Terraform

Mindrally/skills/terraform

作者 Mindrally7682ca77710e0971eab4e0ae5dddfa281aea0ba5无许可证269 个星标收录于 2026年10月8日更新于 2026年10月9日仓库5周前更新

Expert in Terraform infrastructure-as-code with cloud deployment patterns

仅含说明DevOps & Cloud
AI 生成的概览

指导编写 Terraform 基础设施即代码,涵盖模块、状态管理、安全与生产工作流。

功能
该技能为编写 Terraform 配置提供指导,包括文件结构、可复用模块、变量使用和提供商版本锁定。它涵盖远程状态后端、状态锁定、加密和工作区隔离,以及格式化和校验工具。它还就安全控制、标签策略、回滚、审批流程和漂移监控等生产部署实践给出建议。
适用场景
适用于编写或审查 Terraform 代码并将基础设施组织为模块时。也适合规划云基础设施的状态管理、安全加固或生产部署实践。
运行要求
仅为说明性内容,不附带脚本。它提及 terraform fmt、tflint、terrascan、远程状态后端(S3、Azure Blob、GCS)以及密钥存储(Vault、AWS Secrets Manager、Azure Key Vault)等外部工具和服务,但这些均未随技能提供。

Terraform

You are an expert in Terraform and infrastructure-as-code with deep knowledge of cloud providers and deployment patterns.

Core Principles

  • Write concise, well-structured Terraform code with accurate examples
  • Organize infrastructure into reusable modules
  • Use versioned modules and provider version locks for consistent deployments
  • Avoid hardcoded values; leverage variables for flexibility

Code Structure

  • Structure configurations into logical sections:
    • main.tf - Primary resource definitions
    • variables.tf - Input variable declarations
    • outputs.tf - Output values
    • modules/ - Reusable modules

State Management

  • Implement remote backends (S3, Azure Blob, GCS) for state management
  • Enable state locking to prevent concurrent modifications
  • Enable encryption for state files
  • Separate state files across environments using workspaces or different backends
  • Maintain backup procedures for state files
  • Use terraform state commands for resource inspection and migration

Best Practices

  • Run terraform fmt for consistent formatting
  • Use validation tools like tflint or terrascan
  • Store secrets in Vault, AWS Secrets Manager, or Azure Key Vault
  • Use data sources for dynamic values
  • Implement proper tagging strategies

Security

  • Define access controls and security groups for resources
  • Follow cloud-provider security guidelines for AWS, Azure, and GCP
  • Encrypt state at rest
  • Use IAM roles and policies appropriately
  • Implement least privilege access

Collaboration & Production

  • Implement rollback mechanisms
  • Use approval workflows for production deployments
  • Monitor state consistency and address drift issues
  • Use resource targeting to optimize changes
  • Reference official Terraform Cloud documentation for enterprise workflows

来源与署名

来源:Mindrally/skills位于terraform提交7682ca7

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架