Agent instructions, skills, SSH host aliases and expansion triggers are worth having identical on every machine one person owns, and belong in none of the shared configuration. They live in user/ now, with a manifest saying where each piece goes and a link-user stage that puts it there. That stage does nothing unless the machine said yes. Somebody who clones Panama to try the desktop keeps their own ~/.claude/CLAUDE.md exactly where it was; the question names the destinations and defaults to no. Anything displaced goes to config/old rather than being deleted. ~/.claude/CLAUDE.md and ~/.codex/AGENTS.md were byte-identical copies of one file, which is the drift this exists to prevent. Also adds the vitals toggles for the battery and Claude usage readouts, which had preferences and no way to reach them.
2.3 KiB
2.3 KiB
name, description, triggers
| name | description | triggers | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|
| infisical-terraform | Expert guidance for the Infisical Terraform Provider. Covers HCL resource configuration, ephemeral secrets management, data source patterns, project role permissions, and OIDC authentication for Terraform Cloud. Use for secret injection via IaC, Machine Identity setup, access approval policies, and cloud-native integration patterns. |
|
Infisical Terraform Provider
Help users confidently integrate Infisical secret management with their Terraform infrastructure.
What users typically ask for
- "How do I use Infisical with Terraform?" — Provider setup and auth
- "How do I prevent secrets in my Terraform state?" — Ephemeral resources
- "How do I set up Terraform Cloud with Infisical?" — OIDC integration
- "How do I configure project roles and permissions?" — Role definitions
- "What's the difference between ephemeral and data sources?" — Resource patterns
Quick routing
- Provider authentication, configuration, env vars → Provider Setup
- HCL resources: infisical_secret, data sources, project roles, access approval → Resources & Data Sources
- Terraform Cloud OIDC integration, machine identity setup → Terraform Cloud OIDC
Key principles to uphold
- Ephemeral over state: Always recommend
ephemeralresources (Terraform 1.10+) for secrets—values never land in state files. - Machine Identity auth: Universal Auth or OIDC; never Service Tokens (deprecated).
- Permissions v2 format: Use
permissions_v2(subject/action structure); deprecatepermissions(v1). - OIDC for Terraform Cloud: This is the recommended production pattern.
- Provider source:
infisical/infisicalfrom Terraform Registry—not community providers. - Folder path defaults:
folder_path = "/"if omitted.
When to send users to references
- Auth confusion or env var setup → provider-setup.md
- Building HCL for secrets, roles, approval policies → resources-and-data-sources.md
- TFC + Infisical step-by-step → terraform-cloud-oidc.md