraform Module Patterns is instructions for the agent only.

Does Terraform Module Patterns access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Terraform Module Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Terraform Module Patterns use?

Terraform Module Patterns is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Terraform Module Patterns use?

About 1.4k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Terraform Module Patterns?

Skills that share tags, products or a category with Terraform Module Patterns: Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 35k stars), Terraform Skill (antonbabenko/terraform-skill, 2.4k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 259 stars) and Cloudflare (hodgef/apiker, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Terraform Module Patterns?

revfactory (a GitHub user) maintains it in revfactory/harness-100, which has 1,290 GitHub stars. The repository holds 464 skills in this directory. The repository was last updated on March 22, 2026.

Source: revfactory/harness-100 on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.