技能低风险未认领

terraform-policy

Write, test, or convert Terraform Policy files (.policy.hcl, .policytest.hcl, Sentinel→tfpolicy). Triggers: policy.hcl, policytest, convert sentinel, tfpolicy, write a policy.

hashicorphashicorp/terraform-policy★ 890更新于 2026年9月28日

说明

UTILITY SKILL — INVOKES: tfpolicy-author | tfpolicy-test

USE FOR:

  • Writing a new .policy.hcl policy from a description or requirement
  • Converting a .sentinel policy to Terraform Policy
  • Writing or debugging a .policytest.hcl test file
  • Migrating a Sentinel policy library to Terraform Policy

Before giving authoring or testing instructions, check the installed tfpolicy CLI version and tailor guidance accordingly. This skill maintains guidance for the two most recent minor lines, 0.2.x and 0.3.x; when a new minor ships, drop the oldest line and add the new one.

  • If the CLI is 0.2.x (baseline), include a top-level policy { required_providers { ... } } block when authoring .policy.hcl files containing resource or provider policies. It is mandatory for tfpolicy validate; version-range validation is best effort, and wildcard targets such as resource_policy "*" are not schema-validated. tfpolicy test does not preflight mocked attrs/prior_attrs against provider schemas, core::alltrue/core::anytrue do not exist, and, only in this 0.2.x line, mock resource {} blocks may omit attrs/prior_attrs entirely.
  • If the CLI is 0.3.x or newer, the other guidance above still applies, but the 0.2.x allowance for omitting resource state does not: every mock resource {} block in .policytest.hcl files must declare attrs or prior_attrs; if both evaluate to empty, the test case is skipped (provider {} and module {} mocks are unaffected) (see tfpolicy-test). tfpolicy test reuses the target .policy.hcl's existing top-level policy { required_providers { ... } } block (there is no separate .policytest.hcl-level declaration) to validate provider, resource, and data-source policies and core::getdatasource()/core::getresources() arguments against resolved provider schemas before any test runs, failing the whole run on a schema mismatch (see tfpolicy-test). core::alltrue(list) and core::anytrue(list) are also available — prefer them over the core::length() list-comprehension workaround (see tfpolicy-author). meta.tfe_stack and meta.tfe_workspace.tags are available to resource, provider, and module policies; Stack fields are empty outside Stack evaluations.
  • If the CLI version is unknown, ask the user to check it first or provide guidance that clearly distinguishes the 0.2.x and 0.3.x paths.

DO NOT USE FOR:

  • Writing .tftest.hcl files for Terraform modules — use terraform-test
  • General Terraform HCL authoring — use terraform-style-guide

Routing

Task Sub-skill
Write or convert a .policy.hcl policy tfpolicy-author
Write or debug a .policytest.hcl test tfpolicy-test

Examples

  • "Block EC2 instances without encryption" → tfpolicy-author
  • "Convert this Sentinel policy to tfpolicy" → tfpolicy-author
  • "Write a policytest for my EBS policy" → tfpolicy-test

Troubleshooting

  • Wrong skill triggered? Load the sub-skill directly from the routing table above.
npx skills add hashicorp/agent-skills/terraform/terraform-policy/skills/tfpolicy-author
npx skills add hashicorp/agent-skills/terraform/terraform-policy/skills/tfpolicy-test

权限

声明检测
运行代码—无
安装—npx
安装时运行脚本—无
网络—developer.hashicorp.comdocs.aws.amazon.comraw.githubusercontent.com
需要的凭据—无
工作区外的路径—无
智能体工具—无

