Usage walkthrough
This walkthrough is a complete end-to-end run: install the CLI, scaffold a project, drive the AI agent through the command workflow, and finish with generated Terraform. It uses the single-application scenario from the scenario examples; substitute any other scenario description to build something larger.
Prerequisites
The sap-iac CLI (see Setup) and an AI agent — Claude Code, Codex, Cursor, or GitHub Copilot. Terraform and Git are recommended but optional.
1 · Scaffold the project
sap-iac init hr-leave --agent claude
cd hr-leave
This creates the specs/, memory/, terraform/, and .sap-iac/ (internal state) directories, a .gitignore, and the sap-iac.* command files for your agent (here, under .claude/commands/). It also creates the editable memory/service-params-catalogue.yaml and prompts for an optional global-account subdomain, saved to memory/global-account.md. Missing Terraform, Git, or MCP servers produce warnings only — the scaffold still succeeds. If anything looks off, see Troubleshooting.
2 · Open the project in your agent
claude
Run the commands below as slash commands inside the agent (/sap-iac.govern, /sap-iac.scenario, and so on), in order.
3 · Run the command workflow
| # | Command | What it does | Writes |
|---|---|---|---|
| ○ | sap-iac.govern |
Set guardrails — regions, naming, service plans, cost policy (optional; recommended first) | memory/governance.md |
| 1 | sap-iac.scenario |
Describe the application (see below) | specs/scenario.md |
| 2 | sap-iac.analyse |
Scan existing source or Terraform to enrich the scenario (optional) | specs/scenario.md |
| 3 | sap-iac.accounts |
Map the application to directories and subaccounts | specs/landscape.md |
| 4 | sap-iac.services |
Resolve the BTP services each subaccount needs | specs/services.md |
| 5 | sap-iac.security |
Set up IdP trust, role collections, and assignments | specs/trust.md |
| 6 | sap-iac.connectivity |
Define destinations and certificates (optional) | specs/connectivity.md |
| 7 | sap-iac.tasks |
Build a dependency-ordered execution plan | specs/tasks.md |
| 8 | sap-iac.design |
Annotate each task with its target Terraform file | specs/tasks.md |
| 9 | sap-iac.generate |
Write and validate all Terraform HCL | terraform/ |
For the scenario step, provide a description. Using the single-application example:
Single-application scenario
"An internal HR leave-request app built with CAP (Node.js) on Cloud Foundry. It stores leave requests in SAP HANA Cloud and authenticates employees via XSUAA. Single environment, one subaccount, region eu10."
When Cloud Foundry is selected, scenario also asks for each application's memory allocation. services converts the total for each subaccount into the required APPLICATION_RUNTIME / MEMORY entitlement. If a service matches memory/service-params-catalogue.yaml, it also asks for the configured instance parameters.
When memory/governance.md is present, accounts, services, security, and generate validate against it and block on applicable violations. Without it, the workflow continues without governance enforcement.
Lost track of where you are?
Run /sap-iac.next any time — it inspects the project files and tells you which command to run next.
4 · Review and apply
The toolkit generates and validates the configuration; applying it against your BTP account remains under your control.
cd terraform
terraform init
terraform plan
Try a larger scenario
Repeat from step 1 with a different name and a more complex description from the scenario examples — multiple environments, external integrations, a multi-application directory, or a full enterprise landing zone. The commands stay the same; only what each one produces grows.