"If it's not in Git, it doesn't exist."
What is Infrastructure as Code?
Managing and provisioning infrastructure through machine-readable definition files rather than manual processes.
Core Principles
Declarative > Imperative
- Declarative โ Describe desired state, tool figures out how
- Imperative โ Describe steps to achieve state
Immutable Infrastructure
- Never modify running infrastructure
- Replace instead of update
- Every change is a new deployment
Version Control
- All infrastructure code in Git
- Pull requests for changes
- Audit trail of who changed what when
Key Concepts
State Management
- Local state โ Simple but dangerous (drift, conflicts)
- Remote state โ Shared, locked, versioned (S3, GCS, Terraform Cloud)
- State locking โ Prevent concurrent modifications
Drift Detection
- Actual infrastructure diverges from code
- Causes: manual changes, failed applies, external systems
- Solutions: regular plan/diff, automated remediation
Modules and Reusability
modules/
โโโ vpc/ # Reusable VPC module
โโโ eks-cluster/ # Reusable EKS module
โโโ rds/ # Reusable RDS module
environments/
โโโ dev/ # Uses modules
โโโ staging/ # Uses modules
โโโ prod/ # Uses modules
Topics
- โ Terraform fundamentals
- โ State management strategies
- โ Module design patterns
- โ Environment promotion
- โ Secret management in IaC
- โ Testing infrastructure code
- โ Policy as code (OPA, Sentinel)
- โ GitOps workflows
- โ Drift detection and remediation
- โ Cost estimation in IaC
GitOps
Pull-Based Deployment
Git Repo โ GitOps Operator โ Kubernetes
(ArgoCD/Flux)
Benefits
- Single source of truth
- Audit log built-in
- Easy rollback (git revert)
- Self-healing (reconciliation loop)
Tools
| Tool | Purpose |
|---|---|
| Terraform | Multi-cloud IaC |
| Pulumi | IaC with real programming languages |
| CloudFormation | AWS-native IaC |
| Ansible | Configuration management |
| ArgoCD | Kubernetes GitOps |
| Flux | Kubernetes GitOps |
| Crossplane | Kubernetes-native IaC |
Directory Structure
infrastructure/
โโโ modules/ # Reusable components
โ โโโ networking/
โ โโโ compute/
โ โโโ database/
โโโ environments/ # Environment-specific
โ โโโ dev/
โ โโโ staging/
โ โโโ prod/
โโโ policies/ # OPA/Sentinel policies
โโโ .github/workflows/ # CI/CD for infrastructure
Anti-Patterns
- ClickOps (manual console changes)
- Monolithic configurations
- Hardcoded values
- No state locking
- Secrets in code
- No environment separation
CI/CD for Infrastructure
# Example GitHub Actions workflow
on: pull_request
jobs:
terraform:
steps:
- terraform fmt -check
- terraform init
- terraform validate
- terraform plan
- # Apply only on merge to main
Reading
- Terraform: Up & Running (O'Reilly)
- Infrastructure as Code (O'Reilly)
- Google SRE Book: Chapter 8 (Release Engineering)
Regulatory and control mappings
- ISO 27001 Annex A.8 Technological Controls A.8.9 Configuration management. A.8.32 Change management. A.8.31 Separation of dev/test/prod environments.
- NIS2 Security Measures Art 21(e) secure development.
- DORA ICT Risk Management Art 9 protection (configuration).
- ITIL 4 Practices Service Configuration Management + Deployment Management + Change Enablement.
- SLSA SBOM Cluster โ supply chain integrity for IaC modules and dependencies.