Terraform Policy

by hashicorpf706481af9b8MPL-2.0890 starsListed Oct 8, 2026Updated Oct 8, 2026Repository updated 3 days ago

Write, test, or convert Terraform Policy files (.policy.hcl, .policytest.hcl, Sentinel→tfpolicy). Triggers: policy.hcl, policytest, convert sentinel, tfpolicy, write a policy.

Only the file list is public. File contents are available once the skill is installed in a workspace.

PathSizeType
examples/conversion/cloudfront-associated-with-waf/cloudfront-associated-with-waf.policy.hcl589 Btext/plain
examples/conversion/cloudfront-associated-with-waf/cloudfront-associated-with-waf.sentinel1.6 KBtext/plain
examples/conversion/cloudfront-associated-with-waf/README.md871 Btext/markdown
examples/conversion/cloudtrail-server-side-encryption-enabled/cloudtrail-server-side-encryption-enabled.policy.hcl512 Btext/plain
examples/conversion/cloudtrail-server-side-encryption-enabled/cloudtrail-server-side-encryption-enabled.sentinel1.4 KBtext/plain
examples/conversion/cloudtrail-server-side-encryption-enabled/README.md846 Btext/markdown
examples/conversion/dms-endpoint-should-be-ssl-configured/dms-endpoint-should-be-ssl-configured.policy.hcl516 Btext/plain
examples/conversion/dms-endpoint-should-be-ssl-configured/dms-endpoint-should-be-ssl-configured.sentinel1.5 KBtext/plain
examples/conversion/dms-endpoint-should-be-ssl-configured/README.md872 Btext/markdown
examples/conversion/dms-endpoints-should-use-ssl/dms-endpoints-should-use-ssl.policy.hcl579 Btext/plain
examples/conversion/dms-endpoints-should-use-ssl/dms-endpoints-should-use-ssl.sentinel1.4 KBtext/plain
examples/conversion/dms-endpoints-should-use-ssl/README.md800 Btext/markdown
examples/conversion/ec2-network-acl-should-have-subnet-ids/ec2-network-acl-should-have-subnet-ids.policy.hcl1 KBtext/plain
examples/conversion/ec2-network-acl-should-have-subnet-ids/ec2-network-acl-should-have-subnet-ids.sentinel2.9 KBtext/plain
examples/conversion/ec2-network-acl-should-have-subnet-ids/README.md970 Btext/markdown
examples/conversion/ec2-vpc-default-security-group-no-traffic/ec2-vpc-default-security-group-no-traffic.policy.hcl865 Btext/plain
examples/conversion/ec2-vpc-default-security-group-no-traffic/ec2-vpc-default-security-group-no-traffic.sentinel3.6 KBtext/plain
examples/conversion/ec2-vpc-default-security-group-no-traffic/README.md1.1 KBtext/markdown
examples/conversion/efs-access-point-should-enforce-user-identity/efs-access-point-should-enforce-user-identity.policy.hcl448 Btext/plain
examples/conversion/efs-access-point-should-enforce-user-identity/efs-access-point-should-enforce-user-identity.sentinel1.3 KBtext/plain
examples/conversion/efs-access-point-should-enforce-user-identity/README.md727 Btext/markdown
examples/conversion/elasticache-redis-replication-group-encryption-at-transit-enabled/elasticache-redis-replication-group-encryption-at-transit-enabled.policy.hcl547 Btext/plain
examples/conversion/elasticache-redis-replication-group-encryption-at-transit-enabled/elasticache-redis-replication-group-encryption-at-transit-enabled.sentinel1.5 KBtext/plain
examples/conversion/elasticache-redis-replication-group-encryption-at-transit-enabled/README.md777 Btext/markdown
examples/conversion/elasticsearch-encrypted-at-rest/elasticsearch-encrypted-at-rest.policy.hcl584 Btext/plain
examples/conversion/elasticsearch-encrypted-at-rest/elasticsearch-encrypted-at-rest.sentinel1.5 KBtext/plain
examples/conversion/elasticsearch-encrypted-at-rest/README.md734 Btext/markdown
examples/conversion/elasticsearch-https-required/elasticsearch-https-required.policy.hcl1.1 KBtext/plain
examples/conversion/elasticsearch-https-required/elasticsearch-https-required.sentinel2.3 KBtext/plain
examples/conversion/elasticsearch-https-required/README.md904 Btext/markdown
examples/conversion/elasticsearch-in-vpc-only/elasticsearch-in-vpc-only.policy.hcl589 Btext/plain
examples/conversion/elasticsearch-in-vpc-only/elasticsearch-in-vpc-only.sentinel1.9 KBtext/plain
examples/conversion/elasticsearch-in-vpc-only/README.md890 Btext/markdown
examples/conversion/eventbridge-custom-event-bus-should-have-attached-policy/eventbridge-custom-event-bus-should-have-attached-policy.policy.hcl845 Btext/plain
examples/conversion/eventbridge-custom-event-bus-should-have-attached-policy/eventbridge-custom-event-bus-should-have-attached-policy.sentinel2.1 KBtext/plain
examples/conversion/eventbridge-custom-event-bus-should-have-attached-policy/README.md1.1 KBtext/markdown
examples/conversion/s3-block-public-access-bucket-level/README.md1.1 KBtext/markdown
examples/conversion/s3-block-public-access-bucket-level/s3-block-public-access-bucket-level.policy.hcl1.2 KBtext/plain
examples/conversion/s3-block-public-access-bucket-level/s3-block-public-access-bucket-level.sentinel3.2 KBtext/plain
examples/conversion/s3-bucket-should-have-object-lock-enabled/README.md975 Btext/markdown
examples/conversion/s3-bucket-should-have-object-lock-enabled/s3-bucket-should-have-object-lock-enabled.policy.hcl1 KBtext/plain
examples/conversion/s3-bucket-should-have-object-lock-enabled/s3-bucket-should-have-object-lock-enabled.sentinel2.8 KBtext/plain
examples/conversion/secretsmanager-auto-rotation-enabled-check/README.md955 Btext/markdown
examples/conversion/secretsmanager-auto-rotation-enabled-check/secretsmanager-auto-rotation-enabled-check.policy.hcl867 Btext/plain
examples/conversion/secretsmanager-auto-rotation-enabled-check/secretsmanager-auto-rotation-enabled-check.sentinel2.2 KBtext/plain
examples/conversion/step-functions-state-machine-logging-enabled/README.md778 Btext/markdown
examples/conversion/step-functions-state-machine-logging-enabled/step-functions-state-machine-logging-enabled.policy.hcl724 Btext/plain
examples/conversion/step-functions-state-machine-logging-enabled/step-functions-state-machine-logging-enabled.sentinel1.6 KBtext/plain
examples/README.md2.5 KBtext/markdown
.gitignore29 Btext/plain
README.md2.8 KBtext/markdown
references/tfpolicy-author.md97.6 KBtext/markdown
references/tfpolicy-test.md45.1 KBtext/markdown
references/verified-syntax.md100 KBtext/markdown
SKILL.md3.9 KBtext/markdown

