Set up with a coding agent
Optional: hand this page to your coding agentThe steps work by hand too.Show the whole prompt
Set up terragucci in this repository.
Read https://intentius.io/terragucci/llms.txt first, then
https://intentius.io/terragucci/getting-started/agents/ and follow it.
Open a pull request with the result.
Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`.Setup needs no agent. Get your first plan note gives every step by hand, and only four opt-in features run a model.
Give the prompt above to an agent working in a repository of Terraform or OpenTofu roots, including a Terragrunt, Atmos, Terramate or CDK Terrain repo.
Agent inputs
Section titled “Agent inputs”| File | Holds |
|---|---|
llms.txt |
every page, with a one-line description |
llms-full.txt |
the text of every page in one file |
| Copy page as Markdown, under each page’s title | that page’s text, with its prompt |
A task page’s own prompt sits under its title as “Optional: hand this page to your coding agent”. Each one carries the line in step 5.
A key that terragucci config check refuses is not part of terragucci.
Steps for the agent
Section titled “Steps for the agent”-
Install terragucci with
npm i -D @intentius/terragucciand runnpx terragucci init --dry-run --json. Show the user the findings with their reasons and the files it would write. -
Check what it found. Pass
--binaryor--forgeif either is wrong, or ask the user. -
Write a
terragucci.yml, as small as possible, only if the defaults are wrong; terragucci.yml keys lists every key. -
Run
npx terragucci initto write the pipeline, and show the user the file it wrote. -
Open a pull request with the config and the files
initwrote; checkgit statusso the commit holds nothing else. Then stop. Approvals are records onchant/lifecycle, and they belong to the user.Never apply, approve (a pull request review or `terragucci approve`), override a policy denial (`terragucci override`), use `--mode apply`, or merge; never touch `.chant/allowed_signers` or `chant/lifecycle`. -
Under
approval: sealed, tell the user to add their key to.chant/allowed_signers(Before your first approval). Do not add a key yourself. The file must be on the default branch before the first merge that destroys something, because the apply reads it from before the merge.
Rules for the agent
Section titled “Rules for the agent”- Set terragucci up or change its config from the shell with
--json, and parse the envelope (JSON output). - Read what terragucci already wrote through
terragucci mcp, when the user has added it (Read the estate over MCP). - Run
npx terragucci config check --jsonafter writing a config; it lists every problem at once. - Approvals belong to people. Print the
terragucci approvecommand for a waiting wave but never run it; an approval made over MCP or ACP is refused. - Responses to pipeline events need no model.
- Credentials stay in the forge’s secrets. The config names environment variables (
token_env) and never holds a value.
MCP or --json
Section titled “MCP or --json”| You want to | Use | Why |
|---|---|---|
| find the roots, binary and forge, write a config, check it, write the pipeline | the CLI with --json |
these commands write files in the repo, and the envelope gives each finding and the exit code |
| plan a root, or run a response in dry run | the CLI with --json |
they run the binary in the checkout |
| read the estate, a root’s last apply, a run’s report, the state versions, the audit trail or the DORA figures | terragucci mcp |
it reads the reports bucket with the credentials in its own environment, and every tool only reads |
| find a waiting wave and its digest | terragucci mcp’s waiting tool |
it prints the terragucci approve command for a person to run |
| approve, apply, override or merge | neither | these belong to a person at a shell; the server has no such tool, and an approval made over MCP is refused |
After setup, see read the estate over MCP, summarize a refused wave (comment-only token), change a pull request, fix drift, and review a pull request.
These docs count page views and clicks with PostHog. They set no cookies, store nothing in your browser, and send nothing when your browser asks not to be tracked.