Terraform Patterns
Predictable infrastructure. Secure state. Modules that compose. No drift.
Opinionated Terraform workflow that turns sprawling HCL into well-structured, secure, production-grade infrastructure code. Covers module design, state management, provider patterns, security hardening, and CI/CD integration.
Not a Terraform tutorial — a set of concrete decisions about how to write infrastructure code that doesn't break at 3 AM.
Slash Commands
When This Skill Activates
Recognize these patterns from the user:
- "Review this Terraform code"
- "Design a Terraform module for..."
- "My Terraform state is..."
- "Set up remote state backend"
- "Multi-region Terraform deployment"
- "Terraform security review"
- "Module structure best practices"
- "Terraform CI/CD pipeline"
- Any request involving:
.tffiles, HCL, Terraform modules, state management, provider configuration, infrastructure-as-code
If the user has .tf files or wants to provision infrastructure with Terraform → this skill applies.
Workflow
/terraform:review — Terraform Code Review
-
Analyze current state
- Read all
.tffiles in the target directory - Identify module structure (flat vs nested)
- Count resources, data sources, variables, outputs
- Check naming conventions
- Read all
-
Apply review checklist
-
Generate report
-
Run security scan
/terraform:module — Module Design
-
Identify module scope
- Single responsibility: one module = one logical grouping
- Determine inputs (variables), outputs, and resource boundaries
- Decide: flat module (single directory) vs nested (calling child modules)
-
Apply module design checklist
-
Generate module scaffold
- Output file structure with boilerplate
- Include variable validation blocks
- Add lifecycle rules where appropriate
/terraform:security — Security Audit
-
Code-level audit
-
State security audit
-
Generate security report
Tooling
scripts/tf_module_analyzer.py
CLI utility for analyzing Terraform directory structure and module quality.
Features:
- Resource and data source counting
- Variable and output analysis (missing descriptions, types, validation)
- Naming convention checks
- Module composition detection
- File structure validation
- JSON and text output
Usage:
scripts/tf_security_scanner.py
CLI utility for scanning .tf files for common security issues.
Features:
- Hardcoded secret detection (AWS keys, passwords, tokens)
- Overly permissive IAM policy detection
- Open security group detection (0.0.0.0/0 on sensitive ports)
- Missing encryption checks (S3, RDS, EBS)
- Public access detection (S3, RDS, EC2)
- Sensitive variable audit
- JSON and text output
Usage:
Module Design Patterns
Pattern 1: Flat Module (Small/Medium Projects)
Best for: Single application, < 20 resources, one team owns everything.
Pattern 2: Nested Modules (Medium/Large Projects)
Best for: Multiple environments, shared infrastructure patterns, team collaboration.
Pattern 3: Mono-Repo with Terragrunt
Best for: Large-scale, many environments, DRY configuration, team-level isolation.
Provider Configuration Patterns
Version Pinning
Multi-Region with Aliases
Multi-Account with Assume Role
State Management Decision Tree
CI/CD Integration Patterns
GitHub Actions Plan/Apply
Drift Detection
Proactive Triggers
Flag these without being asked:
- No remote backend configured → Migrate to S3/GCS/Azure Blob with locking and encryption.
- Provider without version constraint → Add
version = "~> X.0"to prevent breaking upgrades. - Hardcoded secrets in .tf files → Use variables with
sensitive = true, or integrate Vault/SSM. - IAM policy with
"Action": "*"→ Scope to specific actions. No wildcard actions in production. - Security group open to 0.0.0.0/0 on SSH/RDP → Restrict to bastion CIDR or use SSM Session Manager.
- No state locking → Enable DynamoDB table for S3 backend, or use TF Cloud.
- Resources without tags → Add default_tags in provider block. Tags are mandatory for cost tracking.
- Missing
prevent_destroyon databases/storage → Add lifecycle block to prevent accidental deletion.
Multi-Cloud Provider Configuration
When a single root module must provision across AWS, Azure, and GCP simultaneously.
Provider Aliasing Pattern
Shared Variables Across Providers
When to Use Multi-Cloud
- Yes: Regulatory requirements mandate data residency across providers, or the org has existing workloads on multiple clouds.
- No: "Avoiding vendor lock-in" alone is not sufficient justification. Multi-cloud doubles operational complexity. Prefer single-cloud unless there is a concrete business requirement.
OpenTofu Compatibility
OpenTofu is an open-source fork of Terraform maintained by the Linux Foundation under the MPL 2.0 license.
Migration from Terraform to OpenTofu
License Considerations
Feature Parity
OpenTofu tracks Terraform 1.6.x features. Key additions unique to OpenTofu:
- Client-side state encryption (
tofu init -encryption) - Early variable/locals evaluation
- Provider-defined functions
When to Choose OpenTofu
- You need a fully open-source license for your supply chain.
- You want client-side state encryption without Terraform Cloud.
- Otherwise, either tool works — the HCL syntax and provider ecosystem are identical.
Infracost Integration
Infracost estimates cloud costs from Terraform code before resources are provisioned.
PR Workflow
GitHub Actions Cost Comment
Budget Thresholds and Cost Policy
Import Existing Infrastructure
Bring manually-created resources under Terraform management.
terraform import Workflow
Bulk Import with Config Generation (Terraform 1.5+)
Common Pitfalls
- Resource drift after import: The imported resource may have attributes Terraform does not manage. Run
terraform planimmediately and resolve every diff. - State manipulation: Use
terraform state mvto rename or reorganize. Useterraform state rmto remove without destroying. Always back up state before manipulation:terraform state pull > backup.tfstate. - Sensitive defaults: Imported resources may expose secrets in state. Restrict state access and enable encryption.
Terragrunt Patterns
Terragrunt is a thin wrapper around Terraform that provides DRY configuration for multi-environment setups.
Root terragrunt.hcl (Shared Config)
Child terragrunt.hcl (Environment Override)
Dependencies Between Modules
When Terragrunt Adds Value
- Yes: 3+ environments with identical module structure, shared backend config, or cross-module dependencies.
- No: Single environment, small team, or simple directory-based isolation already works. Terragrunt adds a learning curve and another binary to manage.
Installation
One-liner (any tool)
Multi-tool install
OpenClaw
Related Skills
- senior-devops — Broader DevOps scope (CI/CD, monitoring, containerization). Complementary — use terraform-patterns for IaC-specific work, senior-devops for pipeline and infrastructure operations.
- aws-solution-architect — AWS architecture design. Complementary — terraform-patterns implements the infrastructure, aws-solution-architect designs it.
- senior-security — Application security. Complementary — terraform-patterns covers infrastructure security posture, senior-security covers application-level threats.
- ci-cd-pipeline-builder — Pipeline construction. Complementary — terraform-patterns defines infrastructure, ci-cd-pipeline-builder automates deployment.


