StarCURSOR RULES
DevOps & Tooling
Cursor Rules (.mdc) Hub Directory

Terraform & OpenTofu Cursor Rules (.mdc) | Cloud Infrastructure as Code

Production-grade architectural rulebook for Terraform & OpenTofu IaC. Engineered to eliminate LLM hallucinations, enforce strict deterministic conventions, and prevent architectural drift across Cursor IDE, Claude Code CLI, and autonomous multi-agent pipelines.

Target Path
.cursor/rules/terraform.mdc
Execution Scope
Glob Pattern Auto-Match
Specification Format
Frontmatter MDC (.mdc)
AI Tool Support
Cursor IDE & Composer
02 / DRIFT ANALYSIS & VALUE PROPOSITION

Failure Patterns Prevented for Terraform & OpenTofu IaC

Without This Rule (Default LLM Behavior)Vulnerable

Cloud infrastructure provisioning through AI often leads to catastrophic resource destruction, unpinned provider versions, missing remote state locks, and hardcoded plaintext credentials.

Hallucination Symptoms
  • Invokes deprecated or removed APIs from older model training weights
  • Generates conflicting configuration files and invalid imports
  • Silently drops type-safety, boundaries, or transaction isolation
With This Rule (Guaranteed Invariants)Deterministic
Pin explicit version constraints for all providers and required Terraform/OpenTofu core versions (required_providers).
Store state securely in remote backends (S3 with DynamoDB state locking or GCS/Terraform Cloud); ban local terraform.tfstate.
Enforce mandatory resource tagging (Environment, Project, Owner, ManagedBy) on all provisioned cloud assets.
Never hardcode secrets, API keys, or master database passwords; inject via secure variables with sensitive = true or secret managers.
Declare explicit lifecycle { prevent_destroy = true } blocks on critical production databases and storage buckets.
03 / VERIFIED CODE PATTERNS

Code Standards: Anti-Pattern vs Verified Implementation

Discouraged Anti-Pattern
# Dangerous: Hardcoded secret, no version lock, unmanaged state
resource "aws_db_instance" "bad_db" {
  engine   = "postgres"
  password = "plaintextpassword123" # Leaked credentials in git!
}
Verified Production Standard
terraform {
  required_version = ">= 1.7.0"
  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 5.40"
    }
  }
  backend "s3" {
    bucket         = "corp-tf-state-prod"
    key            = "vpc/terraform.tfstate"
    region         = "us-east-1"
    dynamodb_table = "terraform-locks"
    encrypt        = true
  }
}

resource "aws_db_instance" "primary" {
  identifier          = "app-db-prod"
  allocated_storage   = 50
  engine              = "postgres"
  instance_class      = "db.r6g.large"
  password            = var.db_password
  skip_final_snapshot = false
  
  lifecycle {
    prevent_destroy = true
  }
}
04 / REPOSITORY PLACEMENT & 3-STEP TERMINAL INSTALLATION

How to Install Terraform & OpenTofu IaC Cursor Rules (.mdc) via Terminal

1

Step 1: Open Project Directory & Verify Target Placement

Open your terminal and navigate to your project root folder where the .cursor/rules/terraform.mdc file will reside. Ensure the file is placed at the exact path below relative to your project root so the AI engine automatically loads it:

.cursor/rules/terraform.mdc
2

Step 2: Fetch Rule File via Terminal Command

Run curl, PowerShell, or wget to stream the rule directly from the DevScratchpad raw API endpoint and write it to .cursor/rules/terraform.mdc:

Terminal One-Liner Install

Run directly in your project root to stream and write this rule file with one command.

Raw API Stream
$mkdir -p ".cursor/rules" && curl -fsSL "https://www.devscratchpad.tech/api/raw/cursor-rules/terraform-iac" -o ".cursor/rules/terraform.mdc"
3

Step 3: Verify and Activate with AI Agent

Launch your AI coding assistant (Cursor IDE & Composer). The assistant will automatically discover .cursor/rules/terraform.mdc in your repository and apply the architectural guardrails, type constraints, and verification protocols during code generation.

05 / ROUTE DIRECTORY & CROSS-TOOLING
Format Pillar HubComprehensive Manual

Cursor Rules (.mdc) Directory & Generator

Inspect the complete specification manual, glob patterns, directory rules, and all available presets in our central directory.

/cursor-rules Directory
06 / FREQUENTLY ASKED QUESTIONS

Technical FAQ: Terraform & OpenTofu IaC AI Rulebooks

Does this rulebook support OpenTofu?

Yes, OpenTofu is fully compatible with standard Terraform HCL and shares identical provider pinning standards.

How does it handle secret management?

It mandates that all secret variables declare sensitive = true and prohibits hardcoded tokens in .tf source files.