- Knowledge
- technology
- OOP
- Tips
- Programming
- Tips
- Tutorial
- SEO
- Ranking
- Knowledge
- Special Day
- Seo
- Bug
- Data science
- Seo
- artificial intelligence
- Machine Learning
- Robotics
- happyNewYear2021
- newYearEve
- 2021
- Automation
- Smart Home
- Career
- Best Practices
- Git
- Logging
- Web Fundamentals
- DNS
- HTTPS
- Performance
- AI Tools
- ChatGPT
- Claude
- Gemini
- Laravel
- Eloquent
- MySQL
- HTTPS
- TLS
- Web Security
- Certificates
- Developer Life
- Debugging
- Docker
- DevOps
- Transactions
- Queues
- LLMs
- AI
- AI Coding
- Developer Tools
- React Native
- Expo
- Kate PMS
- Mobile Apps
- Laravel
- Authentication
- Sanctum
- Cookies
- API Design
- Payments
- Idempotency
- DeepSeek
- Open Source AI
- LLMs
- AI News
- Git
- Version Control
- AI Coding
- Prompting
- PHP
- Checklist
- MCP
- AI Agents
- OpenAI
- Architecture
- Microservices
- Modular Monolith
- Estimation
- Developer Life
- Project Planning
- Humour
- OAuth
- OpenID Connect
- Authentication
- Embeddings
- Vector Search
- RAG
- pgvector
- OpenAI
- GPT-4.1
- Codex CLI
- Events
- Testing
- Clean Code
- Maintainability
- Code Review
- Webhooks
- API
- Security
- Claude Code
- Workflow
- AI
- LLM
- Prompt Injection
- Mobile
- React
- Networking
- TCP
- UDP
- HTTP/3
- CLAUDE.md
- AWS
- Cloud Security
- Backups
- PHPUnit
- Software Engineering
- Leadership
- Communication
- RAG
- Embeddings
- AI Engineering
- IT Infrastructure
- Networking
- Access Control
- CI/CD
- GitHub Actions
- Gemini CLI
- Claude Code
- JavaScript
- Async/Await
- Node.js
- Promises
- Security
- Cryptography
- Passwords
- MySQL
- Database
- Vibe Coding
- Software Quality
- DNS
- Code Reading
- Onboarding
- Productivity
- Background Jobs
- Developer Humour
- Estimates
- Dev Life
- JWT
- o3-mini
- DeepSeek R1
- Rate Limiting
- Kate PMS
- E-Signing
- Audit Trail
- REST
- GraphQL
- API Design
- Laravel 12
- Upgrade Guide
- Open Source
- Self-Hosting
- Task Scheduling
- Cron
- Secrets
- CORS
- PHP
- PHP-FPM
- OPcache
- GitHub Copilot
- Software Architecture
- Engineering
- TypeScript
- JavaScript
- Type Safety
- AI Security
- React Native
- Product Design
- AI Agents
- Kiro
- Queues
- Redis
- RabbitMQ
- AWS SQS
- Nginx
- Apache
- GPT-5
- gpt-oss
- Clean Code
- Architecture
- Naming
- Documentation
- Career
- ADR
- Teamwork
- Supply Chain
- Kate HRM
- HR Software
- Permissions
- System Design
- Pagination
- SSH
- Linux
- Big O
- Databases
- Laravel Boost
- MCP
- Developer Skills
- Validation
- Databases
- Indexes
- Code Quality
- Deployment
- Developer Humour
- Feature Flags
- Code Review
- Pull Requests
- Docker
- Cursor
- Authorization
- RBAC
- Gemini
- Long Context
- PHP 8.4
- Caching
- Dependency Injection
- Web Performance
- Browser
- CSS
- Database
- Migrations
- ChatGPT
- AI for Developers
- Monitoring
- On-Call
- REST
- Backend
- SQL
- NoSQL
- Database Design
- Coding Agents
- Claude 4
- API Resources
- REST API
- Load Balancing
- Scaling
- AWS
- AI Tools
- Claude
- Sora 2
- CTE
- 2FA
- TOTP
- Programming Languages
- Prompts
- Developer Workflow
- API Gateway
- APIs
- Passport
- API Auth
- Learning
- Burnout
- Developer Growth
- Web Development
- SEO
- Kate Mall
- ChatGPT Atlas
- Agent Skills
- Middleware
- Laravel 12
- Collections
- Context Window
- Monitoring
- Commit Messages
- Self Review
- Growth
- Regex
- Programming Basics
- Text Processing
- Database Design
- Normalization
- Linux
- Server Security
- Linux Foundation
- Open Standards
- Legacy Code
- Documentation
- AI Workflow
- File Uploads
- Test Data
- Hashing
- Performance
