Infrastructure as Code — Terraform State, Modules & Safe Change
Studies in this cluster, in series order. Each one keeps its own URL.
DevOps
Kubernetes workloads, CI/CD pipelines, artifact digests, supply-chain controls, Git rebase, merge, and recovery, and Terraform state, modules, and safe change you can defend in interviews.
- 1.Infrastructure as Code — Terraform State, Modules & Safe ChangeInfrastructure as code turns console clicks into reviewable change with a known blast radius. This hub is the Terraform decision map for remote state, modules, saved plans, drift, and policy, with a light contrast to Pulumi, CloudFormation, and Crossplane.
- 2.State, Backends, Locking & WorkspacesTerraform state maps configuration addresses to real resource IDs. This page covers remote backends, locking, encryption, and why prod usually gets its own root instead of a workspace.
- 3.Resources, Providers & the Dependency GraphProviders turn HCL into API calls, and resources are the nodes in the graph. This page covers aliases, implicit edges, lifecycle, and why for_each beats count when a set changes shape.
- 4.Modules, Composition & VersioningA Terraform module is a versioned interface, not a dump of the whole account. This page covers composition, pins, registries, and when a root should stay flat.
- 5.Plan, Apply, Drift Detection & ImportSafe Terraform change is a pipeline: a saved plan, a review of replaces, an apply of that file, then drift detection and a deliberate import or recreate.
- 6.Blast Radius — Policy-as-Code, Secrets & CI AppliesTerraform outages are usually applies that were allowed to do too much. This page covers policy on plan JSON, secret hygiene, least-privilege CI roles, and gates sized to blast radius.