terraform reference

Keywords

Difference of resource and data

Command Line

Provisioning Infrastructure

Interally, Terraform uses API to create and manage cloud resources.

Inspecting Infrastructure

Developing

See Also: terraform cli doc

Use Cases

Concepts

Terraform module

  1. Group resources that you usually deploy together, letting you define reusable units of infrastructure code. For example, the official “VPC module” let you customise using input variables to quickly create VPC, subnets, route table, internet gateway, security groups…
  2. Help teams establish infrastructure configuration standards. For example, you can write a module to create a database used by your application that includes all of the defaults that your architecture requires. The module can define the database size, type and handle all of the required networking. This ensures that module consumers provision infrastructure in line with your organisation standard and requirements.

Terraform state

Terraform stores state about your workspace’s managed infrastructure and configuration due to following reasons.

Why does Terraform use state?

  1. Terraform uses your workspace’s state of map real world resources to your configuration.Prior to any operation, Terraform does a “refresh” to update the state with the real infrastructure. The primary purpose of state is to store bindings between objects in a remote system and resource instances declared in your configuration. When Terraform creates a remote object in response to a change of configuration, it records the identify of that remote object against a particular resource instance, and potentially updates and deleted that objects in response to future configuration changes.
  2. keep track of metadata, such as resource dependencies, terraform uses configuration to determine dependency order.
  3. remote backend is for securely store state and collaborates with team members.
  4. performance, cache attribute values for remote resources, avoid network requests, more useful for large infrastructure.

The primary purpose of state is to store bindings between objects in a remote system and resource instances declared in your configuration. When Terraform creates a remote object in response to a change of configuration, it records the identity of that remote object against a particular resource instance, and potentially updates and deletes that objects in response to future configuration changes.

Internal to terraform, workspace state is stored as JSON file. Do not directly edit this file. Terraform expects a one-to-one mapping between configured resource instance and remote objects. Normally that is guranteed by Terraform being the one to create each object and record its identity in the state, or to destroy an object and then remove the binding for it. If you add or remote bindings in the state by other means, such as by importing externally - created objects with ‘terraform import’, or by asking Terraform to ‘forget’ an existing object with ‘terraform state rm’, you’ll then need to ensure for yourself that this one-to-one rule is followed, such as by manually deleting an object that you asked terraform to forget, or by re-importing it to bind it to some other resource instance.

remote state backends

Helps collaboration and coordinate execution for multiple developers working on the same codebase.

scale Terraform

how to define boundaries or infrastructure ownership. need to decide on a cloud deployment strategy, possible approaches include using a single account in a single cloud provider, a hybrid or multi-cloud approach, or to divide up resources across accounts by environments.

Divide infrastructure responsibility

It’s common for different teams to focus on different parts of your organisation’s infrastructure. Networking team manage the VPCs, application team only needs to know where to deploy their application and focus on configuring servers and databases. But application still needs to access data about the networking resources for their own configuration - use reference data about other resources in your configuration without having to manage them in the same state file, allowing you to maintain distinct areas of ownership and infrastructure decoupling.