terraform-principles
- Repo stars 0
- Author repo skills-registry
Terraform Principles
Use this skill as standing guidance for this domain. Apply the checklist first; read the detailed reference only when the task is substantial, risky, unfamiliar, or review-oriented.
Operating Rules
- Prefer the repository's existing conventions, toolchain, and CI commands over generic defaults.
- Make the smallest coherent change that satisfies the request while preserving behavior.
- Treat tests, linting, dependency hygiene, and security review as part of completion.
- If a principle conflicts with higher-priority repository instructions or an explicit user request, follow the higher-priority instruction and call out the tradeoff.
Core Checklist
- Use modules to create reusable boundaries, but keep module interfaces small and explicit.
- Store state remotely with encryption and locking; restrict state access because state can contain secrets.
- Pin Terraform/OpenTofu and provider versions; commit lock files where applicable.
- Keep variables typed, outputs intentional, and sensitive values marked
sensitive = true. - Prefer data sources and locals over hardcoded environment-specific values.
- Review plans in CI and separate plan from apply with approval for production.
- Apply least-privilege IAM and policy-as-code checks for sensitive infrastructure.
- Support OpenTofu deliberately when the project has chosen it; do not mix CLIs accidentally.
Validation
Run applicable checks when they exist in the project; if a tool is missing, report that it was skipped.
terraform fmt -recursiveortofu fmt -recursiveterraform validateortofu validatetflint --recursivewhen configuredtrivy config ., Checkov, Conftest, or the project's policy scanner for risky infrastructure
Detailed Reference
For the complete principle set with examples and edge cases, read references/principles.md when deeper guidance is useful.
<!-- tomevault:4.0:skill_md:2026-05-22 -->Source: asciifylabs/asciify-skills — distributed by TomeVault.
- Fluxly category
- DevOps
- Author-declared agents
- No explicit declaration found; this is not inferred or tested compatibility
- Static check
- 88 / 100 · heuristic scan, not runtime safety proof
- Author / version / license
- @tomevault-io · no license declared
- Fluxly token estimate
- Lean
- Fluxly setup estimate
- Plug-and-play
- External API key
- No requirement detected
- Detected OS requirements
- Unspecified
- Runtime requirements
- Unspecified
- Detected file/system behavior
-
- Read-only
- Write / modify
- Detected network behavior
- Local-only
- Install commands
- None (reference only)
Profile is derived at build time from SKILL.md and install vectors. Subject to drift from author intent.
Heads up: 未限定 allowed-tools,默认拥有全部工具权限。
The current SKILL.md does not define a fixed output example. Prefer the repository's existing conventions, toolchain, and CI commands over generic defaults. Make the smallest coherent change that satisfies the request while preserving behavior. Treat tests, linting, dependency hygiene, and security review as part of…
Use modules to create reusable boundaries, but keep module interfaces small and explicit. Store state remotely with encryption and locking; restrict state access because state can contain secrets. Pin Terraform/OpenTofu and provider versions; commit lock files…
Run applicable checks when they exist in the project; if a tool is missing, report that it was skipped. terraform fmt -recursive or tofu fmt -recursive terraform validate or tofu validate
For the complete principle set with examples and edge cases, read references/principles.md when deeper guidance is useful. Source: asciifylabs/asciify-skills — distributed by TomeVault. <!-- tomevault:4.0:skillmd:2026-05-22 -->
# Terraform Principles
Use this skill as standing guidance for this domain. Apply the checklist first; read the detailed reference only when the task is substantial, risky, unfamiliar, or review-oriented.
## Operating Rules
- Prefer the repository's existing conventions, toolchain, and CI commands over generic defaults.
- Make the smallest coherent change that satisfies the request while preserving behavior.
- Treat tests, linting, dependency hygiene, and security review as part of completion.
- If a principle conflicts with higher-priority repository instructions or an explicit user request, follow the higher-priority instruction and call out the tradeoff.
## Core Checklist
- Use modules to create reusable boundaries, but keep module interfaces small and explicit.
- Store state remotely with encryption and locking; restrict state access because state can contain secrets.
- Pin Terraform/OpenTofu and provider versions; commit lock files where applicable.
- Keep variables typed, outputs intentional, and sensitive values marked `sensitive = true`.
- Prefer data sources and locals over hardcoded environment-specific values.
- Review plans in CI and separate plan from apply with approval for production.
- Apply least-privilege IAM and policy-as-code checks for sensitive infrastructure.
- Support OpenTofu deliberately when the project has chosen it; do not mix CLIs accidentally.
## Validation
Run applicable checks when they exist in the project; if a tool is missing, report that it was skipped.
- `terraform fmt -recursive` or `tofu fmt -recursive`
- `terraform validate` or `tofu validate`
- `tflint --recursive` when configured
- `trivy config .`, Checkov, Conftest, or the project's policy scanner for risky infrastructure
## Detailed Reference
… Author text anchors workflow facts; Fluxly only indexes current sections, terms, files, and commands.
sections -> Operating Rules → Core Checklist → Validation → Detailed Reference
terms -> Use this skill as standing guidance for this domain. · - Prefer the repository's existing conventions, toolchain, and CI commands over generic defaults. · - Use modules to create reusable boundaries, but keep module interfaces small and explicit. · Run applicable checks when they exist in the project; if a tool is missing, report that it was skipped. · --- > Source: [asciifylabs/asciify-skills](https://github.com/asciifylabs/asciify-skills) — distributed by [TomeVault](https://tomevault.io).
files/cmd -> sensitive = true · terraform fmt -recursive · tofu fmt -recursive · terraform validate · tofu validate · tflint --recursive · trivy config .
body sha256 -> 3326c1a641ef
Decide Fit First
Design Intent
How To Use It
Boundaries And Review