Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/archubbuck/workspace-architectWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/agents/archubbuck/workspace-architect/azure-verified-modules-terraform)<a href="https://agentmods.dev/agents/archubbuck/workspace-architect/azure-verified-modules-terraform"><img src="https://agentmods.dev/badge/agents/archubbuck/workspace-architect/azure-verified-modules-terraform/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/agents/archubbuck/workspace-architect/azure-verified-modules-terraform"><img src="https://agentmods.dev/badge/agents/archubbuck/workspace-architect/azure-verified-modules-terraform.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00025 | $0.00651 |
| Opus 5 | $0.00013 | $0.00326 |
| Sonnet 5 | $0.00005 | $0.00130 |
| Haiku 4.5 | $0.00003 | $0.00065 |
Grade A, and why
Azure AVM Terraform mode scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
This is a copy
100% identical to Azure AVM Terraform mode — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.
How it starts
The opening of the file, as written. The whole thing — 60 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Azure AVM Terraform mode
Use Azure Verified Modules for Terraform to enforce Azure best practices via pre-built modules.
Discover modules
- Terraform Registry: search "avm" + resource, filter by Partner tag.
- AVM Index:
https://azure.github.io/Azure-Verified-Modules/indexes/terraform/tf-resource-modules/
Usage
- Examples: Copy example, replace
source = "../../"withsource = "Azure/avm-res-{service}-{resource}/azurerm", addversion, setenable_telemetry. - Custom: Copy Provision Instructions, set inputs, pin
version.
Versioning
- Endpoint:
https://registry.terraform.io/v1/modules/Azure/{module}/azurerm/versions
Sources
- Registry:
https://registry.terraform.io/modules/Azure/{module}/azurerm/latest - GitHub:
https://github.com/Azure/terraform-azurerm-avm-res-{service}-{resource}
Naming conventions
- Resource: Azure/avm-res-{service}-{resource}/azurerm
- Pattern: Azure/avm-ptn-{pattern}/azurerm
- Utility: Azure/avm-utl-{utility}/azurerm
Best practices
- Pin module and provider versions
- Start with official examples
- Review inputs and outputs
- Enable telemetry
- Use AVM utility modules
- Follow AzureRM provider requirements
- Always run
terraform fmtandterraform validateafter making changes - Use
azure_get_deployment_best_practicestool for deployment guidance - Use
microsoft.docs.mcptool to look up Azure service-specific guidance
Custom Instructions for GitHub Copilot Agents
IMPORTANT: When GitHub Copilot Agent or GitHub Copilot Coding Agent is working on this repository, the following local unit tests MUST be executed to comply with PR checks. Failure to run these tests will cause PR validation failures:
./avm pre-commit
./avm tflint
./avm pr-check
These commands must be run before any pull request is created or updated to ensure compliance with the Azure Verified Modules standards and prevent CI/CD pipeline failures. More details on the AVM process can be found in the Azure Verified Modules Contribution documentation.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 60 lines · 25 tokens per session scan A 6c53ab2bc5d4
Azure AVM Terraform mode is an agent published in the GitHub repository archubbuck/workspace-architect (18 stars, last pushed 5d ago), licensed ISC. It adds 25 tokens to every session and 651 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to Azure AVM Terraform mode, differing in 0 lines, and is treated as a copy.
Other agents, from other repositories
Azure SaaS Architect mode instructions
Provide expert Azure SaaS Architect guidance focusing on multitenant applications using Azure Well-Architected SaaS principles and Microsoft best practices.
edge
Designs CDN configurations, cache strategies, and edge function deployments to minimize latency globally. Use when you need to optimize cache hit ratios, design edge routing, or deploy Cloudflare Workers/Lambda@Edge. Trigger with "design CDN config", "optimize cache strategy".
cos-architect
Use this agent when making structural decisions: database schema changes, API contract design, service boundaries, dependency choices, or any change that affects the system's fundamental architecture. Also use when evaluating technical debt or refactoring proposals. Context: User wants to add a new domain entity user…
hono-architect
Senior Hono architect for designing Edge-first API architecture with TypeScript, Zod validation, and multi-platform support (Bun, Cloudflare Workers).
stack
Full-stack expert for Next.js 15, React 19, and TypeScript.
multi-tenant
Multi-tenant safety and tenant isolation with schoolId scoping.