> **terraform-policy** — skill 16 of 20 in [hashicorp/agent-skills](https://skillsdocs.com/hashicorp/agent-skills).
>
> Book (all skills, one file): https://skillsdocs.com/hashicorp/agent-skills.md
> Machine manifest: https://skillsdocs.com/hashicorp/agent-skills/.well-known/agent-skills/index.json
> Install the book: `npx skills add hashicorp/agent-skills`
> Upstream: https://github.com/hashicorp/agent-skills/blob/main/plugins/terraform/skills/terraform-policy/SKILL.md @ `main`
> Raw bytes, no header: https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/SKILL.md
> Base for relative paths: https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/
> Licence: MPL-2.0 — https://spdx.org/licenses/MPL-2.0.html
>
> Bundled files (54), referenced from this skill's directory:
>   - `.gitignore` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/.gitignore
>   - `examples/conversion/cloudfront-associated-with-waf/cloudfront-associated-with-waf.policy.hcl` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/cloudfront-associated-with-waf/cloudfront-associated-with-waf.policy.hcl
>   - `examples/conversion/cloudfront-associated-with-waf/cloudfront-associated-with-waf.sentinel` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/cloudfront-associated-with-waf/cloudfront-associated-with-waf.sentinel
>   - `examples/conversion/cloudfront-associated-with-waf/README.md` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/cloudfront-associated-with-waf/README.md
>   - `examples/conversion/cloudtrail-server-side-encryption-enabled/cloudtrail-server-side-encryption-enabled.policy.hcl` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/cloudtrail-server-side-encryption-enabled/cloudtrail-server-side-encryption-enabled.policy.hcl
>   - `examples/conversion/cloudtrail-server-side-encryption-enabled/cloudtrail-server-side-encryption-enabled.sentinel` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/cloudtrail-server-side-encryption-enabled/cloudtrail-server-side-encryption-enabled.sentinel
>   - `examples/conversion/cloudtrail-server-side-encryption-enabled/README.md` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/cloudtrail-server-side-encryption-enabled/README.md
>   - `examples/conversion/dms-endpoint-should-be-ssl-configured/dms-endpoint-should-be-ssl-configured.policy.hcl` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/dms-endpoint-should-be-ssl-configured/dms-endpoint-should-be-ssl-configured.policy.hcl
>   - `examples/conversion/dms-endpoint-should-be-ssl-configured/dms-endpoint-should-be-ssl-configured.sentinel` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/dms-endpoint-should-be-ssl-configured/dms-endpoint-should-be-ssl-configured.sentinel
>   - `examples/conversion/dms-endpoint-should-be-ssl-configured/README.md` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/dms-endpoint-should-be-ssl-configured/README.md
>   - `examples/conversion/dms-endpoints-should-use-ssl/dms-endpoints-should-use-ssl.policy.hcl` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/dms-endpoints-should-use-ssl/dms-endpoints-should-use-ssl.policy.hcl
>   - `examples/conversion/dms-endpoints-should-use-ssl/dms-endpoints-should-use-ssl.sentinel` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/dms-endpoints-should-use-ssl/dms-endpoints-should-use-ssl.sentinel
>   - `examples/conversion/dms-endpoints-should-use-ssl/README.md` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/dms-endpoints-should-use-ssl/README.md
>   - `examples/conversion/ec2-network-acl-should-have-subnet-ids/ec2-network-acl-should-have-subnet-ids.policy.hcl` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/ec2-network-acl-should-have-subnet-ids/ec2-network-acl-should-have-subnet-ids.policy.hcl
>   - `examples/conversion/ec2-network-acl-should-have-subnet-ids/ec2-network-acl-should-have-subnet-ids.sentinel` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/ec2-network-acl-should-have-subnet-ids/ec2-network-acl-should-have-subnet-ids.sentinel
>   - `examples/conversion/ec2-network-acl-should-have-subnet-ids/README.md` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/ec2-network-acl-should-have-subnet-ids/README.md
>   - `examples/conversion/ec2-vpc-default-security-group-no-traffic/ec2-vpc-default-security-group-no-traffic.policy.hcl` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/ec2-vpc-default-security-group-no-traffic/ec2-vpc-default-security-group-no-traffic.policy.hcl
>   - `examples/conversion/ec2-vpc-default-security-group-no-traffic/ec2-vpc-default-security-group-no-traffic.sentinel` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/ec2-vpc-default-security-group-no-traffic/ec2-vpc-default-security-group-no-traffic.sentinel
>   - `examples/conversion/ec2-vpc-default-security-group-no-traffic/README.md` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/ec2-vpc-default-security-group-no-traffic/README.md
>   - `examples/conversion/efs-access-point-should-enforce-user-identity/efs-access-point-should-enforce-user-identity.policy.hcl` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/efs-access-point-should-enforce-user-identity/efs-access-point-should-enforce-user-identity.policy.hcl
>   - `examples/conversion/efs-access-point-should-enforce-user-identity/efs-access-point-should-enforce-user-identity.sentinel` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/efs-access-point-should-enforce-user-identity/efs-access-point-should-enforce-user-identity.sentinel
>   - `examples/conversion/efs-access-point-should-enforce-user-identity/README.md` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/efs-access-point-should-enforce-user-identity/README.md
>   - `examples/conversion/elasticache-redis-replication-group-encryption-at-transit-enabled/elasticache-redis-replication-group-encryption-at-transit-enabled.policy.hcl` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/elasticache-redis-replication-group-encryption-at-transit-enabled/elasticache-redis-replication-group-encryption-at-transit-enabled.policy.hcl
>   - `examples/conversion/elasticache-redis-replication-group-encryption-at-transit-enabled/elasticache-redis-replication-group-encryption-at-transit-enabled.sentinel` — https://raw.githubusercontent.com/hashicorp/agent-skills/main/plugins/terraform/skills/terraform-policy/examples/conversion/elasticache-redis-replication-group-encryption-at-transit-enabled/elasticache-redis-replication-group-encryption-at-transit-enabled.sentinel
>   - …and 30 more, listed in https://skillsdocs.com/api/v1/books/hashicorp/agent-skills/skills/terraform-policy
>
> Content © its authors, served unmodified. Takedown: https://github.com/DreambaseAI/skillsdocs/issues/new?labels=takedown&title=Takedown+request

