From terraform-iac
Gate infrastructure with policy-as-code: evaluate the Terraform plan JSON with OPA/Conftest (or Sentinel) to reject misconfigurations — public exposure, wildcard IAM, missing tags, unencrypted resources — before apply, preventively.
How this skill is triggered — by the user, by Claude, or both
Slash command
/terraform-iac:policy-as-code-iacThe summary Claude sees in its skill listing — used to decide when to auto-load this skill
Run `terraform plan -out` -> `terraform show -json` -> evaluate with **OPA/Conftest** (or Sentinel). Fail the pipeline on violations **before apply**.
Run terraform plan -out -> terraform show -json -> evaluate with OPA/Conftest (or Sentinel). Fail the pipeline on violations before apply.
0.0.0.0/0 to admin ports* action/resource)Blocking the misconfigured plan beats auditing the breached resource later. Route the security verdict to security-engineering; the gate just enforces the rule.
npx claudepluginhub mcorbett51090/ravenclaude --plugin terraform-iacGuides completion of development work by verifying tests, detecting environment, and presenting structured options for merge, PR, or cleanup.
Enforces test-driven development: write failing test first, then minimal code to pass. Use when implementing features or bugfixes.
Guides creation and editing of skills using test-driven development with pressure scenarios and subagents to verify agent compliance.