Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Managing cloud infrastructure using declarative and imperative IaC tools. Use when provisioning cloud resources (Terraform/OpenTofu for multi-cloud, Pulumi for developer-centric workflows, AWS CDK for AWS-native infrastructure), designing reusable modules, implementing state management patterns, or establishing infrastructure deployment workflows.
.claude/skills/ancoleman-writing-infrastructure-code/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-05 | ✗→✓ | ▲ Improved | 105% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 183% | 0% |
| case-01 | ✓→✓ | = Same ✓ | 185% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 176% | 0% |
| case-03 | ✓→✓ | = Same ✓ | 194% | 0% |
Provision and manage cloud infrastructure using code-based automation tools. This skill covers tool selection, state management, module design, and operational patterns across Terraform/OpenTofu, Pulumi, and AWS CDK.
Use this skill when:
Common requests:
Key Principles:
Benefits:
Choose IaC tools based on team composition and cloud strategy:
Terraform/OpenTofu - Declarative, HCL-based
Pulumi - Imperative, programming language-based
AWS CDK - AWS-native, programming language-based
Decision Tree:
Multi-cloud required?
├─ YES → Team composition?
│ ├─ Ops/SRE focused → Terraform/OpenTofu
│ └─ Developer focused → Pulumi
└─ NO → AWS only?
├─ YES → Language preference?
│ ├─ HCL/declarative → Terraform
│ ├─ TypeScript/Python → AWS CDK
│ └─ YAML/simple → CloudFormation
└─ NO → GCP/Azure only?
└─ Terraform or PulumiRemote state with locking enables team collaboration:
Backend Selection:
| Cloud Provider | Recommended Backend | Locking Mechanism | |----------------|---------------------|-------------------| | AWS | S3 + DynamoDB | DynamoDB table | | GCP | Google Cloud Storage | Native | | Azure | Azure Blob Storage | Lease-based | | Multi-cloud | Terraform Cloud/Enterprise | Built-in | | Pulumi | Pulumi Service | Built-in |
State Isolation Strategies:
prod/, staging/, dev/)Critical State Management Rules:
sensitive = trueComposable Module Structure:
modules/
├── vpc/ # Network foundation
├── security-group/ # Reusable security group patterns
├── rds/ # Database with backups, encryption
├── ecs-cluster/ # Container orchestration base
├── ecs-service/ # Individual microservice
└── alb/ # Application load balancerModule Versioning:
version = "5.1.0")Module Design Principles:
When to Create a Module:
When to Keep Monolithic:
bash# Initialize providers and backend terraform init # Plan changes (preview) terraform plan # Apply changes terraform apply # Destroy infrastructure terraform destroy # Format HCL files terraform fmt # Validate syntax terraform validate # Show state terraform state list terraform state show <resource> # Import existing resources terraform import <resource.name> <id> # Workspace management terraform workspace list terraform workspace new staging terraform workspace select prod
bash# Initialize new project pulumi new aws-typescript # Preview changes pulumi preview # Apply changes pulumi up # Destroy infrastructure pulumi destroy # Show stack outputs pulumi stack output # Manage stacks pulumi stack ls pulumi stack select prod # Import existing resources pulumi import <type> <name> <id> # Export/import state pulumi stack export > state.json pulumi stack import < state.json
