Infrastructure as Code
- In Turkish
- Kod Olarak Altyapı
In short
Infrastructure as code is the practice of defining servers, networks, and other infrastructure in version-controlled files that tools apply automatically.
What is infrastructure as code?
Infrastructure as code (IaC) means managing infrastructure, such as virtual machines, networks, load balancers, databases, and DNS records, through code files instead of clicking through a web console or running commands by hand. The files describe what the infrastructure should look like, and a tool reads them and makes the real environment match.
Most IaC tools are declarative: you describe the desired end state, such as 'two web servers behind a load balancer', and the tool compares it with what already exists and creates, changes, or deletes resources to close the gap. Applying the same configuration twice makes no further changes, a property called idempotency. A typical workflow is to edit the files, run a plan step that previews the changes, review them in a pull request, and then apply them. Well-known tools include Terraform, OpenTofu, Pulumi, and Ansible, and each major cloud provider also offers its own template format.
Think of IaC as a written recipe instead of a meal cooked from memory: anyone can follow it and get the same result, and every change to it is written down. Because the files live in version control such as Git, each change has a history, can be reviewed like application code, and can be rolled back. The same code can also create matching development, staging, and production environments, which helps prevent configuration drift, where servers slowly become different through manual tweaks.
Infrastructure as code is sometimes confused with configuration management or with CI/CD. Provisioning tools create the infrastructure itself, such as networks, VMs, and databases, while configuration management tools install software and apply settings on servers that already exist, although many tools do some of both. CI/CD pipelines often run IaC tools, but IaC describes what infrastructure should exist, while CI/CD automates how code is built, tested, and released.
Key takeaways
- IaC defines infrastructure in code files instead of manual console clicks.
- Declarative tools compare the desired state with reality and apply the difference.
- Infrastructure changes are versioned, reviewed, and rolled back like application code.
- The same code creates consistent environments and helps prevent configuration drift.
- IaC is a core DevOps practice and is often run from CI/CD pipelines.
Example
# main.tf: declare what should exist; the tool creates or changes resources to match
terraform {
required_providers {
docker = { source = "kreuzwerker/docker" }
}
}
resource "docker_image" "nginx" {
name = "nginx:stable"
}
resource "docker_container" "web" {
name = "web"
image = docker_image.nginx.image_id
}Readers ask
What are the benefits of infrastructure as code?
IaC makes infrastructure repeatable, reviewable, and easy to recreate. Changes are tracked in version control, environments stay consistent, and a whole setup can be rebuilt from the code after a failure or copied to a new region.
What is the difference between declarative and imperative infrastructure as code?
Declarative IaC describes the desired end state and lets the tool work out the steps, as Terraform and OpenTofu do. Imperative IaC lists the exact steps to run in order, like a script, which gives more control but makes the result harder to predict when the script runs again.
What is configuration drift?
Configuration drift happens when real infrastructure slowly stops matching its intended configuration, usually because of manual changes. IaC tools can detect drift by comparing the code with what actually exists and then restore the declared state.
See also
- DevOpsDevOps & Cloud, p. 14DevOps is a set of practices and a culture that brings software development and IT operations together to deliver software faster and more reliably.
- CI/CDDevOps & Cloud, p. 9CI/CD is a set of automated practices that build, test, and release code changes frequently, so software can be delivered to users quickly and safely.
- GitVersion Control, p. 10Git is a free, open-source distributed version control system that tracks changes to files over time, so developers can collaborate and undo mistakes.
- Virtual MachineDevOps & Cloud, p. 53A virtual machine is a software-based computer that runs its own operating system on shared physical hardware, isolated from other machines on the same host.
- KubernetesDevOps & Cloud, p. 32Kubernetes is an open-source system that automates deploying, scaling, and managing containerized applications across a cluster of machines.
- IdempotencyBackend & APIs, p. 24Idempotency is the property of an operation that produces the same result whether it runs once or many times, so accidentally repeating a request is safe.
- TerraformDevOps & Cloud, p. 52Terraform is an infrastructure-as-code tool: you describe cloud resources in configuration files, and one command creates or updates them to match.
Spotted a mistake or something missing on this page?Suggest an edit