File contents Terraform Best Practices
Comprehensive optimization guide for Terraform and Infrastructure as Code, maintained by Terramate. Contains 37 rules across 10 categories, prioritized by impact to guide automated refactoring and code generation.
When to Apply
Reference these guidelines when:
Writing new Terraform modules or configurations
Implementing infrastructure patterns (AWS, GCP, Azure, etc.)
Reviewing code for security and reliability issues
Refactoring existing Terraform/OpenTofu code
Optimizing state management and performance
Setting up team workflows and governance
Rule Categories by Priority
Priority
Category
Impact
Prefix
1
Organization & Workflow
CRITICAL
org-
2
State Management
CRITICAL
state-
3
Security Best Practices
CRITICAL
security-
4
Module Design
HIGH
module-
5
Resource Organization
MEDIUM-HIGH
resource-
6
Variable & Output Patterns
MEDIUM
variable-, output-
7
Language Best Practices
MEDIUM
language-
8
Provider Configuration
MEDIUM
provider-
9
Performance Optimization
LOW-MEDIUM
perf-
10
Testing & Validation
LOW
test-
Quick Reference
1. Organization & Workflow (CRITICAL) - 5 rules
org-version-control - All Terraform code in version control
org-workspaces - One workspace per environment per configuration
org-access-control - Control who can change what infrastructure
org-change-workflow - Formal process for infrastructure changes
org-audit-logging - Track all infrastructure changes
2. State Management (CRITICAL) - 3 rules
state-remote-backend - Always use remote state backends
state-locking - Enable state locking to prevent corruption
state-import - Import existing infrastructure into Terraform
3. Security Best Practices (CRITICAL) - 3 rules
security-no-hardcoded-secrets - Never hardcode secrets in code
security-credentials - Use proper credential management (OIDC, Vault, IAM roles)
security-iam-least-privilege - Follow least privilege principle
4. Module Design (HIGH) - 5 rules
module-single-responsibility - One module per logical component
module-naming - Use consistent naming conventions (terraform--)
module-versioning - Version all module references
module-composition - Compose modules like building blocks
module-registry - Use existing community/shared modules
5. Resource Organization (MEDIUM-HIGH) - 5 rules
resource-naming - Use consistent naming conventions
resource-tagging - Tag all resources for cost tracking
resource-lifecycle - Use lifecycle blocks (prevent_destroy, ignore_changes)
resource-count-vs-foreach - Prefer for_each over count
resource-immutable - Prefer immutable infrastructure patterns
6. Variable & Output Patterns (MEDIUM) - 6 rules
variable-types - Use specific types, positive naming, nullable
variable-validation - Add validation rules for early error detection
variable-sensitive - Mark secrets as sensitive, no defaults
variable-descriptions - Document all variables with descriptions
output-descriptions - Document all outputs with descriptions
output-no-secrets - Never output secrets directly
7. Language Best Practices (MEDIUM) - 5 rules
language-no-heredoc-json - Use jsonencode/yamlencode, not HEREDOC
language-locals - Use locals to name complex expressions
language-linting - Run terraform fmt and tflint
language-data-sources - Use data sources instead of hardcoding
language-dynamic-blocks - Use dynamic blocks for DRY code
8. Provider Configuration (MEDIUM) - 1 rule
provider-version-constraints - Pin provider versions
9. Performance Optimization (LOW-MEDIUM) - 2 rules
perf-parallelism - Tune parallelism for large deployments
perf-debug - Enable debug logging for troubleshooting
10. Testing & Validation (LOW) - 2 rules
test-strategies - Testing pyramid (validate, lint, plan, integration)
test-policy-as-code - Implement policy checks (OPA, Checkov, tfsec)
How to Use
Read individual rule files for detailed explanations and code examples:
rules/state-remote-backend.md
rules/security-no-hardcoded-secrets.md
rules/module-versioning.md
Each rule file contains:
Brief explanation of why it matters
Incorrect code example with explanation
Correct code example with explanation
Additional context and references
Full Compiled Document
For the complete guide with all rules expanded: AGENTS.md
1 --- 2 name: terraform-best-practices 3 description: Terraform Best Practices 4 --- 5 # Terraform Best Practices 6 7 Comprehensive optimization guide for Terraform and Infrastructure as Code, maintained by Terramate. Contains 37 rules across 10 categories, prioritized by impact to guide automated refactoring and code generation. 