terraform-security
Installation
SKILL.md
When to Use
- Adding any secret, token, password, or API key to Terraform
- Configuring local or remote state backends
- Setting up
.gitignorefor a Terraform directory - Creating CI/CD pipelines that run
terraform plan/apply - Reviewing Terraform code for security issues
- Deciding how to pass secrets to Terraform
Critical Patterns
The Three Things You NEVER Commit
| File/Pattern | Why | Consequence if Leaked |
|---|---|---|
*.tfvars |
Contains actual secret values | Full credential exposure |
*.tfstate / *.tfstate.backup |
Contains ALL resource attributes including secrets in plaintext | Infrastructure takeover |
Related skills