HCL/Terraform — 112 Operations for AI Agents
This page is the canonical reference an AI coding agent uses to refactor, query, and analyze HCL/Terraform code through the act MCP server. 112 operations available: 38 refactor, 18 query, 42 analysis, 14 verification. Each operation is callable from Claude Code, Cursor, Codex, OpenCode, or any MCP-compatible agent host. Click any operation for a stable anchor link suitable for citation.
Worked HCL/Terraform examples
act101 edits Terraform configuration using the block and attribute structure the tree-sitter grammar exposes, so an edit targets a specific resource, variable, or attribute rather than a raw text position. It can add a description attribute to an output block that lacks one, extract a hardcoded literal into a new variable block and replace every occurrence with a var. reference, and rename a resource block's name label while updating every resource_type.old_name reference elsewhere in the file. Each of these edits reads the targeted block by its own type and name. Each example below is the verbatim output of the command shown, run against the file shown.
Add a description to an output block
outputs.tf declares the bucket_arn output with only a value, no description.
$ act refactor-lang add_output_description --file outputs.tf --params '{"output_name":"bucket_arn","description":"ARN of the S3 bucket","line":1,"column":1,"symbol":"output.bucket_arn"}'
Before
output "bucket_arn" {
value = aws_s3_bucket.main.arn
}
After
output "bucket_arn" {
description = "ARN of the S3 bucket"
value = aws_s3_bucket.main.arn
}
description = "ARN of the S3 bucket" is inserted as the first line inside the output "bucket_arn" block, above the existing value line.
Extract a hardcoded value into a variable
web.tf sets region = "us-east-1" directly on the aws_instance resource, alongside its ami, instance_type, and tags.
$ act refactor-lang convert_hard_coded_value_to_variable --file web.tf --params '{"value":"\"us-east-1\"","variable_name":"region","variable_type":"string","line":4,"column":1,"symbol":"region"}'
Before
resource "aws_instance" "web" {
ami = "ami-0c55b159cbfafe1f0"
instance_type = "t2.micro"
region = "us-east-1"
tags = {
Name = "web-server"
}
}
After
variable "region" {
type = string
default = "us-east-1"
}
resource "aws_instance" "web" {
ami = "ami-0c55b159cbfafe1f0"
instance_type = "t2.micro"
region = var.region
tags = {
Name = "web-server"
}
}
A variable "region" block with default = "us-east-1" is inserted above the resource, and region now reads var.region instead of the literal string; ami, instance_type, and tags are unchanged.
Rename a resource and its cross-references
storage.tf declares aws_s3_bucket.data, a second resource that reads its id as aws_s3_bucket.data.id, and an output that reads its arn.
$ act refactor-lang rename_resource --file storage.tf --params '{"resource_type":"aws_s3_bucket","old_name":"data","new_name":"primary","line":1,"column":1,"symbol":"data"}'
Before
resource "aws_s3_bucket" "data" {
bucket = "my-data-bucket"
tags = {
Name = "data-bucket"
}
}
resource "aws_s3_bucket_versioning" "data_versioning" {
bucket = aws_s3_bucket.data.id
versioning_configuration {
status = "Enabled"
}
}
output "bucket_arn" {
value = aws_s3_bucket.data.arn
}
After
resource "aws_s3_bucket" "primary" {
bucket = "my-data-bucket"
tags = {
Name = "data-bucket"
}
}
resource "aws_s3_bucket_versioning" "data_versioning" {
bucket = aws_s3_bucket.primary.id
versioning_configuration {
status = "Enabled"
}
}
output "bucket_arn" {
value = aws_s3_bucket.primary.arn
}
The bucket's name label becomes primary, and both aws_s3_bucket.data.id in the versioning resource and aws_s3_bucket.data.arn in the output become aws_s3_bucket.primary.id/.arn.
