Skip to main content

Terraform Concepts

Step-by-step explanations, real-world issues, and simplified understanding. Master every angle — from foundational concepts to real-world troubleshooting.

What we cover

Terraform CI/CD — Automating Plan and Apply with GitHub ActionsAtlantis — Pull Request Automation for Terraform TeamsTerraform Drift Detection — Finding and Fixing Infrastructure That Changed

3 Subtopics

Interactive guides & progressions

4 Articles

In-depth technical readings

26 Glossary Terms

Platform terminology defined

3 FAQs

Common questions answered

Terraform in Production — CI/CD, Secrets, and Governance

Run Terraform safely in production — automating plan and apply through GitHub Actions and Atlantis, managing secrets, detecting drift, and applying governance at scale.

What goes wrong when a team of ten engineers all have terraform apply access directly on their laptops? Everything, eventually. Someone applies from an outdated branch. Two people apply at the same time. A password ends up in a .tfvars file that gets committed to Git. A manual console change goes unnoticed for six months until the next apply silently reverts it. Automating Terraform through pull requests is not optional at production scale — it is the only way to keep infrastructure auditable, safe, and consistent.

What This Pillar Covers

  • GitHub Actions workflows for automated terraform plan on pull requests and terraform apply on merge
  • OIDC authentication for AWS — eliminating long-lived access keys from CI/CD pipelines entirely
  • Atlantis as a self-hosted Terraform pull request automation tool for teams
  • Managing secrets without letting them appear in state files — Vault, AWS Secrets Manager, and environment variables
  • terraform validate and tflint in CI for catching errors before plan
  • Drift detection with scheduled terraform plan -refresh-only jobs
  • Cost estimation with Infracost integrated into pull request comments
  • Policy as code with Sentinel and OPA for governance at scale

Who This Is For

Senior DevOps engineers, platform engineers, and engineering managers who are responsible for making Terraform safe and scalable for a team of more than two or three engineers — or for organisations that need audit trails, cost visibility, and policy enforcement on infrastructure changes.

Why This Matters in Production

At Razorpay, before Terraform CI/CD, engineers applied infrastructure changes directly from their laptops using personal AWS credentials. One engineer applied from a feature branch instead of main, creating resources with the wrong configuration. The mistake was not caught for four days. After adopting Atlantis, every infrastructure change happens through a pull request — every plan is reviewed, every apply is logged, and the main branch is always the source of truth.

Prerequisites

  • Terraform Fundamentals — the full plan/apply workflow
  • Terraform State — remote backends and locking
  • Terraform Modules — understanding module structure and code organisation
  • Basic GitHub Actions or CI/CD pipeline knowledge

Frequently Asked Questions

What does the Terraform in Production — CI/CD, Secrets, and Governance concept cover?

Terraform in Production — CI/CD, Secrets, and Governance covers a variety of key topic guides, including: Terraform CI/CD — Automating Plan and Apply with GitHub Actions, Atlantis — Pull Request Automation for Terraform Teams, Terraform Drift Detection — Finding and Fixing Infrastructure That Changed. Run Terraform safely in production — automating plan and apply through GitHub Actions and Atlantis, managing secrets, detecting drift, and applying governance at scale.

How does Terraform in Production — CI/CD, Secrets, and Governance relate to the Terraform hub?

Terraform in Production — CI/CD, Secrets, and Governance is a core learning conceptual pillar mapped within the Terraform engineering hub of the DevOps Network.

Are these DevOps concepts free to learn?

Yes, all lessons, visual roadmaps, and guides on DevOps Network are 100% free with no paywalls or sign-up gates for learning content.