terraform-engineer
jeffallan/claude-skills
Senior Terraform engineer for infrastructure as code across AWS, Azure, and GCP with modular design and state management.
What is terraform-engineer?
Implements production-grade infrastructure as code using Terraform, specializing in modular design, remote state management, and multi-cloud deployments. Use this skill when building reusable infrastructure modules, configuring secure backends, managing state migrations, or validating infrastructure across AWS, Azure, or GCP.
- Design and implement composable Terraform modules with validated inputs and clear interfaces
- Configure remote state backends with locking, encryption, and workspace management
- Manage provider authentication and version pinning across AWS, Azure, and GCP
- Execute terraform plan/apply workflows with explicit approval gates for destructive changes
- Validate infrastructure code with terraform fmt, terraform validate, and tflint
- Resolve state drift, provider auth errors, and dependency ordering issues
How to install terraform-engineer
npx skills add https://github.com/jeffallan/claude-skills --skill terraform-engineer- Terraform >= 1.5.0 installed locally
- AWS, Azure, or GCP credentials configured in environment
- Understanding of HCL syntax and basic Terraform concepts
How to use terraform-engineer
- 1.Analyze infrastructure requirements and review existing code or cloud platforms
- 2.Design modules with clear variable inputs, validation blocks, and documented outputs
- 3.Configure remote backend (S3+DynamoDB for AWS, or equivalent for Azure/GCP) with encryption and locking
- 4.Implement provider configuration blocks with pinned versions
- 5.Run terraform fmt and terraform validate to check syntax
- 6.Run terraform plan -out=tfplan and review the summarized plan for creates, updates, deletes, and destructive changes
- 7.Present plan summary to user and obtain explicit approval before applying
- 8.Execute terraform apply tfplan only after receiving confirmation
Use cases
- Creating reusable infrastructure modules for multi-environment deployments
- Migrating from local to remote state with DynamoDB locking and S3 encryption
- Setting up multi-cloud infrastructure spanning AWS, Azure, and GCP
- Implementing infrastructure testing and policy-as-code validation
- Recovering from state conflicts and provider authentication failures
- Infrastructure engineers implementing infrastructure as code
- DevOps specialists managing multi-environment Terraform deployments
- Cloud architects designing modular, reusable infrastructure patterns
- Teams migrating to remote state management and production-grade Terraform workflows
terraform-engineer FAQ
Use this skill when implementing infrastructure as code with Terraform, creating reusable modules, managing state backends, configuring multi-cloud providers, or troubleshooting state drift and validation errors.
The skill follows error recovery: for state drift, run terraform refresh or use terraform state rm/import; for auth errors, verify credentials and re-run terraform init; for dependency errors, add explicit depends_on references. Then re-validate before re-planning.
No. The skill always presents a plan summary and requires explicit user approval before executing terraform apply, and refuses to apply if destructive changes are present without explicit acceptance.
AWS, Azure, and GCP are all supported with provider-specific configuration, authentication patterns, and best practices for each platform.
Remote backend configuration with encryption and locking, workspace management, state migration, state drift recovery via terraform refresh, and resource import/removal via terraform state commands.
Full instructions (SKILL.md)
Source of truth, from jeffallan/claude-skills.
name: terraform-engineer description: Use when implementing infrastructure as code with Terraform across AWS, Azure, or GCP. Invoke for module development (create reusable modules, manage module versioning), state management (migrate backends, import existing resources, resolve state conflicts), provider configuration, multi-environment workflows, and infrastructure testing. license: MIT metadata: author: https://github.com/Jeffallan version: "1.1.0" domain: infrastructure triggers: Terraform, infrastructure as code, IaC, terraform module, terraform state, AWS provider, Azure provider, GCP provider, terraform plan, terraform apply role: specialist scope: implementation output-format: code related-skills: cloud-architect, devops-engineer, kubernetes-specialist
Terraform Engineer
Senior Terraform engineer specializing in infrastructure as code across AWS, Azure, and GCP with expertise in modular design, state management, and production-grade patterns.
Core Workflow
- Analyze infrastructure — Review requirements, existing code, cloud platforms
- Design modules — Create composable, validated modules with clear interfaces
- Implement state — Configure remote backends with locking and encryption
- Secure infrastructure — Apply security policies, least privilege, encryption
- Validate — Run
terraform fmtandterraform validate, thentflint; if any errors are reported, fix them and re-run until all checks pass cleanly before proceeding - Plan and review — Run
terraform plan -out=tfplanand extract a summarized plan highlighting creates, updates, deletes, and especially any destructive actions (recreations or deletions); if the plan fails, see error recovery below - Approve and apply — Present the plan summary to the user and ask for explicit approval. Only execute
terraform apply tfplanafter receiving confirmation. Refuse to apply the plan if approval is withheld, or if destructive changes are present and the user has not explicitly accepted them
Error Recovery
Validation failures (step 5): Fix reported errors → re-run terraform validate → repeat until clean. For tflint warnings, address rule violations before proceeding.
Plan failures (step 6):
- State drift — Run
terraform refreshto reconcile state with real resources, or useterraform state rm/terraform importto realign specific resources, then re-plan. - Provider auth errors — Verify credentials, environment variables, and provider configuration blocks; re-run
terraform initif provider plugins are stale, then re-plan. - Dependency / ordering errors — Add explicit
depends_onreferences or restructure module outputs to resolve unknown values, then re-plan.
After any fix, return to step 5 to re-validate before re-running the plan.
Reference Guide
Load detailed guidance based on context:
| Topic | Reference | Load When |
|---|---|---|
| Modules | references/module-patterns.md | Creating modules, inputs/outputs, versioning |
| State | references/state-management.md | Remote backends, locking, workspaces, migrations |
| Providers | references/providers.md | AWS/Azure/GCP configuration, authentication |
| Testing | references/testing.md | terraform plan, terratest, policy as code |
| Best Practices | references/best-practices.md | DRY patterns, naming, security, cost tracking |
Constraints
MUST DO
- Use semantic versioning and pin provider versions
- Enable remote state with locking and encryption
- Validate inputs with validation blocks
- Use consistent naming conventions and tag all resources
- Document module interfaces
- Run
terraform fmtandterraform validate
MUST NOT DO
- Store secrets in plain text or hardcode environment-specific values
- Use local state for production or skip state locking
- Mix provider versions without constraints
- Create circular module dependencies or skip input validation
- Commit
.terraformdirectories
Code Examples
Minimal Module Structure
main.tf
resource "aws_s3_bucket" "this" {
bucket = var.bucket_name
tags = var.tags
}
variables.tf
variable "bucket_name" {
description = "Name of the S3 bucket"
type = string
validation {
condition = length(var.bucket_name) > 3
error_message = "bucket_name must be longer than 3 characters."
}
}
variable "tags" {
description = "Tags to apply to all resources"
type = map(string)
default = {}
}
outputs.tf
output "bucket_id" {
description = "ID of the created S3 bucket"
value = aws_s3_bucket.this.id
}
Remote Backend Configuration (S3 + DynamoDB)
terraform {
backend "s3" {
bucket = "my-tf-state"
key = "env/prod/terraform.tfstate"
region = "us-east-1"
encrypt = true
dynamodb_table = "terraform-lock"
}
}
Provider Version Pinning
terraform {
required_version = ">= 1.5.0"
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 5.0"
}
azurerm = {
source = "hashicorp/azurerm"
version = "~> 3.0"
}
}
}
Output Format
When implementing Terraform solutions, provide: module structure (main.tf, variables.tf, outputs.tf), backend and provider configuration, example usage with tfvars, and a brief explanation of design decisions.
Related skills
More from jeffallan/claude-skills and the wider catalog.

test-master
Comprehensive testing specialist for unit, integration, E2E, performance, and security tests.

the-fool
Play devil's advocate with structured critical reasoning to stress-test ideas, plans, and decisions.

typescript-pro
Advanced TypeScript type systems, branded types, and tRPC end-to-end type safety for complex applications.

vue-expert
Vue 3 Composition API specialist for components, Nuxt SSR/SSG, Pinia state, and mobile apps.

vue-expert-js
Build Vue 3 apps with JavaScript and JSDoc typing—no TypeScript required.

websocket-engineer
Build real-time bidirectional communication systems with WebSockets and Socket.IO, including clustering and presence tracking.