5. Infrastructure as Code

Vault note, not reviewed against the source. Written in the knowledge vault on 2026-04-25 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.

"If it's not in Git, it doesn't exist."

What is Infrastructure as Code?

Managing and provisioning infrastructure through machine-readable definition files rather than manual processes.

Core Principles

Declarative > Imperative

  • Declarative โ€” Describe desired state, tool figures out how
  • Imperative โ€” Describe steps to achieve state

Immutable Infrastructure

  • Never modify running infrastructure
  • Replace instead of update
  • Every change is a new deployment

Version Control

  • All infrastructure code in Git
  • Pull requests for changes
  • Audit trail of who changed what when

Key Concepts

State Management

  • Local state โ€” Simple but dangerous (drift, conflicts)
  • Remote state โ€” Shared, locked, versioned (S3, GCS, Terraform Cloud)
  • State locking โ€” Prevent concurrent modifications

Drift Detection

  • Actual infrastructure diverges from code
  • Causes: manual changes, failed applies, external systems
  • Solutions: regular plan/diff, automated remediation

Modules and Reusability

modules/
โ”œโ”€โ”€ vpc/           # Reusable VPC module
โ”œโ”€โ”€ eks-cluster/   # Reusable EKS module
โ””โ”€โ”€ rds/           # Reusable RDS module

environments/
โ”œโ”€โ”€ dev/           # Uses modules
โ”œโ”€โ”€ staging/       # Uses modules
โ””โ”€โ”€ prod/          # Uses modules

Topics

  • โ˜ Terraform fundamentals
  • โ˜ State management strategies
  • โ˜ Module design patterns
  • โ˜ Environment promotion
  • โ˜ Secret management in IaC
  • โ˜ Testing infrastructure code
  • โ˜ Policy as code (OPA, Sentinel)
  • โ˜ GitOps workflows
  • โ˜ Drift detection and remediation
  • โ˜ Cost estimation in IaC

GitOps

Pull-Based Deployment

Git Repo โ†’ GitOps Operator โ†’ Kubernetes
         (ArgoCD/Flux)

Benefits

  • Single source of truth
  • Audit log built-in
  • Easy rollback (git revert)
  • Self-healing (reconciliation loop)

Tools

ToolPurpose
TerraformMulti-cloud IaC
PulumiIaC with real programming languages
CloudFormationAWS-native IaC
AnsibleConfiguration management
ArgoCDKubernetes GitOps
FluxKubernetes GitOps
CrossplaneKubernetes-native IaC

Directory Structure

infrastructure/
โ”œโ”€โ”€ modules/           # Reusable components
โ”‚   โ”œโ”€โ”€ networking/
โ”‚   โ”œโ”€โ”€ compute/
โ”‚   โ””โ”€โ”€ database/
โ”œโ”€โ”€ environments/      # Environment-specific
โ”‚   โ”œโ”€โ”€ dev/
โ”‚   โ”œโ”€โ”€ staging/
โ”‚   โ””โ”€โ”€ prod/
โ”œโ”€โ”€ policies/          # OPA/Sentinel policies
โ””โ”€โ”€ .github/workflows/ # CI/CD for infrastructure

Anti-Patterns

  • ClickOps (manual console changes)
  • Monolithic configurations
  • Hardcoded values
  • No state locking
  • Secrets in code
  • No environment separation

CI/CD for Infrastructure

# Example GitHub Actions workflow
on: pull_request
jobs:
  terraform:
    steps:
      - terraform fmt -check
      - terraform init
      - terraform validate
      - terraform plan
      - # Apply only on merge to main

Reading

  • Terraform: Up & Running (O'Reilly)
  • Infrastructure as Code (O'Reilly)
  • Google SRE Book: Chapter 8 (Release Engineering)

Regulatory and control mappings

Atoms