What goes wrong when a team of ten engineers all have terraform apply access directly on their laptops? Everything, eventually. Someone applies from an outdated branch. Two people apply at the same time. A password ends up in a .tfvars file that gets committed to Git. A manual console change goes unnoticed for six months until the next apply silently reverts it. Automating Terraform through pull requests is not optional at production scale — it is the only way to keep infrastructure auditable, safe, and consistent.
What This Pillar Covers
- GitHub Actions workflows for automated
terraform planon pull requests andterraform applyon merge - OIDC authentication for AWS — eliminating long-lived access keys from CI/CD pipelines entirely
- Atlantis as a self-hosted Terraform pull request automation tool for teams
- Managing secrets without letting them appear in state files — Vault, AWS Secrets Manager, and environment variables
terraform validateandtflintin CI for catching errors before plan- Drift detection with scheduled
terraform plan -refresh-onlyjobs - Cost estimation with Infracost integrated into pull request comments
- Policy as code with Sentinel and OPA for governance at scale
Who This Is For
Senior DevOps engineers, platform engineers, and engineering managers who are responsible for making Terraform safe and scalable for a team of more than two or three engineers — or for organisations that need audit trails, cost visibility, and policy enforcement on infrastructure changes.
Why This Matters in Production
At Razorpay, before Terraform CI/CD, engineers applied infrastructure changes directly from their laptops using personal AWS credentials. One engineer applied from a feature branch instead of main, creating resources with the wrong configuration. The mistake was not caught for four days. After adopting Atlantis, every infrastructure change happens through a pull request — every plan is reviewed, every apply is logged, and the main branch is always the source of truth.
Prerequisites
- Terraform Fundamentals — the full plan/apply workflow
- Terraform State — remote backends and locking
- Terraform Modules — understanding module structure and code organisation
- Basic GitHub Actions or CI/CD pipeline knowledge