writing-infrastructure-code — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited writing-infrastructure-code (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Provision and manage cloud infrastructure using code-based automation tools. This skill covers tool selection, state management, module design, and operational patterns across Terraform/OpenTofu, Pulumi, and AWS CDK.
Use this skill when:
Common requests:
Key Principles:
Benefits:
Choose IaC tools based on team composition and cloud strategy:
Terraform/OpenTofu - Declarative, HCL-based
Pulumi - Imperative, programming language-based
AWS CDK - AWS-native, programming language-based
Decision Tree:
Multi-cloud required?
├─ YES → Team composition?
│ ├─ Ops/SRE focused → Terraform/OpenTofu
│ └─ Developer focused → Pulumi
└─ NO → AWS only?
├─ YES → Language preference?
│ ├─ HCL/declarative → Terraform
│ ├─ TypeScript/Python → AWS CDK
│ └─ YAML/simple → CloudFormation
└─ NO → GCP/Azure only?
└─ Terraform or PulumiRemote state with locking enables team collaboration:
Backend Selection:
| Cloud Provider | Recommended Backend | Locking Mechanism |
|---|---|---|
| AWS | S3 + DynamoDB | DynamoDB table |
| GCP | Google Cloud Storage | Native |
| Azure | Azure Blob Storage | Lease-based |
| Multi-cloud | Terraform Cloud/Enterprise | Built-in |
| Pulumi | Pulumi Service | Built-in |
State Isolation Strategies:
prod/, staging/, dev/)Critical State Management Rules:
sensitive = trueComposable Module Structure:
modules/
├── vpc/ # Network foundation
├── security-group/ # Reusable security group patterns
├── rds/ # Database with backups, encryption
├── ecs-cluster/ # Container orchestration base
├── ecs-service/ # Individual microservice
└── alb/ # Application load balancerModule Versioning:
version = "5.1.0")Module Design Principles:
When to Create a Module:
When to Keep Monolithic:
# Initialize providers and backend
terraform init
# Plan changes (preview)
terraform plan
# Apply changes
terraform apply
# Destroy infrastructure
terraform destroy
# Format HCL files
terraform fmt
# Validate syntax
terraform validate
# Show state
terraform state list
terraform state show <resource>
# Import existing resources
terraform import <resource.name> <id>
# Workspace management
terraform workspace list
terraform workspace new staging
terraform workspace select prod# Initialize new project
pulumi new aws-typescript
# Preview changes
pulumi preview
# Apply changes
pulumi up
# Destroy infrastructure
pulumi destroy
# Show stack outputs
pulumi stack output
# Manage stacks
pulumi stack ls
pulumi stack select prod
# Import existing resources
pulumi import <type> <name> <id>
# Export/import state
pulumi stack export > state.json
pulumi stack import < state.json# Initialize new app
cdk init app --language typescript
# Synthesize CloudFormation
cdk synth
# Preview changes
cdk diff
# Deploy stack
cdk deploy
# Destroy stack
cdk destroy
# Bootstrap account/region
cdk bootstrap
# List stacks
cdk listInfrastructure Provisioning:
Module Development:
Operational Readiness:
For comprehensive patterns and implementation details:
Tool-Specific Patterns:
references/terraform-patterns.md - Terraform/OpenTofu best practices, HCL patternsreferences/pulumi-patterns.md - Pulumi across TypeScript/Python/GoArchitecture and Design:
references/state-management.md - Remote state, locking, isolation strategiesreferences/module-design.md - Composable modules, versioning, registriesOperations:
references/drift-detection.md - Detecting and remediating infrastructure driftPractical implementations demonstrating IaC patterns:
Terraform Examples:
examples/terraform/vpc-module/ - Multi-AZ VPC with public/private subnetsexamples/terraform/ecs-service/ - ECS service with ALB, autoscalingexamples/terraform/rds-cluster/ - Aurora cluster with backups, encryptionexamples/terraform/state-backend/ - S3 + DynamoDB backend setupPulumi Examples:
examples/pulumi/typescript/vpc/ - TypeScript VPC componentexamples/pulumi/python/ecs-service/ - Python ECS serviceexamples/pulumi/go/rds-cluster/ - Go RDS clusterexamples/pulumi/testing/ - Unit tests for Pulumi programsAWS CDK Examples:
examples/cdk/typescript/vpc-stack/ - VPC using L2 constructsexamples/cdk/typescript/ecs-fargate/ - Fargate service with ALBexamples/cdk/typescript/pipeline-stack/ - Self-mutating CDK pipelineexamples/cdk/testing/ - CDK assertions and snapshot testsAutomated validation and operational tools:
scripts/validate-terraform.sh - Terraform fmt, validate, tflintscripts/cost-estimate.sh - Infracost wrapper for cost analysisscripts/drift-check.sh - Scheduled drift detectionscripts/security-scan.sh - Checkov/tfsec security scanningscripts/state-backup.sh - State file backup automationscripts/module-release.sh - Module versioning and publishingDeployment Pipeline:
building-ci-pipelines - Automate terraform plan/apply in CI/CDgitops-workflows - GitOps-based infrastructure deploymentPlatform Engineering:
kubernetes-operations - Provision EKS, GKE, AKS clustersplatform-engineering - Internal developer platform infrastructureSecurity:
secret-management - Provision Vault, External Secrets Operatorsecurity-hardening - Implement infrastructure security controlscompliance-frameworks - Policy-as-code for complianceOperations:
observability - Provision monitoring infrastructure (Prometheus, Grafana)disaster-recovery - Infrastructure rebuild procedurescost-optimization - Implement cost controls via IaCData Platform:
data-architecture - Provision data lakes, warehousesstreaming-data - Provision Kafka, Kinesis infrastructureDevelopment Workflow:
terraform plan / pulumi preview locallyState Management:
Module Development:
examples/ directorySecurity:
sensitive = trueCost Management:
Operational Excellence:
State File Issues:
Module Design:
Operations:
Security:
State Lock Issues:
terraform force-unlock <lock-id> # Use only if certain no other process runningImport Existing Resources:
terraform import aws_vpc.main vpc-12345678
pulumi import aws:ec2/vpc:Vpc main vpc-12345678Drift Detection:
terraform plan -detailed-exitcode # Exit 2 = drift detected
pulumi preview --diffFor detailed drift remediation, see references/drift-detection.md.
State Recovery:
# Terraform: Restore from S3 versioning
aws s3 cp s3://bucket/backup/terraform.tfstate terraform.tfstate
# Pulumi: Restore from checkpoint
pulumi stack export --version <timestamp> | pulumi stack importFor cloud-specific implementations:
aws-patterns - AWS-specific resource patternsgcp-patterns - GCP-specific resource patternsazure-patterns - Azure-specific resource patternsFor infrastructure operations:
kubernetes-operations - Manage Kubernetes clusters provisioned via IaCgitops-workflows - GitOps-based infrastructure deploymentplatform-engineering - Internal developer platformsFor security and compliance:
security-hardening - Infrastructure security controlssecret-management - Secret injection and rotationcompliance-frameworks - Policy-as-code for complianceFor deployment automation:
building-ci-pipelines - CI/CD for infrastructure codedeploying-applications - Application deployment to provisioned infrastructureFor cost and observability:
cost-optimization - FinOps practices for infrastructureobservability - Monitoring infrastructure health~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.