when packaging a release, or when storing tokens in an Electron app.
- `iac-security` — Terraform, CloudFormation, and Pulumi hardening: state as a secret store, pinned providers and modules, encryption
Copilot Instructions for terraform-cdk-constructs
## Project Overview
This is `@microsoft/terraform-cdk-constructs` — a JSII-compatible TypeScript library providing Azure CDK constructs using the AZAPI Terraform provider for direct Azure REST
secret** and
return 503 until it exists. Deploy is imperative `gcloud` via `infra/deploy-api.sh` (not Terraform).
Full state and secret table: [`docs/deployment.md`](../docs/deployment.md).
## Reviewing or verifying work you didn't write
Terraform State Importer
Terraform State Importer is a Go CLI tool that helps migrate Azure workloads to Terraform by analyzing existing Azure resources and generating import blocks for new Terraform
describe and drive existing SDAF
behaviour; they never modify pipelines, PowerShell utilities, playbooks, or
Terraform.
3. **Two skills, disjoint triggers.** "Set up SDAF on ADO" / "onboard a
workload zone" → `sdaf
here — that belongs in `production-ready/`.
- `aks/` — minimal AKS cluster (the primary working sample, Terraform).
- `sap/` — SAP BTP entitlement for the `edge_integration_cell` plan via the `SAP/btp` Terraform provider
files under `output/`. No
`az ... create/update/delete/set`, no `New-Az*` / `Set-Az*` / `Remove-Az*`, no `terraform apply`,
no `kubectl apply/delete` on your own initiative.
- **One opt-in write tool.** `Deploy-QuotaGroups
Model | High stakes
Quick Lookup | Fast Model | Cost/speed efficiency
Summarization | Fast Model | Simple task
Terraform Refactor | Powerful Model | Complex analysis
PR Review | Powerful Model | Context matters
```
### Model Fallback Chain
across every major registry. It also includes a production fullstack template (FastAPI + React + PostgreSQL + Terraform) and persistent background agents.
## CLI Architecture
The CLI (`cli/`) is the primary product
Repository Purpose
This repository contains pre-written HashiCorp Sentinel policies for AWS Terraform that enforce ISO/IEC 27001:2013 Annex A security controls. The policies are consumed by HCP Terraform
when and how to use `aztfexport` to reverse engineer manually created Azure resources into Terraform Infrastructure-as-Code templates.
## When to Use aztfexport
Use `aztfexport` when:
- The user wants
playbook for the claude-skill-deployer VS Code extension, with a DevOps-workspace focus (Terraform, Kubernetes/Helm, Azure/AWS, CI/CD). Covers live-verification benchmarking against synthetic DevOps repos, release-pipeline health checks