Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
f447eca
feat(agent-skills): add toolchain-manager migration guides to atmos-m…
osterman Aug 5, 2026
1e25886
Merge remote-tracking branch 'origin/main' into osterman/toolchain-mi…
osterman Aug 5, 2026
bfe2410
fix(agent-skills): address CodeRabbit review on toolchain migration g…
osterman Aug 6, 2026
7840da5
fix(agent-skills): use verified kubectl alias and clarify shell integ…
osterman Aug 6, 2026
edf2250
Merge remote-tracking branch 'origin/main' into osterman/toolchain-mi…
osterman Aug 11, 2026
51a9806
docs(agent-skills): fix Aqua migration references per CodeRabbit review
osterman Aug 12, 2026
57d4aa0
fix(agent-skills): address PR review feedback on toolchain migration …
osterman Aug 14, 2026
63b6606
Merge remote-tracking branch 'origin/main' into osterman/toolchain-mi…
osterman Aug 19, 2026
48ff463
Merge remote-tracking branch 'origin/main' into osterman/toolchain-mi…
osterman Aug 31, 2026
deaa7bf
fix(skills): correct tool-manager command mappings in atmos-migration…
osterman Sep 2, 2026
07e8bb4
fix(skills): drop leftover TFLint mentions in tenv cross-references
osterman Sep 2, 2026
de68eb6
Merge remote-tracking branch 'origin/main' into osterman/toolchain-mi…
osterman Sep 2, 2026
cba8029
fix(security): bump fast-uri, browserslist, postcss-selector-parser
osterman Sep 2, 2026
b8dad0c
Merge remote-tracking branch 'origin/main' into osterman/toolchain-mi…
osterman Sep 3, 2026
2503e0d
fix(security): bump golang.org/x/crypto to v0.56.0
osterman Sep 3, 2026
18a0eb7
[autocommit] formatting fixes
atmos-pro[bot] Sep 3, 2026
bd0ebe1
Merge remote-tracking branch 'origin/main' into osterman/toolchain-mi…
osterman Sep 3, 2026
6f7ceea
docs(agent-skills): fix CodeRabbit findings in tenv/tfenv/tofuenv mig…
osterman Sep 3, 2026
222fa4c
docs(agent-skills): trim atmos-migration SKILL.md under 20KB CI limit
osterman Sep 3, 2026
673d26b
Merge remote-tracking branch 'origin/main' into osterman/toolchain-mi…
osterman Sep 3, 2026
8442e0e
Merge remote-tracking branch 'origin/main' into osterman/toolchain-mi…
osterman Sep 4, 2026
a7d7e9d
Merge remote-tracking branch 'origin/main' into osterman/toolchain-mi…
osterman Sep 7, 2026
27f00fa
Merge remote-tracking branch 'origin/main' into osterman/toolchain-mi…
osterman Oct 6, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
86 changes: 52 additions & 34 deletions agent-skills/skills/atmos-migration/SKILL.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
---
name: atmos-migration
description: "Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from mise or Aqua CLI; migrate AWS/GCP/Azure CLI configs, Leapp, Granted, saml2aws, or okta-aws-cli to atmos auth; and replace GitHub Actions CI (dflook, tfcmt, cloud OIDC, component updater, TFLint, Checkov, Trivy, KICS, Infracost, tfsec) with Atmos Native CI. Use for incremental adoption that preserves layout, state, task behavior, and CI enforcement."
description: "Migrate to Atmos from native Terraform, Terraform Workspaces, Terramate, Terragrunt, Make, Just, or Task; migrate tool versions from asdf, aqua, tfenv, tofuenv, tenv, mise, or a Homebrew Brewfile; migrate AWS/GCP/Azure CLI configs, Leapp, Granted, saml2aws, or okta-aws-cli to atmos auth; and replace GitHub Actions CI (dflook, tfcmt, cloud OIDC, component updater, TFLint, Checkov, Trivy, KICS, Infracost, tfsec) with Atmos Native CI. Use for incremental adoption that preserves layout, state, task behavior, and CI enforcement."
metadata:
copyright: Copyright Cloud Posse, LLC 2026
version: "1.0.0"
Expand All @@ -17,6 +17,11 @@
- references/from-terragrunt.md
- references/from-mise.md
- references/from-aqua.md
- references/from-asdf.md
- references/from-tfenv.md
- references/from-tofuenv.md
- references/from-tenv.md
- references/from-homebrew-brewfile.md
- references/from-aws-config.md
- references/from-gcp-config.md
- references/from-azure-config.md
Expand Down Expand Up @@ -102,23 +107,32 @@
Find the user's source pattern before you propose any change. Each pattern points to a different
reference file:

