AI RULEBOOKTerraform & OpenTofu IaC GitHub Copilot Instructions
Production-grade architectural rulebook for Terraform & OpenTofu IaC. Engineered to eliminate LLM hallucinations, enforce strict deterministic conventions, and prevent architectural drift across Cursor IDE, Claude Code CLI, and autonomous multi-agent pipelines.
.github/copilot-instructions.mdFailure Patterns Prevented for Terraform & OpenTofu IaC
Cloud infrastructure provisioning through AI often leads to catastrophic resource destruction, unpinned provider versions, missing remote state locks, and hardcoded plaintext credentials.
- Invokes deprecated or removed APIs from older model training weights
- Generates conflicting configuration files and invalid imports
- Silently drops type-safety, boundaries, or transaction isolation
Code Standards: Anti-Pattern vs Verified Implementation
# Dangerous: Hardcoded secret, no version lock, unmanaged state
resource "aws_db_instance" "bad_db" {
engine = "postgres"
password = "plaintextpassword123" # Leaked credentials in git!
}terraform {
required_version = ">= 1.7.0"
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 5.40"
}
}
backend "s3" {
bucket = "corp-tf-state-prod"
key = "vpc/terraform.tfstate"
region = "us-east-1"
dynamodb_table = "terraform-locks"
encrypt = true
}
}
resource "aws_db_instance" "primary" {
identifier = "app-db-prod"
allocated_storage = 50
engine = "postgres"
instance_class = "db.r6g.large"
password = var.db_password
skip_final_snapshot = false
lifecycle {
prevent_destroy = true
}
}How to Install Terraform & OpenTofu IaC GitHub Copilot Instructions via Terminal
Step 1: Open Project Directory & Verify Target Placement
Open your terminal and navigate to your project root folder where the .github/copilot-instructions.md file will reside. Ensure the file is placed at the exact path below relative to your project root so the AI engine automatically loads it:
Step 2: Fetch Rule File via Terminal Command
Run curl, PowerShell, or wget to stream the rule directly from the DevScratchpad raw API endpoint and write it to .github/copilot-instructions.md:
Terminal One-Liner Install
Run directly in your project root to stream and write this rule file with one command.
mkdir -p ".github" && curl -fsSL "https://www.devscratchpad.tech/api/raw/copilot-instructions/terraform-iac" -o ".github/copilot-instructions.md"Step 3: Verify and Activate with AI Agent
Launch your AI coding assistant (Universal AI Assistants). The assistant will automatically discover .github/copilot-instructions.md in your repository and apply the architectural guardrails, type constraints, and verification protocols during code generation.
GitHub Copilot Instructions Generator
Inspect the complete specification manual, glob patterns, directory rules, and all available presets in our central directory.
Pair With Terraform & OpenTofu IaC Client-Side Utilities
100% private, browser-based utilities to test, format, and inspect code generated by your AI rules.
YAML to JSON / JSON to YAML Converter
Bidirectional YAML and JSON conversion with syntax validation.
Cron Expression Visualizer
Translates complex cron schedules into plain English with a 5-column breakdown grid.
CIDR Calculator & Subnet Inspector
Calculate IPv4 and IPv6 subnet masks, broadcast addresses, and usable ranges.
Base64 / Hex / Binary Multi-Inspector & Image Previewer
Auto-detects and converts between Base64, URL-Safe Base64, Hexadecimal streams, Canonical Hex Dumps, Binary octets, and Data URL images.
Migrating from Legacy .cursorrules or CLAUDE.md?
Use our free, offline converter to transform monolithic rulebooks into modular Cursor .mdc, Claude SKILL.md, and Windsurf Cascade rules.
Technical FAQ: Terraform & OpenTofu IaC AI Rulebooks
Does this rulebook support OpenTofu?
Yes, OpenTofu is fully compatible with standard Terraform HCL and shares identical provider pinning standards.
How does it handle secret management?
It mandates that all secret variables declare sensitive = true and prohibits hardcoded tokens in .tf source files.