terraform-policy

tarafından hashicorp

Terraform Policy dosyalarını yazın, test edin veya dönüştürün (.policy.hcl, .policytest.hcl, Sentinel→tfpolicy). Tetikleyiciler: policy.hcl, policytest, convert sentinel, tfpolicy,…

npx skills add https://github.com/hashicorp/agent-skills --skill terraform-policy

terraform-policy

UTILITY SKILL — INVOKES: tfpolicy-author | tfpolicy-test

USE FOR:

  • Writing a new .policy.hcl policy from a description or requirement
  • Converting a .sentinel policy to Terraform Policy
  • Writing or debugging a .policytest.hcl test file
  • Migrating a Sentinel policy library to Terraform Policy

Before giving authoring or testing instructions, check the installed tfpolicy CLI version and tailor guidance accordingly. This skill maintains guidance for the two most recent minor lines, 0.2.x and 0.3.x; when a new minor ships, drop the oldest line and add the new one.

  • If the CLI is 0.2.x (baseline), include a top-level policy { required_providers { ... } } block when authoring .policy.hcl files containing resource or provider policies. It is mandatory for tfpolicy validate; version-range validation is best effort, and wildcard targets such as resource_policy "*" are not schema-validated. tfpolicy test does not preflight mocked attrs/prior_attrs against provider schemas, core::alltrue/core::anytrue do not exist, and, only in this 0.2.x line, mock resource {} blocks may omit attrs/prior_attrs entirely.
  • If the CLI is 0.3.x or newer, the other guidance above still applies, but the 0.2.x allowance for omitting resource state does not: every mock resource {} block in .policytest.hcl files must declare attrs or prior_attrs; if both evaluate to empty, the test case is skipped (provider {} and module {} mocks are unaffected) (see tfpolicy-test). tfpolicy test reuses the target .policy.hcl's existing top-level policy { required_providers { ... } } block (there is no separate .policytest.hcl-level declaration) to validate provider, resource, and data-source policies and core::getdatasource()/core::getresources() arguments against resolved provider schemas before any test runs, failing the whole run on a schema mismatch (see tfpolicy-test). core::alltrue(list) and core::anytrue(list) are also available — prefer them over the core::length() list-comprehension workaround (see tfpolicy-author). meta.tfe_stack and meta.tfe_workspace.tags are available to resource, provider, and module policies; Stack fields are empty outside Stack evaluations.
  • If the CLI version is unknown, ask the user to check it first or provide guidance that clearly distinguishes the 0.2.x and 0.3.x paths.

DO NOT USE FOR:

  • Writing .tftest.hcl files for Terraform modules — use terraform-test
  • General Terraform HCL authoring — use terraform-style-guide

Routing

TaskSub-skill
Write or convert a .policy.hcl policytfpolicy-author
Write or debug a .policytest.hcl testtfpolicy-test

Examples

Troubleshooting

  • Wrong skill triggered? Load the sub-skill directly from the routing table above.
npx skills add hashicorp/agent-skills/terraform/terraform-policy/skills/tfpolicy-author
npx skills add hashicorp/agent-skills/terraform/terraform-policy/skills/tfpolicy-test

hashicorp tarafından daha fazla skill

provider-framework-migration
hashicorp
Terraform sağlayıcı kaynaklarını ve veri kaynaklarını Plugin SDKv2'den Plugin Framework'e taşıyın: her iki eklentiyi tek bir sağlayıcıda birleştirme (terraform-plugin-mux,…
provider-configuration
hashicorp
Terraform sağlayıcı yapılandırmasını ve kimlik doğrulamasını Plugin Framework ile uygulayın: kimlik bilgileri için sağlayıcı şeması (Optional + Sensitive öznitelikleri),…
provider-ephemeral-resources
hashicorp
Terraform sağlayıcı geçici kaynaklarını Plugin Framework ile uygulayın: Open/Renew/Close yaşam döngüsü, geçici şema tasarımı, kayıt işlemi…
terraform-test
hashicorp
Terraform testlerini yazma ve çalıştırma için kapsamlı rehber; assertion'lar, mocking ve modül doğrulama ile birlikte. .tftest.hcl sözdizimini kullanarak plan veya apply modunda çalışan run blokları ile test dosyaları yazın; sıralı ve paralel yürütmeyi, isteğe bağlı durum izolasyonu ile destekler. Kaynak nitelikleri, çıktılar ve veri kaynakları üzerinde koşulları assert edin; geçersiz girdilerin düzgün bir şekilde reddedildiğini doğrulamak için expect_failures kullanın. Mock sağlayıcılar (Terraform 1.7.0+) altyapı davranışını simüle eder...
terraform-search-import
hashicorp
Mevcut bulut kaynaklarını Terraform Search sorguları kullanarak keşfedin ve bunları toplu olarak Terraform yönetimine aktarın. Yönetilmeyen altyapıyı dahil ederken kullanın…
aws-ami-builder
hashicorp
Packer'ın amazon-ebs builder'ı ile özel Amazon Machine Images oluşturun. HCL şablonları kullanarak kaynak AMI'lerden AMI oluşturmayı otomatikleştirir; özelleştirme için provisioner'lar (shell betikleri, dosya yükleme, yapılandırma yönetimi) içerir. ami_regions ile çoklu bölge AMI dağıtımını ve kaynak AMI'lerin ad, sahip ve sanallaştırma türüne göre esnek filtrelenmesini destekler. Ortam değişkenleri, AWS kimlik bilgileri dosyası veya IAM örnek profilleri aracılığıyla kimlik doğrulaması yapar; şablon için doğrulama ve derleme komutlarını içerir...
tfctl
hashicorp
HCP Terraform / Terraform Cloud / Terraform Enterprise ile tfctl CLI kullanarak etkileşim kurun. Tam API kapsamı. HERHANGİ bir HCP Terraform veya Terraform Cloud veya…
provider-actions
hashicorp
Plugin Framework kullanarak kaynak yaşam döngüsü olaylarında imperatif Terraform Provider eylemlerini uygular. Oluşturma öncesi/sonrası ve güncelleme öncesi/sonrası yaşam döngüsü tetikleyicilerini destekler (yok etme olayları Terraform 1.14.0'da mevcut değildir). Doğru framework türleri, koleksiyonlar için ElementType ve giriş doğrulaması için validatörler ile uygun şema tanımı gerektirir. Uzun süren işlemler için ilerleme raporlaması, zaman aşımı yönetimi ve kapsamlı hata işleme içerir. Yoklama ve...