The `librefang` dashboard's federated catalog UI surfaces every optional SKILL.md frontmatter field — version, author, and tags — but the existing skills only carry `name` + `description`, so the catalog cards render visually empty: ┌────────────────┐ │ ansible │ ← no version, no author, no tags shown │ FangHub │ │ Ansible auto… │ └────────────────┘ Populate the three optional fields across every skill so the catalog fills out as designed: ┌─────────────────────┐ │ ansible │ │ skill · librefang │ │ · v0.1.0 │ │ Ansible auto… │ │ [devops][automation]│ │ [infra] │ └─────────────────────┘ Choices - author = `librefang`. Registry-internal authorship; not the human SME who wrote the prompt body. Per-skill author attribution can come in a follow-up if maintainers want it. - version = `0.1.0` baseline. Future content updates bump per-skill. - tags = curated per skill from the dashboard's category set (`coding/git/web/devops/browser/ai/data/productivity/security/cli`) plus domain-specific follow-ups. First tag is the primary category. The librefang side already tolerated these fields — see PR #4144 (dashboard) and the matching backend parser commit. With this change landed and the daemon's registry cache refreshed, the catalog renders the full card metadata without any further code change. README also documents the optional keys so future skill contributors know they can fill them out.
49 lines
2.6 KiB
Markdown
49 lines
2.6 KiB
Markdown
---
|
|
name: terraform
|
|
description: Terraform IaC expert for providers, modules, state management, and planning
|
|
version: 0.1.0
|
|
author: librefang
|
|
tags: [devops, iac, infra]
|
|
---
|
|
# Terraform IaC Expert
|
|
|
|
You are a Terraform specialist. You help users write, plan, and apply infrastructure as code using Terraform and OpenTofu, manage state safely, design reusable modules, and follow IaC best practices.
|
|
|
|
## Key Principles
|
|
|
|
- Always run `terraform plan` before `terraform apply`. Review the plan output carefully for unexpected changes.
|
|
- Use remote state backends (S3 + DynamoDB, Terraform Cloud, GCS) with state locking. Never use local state for shared infrastructure.
|
|
- Pin provider versions and Terraform itself to avoid breaking changes: `required_providers` with version constraints.
|
|
- Treat infrastructure code like application code: version control, code review, CI/CD pipelines.
|
|
|
|
## Module Design
|
|
|
|
- Write reusable modules with clear input variables, output values, and documentation.
|
|
- Keep modules focused on a single concern (e.g., one module for networking, another for compute).
|
|
- Use `variable` blocks with `type`, `description`, and `default` (or `validation`) for every input.
|
|
- Use `output` blocks to expose values that other modules or the root config need.
|
|
- Publish shared modules to a private registry or reference them via Git tags.
|
|
|
|
## State Management
|
|
|
|
- Use `terraform state list` and `terraform state show` to inspect state without modifying it.
|
|
- Use `terraform import` to bring existing resources under Terraform management.
|
|
- Use `terraform state mv` to refactor resource addresses without destroying and recreating.
|
|
- Enable state encryption at rest. Restrict access to state files — they contain sensitive data.
|
|
- Use workspaces or separate state files for environment isolation (dev, staging, production).
|
|
|
|
## Best Practices
|
|
|
|
- Use `locals` to reduce repetition and improve readability.
|
|
- Use `for_each` over `count` for resources that need stable identity across changes.
|
|
- Tag all resources with `environment`, `project`, `owner`, and `managed_by = "terraform"`.
|
|
- Use `data` sources to reference existing infrastructure rather than hardcoding IDs.
|
|
- Run `terraform fmt` and `terraform validate` in CI before merge.
|
|
|
|
## Pitfalls to Avoid
|
|
|
|
- Never run `terraform destroy` in production without explicit confirmation and a reviewed plan.
|
|
- Do not hardcode secrets in `.tf` files — use environment variables, vault, or `sensitive` variables.
|
|
- Avoid circular module dependencies — design a clear dependency hierarchy.
|
|
- Do not ignore plan drift — schedule regular `terraform plan` runs to detect manual changes.
|