| User has... | Use reference |
|----------------------------------------------------------------------|--------------------------------------------------|
| One TF root module, env config via `.tfvars` or env vars | [from-native-terraform.md](references/from-native-terraform.md) |
| Multiple TF root modules in scattered dirs | [from-native-terraform.md](references/from-native-terraform.md) |
| `terraform.workspace`-driven environments with shared state backend | [from-terraform-workspaces.md](references/from-terraform-workspaces.md) |
| User has... | Use reference |
|---|---|
| One TF root module, env config via `.tfvars` or env vars | [from-native-terraform.md](references/from-native-terraform.md) |
| Multiple TF root modules in scattered dirs | [from-native-terraform.md](references/from-native-terraform.md) |
| `terraform.workspace`-driven environments with shared state backend | [from-terraform-workspaces.md](references/from-terraform-workspaces.md) |
| `.tm.hcl` files, `stack.tm.hcl`, `generate_hcl` blocks (Terramate project) | [from-terramate.md](references/from-terramate.md) |
| Need to read outputs from un-migrated TF (legacy or another repo) | [remote-state-bridge.md](references/remote-state-bridge.md) |
| User has a Makefile driving builds/tests/deploys | [from-makefile.md](references/from-makefile.md) |
| User has a Justfile (`just` command runner) | [from-justfile.md](references/from-justfile.md) |
| User has a Taskfile.yml (go-task) | [from-taskfile.md](references/from-taskfile.md) |
| `cloudposse/github-action-atmos-component-updater` | [from-component-updater.md](references/from-component-updater.md) |
| Terragrunt (`terragrunt.hcl` or `terragrunt.stack.hcl`) | [from-terragrunt.md](references/from-terragrunt.md) |
| Need to read outputs from un-migrated TF (legacy or another repo) | [remote-state-bridge.md](references/remote-state-bridge.md) |
| User has a Makefile driving builds/tests/deploys | [from-makefile.md](references/from-makefile.md) |
| User has a Justfile (`just` command runner) | [from-justfile.md](references/from-justfile.md) |
| User has a Taskfile.yml (go-task) | [from-taskfile.md](references/from-taskfile.md) |
| `cloudposse/github-action-atmos-component-updater` | [from-component-updater.md](references/from-component-updater.md) |
| Terragrunt (`terragrunt.hcl` or `terragrunt.stack.hcl`) | [from-terragrunt.md](references/from-terragrunt.md) |
| mise config (`mise.toml`, `.mise.toml`, `.mise/config.toml`, `.tool-versions`) for tool versions | [from-mise.md](references/from-mise.md) |
| `aqua.yaml` (Aqua CLI) for tool versions | [from-aqua.md](references/from-aqua.md) |
| `aqua.yaml` (Aqua CLI) for tool versions | [from-aqua.md](references/from-aqua.md) |
| asdf (`.tool-versions`, asdf plugins) for tool versions | [from-asdf.md](references/from-asdf.md) |
| tfenv (`.terraform-version`) for Terraform versions | [from-tfenv.md](references/from-tfenv.md) |
| tofuenv (`.opentofu-version`) for OpenTofu versions | [from-tofuenv.md](references/from-tofuenv.md) |
| tenv (version files for Terraform, OpenTofu, Terragrunt, Terramate, Atmos) | [from-tenv.md](references/from-tenv.md) |
| Homebrew Brewfile (CLI tools only) | [from-homebrew-brewfile.md](references/from-homebrew-brewfile.md) |
| CI on GitHub Actions (setup-terraform, configure-aws-credentials, dflook, tfcmt) | [to-native-ci.md](references/to-native-ci.md) |
| Scanner actions (TFLint, Checkov, Trivy, KICS, Infracost, tfsec) | [to-native-ci-scanners.md](references/to-native-ci-scanners.md) |

Each tool-version reference has a command-mapping table and a Shell Integration section. The Atmos
toolchain does not add itself to `PATH` by default, unlike shim-based tools. If the user expects a
plain `terraform` command to keep working, point them to `atmos toolchain env` in their shell profile.

The remote-state-bridge pattern makes progressive migration possible. It lets a team migrate one
component at a time. Without it, the team must migrate everything at once. Use this pattern when
the user has existing Terraform state that a new Atmos component must read.
Expand Down Expand Up @@ -154,15 +168,15 @@
their auth setup, both, or neither in a given session. Don't conflate the two. Identify which
credential tooling the user has today and route to the matching reference:

