Terraform Diagram Generator
Generates architecture diagrams directly from Terraform .tf files. Specializes in parsing Terraform code and visualizing infrastructure resources, modules, and their relationships.
When to Use
Activate this skill when:
- User has Terraform files (
.tf, .tfvars) and wants to visualize the infrastructure
- User asks to "diagram my Terraform" or "visualize this infrastructure"
- User mentions Terraform, HCL, or infrastructure-as-code
- User wants to see the architecture of their Terraform-managed resources
How It Works
This skill generates Terraform-specific diagrams by parsing Terraform code and calling the Eraser API directly:
- Parse Terraform Files: Identify resources, modules, data sources, and variables
- Extract Relationships: Map dependencies, resource connections, and module hierarchies
- Generate Eraser DSL: Create Eraser DSL code from Terraform resources
- Call Eraser API: Use
/api/render/elements with diagramType: "cloud-architecture-diagram"
Instructions
When the user provides Terraform code:
Parse the Terraform
- Identify all
resource blocks (AWS, Azure, GCP, etc.)
- Extract
module blocks and their configurations
- Note
data sources and their dependencies
- Identify
variable and output definitions
Map Relationships
- Track resource dependencies (e.g.,
subnet_id = aws_subnet.public.id)
- Group resources by provider (AWS, Azure, GCP)
- Identify VPCs/VNets as containers for other resources
- Note security groups, IAM roles, and networking rules
Generate Eraser DSL Convert Terraform resources to Eraser DSL:
- CRITICAL: Label Formatting Rules
- Labels MUST be on a single line - NEVER use newlines inside label attributes
- Keep labels simple and readable - prefer separate labels over concatenating too much metadata
- Format DSL with proper line breaks (one node/group per line, but labels stay on single lines)
- If including metadata like CIDR blocks or instance types, include them in the same quoted label string:
[label: "VPC 10.0.0.0/16"]
Example:
main-vpc [label: "VPC 10.0.0.0/16"] {
public-subnet [label: "Public Subnet 10.0.1.0/24"] {
web-server [icon: aws-ec2, label: "Web Server t3.micro"]
load-balancer [icon: aws-elb]
}
private-subnet [label: "Private Subnet"] {
database [icon: aws-rds]
}
}
load-balancer -> web-server
web-server -> database
Make the HTTP Request
IMPORTANT: You MUST execute this curl command after generating the DSL. Never stop after generating DSL without making the API call.
CRITICAL: In the X-Skill-Source header below, you MUST replace the value with your AI agent name:
- If you are Claude (Anthropic), use:
claude
- If you are running in Cursor, use:
cursor
- If you are ChatGPT (OpenAI), use:
chatgpt
- If you are Gemini (Google), use:
gemini
- Otherwise, use your model/agent name in lowercase
curl -X POST https://app.eraser.io/api/render/elements \
-H "Content-Type: application/json" \
-H "X-Skill-Source: eraser-skill" \
-H "Authorization: Bearer ${ERASER_API_KEY}" \
-d '{
"elements": [{
"type": "diagram",
"id": "diagram-1",
"code": "<your generated DSL>",
"diagramType": "cloud-architecture-diagram"
}],
"scale": 2,
"theme": "${ERASER_THEME:-dark}",
"background": true
}'
Track Sources During Analysis
As you analyze Terraform files and resources to generate the diagram, track:
- Internal files: Record each Terraform file path you read and what resources were extracted (e.g.,
infra/main.tf - VPC and subnet definitions, infra/rds.tf - Database configuration)
- External references: Note any documentation, examples, or URLs consulted (e.g., Terraform AWS provider documentation, AWS architecture best practices)
- Annotations: For each source, note what it contributed to the diagram
Handle the Response
CRITICAL: Minimal Output Format
Your response MUST always include these elements with clear headers:
Diagram Preview: Display with a header
## Diagram

Use the ACTUAL imageUrl from the API response.
Editor Link: Display with a header
## Open in Eraser
[Edit this diagram in the Eraser editor]({createEraserFileUrl})
Use the ACTUAL URL from the API response.
