Developer Tools · AI Chatbot

tfmcp logo

tfmcp

nwiizo/tfmcp

tfmcp runs local Terraform workflows through the Model Context Protocol (MCP). It helps AI assistants inspect a project, prepare execution, review a saved plan, apply that same plan, and check the result. Registry and HCP/TFE tools support these local workflows.

Install

cargo install tfmcp --version 0.2.4

Client configuration

{
  "mcpServers": {
    "tfmcp": {
      "command": "docker",
      "args": [
        "run",
        "--rm",
        "-v",
        "/path/to/your/terraform:/app/terraform",
        "tfmcp",
        "mcp"
      ],
      "env": {
        "TERRAFORM_DIR": "<TERRAFORM_DIR>"
      }
    }
  }
}

Environment variables

TERRAFORM_DIRTRANSPORT_HOSTTFMCP_ALLOW_DANGEROUS_OPSTFMCP_ALLOW_AUTO_APPROVETFMCP_MAX_RESOURCESTFMCP_AUDIT_ENABLEDTFMCP_AUDIT_LOG_SENSITIVE
GitHub stars
246
Author
@nwiizo
Category
Developer Tools, AI Chatbot
License
MIT
Updated
Oct 6, 2026

About tfmcp

This project includes production-ready security features but is still under active development. While the security system provides robust protection, please review all operations carefully in production environments.

Features

  • Access Controls: Automatic blocking of production/sensitive file patterns

  • Operation Restrictions: Dangerous operations (apply/destroy) disabled by default

  • Resource Limits: Configurable maximum resource count protection

  • Audit Logging: Complete operation tracking with timestamps and user identification

  • Directory Validation: Security policy enforcement for project directories

Tools (40)

  • init_terraform

    Initialize Terraform working directory

  • get_terraform_plan

    Generate a saved plan, or retrieve its redacted result and status by plan ID

  • list_terraform_plans

    List saved plan IDs, targets, statuses, and destroy flags

  • discard_terraform_plan

    Remove an unneeded saved plan and free retention capacity

  • analyze_plan

    NEW Analyze plan with risk scoring and recommendations

  • apply_terraform

    Apply the reviewed saved plan ID and verify state resource addresses

  • destroy_terraform

    Apply a reviewed saved destroy plan with explicit deletion permissions

  • validate_terraform

    Validate configuration syntax

  • validate_terraform_detailed

    Detailed validation with guidelines

  • get_terraform_state

    Show current state

  • analyze_state

    NEW Analyze state with drift detection

  • review_terraform_plan

    Review plan risk, blockers, destructive changes, and recommendations

  • summarize_plan_for_pr

    Generate markdown plan summary for PR comments

  • run_terraform_quality_checks

    Run CI-friendly validation, module health, guideline, and lockfile checks

  • inspect_state_safety

    Inspect state readability, drift risk, lockfile status, and blockers

  • detect_drift_candidates

    Detect drift candidates from readable state without modifying infrastructure

  • prepare_terraform_change

    Generate blockers, warnings, and a recommended change sequence

  • list_terraform_resources

    List all managed resources

  • set_terraform_directory

    Change active project directory

  • terraform_workspace

    NEW Manage workspaces (list, show, new, select, delete)

  • terraform_import

    NEW Import existing resources

  • terraform_taint

    NEW Taint/untaint resources

  • terraform_refresh

    NEW Refresh state

  • terraform_fmt

    NEW Format code

  • terraform_graph

    NEW Generate dependency graph

  • terraform_output

    Get output values with sensitive values redacted, including named queries

  • terraform_providers

    NEW Get provider info with lock file

  • check_provider_lockfile

    Check.terraform.lock.hcl for reproducible provider selections

  • analyze_terraform

    Analyze configuration

  • inspect_terraform_project

    Inspect local Terraform directories, modules, and likely entrypoints

  • detect_terraform_entrypoints

    Detect likely root module entrypoints

  • analyze_module_health

    Module health with cohesion/coupling metrics

  • get_resource_dependency_graph

    Resource dependencies visualization

  • suggest_module_refactoring

    Refactoring suggestions

  • get_security_status

    Security scan with secret detection

  • search_providers

    Search providers (HashiCorp-compatible alias)

  • search_terraform_providers

    Search providers

  • get_provider_details

    Provider details (HashiCorp-compatible alias)

  • get_provider_info

    Provider details

  • get_provider_docs

    Provider documentation

Details on this page are taken from the project's README. Open README

Supported clients

Clients mentioned in this server's README:

View all
Claude Desktop logo

Claude Desktop

Desktop · Freemium · Proprietary

Anthropic's official Claude AI desktop application. Supports MCP servers to extend functionality.

WindowsMacOS

Related MCP servers

More servers
Playwright logo

Playwright

microsoft/playwright

72.2k

Playwright is a framework for web automation and testing. It drives Chromium, Firefox, and WebKit with a single API — in your tests, in your scripts, and as a tool for AI agents.

Developer Tools
repomix logo

repomix

yamadashy/repomix

15.2k

Repomix is a tool that packs a codebase into an AI-friendly format, supporting local and remote repository processing and providing code compression, security checks and multiple output formats.

Developer Tools
UI-TARS-desktop logo

UI-TARS-desktop

bytedance/UI-TARS-desktop

12.9k

TARS is ByteDance's multimodal AI agent stack, shipping two projects: Agent TARS (a CLI and Web UI agent built on MCP) and UI-TARS-desktop (a desktop GUI agent).

Developer Tools
blender logo

blender

ahujasid/blender-mcp

10.6k

formerly blender-mcp — the PyPI package is now mcp-for-blender. Existing setups keep working; no config change is required. Read more.

Developer Tools
Playwright Browser Automation logo

Playwright Browser Automation

microsoft/playwright-mcp

9.2k

A Model Context Protocol (MCP) server that provides browser automation capabilities using Playwright. This server enables LLMs to interact with web pages through structured accessibility snapshots, bypassing the need for screenshots or visually-tuned models.

Developer Tools
2344 logo

2344

comet-ml/opik

7k

Opik is the open-source LLM observability and evaluation platform for AI agent tracing, LLM evaluation, prompt management, and production monitoring. Built by Comet. Apache-2.0 licensed, free to self-host the full platform, with 20,000+ GitHub stars.

Developer Tools