Terraform, developed by HashiCorp, is an open-source Infrastructure as Code (IaC) tool that allows you to define, provision, and manage infrastructure across multiple cloud providers (AWS, Azure, GCP, etc.) using a declarative configuration language (HCL).
In DevOps, Terraform is essential for:
Answer:
Terraform is an Infrastructure as Code (IaC) tool used to define and provision cloud infrastructure declaratively.
Why DevOps teams use it:
Example use case:
A DevOps engineer can deploy an entire VPC with subnets, EC2 instances, and security groups using a single Terraform command:
terraform apply
Answer:
Terraform uses HCL (HashiCorp Configuration Language) — a declarative language designed to describe infrastructure resources in a human-readable format.
Example:
resource "aws_instance" "web" {
ami = "ami-12345"
instance_type = "t2.micro"
}
Declarative means you describe what you want, not how to build it.
Answer:
Providers are plugins that allow Terraform to interact with APIs of cloud platforms or services.
Examples:
aws → Amazon Web Servicesazurerm → Microsoft Azuregoogle → Google Cloudkubernetes, helm, github, etc.Example block:
provider "aws" {
region = "us-east-1"
}
In real-world CI/CD, the provider is often configured using environment variables or credentials stored in Jenkins/AWS Secrets Manager.
Answer:
A resource represents a single piece of infrastructure — like an EC2 instance, S3 bucket, or IAM role.
Example:
resource "aws_s3_bucket" "mybucket" {
bucket = "cloudnukes-bucket"
acl = "private"
}
Each resource has attributes (like bucket, acl) that define its properties.
Answer:
Variables make Terraform configurations reusable and flexible.
Example:
variable "instance_type" {
default = "t2.micro"
}
Then reference it:
instance_type = var.instance_type
In real projects:
Variables store values that change per environment (e.g., region, instance type, tags).
Answer:
Terraform keeps a record of managed infrastructure in a state file (terraform.tfstate).
It tracks what’s been created and helps Terraform know what to change during apply.
Why important:
Security note:
Always store state securely — never commit to Git.
Answer:
Typical workflow:
.tf files).terraform init
terraform validate
terraform plan
terraform apply
terraform destroy
This cycle ensures changes are predictable and reviewable before execution.
Answer:
terraform plan → Shows what Terraform will do (preview).terraform apply → Executes the actual creation/modification/deletion.Example:
terraform plan -out=tfplan
terraform apply tfplan
In interviews:
Emphasize that plan is used for approval workflows in CI/CD pipelines before applying changes.
Answer:
Use:
terraform destroy
It removes all infrastructure defined in .tf files.
You can also delete specific resources:
terraform destroy -target=aws_instance.web
Best practice:
Use plan before destroy to confirm what will be removed.
Answer:
A module is a reusable block of Terraform code.
It allows you to define infrastructure once and use it across multiple environments.
Example:
module "vpc" {
source = "./modules/vpc"
cidr_block = "10.0.0.0/16"
}
Modules improve organization, reusability, and maintainability of large infrastructures.
Answer:
Use Remote Backends (e.g., AWS S3) to store state centrally and DynamoDB for state locking.
Example:
terraform {
backend "s3" {
bucket = "cloudnukes-terraform-state"
key = "prod/terraform.tfstate"
region = "us-east-1"
dynamodb_table = "terraform-lock"
}
}
Why:
Prevents conflicts when multiple users apply changes simultaneously.
Answer:
Terraform Cloud is a SaaS service by HashiCorp that provides:
In enterprise DevOps:
Teams use Terraform Cloud for governance, while the CLI is used for local experimentation.
Answer:
Workspaces allow you to use the same configuration for multiple environments (e.g., dev, staging, prod).
Example:
terraform workspace new dev
terraform workspace select prod
Each workspace maintains its own state file.
Answer:
Use outputs to share data:
# In module A
output "vpc_id" {
value = aws_vpc.main.id
}# In root modulemodule “app” {
source = “./modules/app”
vpc_id = module.network.vpc_id
}
This ensures consistent resource linkage across modules.
Answer:
terraform import aws_instance.myec2 i-12345
Then run terraform plan to sync the configuration with the imported resource.
Why important:
Allows teams to bring legacy infrastructure under Terraform management.
Answer:
Mark them as sensitive:
variable "db_password" {
type = string
sensitive = true
}
Best practices:
export TF_VAR_db_password="mypassword"
Never hardcode passwords in .tf files.
Answer:
.tf files.terraform initterraform plan -out=plan.tfoutterraform apply plan.tfoutExample Jenkinsfile:
stage('Terraform Plan') {
steps {
sh 'terraform init'
sh 'terraform plan -out=tfplan'
}
}
stage('Apply') {
input 'Approve deployment?'
steps {
sh 'terraform apply -auto-approve tfplan'
}
}
This ensures infrastructure changes go through controlled CI/CD workflows.
Answer:
| Feature | count |
for_each |
|---|---|---|
| Type | Indexed (0,1,2) | Key-based (map/set) |
| Use Case | Repeat identical resources | Manage unique named resources |
Example (for_each):
resource "aws_s3_bucket" "buckets" {
for_each = toset(["dev", "prod"])
bucket = "cloudnukes-${each.key}"
}
Answer:
Run:
terraform plan
Terraform compares the state file with the real infrastructure and reports drift.
In CI/CD:
Automated drift detection helps maintain compliance and prevent unauthorized changes.
Answer:
.tf files in Git.provider "aws" {
version = "~> 5.0"
}
This ensures consistency across deployments.
Answer:
dev, prod).Example structure:
├── modules/
│ ├── vpc/
│ ├── ec2/
│ └── s3/
├── envs/
│ ├── dev/
│ ├── prod/
This ensures scalability, maintainability, and security.
Answer:
Terraform automatically infers dependencies through references.
If explicit dependency is needed:
depends_on = [aws_vpc.main]
Use case:
Ensure the VPC is created before the subnet.
Answer:
Lock versions in versions.tf:
terraform {
required_version = ">= 1.5.0"
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 5.0"
}
}
}
Why:
Ensures predictable and stable builds across environments.
Answer:
Example Policy:
Restrict EC2 instances to certain types or regions.
Answer:
Use:
create_before_destroy lifecycle rule:lifecycle {
create_before_destroy = true
}
Answer:
terraform apply -parallelism=10
depends_on.This ensures faster apply times and cleaner code execution.
Answer:
Use Terraform to deploy compliant infrastructure templates defined in AWS Service Catalog.
With AWS Control Tower, Terraform manages multi-account environments automatically using account factory APIs.
This is common in enterprise-level DevOps automation.
Answer:
data "aws_secretsmanager_secret_version" "db" {
secret_id = "prod/db"
}
Q: Your Terraform apply failed halfway due to a network timeout, leaving resources partially deployed. How did you handle it?
Answer (STAR):
terraform refresh to sync actual resources.terraform apply successfully.plan review and apply rollback detection.Q: Your Terraform state file was accidentally deleted. What did you do to recover and prevent it in the future?
Answer (STAR):
terraform import.