| User has... | Use reference |
|------------------------------------------------------------|----------------------------------------------------|
| `~/.aws/config`/`~/.aws/credentials` profiles | [from-aws-config.md](references/from-aws-config.md) |
| `gcloud` CLI config, ADC, or service-account keys | [from-gcp-config.md](references/from-gcp-config.md) |
| `az` CLI config, service principals, or Managed Identity | [from-azure-config.md](references/from-azure-config.md) |
| Leapp (desktop credential manager) | [from-leapp.md](references/from-leapp.md) |
| Granted (the `assume` CLI) | [from-granted.md](references/from-granted.md) |
| saml2aws | [from-aws2saml.md](references/from-aws2saml.md) |
| okta-aws-cli | [from-okta-cli.md](references/from-okta-cli.md) -- **partial support only, read the gap callouts** |
| User has... | Use reference |
|---|---|
| `~/.aws/config`/`~/.aws/credentials` profiles | [from-aws-config.md](references/from-aws-config.md) |
| `gcloud` CLI config, ADC, or service-account keys | [from-gcp-config.md](references/from-gcp-config.md) |
| `az` CLI config, service principals, or Managed Identity | [from-azure-config.md](references/from-azure-config.md) |
| Leapp (desktop credential manager) | [from-leapp.md](references/from-leapp.md) |
| Granted (the `assume` CLI) | [from-granted.md](references/from-granted.md) |
| saml2aws | [from-aws2saml.md](references/from-aws2saml.md) |
| okta-aws-cli | [from-okta-cli.md](references/from-okta-cli.md) -- **partial support only, read the gap callouts** |

All are pure config-translation guides -- there is no `atmos auth import`/`migrate` command.
None of them require touching the user's IaC migration path; they can run before, after, or
Expand Down Expand Up @@ -212,10 +226,10 @@
layout, especially for a new repository or a multi-tool project. You can keep an existing layout
when the user wants less disruption.

| `base_path` | Use when |
|------------------------------------------|-------------------------------------------------------------------------|
| `base_path: "."` | TF root modules live at the repo root; user wants zero file moves |
| `base_path: "terraform"` | TF-only repo with code already in `terraform/`; preserve dir name |
| `base_path` | Use when |
|---|---|
| `base_path: "."` | TF root modules live at the repo root; user wants zero file moves |
| `base_path: "terraform"` | TF-only repo with code already in `terraform/`; preserve dir name |
| `base_path: "."` + `components.terraform.base_path: "components/terraform"` | Multi-toolchain or new repo; canonical Atmos layout |

For more organization patterns, such as multi-region, multi-account, and organization
Expand All @@ -226,14 +240,14 @@
This is a common mistake: an agent chooses a Gomplate datasource when a YAML function is safer
and clearer. Use the option in the right column:

| Goal | Reach for (NOT this) | Use instead |
|-------------------------------|---------------------------------------------------|------------------------------------------|
| Include a file's contents | `gomplate.datasources` with file URL | `!include path/to/file` |
| Read an environment variable | `gomplate getenv "FOO"` | `!env FOO` |
| Run a shell command | Template + `gomplate exec` | `!exec "command"` |
| Read a store value | Custom datasource URL | `!store store_name component stack key` |
| Read Terraform output | Templated remote-state datasource | `!terraform.state component output` |
| Get current AWS account ID | `gomplate.datasources` AWS plugin | `!aws.account_id` |
| Goal | Reach for (NOT this) | Use instead |
|---|---|---|
| Include a file's contents | `gomplate.datasources` with file URL | `!include path/to/file` |
| Read an environment variable | `gomplate getenv "FOO"` | `!env FOO` |
| Run a shell command | Template + `gomplate exec` | `!exec "command"` |
| Read a store value | Custom datasource URL | `!store store_name component stack key` |
| Read Terraform output | Templated remote-state datasource | `!terraform.state component output` |
| Get current AWS account ID | `gomplate.datasources` AWS plugin | `!aws.account_id` |

A YAML function checks its own types. It gives a clear error message. It works without Gomplate
turned on. It does not require the template text to stay valid YAML. Use a Go template only for
Expand Down Expand Up @@ -297,6 +311,10 @@
automation from `atmos.yaml`. Keep infrastructure adoption separate from task-runner adoption.
- **"Delete the existing task file before adopting Atmos."** Atmos can call the existing runner.
Migrate task bodies incrementally and preserve the source tool's ordering and freshness semantics.
- **"Copy `aqua.yaml` packages into Atmos verbatim."** This is false. Atmos supports only part of
the Aqua registry schema. Check the Functional Gaps table in [from-aqua.md](references/from-aqua.md).
- **"Replace the whole Brewfile with the Atmos toolchain."** This is false. Casks, `mas` entries,
and source-built formulae are out of scope. See [from-homebrew-brewfile.md](references/from-homebrew-brewfile.md).
- **"Wrap atmos commands in a Makefile, Justfile, or Taskfile forever."** This is false. A
wrapper is a good bridge while the user builds trust in Atmos, not the final state -- change
each leaf target to a custom command (see Principle 7 and "Common Problems in Task-Runner
Expand Down
Loading
Loading