Skip to content
Back to skills

Civiltekk Opentofu Skill

ASecurity

OpenTofu/Terraform infrastructure as code, five routes. first-time-setup: configure cloud providers, authentication, and remote state backends (S3, Azure Storage, GCS). plan-apply: provisioning workflow — plan→apply discipline, resource lifecycle, state management and drift. explore: AWS, Kubernetes, Neon Postgres, and Keycloak resources as code. ecr-provision: AWS ECR repositories with GitHub OIDC integration per BETEKK standards. shared-infra-split: provision-once shared modules (ECR/Amplif...

  • 6 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
devopsrustgobashdockerkubernetesawsazureterraformgitbackend

Works with

  • cli

Security analysis

A100/100

Pro scans all 6 files and shows the line behind each finding

Scanned October 5, 2026

npx -y skills add darellchua2/civiltekk-skills --skill civiltekk-opentofu-skill --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Civiltekk Opentofu Skill?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Civiltekk Opentofu Skill
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/darellchua2-civiltekk-opentofu-skill-civiltekk-skills/badge)](https://www.skillsdirectory.com/skills/darellchua2-civiltekk-opentofu-skill-civiltekk-skills)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: civiltekk-opentofu-skill
description: >-
  OpenTofu/Terraform infrastructure as code, five routes. first-time-setup:
  configure cloud providers, authentication, and remote state backends (S3,
  Azure Storage, GCS). plan-apply: provisioning workflow — plan→apply
  discipline, resource lifecycle, state management and drift. explore:
  AWS, Kubernetes, Neon Postgres, and Keycloak resources as code.
  ecr-provision: AWS ECR repositories with GitHub OIDC integration per
  BETEKK standards. shared-infra-split: provision-once shared modules
  (ECR/Amplify pattern) vs per-env stacks, and live migrations between
  the two. Triggers: opentofu, tofu, terraform plan, terraform
  apply, infrastructure as code, IaC, provider setup, provider pin, state
  backend, remote state, drift, tofu import, ECR, GitHub OIDC, Neon
  branching, Keycloak realm, Helm release, Kubernetes as code, shared
  module, provision once, module split, shared infra.
license: Apache-2.0
compatibility: opencode
category: OpenTofu
---

Consolidates opentofu-provider-setup-skill + opentofu-provisioning-workflow-skill
+ opentofu-aws-explorer-skill + opentofu-kubernetes-explorer-skill +
opentofu-neon-explorer-skill + opentofu-keycloak-explorer-skill +
opentofu-ecr-provision-skill (#604). Alias: formerly those seven skills.

## What I do

OpenTofu/Terraform infrastructure as code across five routes — provider
bootstrap, provisioning workflow, per-platform resource exploration, ECR
provisioning, and shared-module organization. OpenTofu/Terraform are interchangeable (OpenTofu is
provider-compatible); house commands use `tofu`.

1. **Detect the route** (§Routes) — explicit > inferred > ask-once.
   Explicit: the request names the activity ("set up providers", "state
   backend" → `first-time-setup`; "plan and apply", "update infrastructure",
   "state drift" → `plan-apply`; "AWS/Kubernetes/Neon/Keycloak resources"
   → `explore`; "ECR repo", "GitHub OIDC" → `ecr-provision`; "shared
   module", "split the module", "provision once", "which module owns X" →
   `shared-infra-split`). Inferred:
   the artifact shape (a bootstrap `versions.tf` → `first-time-setup`; a
   reviewed change → `plan-apply`; platform resource work → `explore`;
   container registry + CI → `ecr-provision`; a singleton resource
   claimed by multiple env stacks → `shared-infra-split`). Ambiguous →
   ask once per run, then proceed on the answer.
2. **Load the route's reference file** (§Side files) and apply its pins,
   conventions, and rules — do not improvise provider versions or backend
   shapes.
3. **Follow the route's workflow discipline** — canonical commands in
   `references/workflow.md` apply to every route; route-specific workflows
   live in the reference files.

