terraform-state-and-secret-management
Installation
SKILL.md
Terraform State and Secret Management
When to use
Invoke when configuring the remote state backend for a Terraform repository, restructuring state isolation across environments, or auditing/hardening state encryption, locking, and secret handling before the configuration manages real infrastructure.
Do not use for: repository/module structure (use terraform-module-and-repository-scaffold), pre-merge plan/policy gates (use terraform-plan-gate-and-policy-as-code), apply/promotion orchestration (use terraform-apply-and-promotion-mechanics), or module versioning/provenance (use terraform-module-reuse-and-supply-chain).
Inputs
Required:
- An existing repo/module scaffold from
terraform-module-and-repository-scaffold(provides the env-per-directory layout this skill backs with state). - Approved
architecture/securitydecisions on secret handling, state-at-rest encryption, and provider authentication posture. - Approved
infrastructure-platform.mddecisions on environment isolation and the target cloud(s) (determines the backend choice).
Optional: