Terraform Specifications

Specifications by Category and Module Classification

CategoryResourcePatternUtility
Contribution/Support988
Telemetry222
Naming/Composition20149
CodeStyle313131
Inputs/Outputs141110
Testing10109
Documentation444
Release/Publishing444
Summary948477

How to propose changes to the specifications?

Important

Any updates to existing or new specifications for Terraform must be submitted as a draft for review by Azure Terraform PG/Engineering(@Azure/terraform-avm) and AVM core team(@Azure/avm-core-team).

AzAPI is mandatory for AVM Terraform modules

Every new AVM Terraform module — resource, pattern, or utility — MUST use the AzAPI provider for every control-plane resource and supported data-plane operation. This applies throughout the module repository, including submodules, examples, end-to-end tests, Terraform tests, fixtures, and documentation snippets.

AzureRM is permitted only for a specific data-plane/non-ARM API operation that AzAPI cannot implement, under the narrow exception in TFFR3. It is never permitted for an ARM control-plane resource or as a convenience alternative to AzAPI.

This requirement is intentional and is driven by the following factors:

  • Built-in retries and error handling. AzAPI exposes first-class retry and timeouts blocks, including regex-based error matching, which lets modules handle transient failures (for example, scope locks being removed or eventual-consistency errors) deterministically and without external workarounds.
  • Pre-flight validation. AzAPI performs ARM API pre-flight checks at plan time, surfacing many configuration errors before an apply is attempted. This produces faster feedback loops and fewer partially-deployed resources.
  • Day-zero access to the latest Azure features. Because AzAPI talks directly to the Azure Resource Manager REST API, modules can adopt new resource types, properties and API versions as soon as they ship in Azure — without waiting for an AzureRM provider release.
  • Alignment with Bicep and ARM. AzAPI uses the same resource type identifiers (e.g. Microsoft.KeyVault/vaults@2023-07-01) and the same property shape as Bicep and ARM templates. This makes it dramatically easier to translate documentation, samples and Bicep modules into Terraform, and keeps Bicep and Terraform AVM modules conceptually aligned.
  • Close partnership with the Azure engineering teams. AzAPI is built and maintained in close collaboration with the Azure Resource Provider engineering teams. Issues in AzAPI can be triaged directly against the underlying ARM behavior, and the AVM team works directly with the AzAPI engineering team on roadmap and breaking changes.
  • Consistency across the AVM ecosystem. Standardizing on AzAPI means every AVM Terraform module uses the same patterns for identity, diagnostic settings, role assignments, locks and private endpoints — primarily through the Azure/avm-utl-interfaces/azure utility module — which simplifies authoring, review and consumer experience.

What changed recently?

See what specifications changed in the last 30 days...

#IDLast Modified (UTC)Git HistoryLast Commit
1TFFR52026-08-20 22:31:25All Commitsce104d8
2RMFR72026-08-20 20:03:16All Commitsbd641f6
3TFRMNFR12026-08-20 20:03:16All Commitsbd641f6
4TFFR12026-08-20 20:03:16All Commitsbd641f6
5TFFR22026-08-20 20:03:16All Commitsbd641f6
6TFFR32026-08-20 20:03:16All Commitsbd641f6
7TFFR42026-08-20 20:03:16All Commitsbd641f6
8TFFR62026-08-20 20:03:16All Commitsbd641f6
9TFFR72026-08-20 20:03:16All Commitsbd641f6
10TFFR82026-08-20 20:03:16All Commitsbd641f6
11TFFR92026-08-20 20:03:16All Commitsbd641f6
12TFNFR102026-08-20 20:03:16All Commitsbd641f6
13TFNFR152026-08-20 20:03:16All Commitsbd641f6
14TFNFR202026-08-20 20:03:16All Commitsbd641f6
15TFNFR212026-08-20 20:03:16All Commitsbd641f6
16TFNFR232026-08-20 20:03:16All Commitsbd641f6
17TFNFR252026-08-20 20:03:16All Commitsbd641f6
18TFNFR262026-08-20 20:03:16All Commitsbd641f6
19TFNFR272026-08-20 20:03:16All Commitsbd641f6
20TFNFR392026-08-20 20:03:16All Commitsbd641f6
21TFNFR402026-08-20 20:03:16All Commitsbd641f6
22TFNFR412026-08-20 20:03:16All Commitsbd641f6
23TFNFR82026-08-20 20:03:16All Commitsbd641f6
24TFNFR362026-08-20 19:45:20All Commits6f87e8e
25SFR32026-08-19 12:02:54All Commits5bd25d8
26UMNFR12026-08-19 12:02:54All Commits5bd25d8
27TFNFR72026-08-19 12:02:54All Commits5bd25d8
28TFNFR52026-08-10 16:48:22All Commits43fb148