## Route chain (stated once)

**`first-time-setup` precedes everything** — provider authentication and the
remote state backend must exist before any `plan-apply`, `explore`, or
`ecr-provision` work. The former per-skill prerequisite chain
("Complete opentofu-provider-setup-skill first") is this internal ordering:
when a request assumes infrastructure that has not been bootstrapped, run
`first-time-setup` (or verify its outputs) first. `ecr-provision` and every
`explore` platform additionally flow through `plan-apply` discipline for any
change they make.

## Routes

| Situation | Route |
|-----------|-------|
| New OpenTofu project; provider blocks, authentication, remote state backend (S3/Azure/GCS) | `first-time-setup` |
| Creating/updating/destroying infrastructure; plan review; state management, drift, imports; lifecycle rules | `plan-apply` |
| AWS, Kubernetes (incl. Helm), Neon Postgres, or Keycloak resources as code | `explore` |
| New ECR repository; GitHub Actions → ECR via OIDC (no long-lived keys); BETEKK patterns | `ecr-provision` |
| Which module owns a resource; creating a shared provision-once module (ECR/Amplify pattern); migrating a live resource out of an env stack into a shared module | `shared-infra-split` |
| Ambiguous | ask once (§What I do step 1), then route |

## Side files (load rules)

| Read | When | Use |
|------|------|-----|
| `references/provider-setup.md` | route `first-time-setup` | Chain-root values: provider pin table, per-provider auth essentials, state-backend selection + migration learning |
| `references/workflow.md` | route `plan-apply` (and any route that changes state) | Canonical command workflow, plan-file discipline, lifecycle/state rules, imports, the two CI/CD anti-patterns |
| `references/explorers.md` | route `explore` | Four sections — AWS, Kubernetes, Neon, Keycloak: provider pins, connection methods, house conventions, learnings |
| `references/ecr.md` | route `ecr-provision` | BETEKK standards (pins, OIDC trust scoping, ECR policy deltas), reference implementation pin, lowercase-naming learning |
| `references/shared-infra-split.md` | route `shared-infra-split` | Ownership decision table, shared-module contracts, live-migration recipe, for_each/sensitive trap |

Side files carry VALUES only; this file carries the METHOD — route
detection, the chain, and the workflow discipline pointer.

## Boundaries

- AWS IaC safety review (pre-apply blast radius, destructive-change triage)
  is `aws-iac-safety-skill`'s space — this skill provisions; that skill
  audits.
- Container image building and composition is
  `docker-containerization-skill`'s space; `ecr-provision` only creates the
  registry + CI trust.
- Provider schemas and per-resource HCL are model knowledge — side files
  carry house pins and conventions only; do not expect full resource
  walkthroughs.
- `opentofu-explorer-subagent` is the agent that runs this skill by route
  (delegated IaC work keeps `tofu` output out of the primary context).

## Agent behavior rules

- **Never bare `tofu apply`** — always `plan -out` then `apply tfplan`
  (full rule in `references/workflow.md`).
- **Ask once on ambiguity** — then proceed; headless/CI: no asks, read the
  route from the delegation prompt and use the documented default.
- **Verify before success** — a change is successful only after `tofu
  apply` of the reviewed plan and `tofu state list` shows the expected
  resources.
- `tofu` CLI commands need bash (git-bash/WSL on Windows).

## Return Contract

```
**Status:** [success | partial | failed]
**Output:** [resources/modules changed + route used — one line]
**Summary:** [2–3 sentences max]
**Issues:** [blockers, warnings, uninspected consumers, or "None"]
```

Files in this skill

  • SKILL.md6.4 KB
  • references/ecr.md1.6 KB
  • references/explorers.md5.3 KB
  • references/provider-setup.md4.6 KB
  • references/shared-infra-split.md3.4 KB
  • references/workflow.md2.4 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…