terraform devops iac sitereliabilityengineering moc
Core Idea
Manual provisioning breaks on inconsistency, errors, and no version control; infrastructure as code fixes that with declarative or imperative automation managed through the full infrastructure lifecycle.
- The problems with manual configurations, then IaC’s answer: declarative, imperative, and declarative plus approaches.
- The infrastructure lifecycle: what it is, Day 0, Day 1, Day 2, and idempotent versus non-idempotent operations.
- Terminology kept straight: provisioning versus deployment versus orchestration.
Problem with Manual Configurations
- Manual Infrastructure Provisioning
- Inconsistency Across Environments
- Lack of Version Control
- Human Errors
- No Dependency Management
- Multi Cloud Complexity
- State Management
Infrastructure as Code (IaC)
You write a configuration script to automate creating, updating, or destroying cloud infrastructure.
-
IaC is a blueprint of your infrastructure
-
IaC allows you to easily share, version, or inventory your cloud infrastructure.
-
Its easy to misconfigure a service through human error
-
Its hard to manage the expected state of configuration for compliance
-
Its hard to transfer configuration knowledge to other team members
Info
Terraform
Infrastructure provisioning
- Cloud resources like servers, networks and databases.
Declarative approach (You describe what you want)
Statefull (Stores current infrastructure state)Ansible
Configuration Management
- installing software and setting up services
Procedural (you describe steps to run)
Stateless by default.
[!video]- Terraform
- Terraform provisions servers →
- Ansible installs and configures software on them
Declarative
- You say what you want, and the rest is filled in. Explicit
- More verbose, but zero chance of misconfiguration
- Uses scripting languages
- eg. JSON, YAML, XML
- Example:
- ARM Templates (Supports Azure Only)
- Azure Blueprints (Supports only Azure)
- CloudFormation (Only for AWS)
- Cloud Deployment Manager (Supports on Google Cloud)
- **Terraform** (Supports many cloud service providers (CSPs) and cloud services)
Imperative
- What you see is what you get. Implicit
- Less verbose, you cloud end up with misconfiguration
- Does more than Declarative
- Uses programming languages eg. Python, Ruby, JavaScript
- Example:
- AWS Cloud Development Kit (CDK)
- Supports only AWS
- Many built-in templates for opinionated best practices
- Pulumi
- Supports AWS, Azure, GCP, K8
- AWS Cloud Development Kit (CDK)
Declarative+
Terraform is declarative but the Terraform Language features imperative-like functionality.

Infrastructure Lifecycle
What is Infrastructure Lifecycle?
the idea of having clearly defined and distinct work phases which are used by DevOps Engineers to plan, design, build, test, and deliver, maintain and retire cloud infrastructure.
What is Day 0, Day 1, and Day 2?
Within the software development lifecycle, Day 0, Day 1, and Day 2 operations refer to each stage of the planning, deployment, and management of software across an organization.
- Day 0 - Plan and Design
- Day 1 - Develop and Iterate
- Day 2 - Go live and maintain
Days do not literally mean a 24 hour day and is just a broadway of defining where infrastructure project would be.

How does IaC enhance the Infrastructure Lifecycle?
- Reliability: IaC makes changes idempotent1, consistent, repeatable, and predictable.
- Idempotent: No matter how many times you run IaC, you will always end up with the same state that is expected
- Manageability
- enable mutation via code
- revised, with minimal changes
- Sensibility
- avoid financial and reputational losses to even loss of life when considering government and military dependencies on infrastructure
Idempotent vs non-Idempotent

