Skip to main content

Side by side

TerraformvsAnsible

What is the difference between Terraform and Ansible?

Updated 2 min read6 differences

In short

Terraform declares and creates cloud infrastructure and tracks it in a state file, while Ansible configures existing machines and deploys software over SSH.

Terraform

Terraform is an infrastructure-as-code tool: you describe cloud resources in configuration files, and one command creates or updates them to match.

Read the page on Terraform

Ansible

Ansible is an open-source automation tool that configures servers and deploys applications by running YAML playbooks over SSH, with no agent on the machines.

Read the page on Ansible

Terraform and Ansible compared

AspectTerraformAnsible
Main jobProvisioning infrastructureConfiguring machines and deploying software
StyleDeclarative: describe the end stateTask lists, mostly idempotent modules
LanguageHCLYAML playbooks
StateTracked in a state fileNone; checks machines on each run
How it connectsCloud and service APIsSSH or WinRM, agentless
Made byHashiCorp; OpenTofu is an open forkRed Hat

The difference, explained

Both are infrastructure as code tools, but they focus on different steps. Terraform, released by HashiCorp in 2014, is mainly about provisioning: you describe the resources you want in HCL files, such as a VPC, a Kubernetes cluster or a DNS record, and terraform apply creates, changes or deletes them through each provider's API until reality matches the code.

Ansible, first released in 2012 and part of Red Hat since 2015, is mainly about configuration: playbooks written in YAML list tasks, such as installing packages, editing config files, creating users and restarting services, which Ansible runs on existing machines over SSH. It needs no agent on the servers, and its modules are designed to be idempotent, so running a playbook twice gives the same result.

Terraform keeps a state file that records what it created, so it can compute an exact plan of changes and remove resources that disappear from the code. Ansible doesn't track state; each run checks the machines and applies what is missing. That is why the common pattern is to use both: Terraform to create the servers and cloud services, Ansible to set up what runs on them.

A common misconception is that the tools are interchangeable. Ansible can create some cloud resources and Terraform can run scripts, but each is awkward outside its strength. In container-based setups, Ansible's role shrinks, because images are built with Dockerfiles and run by Kubernetes. Since Terraform's license change in 2023, the open-source fork OpenTofu is another option.

Which one should you use?

Choose Terraform when…

  • You create and manage cloud resources across providers.
  • You want a plan that shows exactly what will change.
  • You manage networks, databases, DNS and clusters as code.

Choose Ansible when…

  • You configure servers, install packages and deploy apps.
  • You manage existing machines, including on-premises ones.
  • You want agentless automation over SSH.

Readers ask

Can Terraform and Ansible be used together?

Yes, and they often are. Terraform creates the infrastructure, then Ansible configures the servers it created, sometimes triggered right after terraform apply.

Is Terraform declarative and Ansible procedural?

Broadly. Terraform describes the desired end state and works out the steps. Ansible playbooks list tasks in order, though each module checks the current state before acting.

What is OpenTofu?

An open-source fork of Terraform maintained under the Linux Foundation, created after HashiCorp moved Terraform to a source-available license in 2023. It is largely compatible with Terraform code.

Read a random page
Open today's review
Switch to the dark theme
Read this page in Türkçe

More

Settings