Sources section: Brief list of files/resources analyzed (if applicable)
## Sources
- `path/to/file` - What was extracted
Diagram Code section: The Eraser DSL in a code block with eraser language tag
## Diagram Code
```eraser
{DSL code here}
Learn More link: You can learn more about Eraser at https://docs.eraser.io/docs/using-ai-agent-integrations
Additional content rules:
- If the user ONLY asked for a diagram, include NOTHING beyond the 5 elements above
- If the user explicitly asked for more (e.g., "explain the architecture", "suggest improvements"), you may include that additional content
- Never add unrequested sections like Overview, Security Considerations, Testing, etc.
The default output should be SHORT. The diagram image speaks for itself.
Handle Multiple Providers
- If Terraform uses multiple providers, group by provider
- Create separate sections for AWS, Azure, GCP resources
- Show cross-provider connections if applicable
Terraform-Specific Tips
- Group by Module: If modules are used, show module boundaries
- Show VPCs/VNets as Containers: These should visually contain subnets and resources
- Include Data Flows: Show how resources connect (e.g., ALB → EC2 → RDS)
- Highlight Security: Include security groups, IAM roles, and network ACLs
- Show Resource Types: Use provider-specific icons (AWS, Azure, GCP)
- Include CIDR Blocks: Show network addressing for VPCs and subnets
Example: Multi-Provider Terraform
User Input
# AWS Resources
resource "aws_vpc" "main" {
cidr_block = "10.0.0.0/16"
}
resource "aws_subnet" "public" {
vpc_id = aws_vpc.main.id
cidr_block = "10.0.1.0/24"
}
resource "aws_instance" "web" {
subnet_id = aws_subnet.public.id
instance_type = "t3.micro"
}
# Azure Resources (multi-provider)
resource "azurerm_resource_group" "main" {
name = "rg-main"
location = "East US"
}
resource "azurerm_virtual_network" "main" {
name = "vnet-main"
resource_group_name = azurerm_resource_group.main.name
address_space = ["10.1.0.0/16"]
}
# Module usage
module "database" {
source = "./modules/rds"
vpc_id = aws_vpc.main.id
}
Expected Behavior
Parses Terraform:
- AWS: VPC, subnet, EC2 instance
- Azure: Resource group, VNet (multi-provider setup)
- Module: Database module with dependency on VPC
Generates DSL showing multi-provider and module structure:
# AWS Resources
aws-vpc [label: "AWS VPC 10.0.0.0/16"] {
aws-subnet [label: "Public Subnet 10.0.1.0/24"] {
web-server [icon: aws-ec2, label: "Web Server t3.micro"]
}
}
# Azure Resources
resource-group [label: "Resource Group rg-main"] {
azure-vnet [label: "Azure VNet 10.1.0.0/16"]
}
# Module
database-module [label: "Database Module"] {
rds-instance [icon: aws-rds]
}
aws-vpc -> database-module
Important: All label text must be on a single line within quotes. Terraform-specific: Show modules as containers, group by provider, include resource dependencies.
Calls /api/render/elements with diagramType: "cloud-architecture-diagram"
Result
User receives a diagram showing:
- VPC as a container
- Public subnet nested inside VPC
- EC2 instance in the subnet
- Proper AWS styling
Converted and distributed by TomeVault — claim your Tome and manage your conversions.