bash# Initialize new app cdk init app --language typescript # Synthesize CloudFormation cdk synth # Preview changes cdk diff # Deploy stack cdk deploy # Destroy stack cdk destroy # Bootstrap account/region cdk bootstrap # List stacks cdk list
Infrastructure Provisioning:
Module Development:
Operational Readiness:
For comprehensive patterns and implementation details:
Tool-Specific Patterns:
references/terraform-patterns.md - Terraform/OpenTofu best practices, HCL patternsreferences/pulumi-patterns.md - Pulumi across TypeScript/Python/GoArchitecture and Design:
references/state-management.md - Remote state, locking, isolation strategiesreferences/module-design.md - Composable modules, versioning, registriesOperations:
references/drift-detection.md - Detecting and remediating infrastructure driftPractical implementations demonstrating IaC patterns:
Terraform Examples:
examples/terraform/vpc-module/ - Multi-AZ VPC with public/private subnetsexamples/terraform/ecs-service/ - ECS service with ALB, autoscalingexamples/terraform/rds-cluster/ - Aurora cluster with backups, encryptionexamples/terraform/state-backend/ - S3 + DynamoDB backend setupPulumi Examples:
examples/pulumi/typescript/vpc/ - TypeScript VPC componentexamples/pulumi/python/ecs-service/ - Python ECS serviceexamples/pulumi/go/rds-cluster/ - Go RDS clusterexamples/pulumi/testing/ - Unit tests for Pulumi programsAWS CDK Examples:
examples/cdk/typescript/vpc-stack/ - VPC using L2 constructsexamples/cdk/typescript/ecs-fargate/ - Fargate service with ALBexamples/cdk/typescript/pipeline-stack/ - Self-mutating CDK pipelineexamples/cdk/testing/ - CDK assertions and snapshot testsAutomated validation and operational tools:
scripts/validate-terraform.sh - Terraform fmt, validate, tflintscripts/cost-estimate.sh - Infracost wrapper for cost analysisscripts/drift-check.sh - Scheduled drift detectionscripts/security-scan.sh - Checkov/tfsec security scanningscripts/state-backup.sh - State file backup automationscripts/module-release.sh - Module versioning and publishingDeployment Pipeline:
building-ci-pipelines - Automate terraform plan/apply in CI/CDgitops-workflows - GitOps-based infrastructure deploymentPlatform Engineering:
kubernetes-operations - Provision EKS, GKE, AKS clustersplatform-engineering - Internal developer platform infrastructureSecurity:
secret-management - Provision Vault, External Secrets Operatorsecurity-hardening - Implement infrastructure security controlscompliance-frameworks - Policy-as-code for complianceOperations:
observability - Provision monitoring infrastructure (Prometheus, Grafana)disaster-recovery - Infrastructure rebuild procedurescost-optimization - Implement cost controls via IaCData Platform:
data-architecture - Provision data lakes, warehousesstreaming-data - Provision Kafka, Kinesis infrastructureDevelopment Workflow:
terraform plan / pulumi preview locallyState Management:
Module Development:
examples/ directorySecurity:
sensitive = trueCost Management:
Operational Excellence:
State File Issues:
Module Design:
Operations:
Security:
State Lock Issues:
bashterraform force-unlock <lock-id> # Use only if certain no other process running
Import Existing Resources:
bashterraform import aws_vpc.main vpc-12345678 pulumi import aws:ec2/vpc:Vpc main vpc-12345678
Drift Detection:
bashterraform plan -detailed-exitcode # Exit 2 = drift detected pulumi preview --diff
For detailed drift remediation, see references/drift-detection.md.
