google-agents-cli-scaffold
Project scaffolding, deployment configuration, and CI/CD setup for Google ADK agents.
terraform-basics
Terraform infrastructure-as-code patterns for AWS and Azure provisioning. Use when creating or modifying .tf files, writing Terraform modules, managing remote state (S3, Azure Storage), working with terraform commands (init, plan, apply, destroy), configuring providers (AWS, Azure, Google Cloud),...
Full skill instructions
Provide infrastructure-as-code best practices, command workflows, and module design patterns for Terraform-based AWS and Azure provisioning.
Key Capabilities:
Auto-activates when:
.tf files (main.tf, variables.tf, outputs.tf)modules/*/)modules/{module-name}/Never commit terraform.tfstate to git. Always use remote backend.
✅ GOOD - Remote state with locking
terraform {
backend "azurerm" {
resource_group_name = "terraform-state-rg"
storage_account_name = "tfstatestorage"
container_name = "tfstate"
key = "prod.terraform.tfstate"
}
}
❌ BAD - Local state (no locking, no collaboration)
# No backend configuration = local state
# terraform.tfstate in .gitignore but risky
Why: State locking prevents concurrent modifications, remote state enables team collaboration.
Review changes before applying to production.
✅ GOOD - Plan → Review → Apply workflow
terraform plan -out=tfplan
# Review plan output carefully
terraform show tfplan
# If approved:
terraform apply tfplan
❌ BAD - Direct apply without review
terraform apply -auto-approve # DANGEROUS in production!
Why: Prevents accidental resource deletion, cost overruns, security misconfigurations.
Don't repeat infrastructure code. Create reusable modules.
✅ GOOD - Reusable module
# modules/azure-vnet/main.tf
resource "azurerm_virtual_network" "vnet" {
name = var.vnet_name
address_space = var.address_space
location = var.location
resource_group_name = var.resource_group_name
}
# Root module usage
module "vnet_prod" {
source = "./modules/azure-vnet"
vnet_name = "prod-vnet"
address_space = ["10.0.0.0/16"]
location = "eastus"
resource_group_name = azurerm_resource_group.prod.name
}
❌ BAD - Copy-pasted resource blocks
resource "azurerm_virtual_network" "vnet_prod" { ... }
resource "azurerm_virtual_network" "vnet_staging" { ... }
resource "azurerm_virtual_network" "vnet_dev" { ... }
# Same code repeated 3 times
Why: Maintainability, consistency, reduced errors.
Lock versions for reproducibility.
✅ GOOD - Version constraints
terraform {
required_version = ">= 1.5.0"
required_providers {
azurerm = {
source = "hashicorp/azurerm"
version = "~> 3.70.0" # Locked to 3.70.x
}
}
}
module "network" {
source = "terraform-aws-modules/vpc/aws"
version = "5.1.0" # Exact version
}
❌ BAD - No version constraints
terraform {
required_providers {
azurerm = {
source = "hashicorp/azurerm"
# No version = latest (unpredictable)
}
}
}
Why: Prevents breaking changes, ensures consistent deployments.
Query existing resources instead of hardcoding.
✅ GOOD - Data source
data "azurerm_resource_group" "existing" {
name = "existing-rg"
}
resource "azurerm_storage_account" "storage" {
resource_group_name = data.azurerm_resource_group.existing.name
location = data.azurerm_resource_group.existing.location
}
❌ BAD - Hardcoded values
resource "azurerm_storage_account" "storage" {
resource_group_name = "existing-rg" # Hardcoded
location = "eastus" # Hardcoded
}
Why: Flexibility, environment portability, reduced duplication.
Add validation rules and output documentation.
✅ GOOD - Input validation
variable "environment" {
type = string
description = "Environment name (dev, staging, prod)"
validation {
condition = contains(["dev", "staging", "prod"], var.environment)
error_message = "Environment must be dev, staging, or prod."
}
}
output "vnet_id" {
description = "Azure Virtual Network ID for use in other modules"
value = azurerm_virtual_network.vnet.id
}
❌ BAD - No validation or documentation
variable "environment" {
type = string
# No validation, no description
}
output "vnet_id" {
value = azurerm_virtual_network.vnet.id
# No description
}
Why: Prevents invalid configurations, improves documentation.
Workspaces for environment isolation (dev, staging, prod).
✅ GOOD - Workspace strategy
terraform workspace new dev
terraform workspace new staging
terraform workspace new prod
# Switch to environment
terraform workspace select prod
terraform plan -var-file=prod.tfvars
❌ BAD - Single workspace for all environments
# No isolation, risk of mixing dev/prod resources
Why: Environment isolation, reduced accidental cross-environment changes.
