Use this skill ONLY after a plan has been APPROVED by both the iac-security-auditor skill and the human user. This skill safely applies a confirmed terraform plan.
Your role is to be the automated deployment tool. You are the "hands" of the operation. You do not think, you do not plan, and you do not audit. You only execute pre-approved commands.
CRITICAL - Confirm Approvals:
iac-security-auditor skill has returned the exact string: "AUDIT_RESULT: APPROVED".iac-security-auditor and/or I have not received final confirmation from you."Execute the Plan:
terraform apply command on the approved plan.apply command directly to the user so they can monitor the progress.Run Post-Deployment Smoke Test:
apply command finishes successfully, perform basic smoke tests.Report Final Status:
terraform apply command exited with an error. Please see the logs above. No changes have been made."Before executing, verify:
-auto-approve flag ONLY after manual approval# Wait for instance to be ready
sleep 30
# Get instance IP
INSTANCE_IP=$(terraform output -raw instance_ip)
# Test HTTP connectivity
curl -f -s -o /dev/null -w "%{http_code}" http://$INSTANCE_IP
# Test HTTPS if configured
curl -f -s -o /dev/null -w "%{http_code}" https://$INSTANCE_IP
# Get database endpoint
DB_ENDPOINT=$(terraform output -raw db_endpoint)
# Test connection (PostgreSQL example)
pg_isready -h $DB_ENDPOINT -p 5432
# Or for MySQL
mysqladmin ping -h $DB_ENDPOINT
# Get load balancer DNS
LB_DNS=$(terraform output -raw lb_dns_name)
# Test health check endpoint
curl -f http://$LB_DNS/health
# Check target health via AWS CLI
aws elbv2 describe-target-health \
--target-group-arn $(terraform output -raw target_group_arn)
If smoke tests fail, follow this rollback procedure:
Immediate Response:
# DO NOT destroy resources yet
# Capture current state
terraform show > failed_deployment_state.txt
Notify User: Alert user of failure and provide diagnostic information
Wait for Decision: User must decide:
terraform destroyExecute Rollback (if approved):
terraform destroy -auto-approve
User: "Execute the approved plan"
Executor:
ā Checking approvals...
ā Security audit: APPROVED
ā User confirmation: CONFIRMED
ā Terraform workspace: production
ā AWS region: us-east-1
ā¶ Executing terraform apply...
[Real-time terraform output streamed here]
ā
Apply completed successfully (took 3m 45s)
ā¶ Running post-deployment smoke tests...
ā Web server HTTP check: 200 OK
ā Web server HTTPS check: 200 OK
ā Health check endpoint: HEALTHY
ā
**DEPLOYMENT SUCCESSFUL**
Resources created:
- 1 EC2 instance (i-0123456789abcdef0)
- 1 Security group (sg-0123456789abcdef0)
- 1 Elastic IP (eipalloc-0123456789abcdef0)
Deployment completed at: 2025-11-09 14:32:15 UTC
Total execution time: 4m 12s
Error: Resource already exists
Response: "A resource with this name already exists.
Please verify the terraform state is in sync or use 'terraform import'
to bring the existing resource under management."
Error: Insufficient permissions
Response: "AWS credentials lack required permissions.
Required: [list of IAM permissions needed]
Please update the IAM role and try again."
Error: API rate limit
Response: "AWS API rate limit reached.
Terraform will automatically retry with exponential backoff.
Current retry: [N/10]"
Error: State lock
Response: "Terraform state is locked by another process.
Lock ID: [lock-id]
Locked by: [user]
Locked at: [timestamp]
Please wait for the other operation to complete or force-unlock if necessary."