Terraform Specifications

Specifications by Category and Module Classification

CategoryResourcePatternUtility
Contribution/Support988
Telemetry222
Naming/Composition20149
CodeStyle313131
Inputs/Outputs141110
Testing10109
Documentation444
Release/Publishing444
Summary948477

How to propose changes to the specifications?

Important

Any updates to existing or new specifications for Terraform must be submitted as a draft for review by Azure Terraform PG/Engineering(@Azure/terraform-avm) and AVM core team(@Azure/avm-core-team).

AzAPI is mandatory for AVM Terraform modules

Every new AVM Terraform module — resource, pattern, or utility — MUST use the AzAPI provider for every control-plane resource and supported data-plane operation. This applies throughout the module repository, including submodules, examples, end-to-end tests, Terraform tests, fixtures, and documentation snippets.

AzureRM is permitted only for a specific data-plane/non-ARM API operation that AzAPI cannot implement, under the narrow exception in TFFR3. It is never permitted for an ARM control-plane resource or as a convenience alternative to AzAPI.

This requirement is intentional and is driven by the following factors:

  • Built-in retries and error handling. AzAPI exposes first-class retry and timeouts blocks, including regex-based error matching, which lets modules handle transient failures (for example, scope locks being removed or eventual-consistency errors) deterministically and without external workarounds.
  • Pre-flight validation. AzAPI performs ARM API pre-flight checks at plan time, surfacing many configuration errors before an apply is attempted. This produces faster feedback loops and fewer partially-deployed resources.
  • Day-zero access to the latest Azure features. Because AzAPI talks directly to the Azure Resource Manager REST API, modules can adopt new resource types, properties and API versions as soon as they ship in Azure — without waiting for an AzureRM provider release.
  • Alignment with Bicep and ARM. AzAPI uses the same resource type identifiers (e.g. Microsoft.KeyVault/vaults@2023-07-01) and the same property shape as Bicep and ARM templates. This makes it dramatically easier to translate documentation, samples and Bicep modules into Terraform, and keeps Bicep and Terraform AVM modules conceptually aligned.
  • Close partnership with the Azure engineering teams. AzAPI is built and maintained in close collaboration with the Azure Resource Provider engineering teams. Issues in AzAPI can be triaged directly against the underlying ARM behavior, and the AVM team works directly with the AzAPI engineering team on roadmap and breaking changes.
  • Consistency across the AVM ecosystem. Standardizing on AzAPI means every AVM Terraform module uses the same patterns for identity, diagnostic settings, role assignments, locks and private endpoints — primarily through the Azure/avm-utl-interfaces/azure utility module — which simplifies authoring, review and consumer experience.

What changed recently?

See what specifications changed in the last 30 days...

#IDLast Modified (UTC)Git HistoryLast Commit
1TFFR92026-09-04 07:52:46All Commits911dd77
2RMFR72026-09-01 19:58:44All Commits917cf78
3TFFR12026-09-01 19:58:44All Commits917cf78
4TFFR22026-09-01 19:58:44All Commits917cf78
5TFFR32026-09-01 19:58:44All Commits917cf78
6TFFR42026-09-01 19:58:44All Commits917cf78
7TFFR52026-09-01 19:58:44All Commits917cf78
8TFFR62026-09-01 19:58:44All Commits917cf78
9TFFR72026-09-01 19:58:44All Commits917cf78
10TFFR82026-09-01 19:58:44All Commits917cf78
11TFNFR102026-09-01 19:58:44All Commits917cf78
12TFNFR232026-09-01 19:58:44All Commits917cf78
13TFNFR252026-09-01 19:58:44All Commits917cf78
14TFNFR272026-09-01 19:58:44All Commits917cf78
15TFNFR392026-09-01 19:58:44All Commits917cf78
16TFNFR402026-09-01 19:58:44All Commits917cf78
17SNFR202026-09-01 19:06:42All Commits20d0864
18SNFR32026-09-01 19:06:42All Commits20d0864
19SNFR92026-09-01 19:06:42All Commits20d0864
20TFRMNFR12026-08-20 20:03:16All Commitsbd641f6
21TFNFR152026-08-20 20:03:16All Commitsbd641f6
22TFNFR202026-08-20 20:03:16All Commitsbd641f6
23TFNFR212026-08-20 20:03:16All Commitsbd641f6
24TFNFR262026-08-20 20:03:16All Commitsbd641f6
25TFNFR412026-08-20 20:03:16All Commitsbd641f6
26TFNFR82026-08-20 20:03:16All Commitsbd641f6
27TFNFR362026-08-20 19:45:20All Commits6f87e8e
28SFR32026-08-19 12:02:54All Commits5bd25d8
29UMNFR12026-08-19 12:02:54All Commits5bd25d8
30TFNFR72026-08-19 12:02:54All Commits5bd25d8