State Recovery:
bash# Terraform: Restore from S3 versioning aws s3 cp s3://bucket/backup/terraform.tfstate terraform.tfstate # Pulumi: Restore from checkpoint pulumi stack export --version <timestamp> | pulumi stack import
For cloud-specific implementations:
aws-patterns - AWS-specific resource patternsgcp-patterns - GCP-specific resource patternsazure-patterns - Azure-specific resource patternsFor infrastructure operations:
kubernetes-operations - Manage Kubernetes clusters provisioned via IaCgitops-workflows - GitOps-based infrastructure deploymentplatform-engineering - Internal developer platformsFor security and compliance:
security-hardening - Infrastructure security controlssecret-management - Secret injection and rotationcompliance-frameworks - Policy-as-code for complianceFor deployment automation:
building-ci-pipelines - CI/CD for infrastructure codedeploying-applications - Application deployment to provisioned infrastructureFor cost and observability:
cost-optimization - FinOps practices for infrastructureobservability - Monitoring infrastructure health| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | pass→pass | 8,848 | 7,598 | -14% | 1 | 1 | 0% | 1,579 | 4,499 | +185% | 0 | 0 | — |
case-02 | pass→pass | 12,099 | 12,353 | +2% | 1 | 1 | 0% | 1,950 | 5,382 | +176% | 0 | 0 | — |
case-03 | pass→pass | 12,274 | 12,147 | -1% | 1 | 1 | 0% | 1,898 | 5,576 | +194% | 0 | 0 | — |
case-04 | pass→pass | 13,815 | 12,930 | -6% | 1 | 1 | 0% | 2,199 | 5,454 | +148% | 0 | 0 | — |
case-05 | fail→pass | 18,869 | 15,341 | -19% | 1 | 1 | 0% | 2,837 | 5,818 | +105% | 0 | 0 | — |
case-11 | pass→pass | 14,170 | 15,761 | +11% | 1 | 1 | 0% | 2,256 | 6,069 | +169% | 0 | 0 | — |
case-06 | pass→pass | 4,134 | 4,161 | +1% | 1 | 1 | 0% | 721 | 4,114 | +471% | 0 | 0 | — |
case-07 | pass→pass | 12,329 | 15,079 | +22% | 1 | 1 | 0% | 1,989 | 5,954 | +199% | 0 | 0 | — |
case-08 | pass→pass | 5,049 | 5,748 | +14% | 1 | 1 | 0% | 848 | 4,406 | +420% | 0 | 0 | — |
case-09 | fail→pass | 11,360 | 11,752 | +3% | 1 | 1 | 0% | 1,892 | 5,355 | +183% | 0 | 0 | — |
case-10 | pass→pass | 8,184 | 6,498 | -21% | 1 | 1 | 0% | 1,431 | 4,523 | +216% | 0 | 0 | — |
case-12 | pass→pass | 5,144 | 4,974 | -3% | 1 | 1 | 0% | 927 | 4,347 | +369% | 0 | 0 | — |
case-13 | pass→pass | 2,985 | 3,584 | +20% | 1 | 1 | 0% | 476 | 4,050 | +751% | 0 | 0 | — |
case-14 | pass→pass | 6,423 | 4,794 | -25% | 1 | 1 | 0% | 1,063 | 4,233 | +298% | 0 | 0 | — |
case-15 | pass→pass | 4,316 | 3,246 | -25% | 1 | 1 | 0% | 669 | 3,992 | +497% | 0 | 0 | — |
case-16 | pass→pass | 15,410 | 18,504 | +20% | 1 | 1 | 0% | 2,653 | 6,616 | +149% | 0 | 0 | — |
case-17 | fail→fail | 13,422 | 14,887 | +11% | 1 | 1 | 0% | 2,212 | 5,940 | +169% | 0 | 0 | — |
case-18 | pass→pass | 19,003 | 18,621 | -2% | 1 | 1 | 0% | 3,221 | 6,905 | +114% | 0 | 0 | — |
case-19 | pass→pass | 14,307 | 13,205 | -8% | 1 | 1 | 0% | 2,335 | 5,595 | +140% | 0 | 0 | — |
case-20 | pass→pass | 17,971 | 23,033 | +28% | 1 | 1 | 0% | 2,825 | 7,379 | +161% | 0 | 0 | — |
case-21 | pass→pass | 9,222 | 8,843 | -4% | 1 | 1 | 0% | 1,749 | 5,008 | +186% | 0 | 0 | — |
case-22 | pass→pass | 19,267 | 17,516 | -9% | 1 | 1 | 0% | 3,847 | 6,925 | +80% | 0 | 0 | — |
case-23 | pass→pass | 8,068 | 7,443 | -8% | 1 | 1 | 0% | 1,514 | 4,784 | +216% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of +9 percentage points is the difference between those two pass rates over the 23 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.