4 ms·
This is a fork of Terraform after Hashicorp changed the license
by SomaticPirate 3y ago
This is a fork of Terraform after Hashicorp changed the license
- kristopolous 3y agoThanks. That's easily discoverable. Can you explain concretely and specifically what terraform does. "infrastructure as code tool that enables you to safely and predictably provision and manage infrastructure in any cloud" Doesn't tell me anything. Is this a markup language for describing networks? Is it some web interface where you drag and drop server icons and then draw lines between them? Is it a simulation tool? Is it some provisioning thing like chef with a database for different machines?
- mping 3y agoInfrastructure as code. You define your infra in a couple of files, then terraform builds it against eg: aws.
- deleted 3y ago[deleted]
- kristopolous 3y agoThrough what? The aws cli tool? Why would I need to encode something like that? Are you talking about maybe having identical setups in different parts of the world?
- bdsa 3y agoYou would encode it for the same reason we use source control - confidence that what is deployed matches some kind of record of it. In development we don't send archives of code to each other (OK, some people do I guess) and in infrastructure we don't click around in AWS to make changes
- kristopolous 3y agoI'm still not convinced on this use case. The click around technique could have logs and audit trails just the same. Someone could also just type up what they did. If you're doing 100 of something I'm sold but the record argument I find unconvincing. A preference sure, but a simplifier, no.
- hiatus 3y agoHave you ever worked in a regulated environment? One where you can't just SSH into production and change things? Logs and audit trails provide attribution, not prevention. How do you prevent unwanted changes to production? How do you block changes to production with quality gates? How do you ensure that modules conform to specific specifications before they are launched? How do you do an equivalent to code review? What happens when AWS rolls out a new feature like blocking public access and you have to roll it out to all of your buckets immediately? All of this is much, much more tedious in an interactive system.
- bdsa 3y agoSome great points from a sibling comment, and the one I'd add is: You don't need 100 instances of something to make managing it programmatically worthwhile. Different environments, for example: Terraform makes it very easy to ensure _all_ of the cloud config in prod matches staging (or the inverse), and to set up and bring down ephemeral development environments, using parameterised Terraform modules so you can be confident changes will propagate appropriately.
- verdverm 3y agoTerraform is a tool and module ecosystem for provisioning cloud resources from a declarative language, called Hashicorp Language (HCL). The idea is to specify your cloud resources in a file, commit that to git, and then run the tool on sets of these resources. The underlying engine will look at what you want this time, compare that to what is in the cloud, and make the appropriate changes, doing some nice graph walking to handle dependencies and work in parallel when it can. For those interested, there is a small package that is the core of the specialized graph data structure that powers this: https://github.com/opentofu/opentofu/blob/main/internal/dag/walk.go#L15 https://github.com/opentofu/opentofu/blob/main/internal/dag/... (link to the most interesting comment block in the package)
- kristopolous 3y agoAmazingly well done. Super clear. Thanks