Module 10 · Infrastructure as Code with Terraform
"Final project: Tallybook's infrastructure review"
Plan your final project, a review of Tallybook's Terraform estate and six pending pull requests, with policy checks, drift and secrets findings, and the plan to make Terraform the only way infrastructure changes.
About 20 minutes
The problem
Tallybook's CTO wants to adopt infrastructure as code properly, and wants one document to do it: what's wrong today, what to do with the six pull requests waiting, and the rules and pipeline from now on. Your final project is that review, built from the state, plans and variable files in this course.
The concept
The parts of the review
| Part | Built in |
|---|---|
| Coverage: what Terraform manages and what it doesn't | lesson 1 |
| Environments compared, with costs | lesson 3 |
| State and secrets | lesson 4 |
| The six PRs: summaries, dangers, fixes | lessons 5 and 6 |
| Policies and their results | lesson 7 |
| Drift and unmanaged resources | lesson 8 |
| Modules and the pipeline | lesson 9 |
One scorecard per PR
For each PR: its plan summary, policy results, decision, and your review comment. That table is what the CTO will read first.
Example
The start of the scorecard, combining the plan summary with a few of the checks:
import json
from urllib.request import urlopen
import pandas as pd
base = "https://academy.cloudtechanalytics.com/datasets/terraform/"
PRS = ["101-web-autoscaling", "102-rename-database", "103-reporting-access", "104-cost-tags", "105-rightsize-api", "106-multi-az-database"]
def load(name):
with urlopen(base + name) as f:
return json.load(f)
def scorecard(pr):
changes = load(f"plan-pr-{pr}.json")["resource_changes"]
actions = [rc["change"]["actions"] for rc in changes]
return {
"add": sum("create" in a for a in actions),
"change": sum(a == ["update"] for a in actions),
"destroy": sum("delete" in a for a in actions),
"touches_database": any(rc["type"] == "aws_db_instance" for rc in changes),
"touches_firewall": any(rc["type"] == "aws_security_group_rule" for rc in changes),
}
pd.DataFrame({pr: scorecard(pr) for pr in PRS}).Tadd change destroy touches_database touches_firewall
101-web-autoscaling 4 0 6 False False
102-rename-database 1 0 1 True False
103-reporting-access 1 0 0 False True
104-cost-tags 0 19 0 False False
105-rightsize-api 0 4 0 False False
106-multi-az-database 0 1 0 True FalseAdd the policy decisions from lesson 7 and your review comments, and the table becomes the first page of the review.
Walkthrough
- Complete the scorecard with policy results and your decision for each PR.
- Write the coverage, drift and secrets findings with their evidence.
- Write the target rules: policies, drift policy and pipeline.
- Open the project brief on the course page and plan the write-up.
Practice
Practice
How many of the six PRs touch a database resource?
Task
10 minWrite the executive summary of your review (100 to 200 words): coverage (what's not in Terraform), the secrets finding, what happens to the six PRs, the drift found, and the rules from now on (policies and pipeline), ending with the first three actions.
Your work is checked for
- Coverage (unmanaged, not in Terraform, by hand)
- Secrets in state
- Mentions PR 102 or the database deletion
- Drift
- Policies and pipeline
- First actions
- Between 100 and 200 words
Check your understanding
Answer every question to check.