1---2name: terraform-diagrams3description: Generates architecture diagrams from Terraform code. Use when user has .tf files or asks to visualize Terraform infrastructure.4license: MIT5---67# Terraform Diagram Generator89Generates architecture diagrams directly from Terraform `.tf` files. Specializes in parsing Terraform code and visualizing infrastructure resources, modules, and their relationships.1011## When to Use1213Activate this skill when:1415- User has Terraform files (`.tf`, `.tfvars`) and wants to visualize the infrastructure16- User asks to "diagram my Terraform" or "visualize this infrastructure"17- User mentions Terraform, HCL, or infrastructure-as-code18- User wants to see the architecture of their Terraform-managed resources1920## How It Works2122This skill generates Terraform-specific diagrams by parsing Terraform code and calling the Eraser API directly:23241. **Parse Terraform Files**: Identify resources, modules, data sources, and variables252. **Extract Relationships**: Map dependencies, resource connections, and module hierarchies263. **Generate Eraser DSL**: Create Eraser DSL code from Terraform resources274. **Call Eraser API**: Use `/api/render/elements` with `diagramType: "cloud-architecture-diagram"`2829## Instructions3031When the user provides Terraform code:32331. **Parse the Terraform**3435 - Identify all `resource` blocks (AWS, Azure, GCP, etc.)36 - Extract `module` blocks and their configurations37 - Note `data` sources and their dependencies38 - Identify `variable` and `output` definitions39402. **Map Relationships**4142 - Track resource dependencies (e.g., `subnet_id = aws_subnet.public.id`)43 - Group resources by provider (AWS, Azure, GCP)44 - Identify VPCs/VNets as containers for other resources45 - Note security groups, IAM roles, and networking rules46473. **Generate Eraser DSL** Convert Terraform resources to Eraser DSL:4849 - **CRITICAL: Label Formatting Rules**50 - Labels MUST be on a single line - NEVER use newlines inside label attributes51 - Keep labels simple and readable - prefer separate labels over concatenating too much metadata52 - Format DSL with proper line breaks (one node/group per line, but labels stay on single lines)53 - If including metadata like CIDR blocks or instance types, include them in the same quoted label string: `[label: "VPC 10.0.0.0/16"]`5455 Example:5657 ```58 main-vpc [label: "VPC 10.0.0.0/16"] {59 public-subnet [label: "Public Subnet 10.0.1.0/24"] {60 web-server [icon: aws-ec2, label: "Web Server t3.micro"]61 load-balancer [icon: aws-elb]62 }63 private-subnet [label: "Private Subnet"] {64 database [icon: aws-rds]65 }66 }67 load-balancer -> web-server68 web-server -> database69 ```70714. **Make the HTTP Request**7273 **IMPORTANT**: You MUST execute this curl command after generating the DSL. Never stop after generating DSL without making the API call.7475 **CRITICAL**: In the `X-Skill-Source` header below, you MUST replace the value with your AI agent name:76 - If you are Claude (Anthropic), use: `claude`77 - If you are running in Cursor, use: `cursor`78 - If you are ChatGPT (OpenAI), use: `chatgpt`79 - If you are Gemini (Google), use: `gemini`80 - Otherwise, use your model/agent name in lowercase8182 ```bash83 curl -X POST https://app.eraser.io/api/render/elements \84 -H "Content-Type: application/json" \85 -H "X-Skill-Source: eraser-skill" \86 -H "Authorization: Bearer ${ERASER_API_KEY}" \87 -d '{88 "elements": [{89 "type": "diagram",90 "id": "diagram-1",91 "code": "<your generated DSL>",92 "diagramType": "cloud-architecture-diagram"93 }],94 "scale": 2,95 "theme": "${ERASER_THEME:-dark}",96 "background": true97 }'98 ```991005. **Track Sources During Analysis**101102 As you analyze Terraform files and resources to generate the diagram, track:103104 - **Internal files**: Record each Terraform file path you read and what resources were extracted (e.g., `infra/main.tf` - VPC and subnet definitions, `infra/rds.tf` - Database configuration)105 - **External references**: Note any documentation, examples, or URLs consulted (e.g., Terraform AWS provider documentation, AWS architecture best practices)106 - **Annotations**: For each source, note what it contributed to the