Creator · hashicorp
Last updated · Sep 2, 2026
Comprehensive guide for writing and running Terraform tests. Use when creating test files (.tftest.hcl), writing test scenarios with run blocks, validating infrastructure behavior with assertions, mocking providers and data sources, testing module outputs and resource configurati
Sandbox only
Install targets
Codex install prompt
Install the "terraform-test" agent skill from https://github.com/hashicorp/agent-skills/tree/main/plugins/terraform/skills/terraform-test. Read its SKILL.md or equivalent instructions first, install only the files needed for this workspace, and summarize any required setup before using it. Skill purpose: Comprehensive guide for writing and running Terraform tests. Use when creating test files (.tftest.hcl), writing test scenarios with run blocks, validating infrastructure behavior with assertions, mocking providers and data sources, testing module outputs and resource configurations, or troubleshooting Terraform test syntax and execution. After the install attempt, report the result to https://www.openagentskill.com/api/agent/outcome with POST JSON {"event_id":"install_<unique-id>","skill_slug":"hashicorp-terraform-test","task":"Install terraform-test","agent":"codex","outcome":"success","install_used":true}. Replace event_id with a unique value and outcome with success or failed. Report success only after the skill is installed and a minimal verification passes.Supply asset profile
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Scenario
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Agent fit
Claude Code + CLI + Codex
Codex, Claude Code, Cursor, CLI, or custom agents.
Install
Ready
npx skills add hashicorp/agent-skills --skill terraform-test
Maintenance
fresh
6d since push
Risk
Needs review
Permission surface may require sandboxing
GitHub quality
858
76/100 Quality · 79/100 Trust
Coverage tags
Review notes
Permission surface may require sandboxing · Financial research output is not financial advice; require human review before any live investment decision
Agent adoption scorecard
These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.
Quality
StrongSolid option that is likely worth shortlisting for production workflows.
Trust
Sandbox onlyUseful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
Audit
Needs reviewA machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
OpenAgentSkill Trust Score v5
Run only in a sandbox and compare close alternatives before using it for real work.
Stars
858 GitHub stars
Repo activity
858 stars, 125 forks
Maintenance
6d since push
License
MPL-2.0
Install
npx skills add hashicorp/agent-skills --skill terraform-test
Install safety
Agent-readable metadata
Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.
Suited tasks
Suited agents
Install decision
Trust and risk
Outcome loop
Install command
npx skills add hashicorp/agent-skills --skill terraform-testDo not use when
Alternative
1.9K Stars
npx skills add yanliudesign/mono-color-skill --skill mono-color
Alternative
61.0K Stars
npx skills add mvanhorn/last30days-skill -g
Alternative
38.4K Stars
npx skills add Imbad0202/academic-research-skills
Alternative
256.3K Stars
npx skills add mattpocock/skills --skill grill-me
Agent safety v2
Sparse or mixed signals. Useful for discovery, but not for autonomous installation.
Test manually in an isolated workspace and compare against safer alternatives.
high
Skill metadata references terminal, CLI, shell, subprocess, or command execution workflows.
medium
Skill likely fetches remote pages, APIs, repositories, or external services.
medium
Skill may read or write project files, documents, generated artifacts, or local workspace state.
Agent resolve plan
The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.
Open JSON
/api/agent/resolve?task=Use%20terraform-test%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Resolve text
/api/agent/resolve?task=Use%20terraform-test%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Install handoff
/api/skills/hashicorp-terraform-test/install
Agent should check
Copy prompt
Task: Use terraform-test in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20terraform-test%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/hashicorp-terraform-test/install
Install command: npx skills add hashicorp/agent-skills --skill terraform-test
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Agent handoff
Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.
Install handoff
/api/skills/hashicorp-terraform-test/install
LLM text format
/api/skills/hashicorp-terraform-test/install?format=text
Find alternatives
/api/skills/search?q=terraform-test&limit=3
Agent prompt
Use terraform-test for this task. Review https://www.openagentskill.com/api/skills/hashicorp-terraform-test/install, then install with: npx skills add hashicorp/agent-skills --skill terraform-testRegistry metadata
This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.
Manifest
/api/registry/manifest/hashicorp-terraform-test
LLM text
/api/registry/manifest/hashicorp-terraform-test?format=text
Install alias
/api/registry/install/hashicorp-terraform-test
Recommend
/api/registry/recommend?task=Use%20terraform-test%20in%20an%20agent%20workflow&limit=3
Agent fit
Coding agents
Use-case tags
Platforms
Claude Code
Audit report
A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.
Agent decision cockpit
Use this as a leading candidate, then validate the README and install path in your own agent stack.
