Manage Terraform infrastructure via natural language with safety checks, cost analysis, drift detection, and audit logging.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent — or use 1-click editor setup below.
We haven't yet run this listing's install command through our automated sandbox check. This isn't a red flag — we're steadily working through the catalog.
💡 Paste the JSON block into your client's configuration file under mcpServers, then restart the application.
Inspect callable tools, capabilities, and parameters exposed to AI agents by MCP Server Terraform.
tf_initInitialize a Terraform working directory
tf_validateValidate configuration syntax
tf_planRun a plan and return the diff + risk/cost summary
tf_applyApply changes (requires `confirmed: true`)
tf_destroyDestroy infrastructure (requires `confirmed: true`)
tf_outputRead output values from state
A Model Context Protocol (MCP) server that lets Claude manage Terraform infrastructure through natural language.
Run plans, apply changes, inspect state, and diagnose failures — all from a Claude conversation.
Instead of switching to a terminal to run terraform plan, you can ask Claude:
"Plan the changes in
/infra/stagingand explain what will change"
"Apply it — but only if no resources will be destroyed"
"Show me all the outputs from the prod workspace"
"Something broke after the last apply — diagnose it"
The server translates these into real terraform CLI commands on your machine, with a built-in safety confirmation flow before any destructive operation runs.
| Tool | Description | Destructive |
|---|---|---|
tf_init | Initialize a Terraform working directory | No |
tf_validate | Validate configuration syntax | No |
tf_plan | Run a plan and return the diff + risk/cost summary | No |
tf_apply | Apply changes (requires confirmed: true) | Yes |
tf_destroy | Destroy infrastructure (requires confirmed: true) | Yes |
tf_output | Read output values from state | No |
tf_state | List, show, move, or remove state entries | Partial |
tf_workspace | List, show, select, or create workspaces | No |
tf_preflight | Check provider CLI authentication before running | No |
tf_drift | Detect resources changed outside Terraform | No |
tf_resource | Import, taint, untaint, or refresh resources | Yes |
Every plan (and every apply preview) is analyzed via terraform show -json and
annotated with a structured summary — destroyed resources are called out, and
always-on resources that commonly cause bill shock are flagged with rough
monthly costs:
Cost-flagged resource types include NAT gateways, load balancers, EKS/AKS/GKE control planes, RDS/Cloud SQL instances, ElastiCache, Redshift, MSK, and Azure Firewall (~$900/month!).
tf_drift runs a refresh-only plan and reports resources that were changed
outside Terraform (e.g. manually in the cloud console), with the changed
attribute names and remediation options.
Set AUDIT_LOG_PATH to a file path and every tool call is appended as a JSON
line with timestamp, tool name, outcome, and duration. Variable values are
always redacted (db_password=<redacted>) — only names are logged.
tf_apply and tf_destroy use a two-step safety flow:
confirmed) → runs terraform plan, shows the diff, does nothing elseconfirmed: true) → actually applies or destroysClaude is instructed to never pass confirmed: true without first presenting the plan to you.
The server exposes a /tf-diagnose prompt that guides Claude through a systematic 5-step diagnosis of plan or apply failures.
No install needed — run it straight from npm:
Or, for development, from source:
Add to your Claude Desktop config file:
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%\Claude\claude_desktop_config.json
(If running from source instead, use "command": "node" with "args": ["/absolute/path/to/dist/index.js"].)
Restart Claude Desktop. You should see a hammer icon indicating tools are available.
Once connected, just talk to Claude about your Terraform workspaces in plain language. Some examples:
"Initialize the terraform config in
C:\infra\stagingand check if I'm logged into the right cloud accounts"
Claude runs tf_init, then tf_preflight — if you're not authenticated it tells you exactly which command to run (az login, aws configure, ...).
"Plan the changes in
C:\infra\stagingand explain what will change"
You get the plan diff plus a summary: how many resources created/updated/destroyed, anything destructive called out explicitly, and cost warnings for expensive always-on resources.
"Looks good, apply it"
Claude shows the plan preview one more time and asks for your confirmation — nothing is applied until you say yes. This two-step gate is built into the server itself, not just the prompt, so Claude cannot skip it.
"Did anyone change anything outside terraform in the prod workspace?"
tf_drift compares state against reality and reports what was modified in the console, with options to accept or revert.
"Show me all the outputs" · "List everything in state" · "What workspaces exist?"
"Apply the VPC lab in
C:\labs\vpc, and when I say 'done' destroy everything"
The cost flags are your friend here — if a lab creates a NAT gateway or EKS cluster, the plan summary warns you what it costs per month if forgotten:
"terraform plan is failing in
C:\infra\staging— diagnose it"
The /tf-diagnose prompt walks Claude through validate → providers → plan → state → outputs systematically. There's also /tf-login for step-by-step authentication setup per provider.
"Import the S3 bucket
my-legacy-bucketinto state asaws_s3_bucket.legacy"
"Taint the web server so it gets recreated on the next apply"
Run with ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS=true (see Safety modes below) so apply/destroy are unavailable entirely, and set AUDIT_LOG_PATH so every operation is logged.
Control which tools are available via environment variables:
| Variable | Effect |
|---|---|
ALLOW_ONLY_READONLY_TOOLS=true | Only tf_validate, tf_plan, tf_output |
ALLOW_ONLY_NON_DESTRUCTIVE_TOOLS=true | Blocks tf_apply, tf_destroy, tf_state mv/rm |
ALLOWED_TOOLS=tf_plan,tf_output | Explicit comma-separated allowlist |
Example — read-only mode:
src/tools/tf-yourcommand.ts — export a *Schema const and an async handler functionsrc/index.tsreadonlyTools or destructiveTools arraycase in the CallToolRequestSchema handler switchSee CONTRIBUTING.md.
MIT — see LICENSE.
Factual signals from GitHub, npm, and our automated checks — not a rating.
No reviews yet — be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/rajeevsirohi-mcp-server-terraform)<a href="https://allmcps.com/mcp/rajeevsirohi-mcp-server-terraform"><img src="https://allmcps.com/api/badge/rajeevsirohi-mcp-server-terraform?style=directory" alt="MCP Server Terraform on AllMCPs" /></a>