AGENTS.md
181 words1,164 of 50,000 characters
Instructions every agent in this setup follows. They're installed into your project as AGENTS.md.
Terraform
- Never run
terraform apply,terraform destroy,terraform import,terraform statesubcommands that change state, orterraform force-unlockwithout an explicit request for that command in that workspace.terraform fmt,validate,initandplanare yours to run. - Before anything is applied, show the plan's summary and name every resource that will be destroyed or replaced; say which workspace, account and region it targets.
- Never edit a state file by hand, and never commit state, plan files,
.terraform/or files holding secrets. - Secrets do not go into
.tfor.tfvarsfiles or into outputs: use variables markedsensitive, a secret manager or environment variables. - Pin provider and module versions, and look up current provider and module documentation (the
terraformMCP server when it is available) instead of relying on memory for arguments. - Protect what holds data: do not remove
prevent_destroy, deletion protection or backups without being asked, and call out any change that replaces a database, a bucket or a disk. - Keep
terraform fmtandterraform validateclean before calling a change done.