Source and attribution

Source:hashicorp/agent-skillsinplugins/terraform/skills/terraform-policyat commitf706481

License: MPL-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from hashicorp/agent-skills

Terraform Test

hashicorp

Guides writing and running Terraform tests with .tftest.hcl files, run blocks, assertions, mocks and CI integration.

Software Development890updated 3 days ago

Terraform Style Guide

hashicorp

Generates and reviews Terraform HCL code following HashiCorp's official style conventions and best practices.

DevOps & Cloud890updated 3 days ago

Terraform Stacks

hashicorp

Guides writing and validating HashiCorp Terraform Stacks configuration files for multi-environment infrastructure.

DevOps & Cloud890updated 3 days ago

Refactor Module

hashicorp

Guides refactoring monolithic Terraform configurations into reusable, maintainable modules with migration and tests.

Software Development890updated 3 days ago

Provider Resources

hashicorp

Implement Terraform Provider resources and data sources using the Plugin Framework: CRUD operations, schema design, plan modifiers and validators, not-found handling, waiters for eventually consistent APIs, import support, resource design principles, and required acceptance test coverage. Use when adding or changing a resource or data source, deciding whether an API concept should be a resource, wiring a resource to the provider's configured client, handling drift or resource-not-found, or reviewing a resource implementation before submission.

Awaiting classification890updated 3 days ago

Provider Framework Migration

hashicorp

Guides migrating Terraform provider resources from Plugin SDKv2 to the Plugin Framework using a muxed provider.

Software Development890updated 3 days ago