πŸ—οΈ
Active Module Path

Terraform

From the declarative model to a production three-tier build β€” providers, plans, state, modules, delivery pipelines and the failure modes that cause real outages.

22 lessons 454 min syllabus

Stage 1 β€” Foundations

3 lessons
Lesson 1 β€’ ⏱️ 16m
Why Infrastructure as Code

What manual infrastructure management actually costs, why declarative beats procedural for provisioning, where Terraform sits relative to configuration management, and the two-part architecture that explains most of its behaviour.

βœ“
Lesson 2 β€’ ⏱️ 20m
Providers, Resources & Your First Apply

The two blocks every configuration starts with, why pinning provider versions is not optional, how resource references build the dependency graph for free, and the lifecycle meta-arguments that control replacement.

βœ“
Lesson 3 β€’ ⏱️ 19m
Reading and Trusting the Plan

The four plan symbols and which two should stop you, why 'forces replacement' is the most important string in the output, the graph and parallelism, and the difference between applying a saved plan file and using auto-approve.

βœ“

Stage 2 β€” The Terraform Language

4 lessons
Lesson 4 β€’ ⏱️ 20m
Variables, Types & Precedence

All eight variable types including the structural ones, why declaring a type prevents a class of silent coercion bugs, validation blocks, and the assignment precedence order that decides which value actually wins.

βœ“
Lesson 5 β€’ ⏱️ 18m
Locals, Outputs & Data Sources

The three constructs that stop a configuration repeating itself: named expressions, return values, and read-only lookups of infrastructure you do not manage β€” plus why you should never compute a value you could reference.

βœ“
Lesson 6 β€’ ⏱️ 18m
Expressions, Functions & Templates

Conditional expressions, the built-in function library you actually reach for, heredoc strings, externalising policy files, and rendering templates with variables and loops.

βœ“
Lesson 7 β€’ ⏱️ 20m
count, for_each & Dynamic Blocks

How to create many resources from one block, why choosing count over for_each is the most common self-inflicted outage in Terraform, migrating between them safely, and when generating nested blocks stops being worth it.

βœ“

Stage 3 β€” State

3 lessons
Lesson 8 β€’ ⏱️ 18m
What State Is and Why It Must Exist

The four reasons Terraform cannot work by reading the world on every run, what state actually contains, why it holds your secrets in plain text, and the inspection commands that tell you what Terraform believes.

βœ“
Lesson 9 β€’ ⏱️ 20m
Remote Backends & Locking

Why local state stops working the moment a second person appears, the backend options and their locking mechanisms, partial configuration for keeping secrets out of the repo, and migrating an existing project without losing anything.

βœ“
Lesson 10 β€’ ⏱️ 22m
Import, State Surgery & Drift

Bringing hand-built infrastructure under management, moving resources between projects without destroying them, detecting out-of-band changes, and why Terraform has no rollback command.

βœ“

Stage 4 β€” Structure & Reuse

3 lessons
Lesson 11 β€’ ⏱️ 22m
Modules

Packaging resources into reusable units, module inputs and outputs as a public interface, sourcing from registries and Git, why pinning with a ref tag is not optional, and how deep to nest before it stops paying.

βœ“
Lesson 12 β€’ ⏱️ 19m
Project Layout & Multi-Environment Patterns

How Terraform actually treats files and folders, the four ways to model dev/staging/prod and when each breaks down, and why splitting state along team boundaries is an organisational decision more than a technical one.

βœ“
Lesson 13 β€’ ⏱️ 16m
Workspaces

Multiple state instances from one configuration directory, referencing the active workspace in code, the delete command that removes state but not infrastructure, and the point at which workspaces stop scaling.

βœ“

Stage 5 β€” Delivery

3 lessons
Lesson 14 β€’ ⏱️ 18m
Provisioners & the Config-Management Boundary

Why every source warns that provisioners are a last resort, the structural reason behind it, creation-time versus destroy-time behaviour, and the three better alternatives ranked.

βœ“
Lesson 15 β€’ ⏱️ 21m
Testing, Validation & CI/CD

The three testing tiers and which tool serves each, static analysis that costs nothing, and the pipeline design whose single most important property is passing a reviewed plan file to apply.

βœ“
Lesson 16 β€’ ⏱️ 19m
Policy as Code & Compliance

Writing compliance rules that evaluate a plan before it applies, the two policy ecosystems, and turning drift detection and audit logging into continuous compliance rather than an annual scramble.

