terraform-policy

作者: hashicorp

编写、测试或转换Terraform策略文件(.policy.hcl、.policytest.hcl、Sentinel→tfpolicy)。触发词:policy.hcl、policytest、convert sentinel、tfpolicy、…

npx skills add https://github.com/hashicorp/agent-skills --skill terraform-policy

terraform-policy

UTILITY SKILL — INVOKES: tfpolicy-author | tfpolicy-test

USE FOR:

  • Writing a new .policy.hcl policy from a description or requirement
  • Converting a .sentinel policy to Terraform Policy
  • Writing or debugging a .policytest.hcl test file
  • Migrating a Sentinel policy library to Terraform Policy

Before giving authoring or testing instructions, check the installed tfpolicy CLI version and tailor guidance accordingly. This skill maintains guidance for the two most recent minor lines, 0.2.x and 0.3.x; when a new minor ships, drop the oldest line and add the new one.

  • If the CLI is 0.2.x (baseline), include a top-level policy { required_providers { ... } } block when authoring .policy.hcl files containing resource or provider policies. It is mandatory for tfpolicy validate; version-range validation is best effort, and wildcard targets such as resource_policy "*" are not schema-validated. tfpolicy test does not preflight mocked attrs/prior_attrs against provider schemas, core::alltrue/core::anytrue do not exist, and, only in this 0.2.x line, mock resource {} blocks may omit attrs/prior_attrs entirely.
  • If the CLI is 0.3.x or newer, the other guidance above still applies, but the 0.2.x allowance for omitting resource state does not: every mock resource {} block in .policytest.hcl files must declare attrs or prior_attrs; if both evaluate to empty, the test case is skipped (provider {} and module {} mocks are unaffected) (see tfpolicy-test). tfpolicy test reuses the target .policy.hcl's existing top-level policy { required_providers { ... } } block (there is no separate .policytest.hcl-level declaration) to validate provider, resource, and data-source policies and core::getdatasource()/core::getresources() arguments against resolved provider schemas before any test runs, failing the whole run on a schema mismatch (see tfpolicy-test). core::alltrue(list) and core::anytrue(list) are also available — prefer them over the core::length() list-comprehension workaround (see tfpolicy-author). meta.tfe_stack and meta.tfe_workspace.tags are available to resource, provider, and module policies; Stack fields are empty outside Stack evaluations.
  • If the CLI version is unknown, ask the user to check it first or provide guidance that clearly distinguishes the 0.2.x and 0.3.x paths.

DO NOT USE FOR:

  • Writing .tftest.hcl files for Terraform modules — use terraform-test
  • General Terraform HCL authoring — use terraform-style-guide

Routing

TaskSub-skill
Write or convert a .policy.hcl policytfpolicy-author
Write or debug a .policytest.hcl testtfpolicy-test

Examples

Troubleshooting

  • Wrong skill triggered? Load the sub-skill directly from the routing table above.
npx skills add hashicorp/agent-skills/terraform/terraform-policy/skills/tfpolicy-author
npx skills add hashicorp/agent-skills/terraform/terraform-policy/skills/tfpolicy-test

来自 hashicorp 的更多技能

provider-framework-migration
hashicorp
将Terraform provider资源和数据源从Plugin SDKv2迁移到Plugin Framework:在一个provider中混合使用两个插件(terraform-plugin-mux,…)
provider-configuration
hashicorp
使用Plugin Framework实现Terraform provider配置和认证:provider schema用于凭据(Optional + Sensitive属性),…
provider-ephemeral-resources
hashicorp
使用Plugin Framework实现Terraform provider的临时资源:Open/Renew/Close生命周期、临时schema设计、通过…注册
terraform-test
hashicorp
关于使用断言、模拟和模块验证编写及运行Terraform测试的全面指南。使用.tftest.hcl语法编写测试文件,通过运行块在计划或应用模式下执行,支持顺序和并行执行,并可选择状态隔离。对资源属性、输出和数据源进行断言条件验证;使用expect_failures确保无效输入被正确拒绝。模拟提供程序(Terraform 1.7.0+)可模拟基础设施行为,无需...
terraform-search-import
hashicorp
使用 Terraform Search 查询发现现有云资源,并将其批量导入 Terraform 管理。适用于将未管理的基础设施纳入管理时…
aws-ami-builder
hashicorp
使用Packer的amazon-ebs构建器创建自定义Amazon Machine Images。通过HCL模板自动化从源AMI创建AMI的过程,并利用配置器(shell脚本、文件上传、配置管理)进行自定义。支持通过ami_regions实现多区域AMI分发,以及按名称、所有者和虚拟化类型灵活过滤源AMI。通过环境变量、AWS凭证文件或IAM实例配置文件进行身份验证;包含模板的验证和构建命令...
tfctl
hashicorp
使用 tfctl CLI 与 HCP Terraform / Terraform Cloud / Terraform Enterprise 交互。完整 API 覆盖。适用于任何 HCP Terraform 或 Terraform Cloud 或…
provider-actions
hashicorp
使用Plugin Framework在资源生命周期事件中实现命令式Terraform Provider操作。支持创建前/后和更新前/后的生命周期触发器(Terraform 1.14.0中不支持销毁事件)。需要正确的模式定义,包括框架类型、集合的ElementType以及输入验证的验证器。包含进度报告、超时管理和长时间运行操作的全面错误处理。实现轮询和...