Terraform 助手
- 作者仓库星标 0
- 作者仓库 skills-registry
Terraform Principles
Use this skill as standing guidance for this domain. Apply the checklist first; read the detailed reference only when the task is substantial, risky, unfamiliar, or review-oriented.
Operating Rules
- Prefer the repository's existing conventions, toolchain, and CI commands over generic defaults.
- Make the smallest coherent change that satisfies the request while preserving behavior.
- Treat tests, linting, dependency hygiene, and security review as part of completion.
- If a principle conflicts with higher-priority repository instructions or an explicit user request, follow the higher-priority instruction and call out the tradeoff.
Core Checklist
- Use modules to create reusable boundaries, but keep module interfaces small and explicit.
- Store state remotely with encryption and locking; restrict state access because state can contain secrets.
- Pin Terraform/OpenTofu and provider versions; commit lock files where applicable.
- Keep variables typed, outputs intentional, and sensitive values marked
sensitive = true. - Prefer data sources and locals over hardcoded environment-specific values.
- Review plans in CI and separate plan from apply with approval for production.
- Apply least-privilege IAM and policy-as-code checks for sensitive infrastructure.
- Support OpenTofu deliberately when the project has chosen it; do not mix CLIs accidentally.
Validation
Run applicable checks when they exist in the project; if a tool is missing, report that it was skipped.
terraform fmt -recursiveortofu fmt -recursiveterraform validateortofu validatetflint --recursivewhen configuredtrivy config ., Checkov, Conftest, or the project's policy scanner for risky infrastructure
Detailed Reference
For the complete principle set with examples and edge cases, read references/principles.md when deeper guidance is useful.
<!-- tomevault:4.0:skill_md:2026-05-22 -->Source: asciifylabs/asciify-skills — distributed by TomeVault.
- 流狐分类
- 运维部署
- 作者声明 Agent
- 未找到明确声明;不据此推断已兼容或已测试
- 静态检查
- 88 / 100 · 启发式扫描,不代表运行安全
- 作者 / 版本 / 许可
- @tomevault-io · 未声明 license
- 流狐 Token 估算
- 低消耗
- 流狐接入估算
- 即装即用
- 是否需要外部 API Key
- 未发现要求
- 检测到的系统要求
- 未声明
- 底层运行要求
- 未声明
- 检测到的文件与系统行为
-
- 只读
- 允许写入 / 修改
- 检测到的网络行为
- 仅限本地
- 安装命令数
- 无(仅作为资料)
档案由构建时根据 SKILL.md 与安装命令自动衍生,可能与作者实际意图存在差异。
需要注意: 未限定 allowed-tools,默认拥有全部工具权限。
作者没有在当前 SKILL.md 中定义固定输出样例。 Prefer the repository's existing conventions, toolchain, and CI commands over generic defaults. Make the smallest coherent change that satisfies the request while preserving behavior. Treat tests, linting, dependency hygiene, and security review as part of…
Use modules to create reusable boundaries, but keep module interfaces small and explicit. Store state remotely with encryption and locking; restrict state access because state can contain secrets. Pin Terraform/OpenTofu and provider versions; commit lock files…
Run applicable checks when they exist in the project; if a tool is missing, report that it was skipped. terraform fmt -recursive or tofu fmt -recursive terraform validate or tofu validate
For the complete principle set with examples and edge cases, read references/principles.md when deeper guidance is useful. Source: asciifylabs/asciify-skills — distributed by TomeVault. <!-- tomevault:4.0:skillmd:2026-05-22 -->
# Terraform Principles
Use this skill as standing guidance for this domain. Apply the checklist first; read the detailed reference only when the task is substantial, risky, unfamiliar, or review-oriented.
## Operating Rules
- Prefer the repository's existing conventions, toolchain, and CI commands over generic defaults.
- Make the smallest coherent change that satisfies the request while preserving behavior.
- Treat tests, linting, dependency hygiene, and security review as part of completion.
- If a principle conflicts with higher-priority repository instructions or an explicit user request, follow the higher-priority instruction and call out the tradeoff.
## Core Checklist
- Use modules to create reusable boundaries, but keep module interfaces small and explicit.
- Store state remotely with encryption and locking; restrict state access because state can contain secrets.
- Pin Terraform/OpenTofu and provider versions; commit lock files where applicable.
- Keep variables typed, outputs intentional, and sensitive values marked `sensitive = true`.
- Prefer data sources and locals over hardcoded environment-specific values.
- Review plans in CI and separate plan from apply with approval for production.
- Apply least-privilege IAM and policy-as-code checks for sensitive infrastructure.
- Support OpenTofu deliberately when the project has chosen it; do not mix CLIs accidentally.
## Validation
Run applicable checks when they exist in the project; if a tool is missing, report that it was skipped.
- `terraform fmt -recursive` or `tofu fmt -recursive`
- `terraform validate` or `tofu validate`
- `tflint --recursive` when configured
- `trivy config .`, Checkov, Conftest, or the project's policy scanner for risky infrastructure
## Detailed Reference
… 作者原文负责流程事实;流狐只索引当前章节、要点、文件与命令。
章节 -> Operating Rules → Core Checklist → Validation → Detailed Reference
要点 -> Use this skill as standing guidance for this domain. · - Prefer the repository's existing conventions, toolchain, and CI commands over generic defaults. · - Use modules to create reusable boundaries, but keep module interfaces small and explicit. · Run applicable checks when they exist in the project; if a tool is missing, report that it was skipped. · --- > Source: [asciifylabs/asciify-skills](https://github.com/asciifylabs/asciify-skills) — distributed by [TomeVault](https://tomevault.io).
文件/命令 -> sensitive = true · terraform fmt -recursive · tofu fmt -recursive · terraform validate · tofu validate · tflint --recursive · trivy config .
内容 SHA-256 -> 3326c1a641ef
原文结构
适用与边界
原文中的明确线索
sensitive = true、terraform fmt -recursive、tofu fmt -recursive、terraform validate、tofu validate、tflint --recursive、trivy config .