Role in stack
Primary pick
Primary fit
Coding agents
Trust label
Production-ready
Install path
Command ready
Use when
Evidence
review first
Implementation path
Trust profile
Useful candidate with missing or mixed trust signals. Keep it in an isolated workspace until the outcome loop proves task fit.
GitHub adoption
INFO858 GitHub stars
Stars/forks activity
INFO858 stars, 125 forks; issue activity unavailable in current metadata
Recent maintenance
PASS6d since push
License clarity
PASSMPL-2.0
Good signals
Review before install
Recommended action
Run only in a sandbox and compare close alternatives before using it for real work.
Quality profile
Solid option that is likely worth shortlisting for production workflows.
Workflow fit
Build and ship code
I need a coding agent that can understand a repository, edit code, and review pull requests.
Manage repositories
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Verify behavior
I need my agent to test a web app, reproduce bugs, and verify fixes.
Workflow fit
Inspect, patch, and verify code
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Ingest, retrieve, and cite
A workflow for document-heavy agents that ingest files, create searchable knowledge, retrieve relevant context, and answer with grounded sources.
Operate and verify web apps
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Alternative shortlist
Similar skills that may fit this task.
Generate original one-ink or controlled two-ink editorial images from any theme, sentence, article idea, object, or reference photo. Always use this skill when the user asks for 单色海报、双色印刷、单色调视觉、蓝色/绿色孔版印刷、risograph、网点照片、复古或当代编辑排版、zine poster, monochrome editorial poster, duotone print, or asks to use the mono-color style. It uses an adaptive white, gray, or pale-beige substrate, no more than two printing inks, active negative space, terse human language, and strong serif/grotesk/mono typography without making retro styling the default or copying a source composition, wording, logo, or artwork. Produce both the final generation prompt and the generated raster image unless the user explicitly asks for prompt only.
Research the last 30 days across Reddit, X, YouTube, Hacker News, Polymarket, GitHub, and the web, then synthesize a grounded brief for an AI agent.
Academic Research Skills for Claude Code: research → write → review → revise → finalize
A relentless interview to sharpen a plan or design.
--- name: terraform-test description: Comprehensive guide for writing and running Terraform tests. Use when creating test files (.tftest.hcl), writing test scenarios with run blocks, validating infrastructure behavior with assertions, mocking providers and data sources, testing module outputs and resource configurations, or troubleshooting Terraform test syntax and execution. metadata: lifecycle-status: active copyright: Copyright IBM Corp. 2026 version: "0.0.2" ---
# Terraform Test
Terraform's built-in testing framework validates that configuration updates don't introduce breaking changes. Tests run against temporary resources, protecting existing infrastructure and state files.
## Reference Files
- `references/MOCK_PROVIDERS.md` — Mock provider syntax, common defaults, when to use mocks (Terraform 1.7.0+ only — skip if the user's version is below 1.7) - `references/CI_CD.md` — GitHub Actions and GitLab CI pipeline examples - `references/EXAMPLES.md` — Complete example test suite (unit, integration, and mock tests for a VPC module)
Read the relevant reference file when the user asks about mocking, CI/CD integration, or wants a full example.
## Core Concepts
- **Test file** (`.tftest.hcl` / `.tftest.json`): Contains `run` blocks that validate your configuration - **Run block**: A single test scenario with optional variables, providers, and assertions - **Assert block**: Conditions that must be true for the test to pass - **Mock provider**: Simulates provider behavior without real infrastructure (Terraform 1.7.0+) - **Test modes**: `apply` (default, creates real resources) or `plan` (validates logic only)
## File Structure
``` my-module/ ├── main.tf ├── variables.tf ├── outputs.tf └── tests/ ├── defaults_unit_test.tftest.hcl # plan mode — fast, no resources ├── validation_unit_test.tftest.hcl # plan mode └── full_stack_integration_test.tftest.hcl # apply mode — creates real resources ```
Use `*_unit_test.tftest.hcl` for plan-mode tests and `*_integration_test.tftest.hcl` for apply-mode tests so they can be filtered separately in CI.