- Caching
- Enums
- Scope Creep
- Estimation
- Codex
- Gemini CLI
- Timezones
- Carbon
- Bugs
- PHP 8.5
- Gemini 3
- GPT-5.1
- Data Integrity
- Event Loop
- Async
- Opus 4.5
- AI Models
- React
- Forms
- Frontend
- Backups
- AI Images
- DALL-E
- Midjourney
- Race Conditions
- Concurrency
- Legacy Code
- Refactoring
- Senior Engineer
- Scope
- LLM
- CDN
- Web
- Sub-Agents
- Soft Deletes
- Audit Log
- Concurrency
- AI Learning
- NestJS
- AI Evals
- Policies
- SPF DKIM DMARC
- Unicode
- UTF-8
- Knowledge Graph
- Value Objects
- Technical Debt
- Feature Flags
- Laravel Pennant
- Deployment
- Copilot
- Composer
- Dependencies
- Artisan
- Automation
- AWS S3
- Object Storage
- Cloud
- Small Language Models
- Ollama
- Production
- Sessions
- HTTP
- Mentoring
- SQL
- Virtual Machines
- Web Development
- HTTP/2
- QUIC
- Web Performance
- AI Integration
- LLM API
- SOLID
- OOP
- Hosting
- Serverless
- Merge Conflicts
- Temperature
- AI Development
- Reverse Proxy
- Nginx
- Infrastructure
- Verification
- Passkeys
- WebAuthn
- Teams
- Communication
- Stakeholders
- Monorepo
- CI/CD
- Versioning
- JSON Schema
- Livewire
- Inertia
- Meetings
- Distributed Systems
- Privacy
- Full-Stack
- T-Shaped Skills
- Money
- Notifications
- Web Security
- HTTP Headers
- CSP
- Function Calling
- Load Testing
- k6
- Data Extraction
- Debugging
- WebSockets
- SSE
- Real-Time
- Laravel Reverb
- Infrastructure as Code
- Terraform
- Side Projects
- Laravel Pint
- OpenAPI
- Swagger
- UX
- Multimodal
- Jest
- Pair Programming
- APIs
- Rate Limiting
- Resilience
- Dev Humour
- Design Tokens
- JWT
- API Keys
- Sessions
- PHPStan
- Rector
- Incidents
- Reporting
- Dashboards
- Zero Trust
- IAM
- Search
- Laravel Scout
- Junior Developers
- Mentoring
- Images
- WebP
- AVIF
- Bug Reports
- Let's Encrypt
- Design Docs
- Software Design
- Observers
- Replication
- Accountability
- Data Structures
- Reliability
- LLM Memory
- Error Handling
- Payments
- Payment Gateway
- Webhooks
- PCI DSS
- Observability
- OpenTelemetry
- Personal Brand
- Writing
- Conventions
- Dates
- Scheduling
- Disaster Recovery
- Compression
- Brotli
- Deadlines
- Developer Habits
- State Machines
- Tech Roles
- UUID
- ULID
- Horizon
- Planning
- Engineering Culture
- Ownership
- Soft Skills
- Socialite
- Cost Control
- Collations
- Unicode
- Octane
- PostgreSQL
What Is Infrastructure as Code? Servers You Can Review, Rebuild and Trust
About Post
Every company has one: the server nobody wants to touch. It was set up years ago by clicking through the AWS console. It has a security group with rules nobody can explain, a cron job someone added over SSH, and a disk that was resized "temporarily". It works. Nobody knows exactly why.
Now imagine it disappears tomorrow. Could you rebuild it, exactly, from memory?
Infrastructure as Code (IaC) exists so the answer is "yes, in one command". Here's how it works, set out as the questions people actually ask when they first meet it.
So what is it, in one sentence?
You describe your infrastructure (servers, networks, databases, buckets, DNS records, permissions) in text files, keep them in Git, and a tool makes the real cloud match the files.
The key word is describe. Most IaC tools are declarative: you write what should exist, not the steps to create it. That's the big difference from a folder of Bash scripts. A script says "create a bucket", and fails or duplicates on the second run. A declaration says "there is a bucket with versioning on", and running it twice changes nothing the second time.
What does it look like?
