Mark HollandSenior AI Solutions Engineer

Cloud CLI Command Forge

PrototypeMy own project

Cloud CLI Command Forge is a Next.js web app I built that turns a plain-English request into an AWS, Azure, or Google Cloud CLI command, or into Terraform, using an AI model. It writes and checks, and it never touches a cloud account.

CLIForge command generator with Google Cloud and CLI output selected, the request 'list all virtual machines in my dev project', and the generated command gcloud compute instances list.

What it does

  • VerifiedTurns a plain-English request into an AWS, Azure, or Google Cloud CLI command, or the same task for all three, using an AI model.
  • VerifiedWrites Terraform in a guided flow: the model names the infrastructure pattern, the app asks follow-up questions, then it generates the files.
  • VerifiedThe test step never runs a command. It returns the expected result marked [SIMULATED], after checking that a local emulator is running for AWS or Azure.
  • VerifiedA validate step runs terraform init and terraform validate on the generated files in a temporary folder, or a built-in syntax check when asked.
  • VerifiedA syntax check per cloud flags a missing resource group, region, or project, and warns on any command that deletes, terminates, or removes.

From the app's own materials. Facts marked Verified were checked against the code or a working copy of the app.

Who it is for

Me and one teammate, through a temporary preview link. It was never opened to other users.

The problem

  • Cloud work means the same kinds of commands again and again: create a resource group, tag it, list what is running.
  • AWS, Azure, and Google Cloud each use their own verbs and flags, and even different words: tags on AWS and Azure, labels on Google Cloud.
  • A model that writes commands is only safe to use if nothing it writes can run by accident.

How it works

Cloud CLI Command Forge, step by step
  1. Ask

    Pick AWS, Azure, Google Cloud, or all three, and describe the task in plain English.

  2. Write

    The server sends the request with instructions for that cloud to an AI model at a low temperature and gets back only the command.

  3. Check

    A syntax check per cloud flags a missing resource group, region, or project, and warns on delete, terminate, or remove.

  4. Simulate

    A test step returns the expected result marked [SIMULATED]. The command itself never runs.

  5. Terraform

    For infrastructure, the model names the pattern, the app asks follow-up questions, and then it writes the Terraform files.

  6. Validate

    A validate step runs terraform init and terraform validate on those files in a temporary folder.

  7. Run

    I copy the command or the files and run them myself.

The real screens

Real screens from a local run on September 30, 2026, with invented requests and names.

CLIForge command generator with Google Cloud and CLI output selected, the request 'list all virtual machines in my dev project', and the generated command gcloud compute instances list.
Demo dataDemo mode, no AI model: a plain-English request turned into a gcloud command.
Two generated AWS commands that create a versioned S3 bucket, with a Security Analysis panel warning to consider enabling S3 encryption.
Demo dataThe built-in security check flags a missing encryption setting. Demo mode output; the simulated test run has no screen yet.
Diagram: my plain-English request goes to the CLIForge web app, where an AI model writes AWS, Azure, or Google Cloud commands or Terraform files, with a simulated test run and a terraform validate check. The commands and files are copied out, and I run them against the cloud accounts myself.
Design diagramThe app writes and checks. It never connects to a cloud account; I run the commands myself.
Terraform code for an Azure Linux virtual machine scale set, with the name, resource group, location, and instance count taken from variables.
Demo dataOne of the Terraform templates built into the app's pattern library.

What it covers

Three clouds and Terraform

One request box, four targets.

  • AWS

    AWS CLI commands with region flags, including tags for EC2, S3, and RDS.

  • Azure

    Azure CLI commands with the resource group and subscription context they need.

  • Google Cloud

    gcloud commands with projects and zones, using labels where AWS and Azure use tags.

  • All three

    The same task written for each cloud, side by side.

  • Terraform

    A guided flow that ends in Terraform files, plus a library of built-in templates for common patterns.

How the checks work

A simulated run and a real validate

Two checks, and neither one touches a cloud account.

  • Simulated run

    For AWS and Azure the test step first checks that a local emulator is running (LocalStack or Azurite), then returns the expected output marked [SIMULATED]. Google Cloud has no emulator here, so it goes straight to the simulated output.

  • terraform validate

    The validate step writes the files to a temporary folder and runs terraform init and terraform validate -json. That checks the configuration without any cloud credentials.

  • Basic check

    The same step can run a built-in syntax and best-practice check instead, without Terraform.

  • Status

    Both checks are built as server steps. In the prototype, the main screens do not have a button for them yet.

Design decisions

Why it is built this way

  • Only the command, at a low temperature

    The model is told to return just the command, with no explanation or markdown, at temperature 0.1, so the output can be copied as it is.

  • Terraform checked by Terraform

    Generated files go through the real terraform validate, not only the model's own judgment.

The decision that matters

It never runs a command

The test step returns a simulated result instead of calling a cloud account, so nothing the model writes can change anything by accident. Running a command stays a separate step that I take myself.

Built with

  • Next.js
  • TypeScript
  • Tailwind CSS
  • Supabase
  • OpenRouter (Claude)
  • Terraform CLI
  • LocalStack and Azurite