跳到主要内容
知仓学习社ZHICANG

terrashark

Prevent Terraform/OpenTofu hallucinations by diagnosing and fixing failure modes: identity churn, secret exposure, blast-radius mistakes, CI drift, …

联网无严重或高危命中LukasNiessen/terrashark

它会碰到什么

扫了多少70 个文本文件,306 KB
它会碰到什么联网
命中总数20 处
命中统计严重 0 · 高 0 · 中 0 · 低 20

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Terrashark: Failure-Mode Workflow for Terraform/OpenTofu

Run this workflow top to bottom.

1) Capture execution context

Record before writing code:

  • runtime (terraform or tofu) and exact version
  • provider(s), target platform, and state backend
  • execution path (local CLI, CI, HCP Terraform/TFE, Atlantis)
  • environment criticality (dev/shared/prod)

If unknown, state assumptions explicitly.

2) Diagnose likely failure mode(s)

Select one or more based on user intent and risk:

  • identity churn: resource addressing instability, refactor breakage
  • secret exposure: secrets in state, logs, defaults, artifacts
  • blast radius: oversized stacks, weak boundaries, unsafe applies
  • CI drift: version mismatch, unreviewed applies, missing artifacts
  • compliance gate gaps: missing policies/approvals/audit controls

3) Load only the relevant reference file(s)

Primary references:

  • references/identity-churn.md
  • references/secret-exposure.md
  • references/blast-radius.md
  • references/ci-drift.md
  • references/compliance-gates.md

Supplemental references (only when needed):

  • references/testing-matrix.md
  • references/quick-ops.md
  • references/examples-good.md
  • references/examples-bad.md
  • references/examples-neutral.md
  • references/coding-standards.md
  • references/module-architecture.md
  • references/ci-delivery-patterns.md
  • references/security-and-governance.md
  • references/do-dont-patterns.md
  • references/mcp-integration.md

Conditional references (CRR; load only on detected signals):

  • references/conditional/backend-state-safety.md (backend is s3, azurerm, gcs, remote, cloud, pg, consul, or local, or task mentions backend migration, locking, state backup, or restore)
  • references/conditional/trusted-modules.md (provider is aws, azurerm, google, oci, or ibm)

Do not load multiple conditional references unless the task spans multiple detected backends, providers, or tools.

4) Propose fix path with explicit risk controls

For each fix, include:

  • why this addresses the failure mode
  • what could still go wrong
  • guardrails (tests, approvals, rollback)

5) Generate implementation artifacts

When applicable, output:

  • HCL changes (typed vars, stable keys, bounded versions)
  • migration blocks (moved, import strategy)
  • CI pipeline updates (plan/apply separation, artifacts, policy checks)
  • compliance controls (approvals, policy rules, evidence paths)

When a trusted registry module covers the requested resource and the user has not asked for raw HCL, default to that module with an exact version pin (see references/conditional/trusted-modules.md).

6) Validate before finalize

Always provide command sequence tailored to runtime and risk tier.

Never recommend direct production apply without reviewed plan and approval.

7) Output contract

Return:

  • assumptions and version floor
  • selected failure mode(s)
  • chosen remediation and tradeoffs
  • validation/test plan
  • rollback/recovery notes for destructive-impact changes

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 322
本站分层T2
该仓技能数1
原文件路径SKILL.md