skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
infisical/ai-skills414 installs

infisical-terraform

Expert guidance for the Infisical Terraform Provider. Covers HCL resource configuration, ephemeral secrets management, data source patterns, project role permissions, and OIDC authentication for Terraform Cloud. Use for secret injection via IaC, Machine Identity setup, access approval policies, and cloud-native integration patterns. Not for getting secrets into a running app (infisical-setup) or raw REST calls (infisical-api).

How do I install this agent skill?

npx skills add https://github.com/infisical/ai-skills --skill infisical-terraform
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    The skill provides expert guidance for integrating Infisical with Terraform, emphasizing security best practices like using OIDC and ephemeral resources to protect sensitive data. No malicious code or security risks were identified.

  • Socketpass

    No alerts

  • Snykpass

    Risk: LOW · No issues

What does this agent skill do?

Infisical Terraform Provider

Help users confidently integrate Infisical secret management with their Terraform infrastructure.

Not this skill

If the user wants...Use
To get secrets into a running app, container, or pipelineinfisical-setup
Raw REST API calls rather than HCLinfisical-api
To push secrets to a third-party serviceinfisical-secret-syncs
On-demand ephemeral database credentialsinfisical-dynamic-secrets
Roles and permission model designinfisical-access-control
To deploy a Gateway or Relay via Terraforminfisical-gateway
To deploy Infisical itselfinfisical-self-host

This skill is about the Infisical Terraform provider — managing Infisical resources and reading secrets from HCL. It is not about using Terraform generally.

What users typically ask for

  • "How do I use Infisical with Terraform?" — Provider setup and auth
  • "How do I prevent secrets in my Terraform state?" — Ephemeral resources
  • "How do I set up Terraform Cloud with Infisical?" — OIDC integration
  • "How do I configure project roles and permissions?" — Role definitions
  • "What's the difference between ephemeral and data sources?" — Resource patterns

Quick routing

Key principles to uphold

  1. Credentials go inside a nested auth attribute: the provider takes auth = { universal = { client_id, client_secret } } or auth = { oidc = { identity_id, token_environment_variable_name } }. Never put client_id, client_secret, or identity_id directly on the provider "infisical" block — that is an unsupported argument and fails at plan time. (Legacy service_token is the one exception and does sit at the top level.)
  2. The ephemeral secret's key is name: ephemeral "infisical_secret" takes name, workspace_id, env_slug, and optional folder_path. There is no secret_key argument.
  3. Ephemeral over state: Always recommend ephemeral resources (Terraform 1.10+) for secrets—values never land in state files. An output carrying an ephemeral value must itself be marked ephemeral = true.
  4. Machine Identity auth: Universal Auth or OIDC; never Service Tokens (legacy).
  5. Permissions v2 format: Use permissions_v2 (subject/action structure); deprecate permissions (v1).
  6. OIDC for Terraform Cloud: This is the recommended production pattern.
  7. Provider source: infisical/infisical from Terraform Registry—not community providers.
  8. Folder path defaults: folder_path = "/" if omitted.
  9. Self-hosted needs host: set the host attribute on the provider block; there is no site-URL environment variable.

When to send users to references

  • Auth confusion or env var setup → provider-setup.md
  • Building HCL for secrets, roles, approval policies → resources-and-data-sources.md
  • TFC + Infisical step-by-step → terraform-cloud-oidc.md

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/infisical/ai-skills/infisical-terraform">View infisical-terraform on skillZs</a>