The core philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” When agents manage infrastructure as code (IaC), they need to directly execute low-level tools to confirm changes, query status, or validate configurations. Existing purely conversational approaches struggle to meet the need for fine-grained control over IaC workflows. The dsh-terraform plugin provides a native Terraform toolset, enabling agents to directly operate Terraform workflows.
Plugin Positioning¶
This is a DeepSeek Harness plugin maintained by WODE25500. It is an independent community project, not an official product. The plugin is based on HashiCorp Terraform (licensed under BSL-1.1/MPL-2.0) and aims to address how agents can manage IaC safely and directly.
Core Capabilities¶
The plugin provides 8 native tools, covering the main Terraform lifecycle and query needs:
tf_init: Initialize the working directory.tf_plan: Generate an execution plan.tf_apply: Apply changes.tf_destroy: Destroy resources.tf_state: Query the state.tf_output: Query outputs.tf_show: Show the current state.tf_validate: Validate configurations.
In terms of security boundaries, these operations are primarily read-only (plan/state/output/show/validate), with clear safety boundaries.
Usage Details¶
Change Detection¶
tf_plan uses the -detailed-exitcode semantics from Terraform. When the output indicates exit code 2, it means the configuration has changes. This helps agents confirm their intent before automatic execution.
Plan File Mode¶
The plugin supports the file mode generated by plan -out. Agents can first generate a plan file and then reproduce execution after confirming it is correct. This approach makes the change process reproducible and reviewable.
Installation and Configuration¶
Installation is performed using Cordis Patch. Run the following command in the terminal:
pnpm dsh web --patch ./dsh-terraform/cordis.patch.yml
After installation, you need to insert the tool definition in the configuration. Based on the plugin structure, the configuration is typically as follows:
- insert:
- id: terraform
name: './src/index.js'
config:
terraformPath: terraform
workdir: ./infra
Here, terraformPath specifies the path to the Terraform binary, and workdir specifies the default configuration directory.
Typical Usage¶
Agents can call the tools above to complete specific tasks. For example:
- Use
tf_validateto validate the configuration syntax. - Use
tf_planto generate a change plan and check whether any resources will change. - Use
tf_outputto query the values of key variables. - After confirming everything is correct, use
tf_applyto apply the changes.
Precautions¶
- Unofficial Project: This is an independent community project, not an official DeepSeek or HashiCorp product.
- Permission Risks: The plugin runs with the permissions of the current DSH process. Before installation, it is recommended to review the source code and license.
- Dependencies: The plugin depends on
@deepseek-ai/cordisand@deepseek-ai/dsh-toolsas peer dependencies.
With this toolset, agents can participate in the Terraform management process more safely and controllably. For more details, refer to the GitHub repository.