An infrastructure-change prompt is a review contract for a stateful system. It should name the environment, workspace, resource owner, desired configuration change, expected plan shape, and effects that must block progress. The prompt can draft configuration or inspect a sanitized plan, but it cannot infer that a repository directory points at the intended cloud account. Require the operator to verify the selected workspace and provider identity outside the model before planning. Separate a proposed edit from a reviewed plan and an applied change. Record the current value and target value so an attractive diff does not quietly expand scope to unrelated resources.
Infrastructure prompts: bind scope, owner, and environment
Operational case
A fictional Aster Reports team wants to change queue retention from 47 hours to 71 hours in its production workspace. The queue is managed by the reports platform team. A database in the same workspace is out of scope; any proposed database replacement blocks the change. The prompt asks for the queue address, workspace identity, current and target retention, owner, and expected in-place update. It leaves provider account and workspace confirmation to a trusted operator check. A model cannot establish that the terminal is in production merely because a folder is named prod.
Environment: Aster Reports production; operator verifies workspace/account.
Owned resource: report queue; retention 47h -> 71h.
Expected: one in-place retention update.
Blocked: database replacement, deletion, import, or address move.
Owner: reports platform team; apply requires reviewed plan and receipt.Performance and operating cost
Inspecting R relevant managed resources is O(R) review work, while verifying the target workspace is a separate identity check. A narrow prompt reduces context size and makes an unexpected replacement easier to notice. A plan can contact provider APIs and may expose sensitive values, so a full raw state dump is not a cheap or safe substitute for a targeted summary. Require a human to confirm the environment before any operation that could change remote state.
Common Mistakes
- Do not infer account identity from a directory name.
- Do not let an unrelated database replacement ride with a queue change.
- Do not report configuration text as an applied infrastructure change.
Connected lessons
- Prompt engineering applications
- Prompt Engineering
- Coding prompts: name the files, behavior, and proof
- Tool calls: validate intent and arguments before an external effect
- Terraform state: shared ownership and safe plans
- Infrastructure plans: classify every action before apply
- Infrastructure prompts: quarantine state secrets and drift
- Infrastructure apply: separate review from execution
- Infrastructure release: verify live state and rollback limits
- Project: review an Aster queue retention change
- Infrastructure-change prompt decisions
Continue with: Terminal agents: request only the missing execution scope.
