Install
$ agentstack add skill-teckedd-code2save-ai-build-tools-infrastructure-as-code-architect ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Infrastructure as Code Architect
Translate local development setups (like a loaded docker-compose.yml) into enterprise-ready, production infrastructure deployments using Terraform, Pulumi, or Bicep.
🎯 When to Use
- After a data platform is generated using the
forgeskill. - When the user asks "How do I deploy this?" or "Can you write the Terraform for this?"
- When migrating from a local Docker environment to managed cloud services (e.g., AWS RDS, Azure Cache for Redis).
- When standing up fresh environments (staging, production).
🛠️ Step-by-Step Workflow
1. Identify Existing Requirements
- Scan the current project for
docker-compose.yml,.env.example, and package files. - Identify the core components:
- Database (PostgreSQL, MySQL, etc.)
- Cache/Message Queue (Redis, RabbitMQ)
- Search/Analytics (Elasticsearch, OpenSearch)
- Application Runtimes (Node.js, Python FastAPI, .NET)
2. Determine the Target Cloud and Tool
Ask the user if they have a preference for:
- Cloud Provider: AWS, Azure, or GCP?
- Tool: Terraform, Pulumi, or Bicep (Azure only)?
If they don't have a preference, default to Terraform on AWS.
3. Generate Infrastructure Code
Create the necessary IaC files (Terraform, Pulumi, or Bicep).
Container Mandate:
- Docker: Always generate a production-ready
Dockerfilefor each application component. Implement multi-stage builds for smaller images and security scan points. - Kubernetes (K8s): For production-grade platforms, map local
docker-composeservices to K8s Manifests or Helm Charts.
| Local Component | Managed K8s Equivalent | AWS RDS/ElastiCache Equivalent | | :--- | :--- | :--- | | PostgreSQL | EKS / AKS / GKE (via StatefulSet) | Amazon RDS | | Redis | EKS / AKS / GKE | Amazon ElastiCache | | App Container | K8s Deployment + Service | App Runner / Container Apps |
4. Implement CI/CD (GitHub Actions Mandate)
MANDATORY: Provide a complete .github/workflows/deploy.yml file that:
- Builds and Pushes Docker Images: Uses
docker/build-push-actionto push to ECR, ACR, or GCR. - Scans for Vulnerabilities: Integrates Snyk or Trivy scans within the pipeline.
- Applies Infrastructure: Automatically runs IaC plan/apply from the pipeline.
- Deploys to K8s: Updates K8s deployments with the new image tag.
5. Infrastructure Best Practices
- Security: Private subnets only. No public IPs for DBs/Caches. Use Managed Identities/IAM Roles.
- State Management: Use remote backends (S3/Blob/GCS) with locking.
- Observability: Include basic monitoring/logging resources (CloudWatch, Azure Monitor).
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: teckedd-code2save
- Source: teckedd-code2save/ai-build-tools
- License: MIT
- Homepage: https://teckedd-code2save.github.io/ai-build-tools/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.