Terraform
- Pronunciation
- TAIR-uh-form
In short
Terraform is an infrastructure-as-code tool: you describe cloud resources in configuration files, and one command creates or updates them to match.
What is Terraform?
Terraform was released by HashiCorp in 2014. Instead of clicking through a cloud console, you write what you want, for example two virtual machines, a database and a load balancer, in files using HCL, HashiCorp Configuration Language. Terraform reads those files and talks to the cloud's API to make reality match. Because the files live in Git, infrastructure gets reviews, history and rollbacks just like code.
Its workflow has two key steps. terraform plan compares the configuration with what exists and shows exactly what would be created, changed or destroyed. terraform apply then carries out that plan. Terraform remembers what it manages in a state file, which is usually stored remotely so a team shares one view of the infrastructure.
Terraform works with almost any platform through providers: plugins for AWS, Azure, Google Cloud, Kubernetes, Cloudflare, GitHub, databases and hundreds more. Reusable modules package common setups, such as a standard network, so teams don't rebuild them each time. The configuration is declarative: you describe the end state, and Terraform works out the order of the steps.
A common misconception is that Terraform configures what runs inside servers. It mainly creates and connects the resources themselves; installing packages and editing files on machines is the job of configuration tools such as Ansible, or of container images. In 2023 HashiCorp moved Terraform to a source-available license, and the community forked the last open-source version as OpenTofu, which works in largely the same way.
At a glance
Key takeaways
- Terraform describes cloud infrastructure as code, in HCL files.
- terraform plan previews changes; terraform apply makes them.
- A state file records which real resources Terraform manages.
- Providers connect it to AWS, Azure, Google Cloud, Kubernetes and more.
- OpenTofu is an open-source fork that works in much the same way.
Example
provider "aws" {
region = "eu-central-1"
}
resource "aws_s3_bucket" "assets" {
bucket = "example-site-assets"
tags = {
Environment = "production"
}
}
# terraform plan -> shows: 1 to add
# terraform apply -> creates the bucketReaders ask
Is Terraform free?
The Terraform CLI can be used free of charge, but since 2023 it is under the Business Source License, which restricts offering it as a competing product. OpenTofu is a fully open-source fork. HashiCorp also sells HCP Terraform, a managed service.
What is the difference between Terraform and Ansible?
Terraform mainly creates and manages infrastructure, such as networks, machines and databases, from a declared end state. Ansible mainly configures machines, installing software and changing settings over SSH. Many teams use both.
What is the Terraform state file?
A file in which Terraform records the real resources it manages and their settings. It lets Terraform work out what has changed, and teams usually keep it in remote storage with locking so that two people can't apply changes at once.
Often compared
See also
- Infrastructure as CodeDevOps & Cloud, p. 29Infrastructure as code is the practice of defining servers, networks, and other infrastructure in version-controlled files that tools apply automatically.
- Cloud ComputingDevOps & Cloud, p. 10Cloud computing is the on-demand delivery of computing resources, such as servers, storage, and databases, over the internet with pay-as-you-go pricing.
- Configuration ManagementDevOps & Cloud, p. 11Configuration management is the practice of defining the desired state of servers and software in code and using tools to apply and keep it automatically.
- AWSDevOps & Cloud, p. 3AWS (Amazon Web Services) is Amazon's cloud platform: more than 200 pay-as-you-go services for servers, storage, databases and much more.
- AnsibleDevOps & Cloud, p. 1Ansible is an open-source automation tool that configures servers and deploys applications by running YAML playbooks over SSH, with no agent on the machines.
- GitOpsDevOps & Cloud, p. 23GitOps is a way of managing infrastructure and deployments where Git holds the desired state of a system and an automated agent keeps the live system in sync.
Sources
Spotted a mistake or something missing on this page?Suggest an edit