Terraform MCP Server

Official

by hashicorp

1.5k 723 downloads Not rated yet MPL-2.0

About

The Terraform MCP Server provides seamless integration with Terraform ecosystem, enabling advanced automation and interaction capabilities for Infrastructure as Code (IaC) development.

Details

License
MPL-2.0

Explore

- Dual Transport Support: Both Stdio and StreamableHTTP transports with configurable endpoints
- Terraform Registry Integration: Direct integration with public Terraform Registry APIs for providers, modules, and policies
- HCP Terraform & Terraform Enterprise Support: Full workspace management, organization/project listing, and private registry access
- Workspace Operations: Create, update, delete workspaces with support for variables, tags, and run management
- OTel metrics for monitoring tool usage: Integration with open telemetry meters to track tool-call volume, latency and failures in Streamable HTTP mode. Also exposes default http server metrics when this feature is enabled

> Security Note: Depending on the query, the MCP server may expose certain Terraform data to the MCP client and LLM. Do not use the MCP server with untrusted MCP clients or LLMs.

> Legal Note: Your use of a third party MCP Client/LLM is subject solely to the terms of use for such MCP/LLM, and IBM is not responsible for the performance of such third party tools. IBM expressly disclaims any and all warranties and liability for third party MCP Clients/LLMs, and may not be able to provide support to resolve issues which are caused by the third party tools.

> Caution: The outputs and recommendations provided by the MCP server are generated dynamically and may vary based on the query, model, and the connected MCP client. Users should thoroughly review all outputs/recommendations to ensure they align with their organization’s security best practices, cost-efficiency goals, and compliance requirements before implementation.

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name Terraform MCP Server
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

From the repository

Prerequisites

1. Ensure Docker is installed and running to use the server in a containerized environment.
1. Install an AI assistant that supports the Model Context Protocol (MCP).

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "terraform mcp server": {
            "terraform-mcp-server": {
                "command": "docker",
                "args": [
                    "run",
                    "-p",
                    "8080:8080",
                    "--rm",
                    "-e",
                    "TRANSPORT_MODE=streamable-http",
                    "-e",
                    "TRANSPORT_HOST=0.0.0.0",
                    "hashicorp/terraform-mcp-server"
                ]
            }
        }
    }
}

McpServers

{
    "terraform-mcp-server": {
        "command": "docker",
        "args": [
            "run",
            "-p",
            "8080:8080",
            "--rm",
            "-e",
            "TRANSPORT_MODE=streamable-http",
            "-e",
            "TRANSPORT_HOST=0.0.0.0",
            "hashicorp/terraform-mcp-server"
        ]
    }
}

The Terraform MCP Server is a Model Context Protocol (MCP)
server that provides seamless integration with Terraform Registry APIs, enabling advanced
automation and interaction capabilities for Infrastructure as Code (IaC) development.

Features

- Dual Transport Support: Both Stdio and StreamableHTTP transports with configurable endpoints
- Terraform Registry Integration: Direct integration with public Terraform Registry APIs for providers, modules, and policies
- HCP Terraform & Terraform Enterprise Support: Full workspace management, organization/project listing, and private registry access
- Workspace Operations: Create, update, delete workspaces with support for variables, tags, and run management
- OTel metrics for monitoring tool usage: Integration with open telemetry meters to track tool-call volume, latency and failures in Streamable HTTP mode. Also exposes default http server metrics when this feature is enabled

> Security Note: Depending on the query, the MCP server may expose certain Terraform data to the MCP client and LLM. Do not use the MCP server with untrusted MCP clients or LLMs.

> Legal Note: Your use of a third party MCP Client/LLM is subject solely to the terms of use for such MCP/LLM, and IBM is not responsible for the performance of such third party tools. IBM expressly disclaims any and all warranties and liability for third party MCP Clients/LLMs, and may not be able to provide support to resolve issues which are caused by the third party tools.

> Caution: The outputs and recommendations provided by the MCP server are generated dynamically and may vary based on the query, model, and the connected MCP client. Users should thoroughly review all outputs/recommendations to ensure they align with their organization’s security best practices, cost-efficiency goals, and compliance requirements before implementation.

Prerequisites

1. Ensure Docker is installed and running to use the server in a containerized environment.
1. Install an AI assistant that supports the Model Context Protocol (MCP).

Command Line Options

Environment Variables:

| Variable | Description | Default |
|----------|-------------|---------|
| TFE_ADDRESS | HCP Terraform or TFE address | "https://app.terraform.io" |
| TFE_TOKEN | Terraform Enterprise API token | "" (empty) |
| TFE_SKIP_TLS_VERIFY | Skip HCP Terraform or Terraform Enterprise TLS verification | false |
| LOG_LEVEL | Logging level: trace, debug, info, warn, error, fatal, panic (overrides --log-level flag) | info |
| LOG_FORMAT | Logging format: text or json (overrides --log-format flag)| text |
| TRANSPORT_MODE | Set to streamable-http to enable HTTP transport (legacy http value still supported) | stdio |
| TRANSPORT_HOST | Host to bind the HTTP server | 127.0.0.1 |
| TRANSPORT_PORT | HTTP server port | 8080 |
| MCP_ENDPOINT | HTTP server endpoint path | /mcp |
| MCP_KEEP_ALIVE | Keep-alive interval for SSE connections (e.g., 30s, 1m). 0 to disable | 0 |
| MCP_SESSION_MODE | Session mode: stateful or stateless | stateful |
| MCP_ALLOWED_ORIGINS | Comma-separated list of allowed origins for CORS | "" (empty) |
| MCP_CORS_MODE | CORS mode: strict, development, or disabled | strict |
| MCP_TLS_CERT_FILE | Path to TLS cert file, required for non-localhost deployment (e.g. /path/to/cert.pem) | "" (empty) |
| MCP_TLS_KEY_FILE | Path to TLS key file, required for non-localhost deployment (e.g. /path/to/key.pem)| "" (empty) |
| MCP_RATE_LIMIT_GLOBAL | Global rate limit (format: rps:burst) | 10:20 |
| MCP_RATE_LIMIT_SESSION | Per-session rate limit (format: rps:burst) | 5:10 |
| MCP_ORGANIZATION_ALLOWLIST | CSV list of HCP Terraform organization names allowed to access the HTTP server | "" (empty) |
| ENABLE_TF_OPERATIONS | Enable tools that require explicit approval | false |
| OTEL_METRICS_ENABLED | Enable tools and server metrics using otel | false |
| OTEL_METRICS_SERVICE_VERSION | Version of the terraform-mcp-server sending metrics, which is used to set metric attributes. It also helps track metrics across different deployments | latest |
| OTEL_METRICS_SERVICE_NAME | Identifies the source of the metrics (e.g., "terraform-mcp-server") | terraform-mcp-server |
| OTEL_METRICS_EXPORT_INTERVAL | Controls the frequency of metric flushes | 2 |
| OTEL_METRICS_ENDPOINT | URL of your OTel Collector or backend | localhost:4318 |

```bash

No reviews yet — be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.

Videos about Terraform MCP Server

Relevant YouTube tutorials, setups, and demos