## Test File Structure
```hcl # Optional: test-wide settings test { parallel = true # Enable parallel execution for all run blocks (default: false) }
# Optional: file-level variables (highest precedence, override all other sources) variables { aws_region = "us-west-2" instance_type = "t2.micro" }
# Optional: provider configuration provider "aws" { region = var.aws_region }
# Required: at least one run block run "test_default_configuration" { command = plan
assert { condition = aws_instance.example.instance_type == "t2.micro" error_message = "Instance type should be t2.micro by default" } } ```
## Run Block
```hcl run "test_name" { command = plan # or apply (default) parallel = true # optional, since v1.9.0
# Override file-level variables variables { instance_type = "t3.large" }
# Reference a specific module module { source = "./modules/vpc" # local or registry only (not git/http) version = "5.0.0" # registry modules only }
# Control state isolation state_key = "shared_state" # since v1.9.0
# Plan behavior plan_options { mode = refresh-only # or normal (default) refresh = true replace = [aws_instance.example] target = [aws_instance.example] }
# Assertions assert { condition = aws_instance.example.id != "" error_message = "Instance should have a valid ID" }
# Expected failures (test passes if these fail) expect_failures = [ var.instance_count ] } ```
## Common Test Patterns
### Validate outputs
```hcl run "test_outputs" { command = plan
assert { condition = output.vpc_id != null error_message = "VPC ID output must be defined" }
assert { condition = can(regex("^vpc-", output.vpc_id)) error_message = "VPC ID should start with 'vpc-'" } } ```
### Conditional resources
```hcl run "test_nat_gateway_disabled" { command = plan
variables { create_nat_gateway = false }
assert { condition = length(aws_nat_gateway.main) == 0 error_message = "NAT gateway should not be created when disabled" } } ```
### Resource counts
```hcl run "test_resource_count" { command = plan
variables { instance_count = 3 }
assert { condition = length(aws_instance.workers) == 3 error_message = "Should create exactly 3 worker instances" } } ```
### Tags
```hcl run "test_resource_tags" { command = plan
variables { common_tags = { Environment = "production" ManagedBy = "Terraform" } }
assert { condition = aws_instance.example.tags["Environment"] == "production" error_message = "Environment tag should be set correctly" }
assert { condition = aws_instance.example.tags["ManagedBy"] == "Terraform" error_message = "ManagedBy tag should be set correctly" } } ```
### Data sources
```hcl run "test_data_source_lookup" { command = plan
assert { condition = data.aws_ami.ubuntu.id != "" error_message = "Should find a valid Ubuntu AMI" }
assert { condition = can(regex("^ami-", data.aws_ami.ubuntu.id)) error_message = "AMI ID should be in correct format" } } ```
### Validation rules
```hcl run "test_invalid_environment" { command = plan
variables { environment = "invalid" }
expect_failures = [ var.environment ] } ```
### Sequential tests with dependencies
```hcl run "setup_vpc" { command = apply
assert { condition = output.vpc_id != "" error_message = "VPC should be created" } }
run "test_subnet_in_vpc" { command = plan
variables { vpc_id = run.setup_vpc.vpc_id }
assert { condition = aws_subnet.example.vpc_id == run.setup_vpc.vpc_id error_message = "Subnet should be in the VPC from setup_vpc" } } ```
### Plan options (refresh-only, targeted)
```hcl run "test_refresh_only" { command = plan
plan_options { mode = refresh-only }
assert { condition = aws_instance.example.tags["Environment"] == "production" error_message = "Tags should be refreshed correctly" } }
run "test_specific_resource" { command = plan
plan_options { target = [aws_instance.example] }
assert { condition = aws_instance.example.instance_type == "t2.micro" error_message = "Targeted resource should be planned" } } ```
### Parallel modules
```hcl run "test_networking_module" { command = plan parallel = true
module { source = "./modules/networking" }
assert { condition = output.vpc_id != "" error_message = "VPC should be created" } }
run "test_compute_module" { command = plan parallel = true
module { source = "./modules/compute" }
assert { condition = output.instance_id != "" error_message = "Instance should be created" } } ```
### State key sharing
```hcl run "create_foundation" { command = apply state_key = "foundation"
assert { condition = aws_vpc.main.id != "" error_message = "Foundation VPC should be created" } }
run "create_application" { command = apply state_key = "foundation"
variables { vpc_id = run.create_foundation.vpc_id }
assert { condition = aws_instance.app.vpc_id == run.create_foundation.vpc_id error_message = "Application should use foundation VPC" } } ```
### Cleanup ordering (S3 objects before bucket)
```hcl run "create_bucket" { command = apply
assert { condition = aws_s3_bucket.example.id != "" error_message = "Bucket should be created" } }
run "add_objects" { command = apply
assert { condition = length(aws_s3_object.files) > 0 error_message = "Objects should be added" } }
# Cleanup destroys in reverse: objects first, then bucket ```
### Multiple aliased providers
```hcl provider "aws" { alias = "primary" region = "us-west-2" }
provider "aws" { alias = "secondary" region = "us-east-1" }
run "test_with_specific_provider" { command = plan
providers = { aws = provider.aws.secondary }
assert { condition = aws_instance.example.availability_zone == "us-east-1a" error_message = "Instance should be in us-east-1 region" } } ```
### Complex conditions
```hcl assert { condition = alltrue([ for subnet in aws_subnet.private : can(regex("^10\\.0\\.", subnet.cidr_block)) ]) error_message = "All private subnets should use 10.0.0.0/8 CIDR range" } ```
## Cleanup
Resources are destroyed in **reverse run block order** after test completion. This matters for dependencies (e.g., S3 objects before bucket). Use `terraform test -no-cleanup` to skip cleanup for debugging.
