first-fluke/oma-tf-infra
Infrastructure-as-code specialist for multi-cloud provisioning using Terraform across any provider (AWS, GCP, Azure, Oracle Cloud). Use for terraform plan/apply, state management, compute, databases, storage, networking, IAM, OIDC, cost optimization, policy-as-code, ISO/IEC 42001 AI controls, ISO 22301 continuity, and ISO/IEC/IEEE 42010 architecture documentation.
npx skills add https://github.com/first-fluke/oh-my-agent --skill oma-tf-infra
Design, implement, review, and document Terraform-based infrastructure across cloud providers with secure state, least privilege, cost awareness, continuity, and policy/testing controls.
.tf, .tfvars, modules, provider versions, CI/CD auth, plan output, or drift symptomsresources/multi-cloud-examples.md, cost guide, policy/testing examples, ISO infra guide, and checklist| Action | SSL primitive | Evidence |
|--------|---------------|----------|
| Detect provider and scope | READ | HCL, providers, modules |
| Select cloud/resource mapping | SELECT | Multi-cloud mapping |
| Write Terraform | WRITE | .tf, .tfvars, modules |
| Validate HCL | CALL_TOOL | terraform fmt, validate, plan |
| Compare plan risk | COMPARE | Plan output and drift |
| Infer cost/security/continuity risks | INFER | Policy, ISO, cost guides |
| Report result | NOTIFY | Final infra summary |
trivy config, successor to tfsec), OPA/Sentinel, native terraform test, Terratest when applicableterraform init # required before validate/plan (-backend=false for static-only checks)
terraform fmt -recursive
terraform validate
terraform plan -out=tfplan
Run scanners when available before any apply:
checkov -d .
trivy config . # tfsec is in maintenance mode; Trivy is its successor
| Scope | Resource target |
|-------|-----------------|
| CODEBASE | Terraform modules, variables, outputs, CI config |
| LOCAL_FS | Plans, state config, documentation |
| PROCESS | Terraform, scanner, and policy commands |
| CREDENTIALS | Cloud provider auth and state backend credentials |
| NETWORK | Cloud APIs and remote state backends |
terraform validate, terraform fmt, terraform plan before apply10. Policy as Code: Run OPA/Sentinel and security scanning (Checkov, Trivy) in CI/CD before apply
11. Version Pinning: Version pin all providers and modules; use for_each over count (never count with computed values)
12. Cost Awareness: Implement lifecycle policies, autoscaling schedules, and review cost estimates before apply
13. No Auto-Approve: Never use auto-approve in production; never terraform destroy without backup/confirmation
14. Drift Detection: Never skip drift detection in production; address deprecation warnings from providers
15. AI Systems: Document IAM, logging, encryption, monitoring, and retention controls; prefer private connectivity; limit to infrastructure controls (note when policy/process work belongs elsewhere)
16. Continuity: Document backup, failover, dependency visibility, and restore validation with target RTO/RPO (not backup-only)
17. Architecture Documentation: Capture stakeholders, concerns, views, interfaces, constraints, and decisions (not a compliance checkbox; improve communication and traceability)
| Indicator | Provider |
|-----------|----------|
| provider "google" or google_* resources | GCP |
| provider "aws" or aws_* resources | AWS |
| provider "azurerm" or azurerm_* resources | Azure |
| provider "oci" or oci_* resources | Oracle Cloud |
| Concept | AWS | GCP | Azure | Oracle (OCI) |
|---------|-----|-----|-------|--------------|
| Container Platform | ECS Fargate | Cloud Run | Container Apps | Container Instances |
| Managed Kubernetes | EKS | GKE | AKS | OKE |
| Managed Database | RDS | Cloud SQL | Azure SQL | Autonomous DB |
| Cache/In-Memory | ElastiCache | Memorystore | Azure Cache | OCI Cache |
| Object Storage | S3 | GCS | Blob Storage | Object Storage |
| Queue/Messaging | SQS/SNS | Pub/Sub | Service Bus | OCI Streaming |
| Task Queue | N/A | Cloud Tasks | Queue Storage | N/A |
| CDN | CloudFront | Cloud CDN | Front Door | OCI CDN |
| Load Balancer | ALB/NLB | Cloud Load Balancing | Load Balancer | OCI Load Balancer |
| IAM Role | IAM Role | Service Account | Managed Identity | Dynamic Group |
| Secrets | Secrets Manager | Secret Manager | Key Vault | OCI Vault |
| VPC | VPC | VPC | Virtual Network | VCN |
| Serverless Function | Lambda | Cloud Functions | Functions | OCI Functions |
Follow resources/execution-protocol.md step by step.
See resources/examples.md for input/output examples.
Use resources/multi-cloud-examples.md for provider-specific HCL patterns.
Use resources/cost-optimization.md for cost reduction strategies.
Use resources/policy-testing-examples.md for OPA, Sentinel, and Terratest patterns.
Use resources/iso-42001-infra.md for AI governance, continuity, and architecture controls.
Before submitting, run resources/checklist.md.
Vendor-specific execution protocols are injected automatically by oma agent:spawn.
Source files live under ../_shared/runtime/execution-protocols/{vendor}.md.
resources/execution-protocol.mdresources/checklist.mdresources/examples.mdresources/multi-cloud-examples.mdresources/cost-optimization.mdresources/policy-testing-examples.mdresources/iso-42001-infra.mdresources/error-playbook.md../_shared/core/context-loading.md../_shared/core/clarification-protocol.md../_shared/core/context-budget.md../_shared/core/difficulty-guide.md../_shared/core/lessons-learned.md../oma-observability/SKILL.md §Integrations — Collector topology, transport tuning, release metadataterraform, opentofu, infrastructure-as-code, iac, cloud, aws, gcp, azure, oracle, oci, multi-cloud, devops, provisioning, infrastructure, compute, database, storage, networking, iam, oidc, workload identity, container, kubernetes, serverless, vpc, subnet, load balancer, cdn, secrets management, ephemeral resources, write-only arguments, state management, drift, import block, terraform test, trivy, checkov, infracost, backend, provider
Take first-fluke/oma-tf-infra from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.