Terraform and OpenTofu infrastructure as code — module design, state management, multi-environment setups, remote backends, secrets management, CI/CD integration. NOT for Pulumi, CDK, Ansible,
Deep-dive Terraform architecture review, module design, state management, and migration. Use for structured investigations of Terraform workspaces, provider configuration, module coupling, import workflows, and test coverage. Triggers on: "Terraform audit", "module review", "state management", "Terraform import", "workspace design", "provider config review", "Terraform testing".
Analyze Terraform plan JSON output for AzureRM Provider to distinguish between false-positive diffs (order-only changes in Set-type attributes) and actual resource changes. Use when reviewing terraform plan output for Azure resources like Application Gateway, Load Balancer, Firewall, Front Door, NSG, and other resources with Set-type attributes that cause spurious diffs due to internal ordering changes.
Generate Terraform docs and inject them into terraform/README.md using terraform-docs markdown table output-mode inject. Use when the user asks to refresh, regenerate, or update Terraform documentation or README.
Terraform and OpenTofu module architecture, remote state with locking and encryption, provider and module version pinning, drift detection, and safe plan/apply workflow. Use when structuring or restructuring a Terraform repository across dev, staging and production environments, writing reusable modules, configuring a state backend, or investigating unexplained infrastructure drift.
Generate Terraform HCL code following HashiCorp's official style conventions and best practices. Use when writing, reviewing, or generating Terraform configurations.
Analyse an OpenTofu/Terraform plan (or `tofu show -json` output) BEFORE approval and produce a per-change risk summary plus a clear APPROVE/REJECT recommendation. Use whenever a plan is awaiting the Spacelift approval gate — especially for any prod / geo-prod stack, or any change touching security groups, KMS, IAM, state/backup buckets, StatefulSets, or PVCs.
Safe Terraform provider upgrades with automatic resource migration, breaking change detection, and state management using moved blocks. Use when upgrading provider versions, handling removed resources, migrating deprecated syntax, or performing major version upgrades.
[omh] Infrastructure-as-code change -- Terraform, OpenTofu, Pulumi, a Kubernetes manifest, a Helm chart: read the drift, the blast radius and the cost delta from the saved plan, then stage the apply behind a health gate with a rollback per stage. Use when the user says: iac-change, iac change, infrastructure as code, infrastructure-as-code, terraform plan, terraform apply, terraform state, terraform drift.
R spatial data: sf vectors, terra rasters, spdep/spatialreg spatial stats, leaflet interactive maps, ggplot2+geom_sf() choropleths. CRS, spatial joins, geometry ops. Use when execution language is R. Python equivalent: geopandas.
Generate Terraform HCL code following HashiCorp's official style conventions and best practices. Use when writing, reviewing, or generating Terraform configurations, HCL code, infrastructure as code, Terraform modules, or refactoring existing Terraform projects. Not for Pulumi, CloudFormation, Bicep, or other IaC tools.
Generate Terraform infrastructure and deployment scaffolding for AWS based on the detected project structure, runtime stack, and explicit infrastructure inputs. Use when a developer wants to deploy an application to AWS using Terraform.
Authors reusable, production-grade Terraform modules with clean typed variables, well-documented outputs, version pinning, state hygiene, and built-in validation. Use this skill when the user asks to "write a Terraform module", "refactor Terraform into a module", "add variable validation", "structure a Terraform repo", "publish a module to the registry", "review my .tf files", or otherwise create, organize, or harden HCL infrastructure code.
Discover existing cloud resources using Terraform Search queries and bulk import them into Terraform management. Use when bringing unmanaged infrastructure under Terraform control, auditing cloud resources, or migrating to IaC.
Use when generating Terraform through the kapicorp Terraform generator: a Kapitan inventory that produces provider blocks, resources, and project layout for Terraform rather than hand-written .tf files. Reach for this whenever the user configures Terraform via a Kapitan components or terraform block, sets a provider, or asks how to manage cloud infrastructure from the inventory.
A folder with a SKILL.md file: a name, a description of when to use it, and instructions. Claude loads a skill only when the task matches its description.
How do I use one I find here?
Copy the folder into your project's .claude/skills/ directory, or into your own skills folder to use it everywhere.
What do the warnings mean?
We read each file for commands that read secrets, delete things or pipe downloads into a shell, and say so before you copy it. No warning is not a promise that a file is safe.
Which skills worked for people?
Open a skill to see its discussion. Reports from people and their agents are coming.