# Infrastructure As Code Architect

> Translates local database and cache requirements (e.g. docker-compose setup with Postgres, Redis, Elasticsearch) into production-ready Infrastructure as Code using Terraform, Pulumi, or Bicep for AWS, Azure, or GCP. Use when a user wants to deploy their application or data platform to the cloud.

- **Type:** Skill
- **Install:** `agentstack add skill-teckedd-code2save-ai-build-tools-infrastructure-as-code-architect`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [teckedd-code2save](https://agentstack.voostack.com/s/teckedd-code2save)
- **Installs:** 0
- **Category:** [Databases](https://agentstack.voostack.com/c/databases)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [teckedd-code2save](https://github.com/teckedd-code2save)
- **Source:** https://github.com/teckedd-code2save/ai-build-tools/tree/main/skills/infrastructure-as-code-architect
- **Website:** https://teckedd-code2save.github.io/ai-build-tools/

## Install

```sh
agentstack add skill-teckedd-code2save-ai-build-tools-infrastructure-as-code-architect
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Infrastructure as Code Architect

Translate local development setups (like a loaded `docker-compose.yml`) into enterprise-ready, production infrastructure deployments using Terraform, Pulumi, or Bicep.

## 🎯 When to Use
- After a data platform is generated using the `forge` skill.
- When the user asks "How do I deploy this?" or "Can you write the Terraform for this?"
- When migrating from a local Docker environment to managed cloud services (e.g., AWS RDS, Azure Cache for Redis).
- When standing up fresh environments (staging, production).

## 🛠️ Step-by-Step Workflow

### 1. Identify Existing Requirements
1. Scan the current project for `docker-compose.yml`, `.env.example`, and package files.
2. Identify the core components:
   - Database (PostgreSQL, MySQL, etc.)
   - Cache/Message Queue (Redis, RabbitMQ)
   - Search/Analytics (Elasticsearch, OpenSearch)
   - Application Runtimes (Node.js, Python FastAPI, .NET)

### 2. Determine the Target Cloud and Tool
Ask the user if they have a preference for:
- **Cloud Provider:** AWS, Azure, or GCP?
- **Tool:** Terraform, Pulumi, or Bicep (Azure only)?

If they don't have a preference, default to **Terraform** on **AWS**.

### 3. Generate Infrastructure Code
Create the necessary IaC files (Terraform, Pulumi, or Bicep). 

**Container Mandate:**
- **Docker**: Always generate a production-ready `Dockerfile` for each application component. Implement multi-stage builds for smaller images and security scan points.
- **Kubernetes (K8s)**: For production-grade platforms, map local `docker-compose` services to **K8s Manifests** or **Helm Charts**. 

| Local Component | Managed K8s Equivalent | AWS RDS/ElastiCache Equivalent |
| :--- | :--- | :--- |
| PostgreSQL | EKS / AKS / GKE (via StatefulSet) | Amazon RDS |
| Redis | EKS / AKS / GKE | Amazon ElastiCache |
| App Container | K8s Deployment + Service | App Runner / Container Apps |

### 4. Implement CI/CD (GitHub Actions Mandate)
**MANDATORY:** Provide a complete `.github/workflows/deploy.yml` file that:
1. **Builds and Pushes Docker Images**: Uses `docker/build-push-action` to push to ECR, ACR, or GCR.
2. **Scans for Vulnerabilities**: Integrates Snyk or Trivy scans within the pipeline.
3. **Applies Infrastructure**: Automatically runs IaC plan/apply from the pipeline.
4. **Deploys to K8s**: Updates K8s deployments with the new image tag.

### 5. Infrastructure Best Practices
- **Security**: Private subnets only. No public IPs for DBs/Caches. Use Managed Identities/IAM Roles.
- **State Management**: Use remote backends (S3/Blob/GCS) with locking.
- **Observability**: Include basic monitoring/logging resources (CloudWatch, Azure Monitor).

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [teckedd-code2save](https://github.com/teckedd-code2save)
- **Source:** [teckedd-code2save/ai-build-tools](https://github.com/teckedd-code2save/ai-build-tools)
- **License:** MIT
- **Homepage:** https://teckedd-code2save.github.io/ai-build-tools/

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** yes
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-teckedd-code2save-ai-build-tools-infrastructure-as-code-architect
- Seller: https://agentstack.voostack.com/s/teckedd-code2save
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