| Command | Purpose | When to Use |
|---|---|---|
terraform init | Initialize backend, download providers | First time, after adding providers/modules |
terraform validate | Check syntax validity | After editing .tf files |
terraform fmt | Format code to standard style | Before committing |
terraform plan | Preview changes | Before apply, during review |
terraform apply | Apply changes | After plan approval |
terraform destroy | Delete all resources | Tearing down environments |
terraform state list | List resources in state | Debugging, auditing |
terraform state show | Show resource details | Inspecting specific resources |
terraform import | Import existing resources | Adopting existing infrastructure |
terraform output | Display output values | Retrieving module outputs |
| File | Purpose |
|---|---|
main.tf | Primary resource definitions |
variables.tf | Input variable declarations |
outputs.tf | Output value definitions |
providers.tf | Provider configurations |
backend.tf | Backend configuration (remote state) |
terraform.tfvars | Variable values (environment-specific) |
versions.tf | Terraform and provider version constraints |
modules/azure-vnet/
├── main.tf # Resource definitions
├── variables.tf # Input variables
├── outputs.tf # Outputs
├── README.md # Module documentation
├── examples/ # Usage examples
│ └── basic/
│ └── main.tf
└── tests/ # Module tests
└── basic_test.go
Problem: Single main.tf with 1000+ lines Issue: Hard to maintain, understand, and collaborate Fix: Split into modules and logical files
Problem: AWS keys or Azure credentials in .tf files Issue: Security risk, credential leakage Fix: Use environment variables, managed identities, or credential helpers
Problem: Multiple users applying changes simultaneously Issue: State corruption, race conditions Fix: Enable state locking (DynamoDB for S3, blob lease for Azure)
Problem: terraform apply -auto-approve in CI/CD
Issue: No human review, risky changes
Fix: Require manual approval for production applies
Problem: Running apply without reviewing plan
Issue: Accidental deletions, unexpected changes
Fix: Always review terraform plan output before apply
# 1. Create project directory
mkdir -p terraform/modules
# 2. Initialize Terraform
cd terraform
terraform init
# 3. Create backend configuration
cat > backend.tf <<EOF
terraform {
backend "azurerm" {
resource_group_name = "terraform-state-rg"
storage_account_name = "tfstate"
container_name = "tfstate"
key = "project.tfstate"
}
}
EOF
# 4. Initialize backend
terraform init -backend-config=backend.hcl
# 5. Create workspace
terraform workspace new dev
# 1. Pull latest state
terraform refresh
# 2. Make changes to .tf files
# Edit main.tf, variables.tf, etc.
# 3. Format code
terraform fmt -recursive
# 4. Validate syntax
terraform validate
# 5. Plan changes
terraform plan -out=tfplan
# 6. Review plan
terraform show tfplan
# 7. Apply changes
terraform apply tfplan
# Deploy to dev
terraform workspace select dev
terraform plan -var-file=dev.tfvars -out=dev.tfplan
terraform apply dev.tfplan
# Deploy to staging
terraform workspace select staging
terraform plan -var-file=staging.tfvars -out=staging.tfplan
terraform apply staging.tfplan
# Deploy to prod (with approval)
terraform workspace select prod
terraform plan -var-file=prod.tfvars -out=prod.tfplan
# Manual review and approval
terraform apply prod.tfplan
| Need to... | Read this |
|---|---|
| Learn terraform commands | terraform-commands.md |
| Manage state files | state-management.md |
| Design reusable modules | module-patterns.md |
Complete command reference with examples, flags, and troubleshooting
Remote state backends, locking, migration, disaster recovery
Module design, composition, testing, versioning, registry publishing
Skill Status: COMPLETE ✅ Line Count: 435 ✅ Progressive Disclosure: 3 resource files ✅
Project scaffolding, deployment configuration, and CI/CD setup for Google ADK agents.
Set up tracing, logging, and monitoring for deployed ADK agents across Cloud Trace, BigQuery, and third-party platforms.
Enterprise Azure infrastructure architect generating Bicep or Terraform from workload descriptions.
Plan and configure production-ready Azure Kubernetes Service clusters with Day-0 and Day-1 best practices.
Raw mechanical interfaces fusing Swiss typographic print with military terminal aesthetics. Rigid grids, extreme type scale contrast, utilitarian color, analog degradation effects. For data-heavy dashboards, portfolios, or editorial sites that need to feel like declassified blueprints.
Web search, scraping, extraction, crawling, and monitoring via ScrapeGraph AI CLI.
Skill for working with Firebase Hosting (Classic). Use this when you want to deploy static web apps, Single Page Apps (SPAs), or simple microservices. Do NOT use for Firebase App Hosting.
Deploy and manage web apps with Firebase App Hosting. Use this skill when deploying Next.js/Angular apps with backends.
Deploy applications and websites to Vercel. Use when the user requests deployment actions like "deploy my app", "deploy and give me the link", "push this live", or "create a preview deployment".
Build SEO-optimized pages at scale using templates, data, and proven playbook patterns.
Design and build isolated, reusable Convex backend components with clear boundaries and app-facing wrappers.
Deploy and manage projects on Vercel using token-based authentication. Use when working with Vercel CLI using access tokens rather than interactive login — e.g. "deploy to vercel", "set up vercel", "add environment variables to vercel".
Opus.ai: Revolutionize Your Web Experience
Build a no-code AI app in minutes.
An IDE for code migration from legacy to modern frameworks through coding agents.
Automate CGI animation in live-action scenes
Branded artistic QR-code concepts
Launch a website in seconds with AI.
Streamline Your Coding Experience with AI Code Helper
Convert any screenshot or design to clean code.