The core philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” When agents manage infrastructure as code (IaC), they need to directly execute low-level tools to confirm changes, query status, or validate configurations. Existing purely conversational approaches struggle to meet the need for fine-grained control over IaC workflows. The dsh-terraform plugin provides a native Terraform toolset, enabling agents to directly operate Terraform workflows.

Plugin Positioning

This is a DeepSeek Harness plugin maintained by WODE25500. It is an independent community project, not an official product. The plugin is based on HashiCorp Terraform (licensed under BSL-1.1/MPL-2.0) and aims to address how agents can manage IaC safely and directly.

Core Capabilities

The plugin provides 8 native tools, covering the main Terraform lifecycle and query needs:

  • tf_init: Initialize the working directory.
  • tf_plan: Generate an execution plan.
  • tf_apply: Apply changes.
  • tf_destroy: Destroy resources.
  • tf_state: Query the state.
  • tf_output: Query outputs.
  • tf_show: Show the current state.
  • tf_validate: Validate configurations.

In terms of security boundaries, these operations are primarily read-only (plan/state/output/show/validate), with clear safety boundaries.

Usage Details

Change Detection

tf_plan uses the -detailed-exitcode semantics from Terraform. When the output indicates exit code 2, it means the configuration has changes. This helps agents confirm their intent before automatic execution.

Plan File Mode

The plugin supports the file mode generated by plan -out. Agents can first generate a plan file and then reproduce execution after confirming it is correct. This approach makes the change process reproducible and reviewable.

Installation and Configuration

Installation is performed using Cordis Patch. Run the following command in the terminal:

pnpm dsh web --patch ./dsh-terraform/cordis.patch.yml

After installation, you need to insert the tool definition in the configuration. Based on the plugin structure, the configuration is typically as follows:

- insert:
    - id: terraform
      name: './src/index.js'
      config:
        terraformPath: terraform
        workdir: ./infra

Here, terraformPath specifies the path to the Terraform binary, and workdir specifies the default configuration directory.

Typical Usage

Agents can call the tools above to complete specific tasks. For example:

  1. Use tf_validate to validate the configuration syntax.
  2. Use tf_plan to generate a change plan and check whether any resources will change.
  3. Use tf_output to query the values of key variables.
  4. After confirming everything is correct, use tf_apply to apply the changes.

Precautions

  • Unofficial Project: This is an independent community project, not an official DeepSeek or HashiCorp product.
  • Permission Risks: The plugin runs with the permissions of the current DSH process. Before installation, it is recommended to review the source code and license.
  • Dependencies: The plugin depends on @deepseek-ai/cordis and @deepseek-ai/dsh-tools as peer dependencies.

With this toolset, agents can participate in the Terraform management process more safely and controllably. For more details, refer to the GitHub repository.