8 9 ## When to Apply 10 11 Reference these guidelines when: 12 - Writing new Terraform modules or configurations 13 - Implementing infrastructure patterns (AWS, GCP, Azure, etc.) 14 - Reviewing code for security and reliability issues 15 - Refactoring existing Terraform/OpenTofu code 16 - Optimizing state management and performance 17 - Setting up team workflows and governance 18 19 ## Rule Categories by Priority 20 21 | Priority | Category | Impact | Prefix | 22 |----------|----------|--------|--------| 23 | 1 | Organization & Workflow | CRITICAL | `org-` | 24 | 2 | State Management | CRITICAL | `state-` | 25 | 3 | Security Best Practices | CRITICAL | `security-` | 26 | 4 | Module Design | HIGH | `module-` | 27 | 5 | Resource Organization | MEDIUM-HIGH | `resource-` | 28 | 6 | Variable & Output Patterns | MEDIUM | `variable-`, `output-` | 29 | 7 | Language Best Practices | MEDIUM | `language-` | 30 | 8 | Provider Configuration | MEDIUM | `provider-` | 31 | 9 | Performance Optimization | LOW-MEDIUM | `perf-` | 32 | 10 | Testing & Validation | LOW | `test-` | 33 34 ## Quick Reference 35 36 ### 1. Organization & Workflow (CRITICAL) - 5 rules 37 38 - `org-version-control` - All Terraform code in version control 39 - `org-workspaces` - One workspace per environment per configuration 40 - `org-access-control` - Control who can change what infrastructure 41 - `org-change-workflow` - Formal process for infrastructure changes 42 - `org-audit-logging` - Track all infrastructure changes 43 44 ### 2. State Management (CRITICAL) - 3 rules 45 46 - `state-remote-backend` - Always use remote state backends 47 - `state-locking` - Enable state locking to prevent corruption 48 - `state-import` - Import existing infrastructure into Terraform 49 50 ### 3. Security Best Practices (CRITICAL) - 3 rules 51 52 - `security-no-hardcoded-secrets` - Never hardcode secrets in code 53 - `security-credentials` - Use proper credential management (OIDC, Vault, IAM roles) 54 - `security-iam-least-privilege` - Follow least privilege principle 55 56 ### 4. Module Design (HIGH) - 5 rules 57 58 - `module-single-responsibility` - One module per logical component 59 - `module-naming` - Use consistent naming conventions (terraform-<PROVIDER>-<NAME>) 60 - `module-versioning` - Version all module references 61 - `module-composition` - Compose modules like building blocks 62 - `module-registry` - Use existing community/shared modules 63 64 ### 5. Resource Organization (MEDIUM-HIGH) - 5 rules 65 66 - `resource-naming` - Use consistent naming conventions 67 - `resource-tagging` - Tag all resources for cost tracking 68 - `resource-lifecycle` - Use lifecycle blocks (prevent_destroy, ignore_changes) 69 - `resource-count-vs-foreach` - Prefer for_each over count 70 - `resource-immutable` - Prefer immutable infrastructure patterns 71 72 ### 6. Variable & Output Patterns (MEDIUM) - 6 rules 73 74 - `variable-types` - Use specific types, positive naming, nullable 75 - `variable-validation` - Add validation rules for early error detection 76 - `variable-sensitive` - Mark secrets as sensitive, no defaults 77 - `variable-descriptions` - Document all variables with descriptions 78 - `output-descriptions` - Document all outputs with descriptions 79 - `output-no-secrets` - Never output secrets directly 80 81 ### 7. Language Best Practices (MEDIUM) - 5 rules 82 83 - `language-no-heredoc-json` - Use jsonencode/yamlencode, not HEREDOC 84 - `language-locals` - Use locals to name complex expressions 85 - `language-linting` - Run terraform fmt and tflint 86 - `language-data-sources` - Use data sources instead of hardcoding 87 - `language-dynamic-blocks` - Use dynamic blocks for DRY code 88 89 ### 8. Provider Configuration (MEDIUM) - 1 rule 90 91 - `provider-version-constraints` - Pin provider versions 92 93 ### 9. Performance Optimization (LOW-MEDIUM) - 2 rules 94 95 - `perf-parallelism` - Tune parallelism for large deployments 96 - `perf-debug` - Enable debug logging for troubleshooting 97 98 ### 10. Testing & Validation (LOW) - 2 rules 99 100 - `test-strategies` - Testing pyramid (validate, lint, plan, integration) 101 - `test-policy-as-code` - Implement policy checks (OPA, Checkov, tfsec) 102 103 ## How to Use 104 105 Read individual rule files for detailed explanations and code examples: 106 107 ``` 108 rules/state-remote-backend.md 109 rules/security-no-hardcoded-secrets.md 110 rules/module-versioning.md 111 ``` 112 113 Each rule file contains: 114 - Brief explanation of why it matters 115 - Incorrect code example with explanation 116 - Correct code example with explanation 117 - Additional context and references 118 119 ## Full Compiled Document 120 121 For the complete guide with all rules expanded: `AGENTS.md`
ComeOnOliver/skillshub/tree/main/skills/terramate-io/agent-skills/terraform-best-practices commit 758def6d26
Frequently asked questions How do I install the Terraform Best Practices skill? Run npx skillmds@latest add comeonoliver/terraform-best-practices in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
What does the Terraform Best Practices skill do? Terraform Best Practices It is listed under DevOps & Infra on SkillMD.
Is Terraform Best Practices safe to use? This skill has not completed SkillMD's automated safety review yet. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
Which AI agents work with Terraform Best Practices? This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Is Terraform Best Practices free to use? Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
Who published Terraform Best Practices? ComeOnOliver (@comeonoliver) published this skill. Their other Agent Skills are listed on their SkillMD profile.