Skip to main content

terraform-azure

Provision Azure infrastructure with Terraform. Configure providers, manage state, and deploy resources. Use when implementing IaC for Azure.

跳到安装

来源信息

仓库
sickn33/agentic-awesome-skills
最近来源活动
2026年9月21日 13:45
检测到的 SKILL.md 语言
英语
星标
46,724
分支
6,804

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。

文件资源管理器
2 个文件

正在显示 SKILL.md

SKILL.md
来源说明 · 只读预览
name
terraform-azure
description
Provision Azure infrastructure with Terraform. Configure providers, manage state, and deploy resources. Use when implementing IaC for Azure.
category
devops
risk
critical
source
https://github.com/BagelHole/DevOps-Security-Agent-Skills
source_repo
BagelHole/DevOps-Security-Agent-Skills
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/BagelHole/DevOps-Security-Agent-Skills/blob/main/LICENSE
compatibility
Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.
metadata
{"author":"devops-skills","version":"1.0"}
# Terraform Azure Provision and manage Azure infrastructure with Terraform using the AzureRM provider. Covers provider configuration, remote state, resource groups, VNets, AKS, Key Vault, complete .tf file examples, and production workflows. ## Prerequisites ```bash # Install Terraform wget -O- https://apt.releases.hashicorp.com/gpg | sudo gpg --dearmor -o /usr/share/keyrings/hashicorp-archive-keyring.gpg echo "deb [signed-by=/usr/share/keyrings/hashicorp-archive-keyring.gpg] https://apt.releases.hashicorp.com $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/hashicorp.list sudo apt update && sudo apt install terraform # Verify installation terraform version # Install Azure CLI and login curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash az login az account set --subscription "my-subscription-id" # Create storage account for remote state az group create --name tfstate-rg --location eastus az storage account create \ --name tfstate$(openssl rand -hex 4) \ --resource-group tfstate-rg \ --sku Standard_LRS \ --encryption-services blob az storage container create \ --name tfstate \ --account-name tfstateXXXXXXXX ``` ## Provider Configuration ### providers.tf ```hcl terraform { required_version = ">= 1.5.0" required_providers { azurerm = { source = "hashicorp/azurerm" version = "~> 3.80" } azuread = { source = "hashicorp/azuread" version = "~> 2.47" } random = { source = "hashicorp/random" version = "~> 3.6" } } backend "azurerm" { resource_group_name = "tfstate-rg" storage_account_name = "tfstate12345abc" container_name = "tfstate" key = "prod.terraform.tfstate" } } provider "azurerm" { features { key_vault { purge_soft_delete_on_destroy = false recover_soft_deleted_key_vaults = true } resource_group { prevent_deletion_if_contains_resources = true } } # Optional: use a specific subscription # subscription_id = var.subscription_id } provider "azuread" {} ``` ### variables.tf ```hcl variable "environment" { description = "Environment name (dev, staging, prod)" type = string validation { condition = contains(["dev", "staging", "prod"], var.environment) error_message = "Environment must be dev, staging, or prod." } } variable "location" { description = "Azure region for all resources" type = string default = "eastus" } variable "project_name" { description = "Project name used in resource naming" type = string default = "myapp" } variable "tags" { description = "Tags applied to all resources" type = map(string) default = {} } variable "sql_admin_password" { description = "SQL Server admin password" type = string sensitive = true } variable "aks_admin_group_id" { description = "Azure AD group ID for AKS admin access" type = string } locals { name_prefix = "${var.project_name}-${var.environment}" common_tags = merge(var.tags, { environment = var.environment project = var.project_name managed_by = "terraform" }) } ``` ### terraform.tfvars (per environment) ```hcl # terraform.prod.tfvars environment = "prod" location = "eastus" project_name = "myapp" aks_admin_group_id = "xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx" tags = { cost_center = "engineering" owner = "platform-team" } ``` ## Resource Group ### resource-group.tf ```hcl resource "azurerm_resource_group" "main" { name = "${local.name_prefix}-rg" location = var.location tags = local.common_tags } ``` ## Virtual Network ### network.tf ```hcl resource "azurerm_virtual_network" "main" { name = "${local.name_prefix}-vnet" location = azurerm_resource_group.main.location resource_group_name = azurerm_resource_group.main.name address_space = ["10.0.0.0/16"] tags = local.common_tags } resource "azurerm_subnet" "aks" { name = "aks-subnet" resource_group_name = azurerm_resource_group.main.name virtual_network_name = azurerm_virtual_network.main.name address_prefixes = ["10.0.1.0/22"] } resource "azurerm_subnet" "app" { name = "app-subnet" resource_group_name = azurerm_resource_group.main.name virtual_network_name = azurerm_virtual_network.main.name address_prefixes = ["10.0.8.0/24"] } resource "azurerm_subnet" "data" { name = "data-subnet" resource_group_name = azurerm_resource_group.main.name virtual_network_name = azurerm_virtual_network.main.name address_prefixes = ["10.0.9.0/24"] private_endpoint_network_policies_enabled = true } resource "azurerm_network_security_group" "app" { name = "${local.name_prefix}-app-nsg" location = azurerm_resource_group.main.location resource_group_name = azurerm_resource_group.main.name security_rule { name = "AllowHTTPS" priority = 100 direction = "Inbound" access = "Allow" protocol = "Tcp" source_port_range = "*" destination_port_range = "443" source_address_prefix = "*" destination_address_prefix = "*" } tags = local.common_tags } resource "azurerm_subnet_network_security_group_association" "app" { subnet_id = azurerm_subnet.app.id network_security_group_id = azurerm_network_security_group.app.id } ``` ## AKS Cluster ### aks.tf ```hcl resource "azurerm_log_analytics_workspace" "aks" { name = "${local.name_prefix}-law" location = azurerm_resource_group.main.location resource_group_name = azurerm_resource_group.main.name sku = "PerGB2018" retention_in_days = 30 tags = local.common_tags } resource "azurerm_kubernetes_cluster" "main" { name = "${local.name_prefix}-aks" location = azurerm_resource_group.main.location resource_group_name = azurerm_resource_group.main.name dns_prefix = "${var.project_name}-${var.environment}" kubernetes_version = "1.28" default_node_pool { name = "system" vm_size = "Standard_D4s_v5" enable_auto_scaling = true min_count = 2 max_count = 5 zones = [1, 2, 3] vnet_subnet_id = azurerm_subnet.aks.id os_disk_size_gb = 128 os_disk_type = "Managed" max_pods = 50 node_labels = { role = "system" } } identity { type = "SystemAssigned" } network_profile { network_plugin = "azure" network_policy = "calico" service_cidr = "10.1.0.0/16" dns_service_ip = "10.1.0.10" load_balancer_sku = "standard" } azure_active_directory_role_based_access_control { managed = true azure_rbac_enabled = true admin_group_object_ids = [var.aks_admin_group_id] } oms_agent { log_analytics_workspace_id = azurerm_log_analytics_workspace.aks.id } key_vault_secrets_provider { secret_rotation_enabled = true secret_rotation_interval = "2m" } tags = local.common_tags } resource "azurerm_kubernetes_cluster_node_pool" "app" { name = "app" kubernetes_cluster_id = azurerm_kubernetes_cluster.main.id vm_size = "Standard_D8s_v5" enable_auto_scaling = true min_count = 2 max_count = 20 zones = [1, 2, 3] vnet_subnet_id = azurerm_subnet.aks.id max_pods = 50 node_labels = { workload = "app" } node_taints = [ "dedicated=app:NoSchedule" ] tags = local.common_tags } ``` ## Key Vault ### keyvault.tf ```hcl data "azurerm_client_config" "current" {} resource "azurerm_key_vault" "main" { name = "${var.project_name}-${var.environment}-kv" location = azurerm_resource_group.main.location resource_group_name = azurerm_resource_group.main.name tenant_id = data.azurerm_client_config.current.tenant_id sku_name = "standard" soft_delete_retention_days = 90 purge_protection_enabled = true enabled_for_disk_encryption = true network_acls { default_action = "Deny" bypass = "AzureServices" ip_rules = var.allowed_ip_ranges virtual_network_subnet_ids = [ azurerm_subnet.app.id, azurerm_subnet.aks.id, ] } tags = local.common_tags } resource "azurerm_key_vault_access_policy" "terraform" { key_vault_id = azurerm_key_vault.main.id tenant_id = data.azurerm_client_config.current.tenant_id object_id = data.azurerm_client_config.current.object_id secret_permissions = [ "Get", "List", "Set", "Delete", "Purge", "Recover" ] key_permissions = [ "Get", "List", "Create", "Delete", "Purge", "Recover", "WrapKey", "UnwrapKey" ] } resource "azurerm_key_vault_access_policy" "aks" { key_vault_id = azurerm_key_vault.main.id tenant_id = data.azurerm_client_config.current.tenant_id object_id = azurerm_kubernetes_cluster.main.key_vault_secrets_provider[0].secret_identity[0].object_id secret_permissions = ["Get", "List"] } resource "azurerm_key_vault_secret" "sql_password" { name = "sql-admin-password" value = var.sql_admin_password key_vault_id = azurerm_key_vault.main.id depends_on = [azurerm_key_vault_access_policy.terraform] } ``` ## Contents - [SQL Database](references/details.md) - [Outputs](references/details.md) - [Terraform Workflow Commands](references/details.md) - [Module Structure](references/details.md) - [Troubleshooting](references/details.md) - [Related Skills](references/details.md) ## When to Use - You need multi-cloud or cloud-agnostic Infrastructure as Code. - Your team standardizes on Terraform across AWS, Azure, and GCP. - You need plan/apply workflows with change preview before deployment. - You want modular, reusable infrastructure components. - You need state locking and drift detection for production infrastructure. ## Limitations - Infrastructure commands can disrupt services: confirm target host/scope and have backups/snapshots before mutating state. - Docs-only import: upstream scripts and templates not bundled.
在 GitHub 查看