Terraform Policy

作者 hashicorpf706481af9b8MPL-2.0890 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫3 天前更新

Write, test, or convert Terraform Policy files (.policy.hcl, .policytest.hcl, Sentinel→tfpolicy). Triggers: policy.hcl, policytest, convert sentinel, tfpolicy, write a policy.

AI 產生的概覽

撰寫、測試與轉換 Terraform Policy 檔案(.policy.hcl、.policytest.hcl)以及 Sentinel 政策。

功能
指導依據描述或需求撰寫 Terraform Policy 的 .policy.hcl 檔案,並將 Sentinel 的 .sentinel 政策轉換為 Terraform Policy。內容也涵蓋 .policytest.hcl 測試檔案的撰寫與除錯,包括模擬資源狀態的要求。相關指引會依已安裝的 tfpolicy CLI 版本調整,涵蓋 0.2.x 與 0.3.x 兩個版本線。
適用情境
適用於依需求建立新的 Terraform Policy、移轉 Sentinel 政策庫,或撰寫與除錯 policytest 檔案。不適用於 Terraform 模組的 .tftest.hcl 檔案或一般 Terraform HCL 撰寫。
執行需求
需要 tfpolicy CLI,且在提供撰寫或測試指引前應先確認已安裝的版本。僅為指示性內容,未隨附指令碼。

terraform-policy

UTILITY SKILL — INVOKES: tfpolicy-author [blocked] | tfpolicy-test [blocked]

USE FOR:

  • Writing a new .policy.hcl policy from a description or requirement
  • Converting a .sentinel policy to Terraform Policy
  • Writing or debugging a .policytest.hcl test file
  • Migrating a Sentinel policy library to Terraform Policy

Before giving authoring or testing instructions, check the installed tfpolicy CLI version and tailor guidance accordingly. This skill maintains guidance for the two most recent minor lines, 0.2.x and 0.3.x; when a new minor ships, drop the oldest line and add the new one.

  • If the CLI is 0.2.x (baseline), include a top-level policy { required_providers { ... } } block when authoring .policy.hcl files containing resource or provider policies. It is mandatory for tfpolicy validate; version-range validation is best effort, and wildcard targets such as resource_policy "*" are not schema-validated. tfpolicy test does not preflight mocked attrs/prior_attrs against provider schemas, core::alltrue/core::anytrue do not exist, and, only in this 0.2.x line, mock resource {} blocks may omit attrs/prior_attrs entirely.
  • If the CLI is 0.3.x or newer, the other guidance above still applies, but the 0.2.x allowance for omitting resource state does not: every mock resource {} block in .policytest.hcl files must declare attrs or prior_attrs; if both evaluate to empty, the test case is skipped (provider {} and module {} mocks are unaffected) (see tfpolicy-test [blocked]). tfpolicy test reuses the target .policy.hcl's existing top-level policy { required_providers { ... } } block (there is no separate .policytest.hcl-level declaration) to validate provider, resource, and data-source policies and core::getdatasource()/core::getresources() arguments against resolved provider schemas before any test runs, failing the whole run on a schema mismatch (see tfpolicy-test [blocked]). core::alltrue(list) and core::anytrue(list) are also available — prefer them over the core::length() list-comprehension workaround (see tfpolicy-author [blocked]). meta.tfe_stack and meta.tfe_workspace.tags are available to resource, provider, and module policies; Stack fields are empty outside Stack evaluations.
  • If the CLI version is unknown, ask the user to check it first or provide guidance that clearly distinguishes the 0.2.x and 0.3.x paths.

DO NOT USE FOR:

  • Writing .tftest.hcl files for Terraform modules — use terraform-test
  • General Terraform HCL authoring — use terraform-style-guide

Routing

TaskSub-skill
Write or convert a .policy.hcl policytfpolicy-author [blocked]
Write or debug a .policytest.hcl testtfpolicy-test [blocked]

Examples

  • "Block EC2 instances without encryption" → tfpolicy-author [blocked]
  • "Convert this Sentinel policy to tfpolicy" → tfpolicy-author [blocked]
  • "Write a policytest for my EBS policy" → tfpolicy-test [blocked]

Troubleshooting

  • Wrong skill triggered? Load the sub-skill directly from the routing table above.
bash
npx skills add hashicorp/agent-skills/terraform/terraform-policy/skills/tfpolicy-authornpx skills add hashicorp/agent-skills/terraform/terraform-policy/skills/tfpolicy-test

來源與署名

來源:hashicorp/agent-skills位於plugins/terraform/skills/terraform-policy提交f706481

授權條款: MPL-2.0

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架