检查

低风险 · 没有发现需要提醒的地方。

未经人工审核 · 已做规则检查;模型审核尚未开启。

文件55 个文件 · 310.6 KB

  • .gitignore29 B
  • README.md2.8 KB
  • SKILL.md3.9 KB
examples/1
  • README.md2.5 KB
examples/conversion/cloudfront-associated-with-waf/3
  • README.md871 B
  • cloudfront-associated-with-waf.policy.hcl589 B
  • cloudfront-associated-with-waf.sentinel1.6 KB
examples/conversion/cloudtrail-server-side-encryption-enabled/3
  • README.md846 B
  • cloudtrail-server-side-encryption-enabled.policy.hcl512 B
  • cloudtrail-server-side-encryption-enabled.sentinel1.4 KB
examples/conversion/dms-endpoint-should-be-ssl-configured/3
  • README.md872 B
  • dms-endpoint-should-be-ssl-configured.policy.hcl516 B
  • dms-endpoint-should-be-ssl-configured.sentinel1.5 KB
examples/conversion/dms-endpoints-should-use-ssl/3
  • README.md800 B
  • dms-endpoints-should-use-ssl.policy.hcl579 B
  • dms-endpoints-should-use-ssl.sentinel1.4 KB
examples/conversion/ec2-network-acl-should-have-subnet-ids/3
  • README.md970 B
  • ec2-network-acl-should-have-subnet-ids.policy.hcl1.0 KB
  • ec2-network-acl-should-have-subnet-ids.sentinel2.9 KB
examples/conversion/ec2-vpc-default-security-group-no-traffic/3
  • README.md1.1 KB
  • ec2-vpc-default-security-group-no-traffic.policy.hcl865 B
  • ec2-vpc-default-security-group-no-traffic.sentinel3.6 KB
examples/conversion/efs-access-point-should-enforce-user-identity/3
  • README.md727 B
  • efs-access-point-should-enforce-user-identity.policy.hcl448 B
  • efs-access-point-should-enforce-user-identity.sentinel1.3 KB
examples/conversion/elasticache-redis-replication-group-encryption-at-transit-enabled/3
  • README.md777 B
  • elasticache-redis-replication-group-encryption-at-transit-enabled.policy.hcl547 B
  • elasticache-redis-replication-group-encryption-at-transit-enabled.sentinel1.5 KB
examples/conversion/elasticsearch-encrypted-at-rest/3
  • README.md734 B
  • elasticsearch-encrypted-at-rest.policy.hcl584 B
  • elasticsearch-encrypted-at-rest.sentinel1.5 KB
examples/conversion/elasticsearch-https-required/3
  • README.md904 B
  • elasticsearch-https-required.policy.hcl1.1 KB
  • elasticsearch-https-required.sentinel2.3 KB
examples/conversion/elasticsearch-in-vpc-only/3
  • README.md890 B
  • elasticsearch-in-vpc-only.policy.hcl589 B
  • elasticsearch-in-vpc-only.sentinel1.9 KB
examples/conversion/eventbridge-custom-event-bus-should-have-attached-policy/3
  • README.md1.1 KB
  • eventbridge-custom-event-bus-should-have-attached-policy.policy.hcl845 B
  • eventbridge-custom-event-bus-should-have-attached-policy.sentinel2.1 KB
examples/conversion/s3-block-public-access-bucket-level/3
  • README.md1.1 KB
  • s3-block-public-access-bucket-level.policy.hcl1.2 KB
  • s3-block-public-access-bucket-level.sentinel3.2 KB
examples/conversion/s3-bucket-should-have-object-lock-enabled/3
  • README.md975 B
  • s3-bucket-should-have-object-lock-enabled.policy.hcl1.0 KB
  • s3-bucket-should-have-object-lock-enabled.sentinel2.8 KB
examples/conversion/secretsmanager-auto-rotation-enabled-check/3
  • README.md955 B
  • secretsmanager-auto-rotation-enabled-check.policy.hcl867 B
  • secretsmanager-auto-rotation-enabled-check.sentinel2.2 KB
examples/conversion/step-functions-state-machine-logging-enabled/3
  • README.md778 B
  • step-functions-state-machine-logging-enabled.policy.hcl724 B
  • step-functions-state-machine-logging-enabled.sentinel1.6 KB
references/3
  • tfpolicy-author.md97.6 KB
  • tfpolicy-test.md45.1 KB
  • verified-syntax.md100.0 KB

版本

  1. #10.1.0最新2026年10月7日