Infrastructure As Code
Purpose
You change infrastructure through code with respect for state, drift, blast radius, and human review. The plan matters as much as the code.
Operational context
- Read
references/workflow.md.
- Identify tool/version, providers, backend, locking, environment model, existing state, import/migration context, and policy constraints.
- Verify current provider/resource/module/backend documentation before writing IaC.
Safe change sequence
- Classify the change: new resource, modification, import, migration, refactor, drift correction, or policy update.
- Identify state impact, dependency impact, recreation risk, and destructive changes.
- Design module boundaries, variables, outputs, provider aliases, naming, tagging, and state separation.
- Implement with version constraints, minimal abstractions, safe lifecycle usage, and migration notes.
- Validate with format, validate, plan, policy checks, and explicit review of destructive actions.
Safety rules
- Use Context7 MCP for current cloud, Kubernetes, IaC, CI/CD, container, observability, security, network, API, CLI, provider, and configuration documentation whenever the task depends on external technology behavior.
Change record
Provide IaC context, documentation validation status, resource/module changes, validation commands, plan review notes, risks, rollback/state notes, and assumptions.
Verification
- Do not hide destructive diffs.
- Do not use IaC without a state and locking strategy.
- Pin providers and explain version constraints.
- Keep sensitive outputs minimal.
- Prefer
for_each over count when stable identity matters.
Handoff
For cloud-specific resources, add cloud-operations. For Kubernetes resources managed by IaC, add kubernetes-operations. For secrets, IAM, or policy, add security-secrets.
References
references/workflow.md for IaC design, implementation, and validation checklist.
1---2name: infrastructure-as-code3description: Use for Terraform, OpenTofu, Pulumi, CloudFormation, Bicep, ARM, Crossplane, provider constraints, remote state, imports, moved blocks, plan review, drift, policy checks, modular infrastructure, and safe resource changes.4---56# Infrastructure As Code78## Purpose910You change infrastructure through code with respect for state, drift, blast radius, and human review. The plan matters as much as the code.1112## Operational context13141. Read `references/workflow.md`.152. Identify tool/version, providers, backend, locking, environment model, existing state, import/migration context, and policy constraints.163. Verify current provider/resource/module/backend documentation before writing IaC.1718## Safe change sequence19201. Classify the change: new resource, modification, import, migration, refactor, drift correction, or policy update.212. Identify state impact, dependency impact, recreation risk, and destructive changes.223. Design module boundaries, variables, outputs, provider aliases, naming, tagging, and state separation.234. Implement with version constraints, minimal abstractions, safe lifecycle usage, and migration notes.245. Validate with format, validate, plan, policy checks, and explicit review of destructive actions.2526## Safety rules2728- Use Context7 MCP for current cloud, Kubernetes, IaC, CI/CD, container, observability, security, network, API, CLI, provider, and configuration documentation whenever the task depends on external technology behavior.2930## Change record3132Provide IaC context, documentation validation status, resource/module changes, validation commands, plan review notes, risks, rollback/state notes, and assumptions.3334## Verification3536- Do not hide destructive diffs.37- Do not use IaC without a state and locking strategy.38- Pin providers and explain version constraints.39- Keep sensitive outputs minimal.40- Prefer `for_each` over `count` when stable identity matters.4142## Handoff4344For cloud-specific resources, add `cloud-operations`. For Kubernetes resources managed by IaC, add `kubernetes-operations`. For secrets, IAM, or policy, add `security-secrets`.4546## References4748- `references/workflow.md` for IaC design, implementation, and validation checklist.