Memory hook: Describe the destination; review the journey.
Must remember
- Declarative configuration describes the desired infrastructure. Terraform compares configuration, recorded identity and provider observations to propose changes. Reapplying unchanged configuration should converge without unnecessary replacement.
- Version control makes changes reviewable. A pull request can show a plan before approval; reusable modules make standards easier to repeat. Configuration still needs testing, credentials and operational ownership.
- Multi-cloud means providers can manage several APIs in one workflow. It does not translate an AWS resource into an equivalent Azure resource. Resource schemas and architecture remain platform-specific.
- Hybrid infrastructure can combine cloud services, DNS, SaaS and supported on-premises APIs. Terraform is primarily a provisioning tool; image building and application configuration may use Packer or a configuration-management system.
- Immutable replacement creates a new object when an attribute cannot change in place. A small code change can therefore have a large availability or data impact. Read the actual plan, including deletions.
Recall drill: explain how a hand-edited production setting becomes drift and why rerunning an imperative script is not the same as comparing desired state.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Repeatable environments | Version configuration, inputs and module versions; review differences. |
| One workflow across cloud vendors | Use the appropriate provider for each API; design each resource explicitly. |
Traps
- A successful plan is not proof that the application will function.
- Code review does not replace review of replacements and destructive actions.
Active recall
1. Does declarative mean Terraform chooses the architecture?
No. You choose the resources and relationships; Terraform calculates operations to reach that configuration.
2. Can an AWS resource block be deployed unchanged to Azure?
No. Provider resource types have different schemas and semantics.
3. Why put infrastructure configuration in Git?
It provides change history, review and a reproducible desired configuration.
4. What is drift?
A real object differs from the intended or previously recorded configuration, often after an external change.
5. Why might a one-line change be risky?
It may force replacement of a stateful or critical resource; inspect the plan and lifecycle behavior.