Provisioning vs Deployment vs Orchestration
Provisioning
To prepare a server with systems, data, and software, and make it ready for network operation.
Using Configuration Management tools like Puppet, Ansible, Chef, Bash scripts, PowerShell, or Cloud-Init you can provision a server.
**When you launch a cloud service and configure it you are “provisioning”**
Deployment
Deployment is the act of delivering a version of your application to run a provisioned server.
Deployment could be performed via AWS CodePipline, Harness, Jenkins, Github Actions, CircleCI
Orchestration
Orchestration is the act of coordinating multiple systems or services.
Orchestration is a common term when working with microservices, Containers, and Kubernetes.
Orchestration could be Kubernetes, Salt, Fabric
Configuration Drift
Configuration Drift is when provisioned infrastructure has an unexpected configuration change due to:
- team members manually adjusting configuration options
- malicious actors
- side effects from APIs, SDK, or CLIs.
eg. a junior developer turns on Delete on Termination for the production database.
Configuration Drift going unnoticed could be a loss or breach of cloud services and residing data or result in interruption of services or unexpected downtime.
How to detect configuration drift?
- A compliance tool that can detect misconfiguration eg. AWS Config, Azure Policies, *GCP Security Health Analytics
- Built-in support for drift detection eg. AWS CloudFormation Drift Detection
- Storing the expected state eg. Terraform state files
How to correct configuration drift?
- A compliance tool that can remediate (correct) misconfiguration e.g. AWS Config
- Terraform refresh and plan commands
- Manually correcting the configuration (not recommended)
- Tearing down and setting up the infrastructure again
Note: Terraform refresh command is not recommended
Please use the alias command: terraform apply -refresh-only -auto-approve or terraform apply -refresh-only
https://www.terraform.io/cli/commands/refresh#usage
How to prevent configuration drift?
- Immutable infrastructure, always create and destroy, never reuse, Blue, Green deployment strategy.
- Servers are never modified after they are deployed
- Baking AMI images or containers via AWS Image Builder or HashiCorp Packer, or a build server eg. GCP Cloud Run
- Using GitOps to version control our IaC, and peer review every single via Pull Requests change to infrastructure
Mutable vs Immutable Infrastrure

HCP Packer
- Image as Code
- Packer standardizes and automates the process of building system and container images.
GitOps
GitOps is when you take Infrastructure as Code (IaC) and you use a git repository to introduce a formal process to review and accept changes to infrastructure code, once that code is accepted, it automatically triggers a deploy.
See
GitOps Workflow
Terraform
Immutable Infrastructure Guarantee
Terraform encourages you towards an Immutable Infrastructure architect so you get the following guarantees.
- Cloud Resource Failure - What if an EC2 instance fails a status check?
- Application Failure - What if your post-installation script fails due to a change in a package?
- Time to Deploy - What if I need to deploy in a hurry?
Worst Case Scenario
- Accidental Deletion
- Compromised by a malicious actor
- Need to Change Regions (region outage)
No Guarantee of 1-to-1
Every time Cloud-Init runs post-deploy there is no guarantee it’s one-to-one with your other VMs.
Golden Images
- Guarantee of 1-to-1 with your fleet
- Increased assurance of consistency, security
- Speeds up your deployments
HashiCorp
HashiCorp is a company specializing in managed open-source tools used to support the development and deployment of large-scale service-oriented software installations
What is HashiCorp Cloud Platform (HCP)?
HCP is a unified platform to access Hashicorp’s various products.
HCP services are cloud-agnostic
- support for the main cloud service providers (CSPs)
- eg. AWS, GCP, and Azure
- highly suited for multi-cloud workloads
HashiCorp Products
Boundary
- secure remote access to systems based on trusted identity.
Consul- service discovery platform. provides a full-featured service mesh for secure service segmentation across any cloud or runtime environment, and distributed key-value storage for application configuration
Nomad- scheduling and deployment of tasks across worker nodes in a cluster
Packer- tool for building virtual machine images for later deployment.
Terraform- infrastructure as code software which enables provisioning and adapting virtual infrastructure across all major cloud provider
Terraform Cloud- a place to store and manage IaC in the cloud or with teams
Vagrant- building and maintenance of reproducible software-development environments via virtualization technology
Vault- secrets management, identity-based access, encrypting application data, and auditing of secrets for applications, systems, and users
Waypoint- modern workflow to build, deploy, and release across platforms
What is Terraform?
Terraform is an open-source and cloud-agnostic Infrastructure as Code tool.
Terraform uses declarative configuration files.
The configuration files are written in HashiCorp Configuration Language (HCL).
Notable features of Terraform:
- Installable modules
- Plan and predict changes
- Dependency graphing
- State management
- Provision infrastructure in familiar languages
- via AWS CDK
- Terraform Registry with 1000+ providers
What is Terraform Cloud

How to Terraform Generate Password: Easy Guide
Master Terraform Null Resource
Terraform Module vs Resource: The Ultimate Difference
How to Use Terraform Concat Function: Practical Examples & Best Practice
Terraform Prevent Destroy: Safeguard Critical Resources
Terraform Base64 Encode: A Comprehensive Guide
Terraform Destroy Specific Resource: Simple Guide
One Function in Terraform: Easy Guide
Terraform Wait for Resource: A Comprehensive Guide
Footnotes
-
Idempotence (UK: /ˌɪdɛmˈpoʊtəns/, US: /ˈaɪdəm-/) is the property of certain operations in mathematics and computer science whereby they can be applied multiple times without changing the result beyond the initial application. ↩