<!-- Verbatim upstream SKILL.md follows, YAML frontmatter included. -->

---
name: terraform-policy
description: "Write, test, or convert Terraform Policy files (.policy.hcl, .policytest.hcl, Sentinel→tfpolicy). Triggers: policy.hcl, policytest, convert sentinel, tfpolicy, write a policy."
license: MPL-2.0
metadata:
  lifecycle-status: active
  copyright: Copyright IBM Corp. 2026
  version: "0.1.0"
---

# terraform-policy

**UTILITY SKILL** — INVOKES: [tfpolicy-author](references/tfpolicy-author.md) | [tfpolicy-test](references/tfpolicy-test.md)

## USE FOR:

- Writing a new `.policy.hcl` policy from a description or requirement
- Converting a `.sentinel` policy to Terraform Policy
- Writing or debugging a `.policytest.hcl` test file
- Migrating a Sentinel policy library to Terraform Policy

Before giving authoring or testing instructions, check the installed `tfpolicy` CLI version and tailor guidance accordingly:
- If the CLI is `0.1.x`, do **not** require `policy { required_providers { ... } }`; generate policies compatible with tfpolicy 0.1.x syntax and behavior.
- If the CLI is `0.2.0` or newer, include a top-level `policy { required_providers { ... } }` block when authoring `.policy.hcl`. It is mandatory for `tfpolicy validate`; version-range validation is best effort, and wildcard targets such as `resource_policy "*"` are not schema-validated.
- If the CLI version is unknown, ask the user to check it first or provide guidance that clearly distinguishes the `0.1.x` and `0.2.0+` paths.

## DO NOT USE FOR:

- Writing `.tftest.hcl` files for Terraform modules — use `terraform-test`
- General Terraform HCL authoring — use `terraform-style-guide`

## Routing

| Task | Sub-skill |
|------|-----------|
| Write or convert a `.policy.hcl` policy | [tfpolicy-author](references/tfpolicy-author.md) |
| Write or debug a `.policytest.hcl` test | [tfpolicy-test](references/tfpolicy-test.md) |

## Examples

- "Block EC2 instances without encryption" → [tfpolicy-author](references/tfpolicy-author.md)
- "Convert this Sentinel policy to tfpolicy" → [tfpolicy-author](references/tfpolicy-author.md)
- "Write a policytest for my EBS policy" → [tfpolicy-test](references/tfpolicy-test.md)

## Troubleshooting

- **Wrong skill triggered?** Load the sub-skill directly from the routing table above.

```bash
npx skills add hashicorp/agent-skills/terraform/terraform-policy/skills/tfpolicy-author
npx skills add hashicorp/agent-skills/terraform/terraform-policy/skills/tfpolicy-test
```