βœ“

Stage 6 β€” Production & Operations

5 lessons
Lesson 17 β€’ ⏱️ 20m
Security & Secrets Management

The three places secrets leak in a Terraform workflow and the three different fixes, why sensitive = true is not a secrets strategy, and locking down the state backend as the production-admin boundary it actually is.

βœ“
Lesson 18 β€’ ⏱️ 22m
Multi-Cloud, Hybrid & Platform Provisioning

Managing several providers from one configuration, connecting on-premises networks to cloud, provisioning Kubernetes clusters and serverless functions, and where to draw the line between infrastructure and application delivery.

βœ“
Lesson 19 β€’ ⏱️ 21m
DR, HA, Cost & Monitoring

Encoding disaster recovery and high availability as code, automating backups and failover, the cost levers Terraform can pull, and wiring alerting alongside the resource it watches.

βœ“
Lesson 20 β€’ ⏱️ 18m
Performance, Scale & Extending Terraform

What slows down large estates and the four levers that fix it, managing state size, and writing a custom provider when nothing exists for the API you need.

βœ“
Lesson 21 β€’ ⏱️ 22m
Troubleshooting & the Error Catalogue

A triage order that works, the eight root-cause classes behind virtually every Terraform error, a grouped catalogue of the hundred most common failures, and the resolution patterns that fix most of them.

βœ“

Stage 7 β€” Capstone Project

1 lesson
Lesson 22 β€’ ⏱️ 45m
Project: Three-Tier Reference Architecture

Build a complete modular three-tier stack β€” network, compute, load balancer, database, artifacts β€” with remote state and locking, then migrate it from local state to a remote backend without recreating anything.

βœ“

πŸ—ΊοΈ Beginner β†’ Expert Roadmap

7 stages with prerequisites and a concrete mastery check at each.

→

🎯 What You'll Learn

  • β€’ Describe infrastructure as a desired end state and let the dependency graph work out the order.
  • β€’ Read a plan the way it should be read: summary first, then destroys, then every forces-replacement marker.
  • β€’ Pin provider versions and module refs so nobody else's merge lands in your production apply.
  • β€’ Choose for_each over count deliberately β€” and explain the churn that makes it the most common self-inflicted outage.
  • β€’ Explain the four reasons state must exist, and treat the backend as the production-secrets store it actually is.
  • β€’ Import hand-built infrastructure and move resources between projects without destroying them.
  • β€’ Detect drift with refresh-only plans and choose between reconciling toward code, toward reality, or ignoring the field.
  • β€’ Build modules with a real interface, and know when nesting stops paying for itself.
  • β€’ Ship a pipeline that passes a reviewed plan file to apply instead of auto-approving whatever the world looks like.
  • β€’ Keep secrets out of configuration, out of logs, and understand why they are still in state.
  • β€’ Triage any Terraform failure in the right order, from validate through console to debug logging.
  • β€’ Assemble the whole path into a modular three-tier stack and migrate it to a remote backend without recreating anything.

πŸ›‘οΈ Best Practices in Production

The short version of this path. Every lesson also ends with the specific mistake it exists to prevent.

Do this
  • βœ“ Read every plan summary first, then destroys, then every forces-replacement marker.
  • βœ“ Pin provider and module versions; a floating version means someone else's release lands in your apply.
  • βœ“ Use a remote backend with locking and versioning, and treat state as production-secret material.
  • βœ“ Prefer for_each over count so removing one item does not renumber the rest.
  • βœ“ Run fmt, validate and a policy check in CI, and apply a reviewed plan file rather than re-planning.
  • βœ“ Keep modules small with a real interface; nest only while it still pays.
  • βœ“ Import existing infrastructure rather than recreating it, and use moved blocks when refactoring.
  • βœ“ Detect drift with scheduled refresh-only plans and decide deliberately which way to reconcile.
Avoid this
  • βœ— terraform apply -auto-approve in a pipeline that has not shown anyone the plan.
  • βœ— Editing state by hand, or running taint when -replace expresses the same intent reviewably.
  • βœ— One giant root module for the whole estate β€” every change plans everything and blast radius is total.
  • βœ— Secrets in variables or outputs. They are stored in plaintext in state regardless of provider support.
  • βœ— count on a list that people insert into β€” the churn is the most common self-inflicted outage.
  • βœ— Committing .terraform/ or a local terraform.tfstate to Git.