diagram1071086. **Handle the Response**109110 **CRITICAL: Minimal Output Format**111112 Your response MUST always include these elements with clear headers:113114 1. **Diagram Preview**: Display with a header115 ```116 ## Diagram117 118 ```119 Use the ACTUAL `imageUrl` from the API response.120121 2. **Editor Link**: Display with a header122 ```123 ## Open in Eraser124 [Edit this diagram in the Eraser editor]({createEraserFileUrl})125 ```126 Use the ACTUAL URL from the API response.127128 3. **Sources section**: Brief list of files/resources analyzed (if applicable)129 ```130 ## Sources131 - `path/to/file` - What was extracted132 ```133134 4. **Diagram Code section**: The Eraser DSL in a code block with `eraser` language tag135 ```136 ## Diagram Code137 ```eraser138 {DSL code here}139 ```140 ```141142 5. **Learn More link**: `You can learn more about Eraser at https://docs.eraser.io/docs/using-ai-agent-integrations`143144 **Additional content rules:**145 - If the user ONLY asked for a diagram, include NOTHING beyond the 5 elements above146 - If the user explicitly asked for more (e.g., "explain the architecture", "suggest improvements"), you may include that additional content147 - Never add unrequested sections like Overview, Security Considerations, Testing, etc.148149 The default output should be SHORT. The diagram image speaks for itself.1501517. **Handle Multiple Providers**152 - If Terraform uses multiple providers, group by provider153 - Create separate sections for AWS, Azure, GCP resources154 - Show cross-provider connections if applicable155156## Terraform-Specific Tips157158- **Group by Module**: If modules are used, show module boundaries159- **Show VPCs/VNets as Containers**: These should visually contain subnets and resources160- **Include Data Flows**: Show how resources connect (e.g., ALB → EC2 → RDS)161- **Highlight Security**: Include security groups, IAM roles, and network ACLs162- **Show Resource Types**: Use provider-specific icons (AWS, Azure, GCP)163- **Include CIDR Blocks**: Show network addressing for VPCs and subnets164165## Example: Multi-Provider Terraform166167### User Input168169```hcl170# AWS Resources171resource "aws_vpc" "main" {172 cidr_block = "10.0.0.0/16"173}174175resource "aws_subnet" "public" {176 vpc_id = aws_vpc.main.id177 cidr_block = "10.0.1.0/24"178}179180resource "aws_instance" "web" {181 subnet_id = aws_subnet.public.id182 instance_type = "t3.micro"183}184185# Azure Resources (multi-provider)186resource "azurerm_resource_group" "main" {187 name = "rg-main"188 location = "East US"189}190191resource "azurerm_virtual_network" "main" {192 name = "vnet-main"193 resource_group_name = azurerm_resource_group.main.name194 address_space = ["10.1.0.0/16"]195}196197# Module usage198module "database" {199 source = "./modules/rds"200 vpc_id = aws_vpc.main.id201}202```203204### Expected Behavior2052061. Parses Terraform:207208 - **AWS**: VPC, subnet, EC2 instance209 - **Azure**: Resource group, VNet (multi-provider setup)210 - **Module**: Database module with dependency on VPC2112122. Generates DSL showing multi-provider and module structure:213214 ```215 # AWS Resources216 aws-vpc [label: "AWS VPC 10.0.0.0/16"] {217 aws-subnet [label: "Public Subnet 10.0.1.0/24"] {218 web-server [icon: aws-ec2, label: "Web Server t3.micro"]219 }220 }221222 # Azure Resources223 resource-group [label: "Resource Group rg-main"] {224 azure-vnet [label: "Azure VNet 10.1.0.0/16"]225 }226227 # Module228 database-module [label: "Database Module"] {229 rds-instance [icon: aws-rds]230 }231232 aws-vpc -> database-module233 ```234235 **Important**: All label text must be on a single line within quotes. Terraform-specific: Show modules as containers, group by provider, include resource dependencies.2362373. Calls `/api/render/elements` with `diagramType: "cloud-architecture-diagram"`238239### Result240241User receives a diagram showing:242243- VPC as a container244- Public subnet nested inside VPC245- EC2 instance in the subnet246- Proper AWS styling247248---249> Converted and distributed by [TomeVault](https://tomevault.io/claim/eraserlabs) — claim your Tome and manage your conversions.250<!-- tomevault:4.0:skill_md:2026-04-11 -->