Query
18 query tools, the same on every supported language. Descriptions live in the shared reference: /docs/query-tools.
callers control_flow data_flow definition diagnostics effect_closure effect_summary fix_auto get_type graph import_organize interface mutations references repo_outline skeleton symbols symbols_batch
Refactor
| Operation | Description |
|---|---|
add-attribute |
Add an attribute to a named block |
add-output-description |
Add a description attribute to an output block |
add-variable-description |
Add a description attribute to a variable block |
convert-count-to-for-each |
Convert count-based iteration to for_each |
convert-hard-coded-value-to-variable |
Extract a literal value into a new variable block |
convert-string-interpolation |
Convert format() calls to template string syntax |
extract-locals |
Extract an expression into a local value |
extract-module |
Extract resources into a new module file |
extract-repeated-attribute |
Extract a repeated attribute value into a local |
extract-variable |
Extract a hardcoded value into a variable block |
extract_function |
Extract a code selection into a new function — automatically infers parameters, return types, and inserts the call site. Use instead of manually cutting/pasting code. Works without LSP; LSP improves type inference. Params: file (string), new_name (string), start_line (u32), start_column (u32), end_line (u32), end_column (u32) [, preview (bool), receipt (bool)] |
extract_variable |
Extract an expression into a named variable — inserts the declaration and replaces the expression with the variable name. Works without LSP. Params: file (string), new_name (string), start_line (u32), start_column (u32), end_line (u32), end_column (u32) [, preview (bool)] |
gen-backend-config |
Generate or insert a terraform backend block |
gen-data-source-lookup |
Generate a data source block |
gen-module-block |
Generate a new module call block |
gen-output-block |
Generate a new output block |
gen-provider-config |
Generate a provider configuration block |
gen-variable-block |
Generate a new variable block |
inline |
Inline a variable, function, or method — replace every usage with its definition body, then remove the original. The inverse of extract. Works without LSP (single-file); LSP enables cross-file inlining. Params: file (string), symbol (string) [, line (u32), preview (bool), receipt (bool)] |
inline-local |
Inline a local value into all reference sites |
inline-variable |
Inline a variable's default value into all var.name references |
insert_body |
Replace a function's implementation body with new code. AST-validated — rejects if the result has parse errors, so you can't accidentally break syntax. Use instead of manual text editing for function rewrites. Params: file (string), symbol (string), code (string) [, commit (bool)] |
move-block |
Move a block to a different file |
move_symbol |
Move a function, class, or type to a different file and automatically update all imports across the codebase. Use instead of manually cut/paste + fixing imports. Works without LSP (single-file); LSP enables cross-file import updates. Params: file (string), symbol (string), destination (string) [, preview (bool), receipt (bool)] |
normalize-resource-attributes |
Sort attributes in a block alphabetically |
organize-imports |
Sort required_providers alphabetically |
recipe_run |
Run a codemod recipe: declarative match → transform → optional verify across modeled grammars. Preview lists matches; apply writes with optional E7 receipts and all-or-nothing rollback. Returns a per-site report. |
refactor-variable-naming |
Rename a variable to follow snake_case conventions |
remove-attribute |
Remove an attribute from a named block |
rename |
Rename a symbol and automatically update ALL references across the codebase. Safer and faster than find-and-replace — AST-aware, won't rename strings or comments. Works without LSP (single-file); LSP enables cross-file renames. Params: file (string), old_name (string), new_name (string) [, line (u32), column (u32), preview (bool), receipt (bool)] |
rename-attribute |
Rename an attribute key in a named block |
rename-data-source |
Rename a data source block and all data.type.name references |
rename-local |
Rename a local value and all local.name references |
rename-module |
Rename a module block and all module.name references |
rename-output |
Rename an output block |
rename-resource |
Rename a resource block and all type.name references |
rename-variable |
Rename a variable block and all var.name references |
simplify-interpolation |
Simplify "${expr}" to expr when it is the entire string value |
Analysis
42 analysis tools, the same on every supported language. Descriptions live in the shared reference: /docs/analysis-tools.
analyze_api_diff analyze_chokepoints analyze_clones analyze_clusters analyze_cohesion analyze_conformance analyze_coupling analyze_cycle_risk analyze_cycles analyze_dead_code analyze_depth analyze_entry_points analyze_export analyze_extraction analyze_fan_balance analyze_features analyze_hotspots analyze_impact analyze_inconsistencies analyze_inheritance analyze_interface_bloat analyze_interfaces analyze_layers analyze_orphan_types analyze_patterns analyze_platform_deps analyze_readiness analyze_roles analyze_seams analyze_stability analyze_surface analyze_test_gaps analyze_thickness analyze_type_completeness churn_hotspots co_change_clusters coverage_overlay ownership_map profile_overlay simulate split_module trace_overlay
Verify
14 verify tools, the same on every supported language. Descriptions live in the shared reference: /docs/verification.
bisect_regression gate generate_test_harness scan secret_surface summarize_pr taint_flow unsafe_surface verify_behavioral_equivalence verify_contract_preserved verify_diff_semantics verify_port_parity verify_side_effects verify_test_impact