## Running Tests
```bash terraform test # all tests terraform test tests/defaults.tftest.hcl # specific file terraform test -filter=test_vpc_configuration # by run block name terraform test -test-directory=integration-tests # custom directory terraform test -verbose # detailed output terraform test -no-cleanup # skip resource cleanup ```
## Best Practices
1. **Naming**: `*_unit_test.tftest.hcl` for plan mode, `*_integration_test.tftest.hcl` for apply mode 2. **Test naming**: Use descriptive run block names that explain the scenario being tested 3. **Default to plan**: Use `command = plan` unless you need to test real resource behavior 4. **Use mocks** for external dependencies — faster and no credentials needed (see `references/MOCK_PROVIDERS.md`) 5. **Error messages**: Make them specific enough to diagnose failures without running the test again 6. **Negative tests**: Use `expect_failures` to verify validation rules reject bad inputs 7. **Variable coverage**: Test different variable combinations to validate all code paths — test variables have the highest precedence and override all other sources 8. **Module sources**: Test files only support local paths and registry modules — not git or HTTP URLs 9. **Parallel execution**: Use `parallel = true` for independent tests with different state files 10. **Cleanup**: Integration tests destroy resources in reverse run block order automatically; use `-no-cleanup` for debugging 11. **CI/CD**: Run unit tests on every PR, integration tests on merge (see `references/CI_CD.md`)
## Troubleshooting
| Issue | Solution | |-------|----------| | Assertion failures | Use `-verbose` to see actual vs expected values | | Missing credentials | Use mock providers for unit tests | | Unsupported module source | Convert git/HTTP sources to local modules | | Tests interfering | Use `state_key` or separate modules for isolation | | Slow tests | Use `command = plan` and mocks; run integration tests separately |
## References
- [Terraform Testing Documentation](https://developer.hashicorp.com/terraform/language/tests) - [Terraform Test Command](https://developer.hashicorp.com/terraform/cli/commands/test)
Source provenance
Decision snapshot
858 GitHub stars
Audit
Install and adoption review
Agent-proven evidence
Outcome reports after resolve, review, install, and one narrow run.
No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.
Install
Free and open source. Review the report before installing into production agents.
Growth loop
Scenario-led draft for terraform-test, ready for a manual X post.
A practical pick for source-backed research: terraform-test: Comprehensive guide for writing and running Terraform tests. Use when creating test files (.tftest.hcl), writing test scena... 858 stars https://www.openagentskill.com/skills/hashicorp-terraform-test?ref=x
Listing + install path for terraform-test: https://www.openagentskill.com/skills/hashicorp-terraform-test?ref=x Install: npx skills add hashicorp/agent-skills --skill terraform-test
Listing source
This listing was indexed from public sources and is not marked official until a maintainer claim is approved.
Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.
Claim this skillOwner claim
This Registry indexed listing is attributed to hashicorp but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.
Creator backlink kit
Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.
[](https://www.openagentskill.com/skills/hashicorp-terraform-test?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/hashicorp-terraform-test?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)
[](https://www.openagentskill.com/skills/hashicorp-terraform-test/audit)
[](https://www.openagentskill.com/skills/hashicorp-terraform-test?ref=github&utm_source=github&utm_medium=referral&utm_campaign=creator_badge)hashicorp
@hashicorp
Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.
Sandbox only
mono-color
Generate original one-ink or controlled two-ink editorial images from any theme, sentence, article idea, object, or reference photo. Always use this skill when the user asks for 单色海报、双色印刷、单色调视觉、蓝色/绿色孔版印刷、risograph、网点照片、复古或当代编辑排版、zine poster, monochrome editorial poster, duotone print, or asks to use the mono-color style. It uses an adaptive white, gray, or pale-beige substrate, no more than two printing inks, active negative space, terse human language, and strong serif/grotesk/mono typography without making retro styling the default or copying a source composition, wording, logo, or artwork. Produce both the final generation prompt and the generated raster image unless the user explicitly asks for prompt only.
1.9K StarsLast30days Skill
Research the last 30 days across Reddit, X, YouTube, Hacker News, Polymarket, GitHub, and the web, then synthesize a grounded brief for an AI agent.
61.0K StarsAcademic Research Skills
Academic Research Skills for Claude Code: research → write → review → revise → finalize
38.4K Starsgrill-me
A relentless interview to sharpen a plan or design.
256.3K StarsPermission surface
shell or command execution, filesystem or document access
Agent outcomes
No agent outcome data yet
Docs
Strong README/SKILL.md context
Risk summary
Install readiness