Terraform: plan changes and operate infrastructure
Six lessons, 30 questions, and six cases on Terraform configuration, plans, state, modules, secrets, and recovery.
Objectives and progression
A six-module technical course on infrastructure as code, plan review, and collaborative operations. Learn to manage dependencies, state, resource identities, secrets, and partially completed changes. Includes fictional APS scenarios, inspected HashiCorp documentation, version and provider boundaries, and an internal assessment of 24 decisions in 60 minutes.
Audience: APS L2/L3, infrastructure, SRE, systems administration teams, and technical managers.
Prerequisites: Application, monitoring, and production-support fundamentals; no bank-specific internal process assumed.
300 estimated study minutes
- Describe infrastructure and dependencies without confusing files with execution order.
- Read plan actions and evidence before authorizing changes.
- Protect resource bindings and coordinate concurrent operations.
- Reuse configuration without losing control of versions and addresses.
- Distinguish redaction, persistence, and protection against destructive changes.
- Adopt existing resources and recover partial changes using actual state.
Modules
- Configuration and dependencies
- Plans and validation
- State and collaboration
- Modules and identity
- Secrets and controls
- Adoption and recovery
Continue learning
References and version
Terraform v1.16 concepts; official documentation consulted 2026-09-30; provider and backend capabilities must be confirmed
- Declarative configuration and dependencies · 2026-09-30
- Plan modes artifacts and detailed exit codes · 2026-09-30
- State bindings and secure storage · 2026-09-30
- Backend locking and force-unlock limits · 2026-09-30
- Provider dependency lock file · 2026-09-30
- Sensitive ephemeral and write-only values · 2026-09-30
- Configuration validation scope · 2026-09-30
- Root and reusable child modules · 2026-09-30
- Stable instance keys and known-value constraints · 2026-09-30
- Replacement and lifecycle controls · 2026-09-30
- Declarative import workflow · 2026-09-30
- Address refactoring through moved blocks · 2026-09-30
- CLI workspace isolation limits · 2026-09-30
- S3 state locking and permissions · 2026-09-30
- Saved plans and partial apply errors · 2026-09-30
- Explicit and implicit dependencies · 2026-09-30
- Stop managing resources with explicit destroy policy · 2026-09-30
- Initialization and backend migration · 2026-09-30
- Preconditions postconditions and nonblocking checks · 2026-09-30
What you will explore
0 / 6Configuration and dependencies
Describe infrastructure and dependencies without confusing files with execution order.
Plans and validation
Read plan actions and evidence before authorizing changes.
State and collaboration
Protect resource bindings and coordinate concurrent operations.
Modules and identity
Reuse configuration without losing control of versions and addresses.
Secrets and controls
Distinguish redaction, persistence, and protection against destructive changes.
Adoption and recovery
Adopt existing resources and recover partial changes using actual state.