Terraform terraform
Search the Terraform registry for providers, modules and policies, and read and manage HCP Terraform workspaces when given a token.
- Homepage
- https://github.com/hashicorp/terraform-mcp-server
- License
- MPL-2.0
- Runtime
native, transportstdio- Categories
- infrastructure
Versions
| Version | Published | Runtime | Blobs |
|---|---|---|---|
| 1.3.0 | 2026-10-06T14:04:59Z | native |
linux/amd64
269ad69c43e0db455183fbbcdd7a34177996fde2b08730437e14dd1606bd1baf 8.9 MiB
curl -fsSLO https://library.pellum.ai/blobs/sha256/269ad69c43e0db455183fbbcdd7a34177996fde2b08730437e14dd1606bd1baf |
Parameters
| Name | Type | Environment | Required | Secret | Description |
|---|---|---|---|---|---|
tfe_token | string | TFE_TOKEN | no | yes | HCP Terraform or Terraform Enterprise API token. Without it only the registry tools are available. |
tfe_address | string | TFE_ADDRESS | no | no | Terraform Enterprise base URL. Leave unset for HCP Terraform; a self-hosted address also needs an egress override. |
Credentials
The server verifies no caller token. The executor's sandbox and listener are the controls on who may call it.
Egress
| Destination | Port | Reason |
|---|---|---|
registry.terraform.io | default web ports | provider, module and policy documentation from the public registry |
app.terraform.io | default web ports | HCP Terraform workspaces, runs and variables when a token is set |
A host of the form ${param.host} is the host of a URL the operator supplies, resolved by the gateway at claim time. The library never knows it.
Resource defaults
memory.max 256Mi, pids.max 128, cpu.max 100000 100000.
Verify a download
Against the library key, which is what a gateway checks:
curl -fsSLO https://library.pellum.ai/blobs/sha256/269ad69c43e0db455183fbbcdd7a34177996fde2b08730437e14dd1606bd1baf curl -fsSLO https://library.pellum.ai/blobs/sha256/269ad69c43e0db455183fbbcdd7a34177996fde2b08730437e14dd1606bd1baf.sig curl -fsSLO https://library.pellum.ai/keys/library-v1.pub echo "269ad69c43e0db455183fbbcdd7a34177996fde2b08730437e14dd1606bd1baf 269ad69c43e0db455183fbbcdd7a34177996fde2b08730437e14dd1606bd1baf" | sha256sum -c - cosign verify-blob --insecure-ignore-tlog --key library-v1.pub --signature 269ad69c43e0db455183fbbcdd7a34177996fde2b08730437e14dd1606bd1baf.sig 269ad69c43e0db455183fbbcdd7a34177996fde2b08730437e14dd1606bd1baf