Terraform Policy

by hashicorpf706481af9b8MPL-2.0890 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 3 days ago

Write, test, or convert Terraform Policy files (.policy.hcl, .policytest.hcl, Sentinel→tfpolicy). Triggers: policy.hcl, policytest, convert sentinel, tfpolicy, write a policy.

AI-generated overview

Writes, tests and converts Terraform Policy files (.policy.hcl, .policytest.hcl) and Sentinel policies.

What it does
Guides authoring of Terraform Policy .policy.hcl files from a description or requirement, and conversion of Sentinel .sentinel policies to Terraform Policy. It also covers writing and debugging .policytest.hcl test files, including mock resource state requirements. Guidance is tailored to the installed tfpolicy CLI version, covering the 0.2.x and 0.3.x lines.
When to use it
Use when creating a new Terraform Policy from a requirement, migrating a Sentinel policy library, or writing and debugging policytest files. Not intended for Terraform module .tftest.hcl files or general Terraform HCL authoring.
Requirements
Requires the tfpolicy CLI, whose installed version should be checked before authoring or testing guidance is given. Instructions only; no scripts are shipped.

terraform-policy

UTILITY SKILL — INVOKES: tfpolicy-author [blocked] | tfpolicy-test [blocked]

USE FOR:

  • Writing a new .policy.hcl policy from a description or requirement
  • Converting a .sentinel policy to Terraform Policy
  • Writing or debugging a .policytest.hcl test file
  • Migrating a Sentinel policy library to Terraform Policy

Before giving authoring or testing instructions, check the installed tfpolicy CLI version and tailor guidance accordingly. This skill maintains guidance for the two most recent minor lines, 0.2.x and 0.3.x; when a new minor ships, drop the oldest line and add the new one.

  • If the CLI is 0.2.x (baseline), include a top-level policy { required_providers { ... } } block when authoring .policy.hcl files containing resource or provider policies. It is mandatory for tfpolicy validate; version-range validation is best effort, and wildcard targets such as resource_policy "*" are not schema-validated. tfpolicy test does not preflight mocked attrs/prior_attrs against provider schemas, core::alltrue/core::anytrue do not exist, and, only in this 0.2.x line, mock resource {} blocks may omit attrs/prior_attrs entirely.
  • If the CLI is 0.3.x or newer, the other guidance above still applies, but the 0.2.x allowance for omitting resource state does not: every mock resource {} block in .policytest.hcl files must declare attrs or prior_attrs; if both evaluate to empty, the test case is skipped (provider {} and module {} mocks are unaffected) (see tfpolicy-test [blocked]). tfpolicy test reuses the target .policy.hcl's existing top-level policy { required_providers { ... } } block (there is no separate .policytest.hcl-level declaration) to validate provider, resource, and data-source policies and core::getdatasource()/core::getresources() arguments against resolved provider schemas before any test runs, failing the whole run on a schema mismatch (see tfpolicy-test [blocked]). core::alltrue(list) and core::anytrue(list) are also available — prefer them over the core::length() list-comprehension workaround (see tfpolicy-author [blocked]). meta.tfe_stack and meta.tfe_workspace.tags are available to resource, provider, and module policies; Stack fields are empty outside Stack evaluations.
  • If the CLI version is unknown, ask the user to check it first or provide guidance that clearly distinguishes the 0.2.x and 0.3.x paths.

DO NOT USE FOR:

  • Writing .tftest.hcl files for Terraform modules — use terraform-test
  • General Terraform HCL authoring — use terraform-style-guide

Routing

TaskSub-skill
Write or convert a .policy.hcl policytfpolicy-author [blocked]
Write or debug a .policytest.hcl testtfpolicy-test [blocked]

Examples

  • "Block EC2 instances without encryption" → tfpolicy-author [blocked]
  • "Convert this Sentinel policy to tfpolicy" → tfpolicy-author [blocked]
  • "Write a policytest for my EBS policy" → tfpolicy-test [blocked]

Troubleshooting

  • Wrong skill triggered? Load the sub-skill directly from the routing table above.
bash
npx skills add hashicorp/agent-skills/terraform/terraform-policy/skills/tfpolicy-authornpx skills add hashicorp/agent-skills/terraform/terraform-policy/skills/tfpolicy-test

Source and attribution

Source:hashicorp/agent-skillsinplugins/terraform/skills/terraform-policyat commitf706481

License: MPL-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from hashicorp/agent-skills

Terraform Test

hashicorp

Guides writing and running Terraform tests with .tftest.hcl files, run blocks, assertions, mocks and CI integration.

Software Development890updated 3 days ago

Terraform Style Guide

hashicorp

Generates and reviews Terraform HCL code following HashiCorp's official style conventions and best practices.

DevOps & Cloud890updated 3 days ago

Terraform Stacks

hashicorp

Guides writing and validating HashiCorp Terraform Stacks configuration files for multi-environment infrastructure.

DevOps & Cloud890updated 3 days ago

Refactor Module

hashicorp

Guides refactoring monolithic Terraform configurations into reusable, maintainable modules with migration and tests.

Software Development890updated 3 days ago

Provider Resources

hashicorp

Implement Terraform Provider resources and data sources using the Plugin Framework: CRUD operations, schema design, plan modifiers and validators, not-found handling, waiters for eventually consistent APIs, import support, resource design principles, and required acceptance test coverage. Use when adding or changing a resource or data source, deciding whether an API concept should be a resource, wiring a resource to the provider's configured client, handling drift or resource-not-found, or reviewing a resource implementation before submission.

Awaiting classification890updated 3 days ago

Provider Framework Migration

hashicorp

Guides migrating Terraform provider resources from Plugin SDKv2 to the Plugin Framework using a muxed provider.

Software Development890updated 3 days ago