Sep 26, 2026
terraform-skill: Terraform and OpenTofu Best Practices Your Coding Agent Actually Follows
Install a 2k-star best-practices skill that hands any Agent Skills-compatible coding agent testing strategy, module structure, remote-state, and CI/CD patterns for Terraform and OpenTofu.
A coding agent will happily write you a Terraform module that runs — and violates half a dozen production conventions you would have caught in review. terraform-skill, a 2k-star Apache-2.0 repository, encodes the patterns so the agent applies them while it writes. The README names its sources: patterns from terraform-best-practices.com and approaches used across the terraform-aws-modules collection.
Why This Skill Matters
The skill ships guidance in six areas, per the README: testing frameworks — including a decision matrix for native Terraform tests versus Terratest — module development with naming and versioning conventions, state management, CI/CD integration, security and compliance, and a quick reference of DO-versus-DON'T patterns. State management covers the S3, Azure, GCS, and Terraform Cloud backends, locking, multi-team isolation, and migration and recovery procedures. The CI/CD section documents GitHub Actions and GitLab CI workflows plus Atlantis and Infracost cost estimation; security guidance covers Trivy and Checkov scanning and policy-as-code patterns.
One scoping note from the README: AWS, Azure, and GCP are all first-class, with AWS kept as the default in examples — ask for the Azure or GCP equivalent of any pattern and the skill maps it.
Installation
The quick install works with any Agent Skills-compatible tool:
npx skills add https://github.com/antonbabenko/terraform-skill
On Claude Code you can instead go through its plugin marketplace:
/plugin marketplace add antonbabenko/agent-plugins
/plugin install terraform-skill@antonbabenko
Mind one clash the README warns about explicitly: do not also add antonbabenko/terraform-skill as a marketplace — both register the same marketplace name and collide.
Requirements are Terraform 1.0+ or OpenTofu 1.6+. Some guidance is version-gated, and the README flags the thresholds: native testing needs 1.6+, native use_lockfile locking 1.10+, and write_only arguments 1.11+.
Real Workflow: Ship a Tested Module With CI
Verify the install with the README's own check prompt: "Create a Terraform module with testing for an S3 bucket." Claude picks up the skill automatically whenever the work involves Terraform or OpenTofu code.
From there, run a real task end to end. Ask for a module with tests:
Create a Terraform module for an AWS VPC with native tests
Then wire up state and delivery — both are README quick-start prompts:
Configure an S3 backend with native use_lockfile locking and encryption for Terraform state
Create a GitHub Actions workflow for Terraform with cost estimation
For an existing codebase, the review prompt audits what you already have: "Review this Terraform configuration following best practices."
Tips
- When the testing approach is unclear, ask the decision question the README suggests: "Help me choose between native tests and Terratest for my modules."
- The skill optionally uses terraform-ls, HashiCorp's language server, to resolve definitions by meaning; without it, the skill falls back to text search and nothing breaks. The language server needs a local
terraformortofubinary and a workspace whereterraform inithas run. - Renames have their own rules: terraform-ls cannot rename for you — find references and edit by hand, and change a resource or module address with a
movedblock rather than a text replace. - The README recommends installing the
code-intelligenceplugin from the same marketplace as a general-purpose companion; it also cautions that the name is not unique, so check the active one is from antonbabenko/agent-plugins.
When Not to Use This
This is guidance the agent reads, not a wrapper around terraform plan or apply — you still run the tools, and the skill does not replace a policy pipeline or a state backend. If your stack is pinned below Terraform 1.6, the native-testing guidance is partly version-gated. And if your agent host has no Agent Skills support at all, there is nothing here to load.
See the leaderboard for more skills.