Here's a small piece of Terraform, the most widely used multi-cloud IaC tool. It describes an S3 bucket for uploads with versioning enabled:
resource "aws_s3_bucket" "uploads" {
bucket = "example-app-uploads"
tags = {
Environment = "production"
}
}
resource "aws_s3_bucket_versioning" "uploads" {
bucket = aws_s3_bucket.uploads.id
versioning_configuration {
status = "Enabled"
}
}
Notice aws_s3_bucket.uploads.id. Resources can reference each other, so Terraform works out the order: the bucket first, then its versioning setting. You never write that order down.
What happens when I run it?
Three commands carry most of the workflow:
terraform initdownloads the providers (the plugins that talk to AWS, Cloudflare and so on).terraform plancompares your files with reality and prints what it would do.terraform applydoes it, after showing the plan again and asking you to confirm.
The plan is the best part. It reads like a diff for your infrastructure:
# aws_s3_bucket_versioning.uploads will be created
+ resource "aws_s3_bucket_versioning" "uploads" {
+ bucket = "example-app-uploads"
...
}
Plan: 1 to add, 0 to change, 0 to destroy.
In a good setup, that plan is posted on the pull request. A teammate reviews the infrastructure change the same way they review code, before anything touches production.
What is "state", and why does everyone warn me about it?
Terraform needs to remember which real thing belongs to which block in your files: "this resource is bucket example-app-uploads, this one is instance i-0abc...". That mapping is the state file.
Three rules keep state from hurting you:
- Store it remotely, not on someone's laptop. An S3 bucket backend is the common choice on AWS.
- Turn on locking, so two people can't apply at the same time and corrupt it.
- Treat it as sensitive. State can contain values like database passwords in plain text. Encrypt it and restrict who can read it.
terraform {
backend "s3" {
bucket = "example-terraform-state"
key = "production/terraform.tfstate"
region = "eu-west-1"
encrypt = true
}
}
AWS CloudFormation, by contrast, keeps the state for you inside AWS (as a "stack"). That's one less thing to manage, at the cost of only working with AWS.
What is drift?
Drift is when reality and your files disagree. Somebody opens a port in the console during an incident "just for now". Someone resizes a database by hand. The code says one thing, the cloud says another.
The next terraform plan will show the difference and offer to put it back. That's either a safety net or a surprise outage, depending on whether the manual change was important. CloudFormation has a drift detection feature for the same reason.
The team rule that makes IaC work: the console is for looking, not for changing. If a change is urgent, make it in code anyway, or make it by hand and put it in code the same day.
Terraform, CloudFormation, or something else?
| Tool | Language | Clouds | State |
|---|---|---|---|
| Terraform | HCL | Many (AWS, Azure, GCP, Cloudflare...) | You manage it |
| OpenTofu | HCL | Many; an open-source fork of Terraform | You manage it |
| CloudFormation | YAML or JSON | AWS only | Managed by AWS |
| AWS CDK / Pulumi | TypeScript, Python and others | CDK: AWS; Pulumi: many | CDK uses CloudFormation; Pulumi manages its own |
My take: if you're all-in on AWS and want the least to manage, CloudFormation or CDK is reasonable. If you use more than one provider (say AWS plus a DNS or CDN provider), Terraform or OpenTofu lets you describe all of it in one place. The concepts transfer either way.
Isn't this overkill for a small team?
Not if you start small. You don't have to codify everything on day one. Start with what would hurt most to rebuild by hand: networking and security groups, the database, the buckets, DNS. Even a few hundred lines that describe your production environment are worth it, because they double as documentation that can't go out of date.
And it's not the same thing as Docker. A Dockerfile describes what's inside the box; IaC describes the boxes, the network between them and who's allowed in.
The traps that bite
- Not reading the plan. Changing some attributes forces Terraform to destroy and recreate a resource. The plan says so (
-/+, "must be replaced"). On a database, that line deserves your full attention. - No guard on precious resources. Add
lifecycle { prevent_destroy = true }to the things that must never be deleted by accident. - Secrets in the repo. Pass them in from a secrets manager or environment variables, never hard-code them in
.tffiles. - One giant state for everything. Split by environment and by area, so a mistake in staging can't touch production.
The short version
IaC turns infrastructure into something you can review, repeat and rebuild. Files in Git, a plan before every change, state stored safely, and no clicking in the console.
What's the one piece of your infrastructure you'd be most nervous to rebuild from memory?

Be first to comment it...