Quick answer: Terraform is an open-source Infrastructure as Code (IaC) tool from HashiCorp that lets you define servers, networks, databases and other cloud resources in human-readable configuration files, then create and manage them with a few commands. Instead of clicking through a cloud console, you write what you want in HCL (HashiCorp Configuration Language), run terraform plan to preview the changes, and terraform apply to make them real β on AWS, Azure, Google Cloud and hundreds of other platforms.
If you have ever set up a virtual machine by hand, forgotten which settings you used, and then had to do it again for staging, you already understand the problem Terraform solves. This guide explains what Terraform is, what Infrastructure as Code means in practice, how a Terraform workflow runs, why teams choose it, a first working example, and the mistakes beginners make in their first month.
What is Infrastructure as Code?
Infrastructure as Code is the practice of describing your infrastructure β compute, storage, networking, DNS, IAM policies β in text files that live in version control, exactly like application code. The benefits follow directly from that one decision:
- Version control. Every change is a commit with an author, a message and a diff. You can review infrastructure changes in a pull request and roll back when something breaks.
- Reproducibility. The same files produce the same environment. Dev, staging and production stop drifting apart.
- Automation. A CI/CD pipeline can create or update infrastructure without a human clicking anything.
- Documentation that cannot go stale. The code is the documentation of what exists.
Terraform is the most widely used tool for this job. Alternatives include AWS CloudFormation (AWS only), Azure Bicep (Azure only), Pulumi (general-purpose languages) and OpenTofu, a community fork of Terraform that stays compatible with the same HCL and providers.
How Terraform works
Terraform follows a simple, repeatable workflow:
- Write β describe the desired infrastructure in
.tffiles using HCL. - Init β
terraform initdownloads the providers (plugins) your configuration needs. - Plan β
terraform plancompares your code with the real world and prints exactly what will be created, changed or destroyed. - Apply β
terraform applyexecutes that plan by calling the cloud provider’s API. - Destroy β
terraform destroyremoves everything the configuration manages, which is perfect for temporary test environments.
Two pieces make this possible. Providers are plugins that know how to talk to a specific platform β the AWS provider knows how to create an EC2 instance, the Azure provider knows how to create a storage account. State is a JSON file (terraform.tfstate) where Terraform records what it has created, so that next time it can work out the difference between what exists and what you asked for.
Because Terraform builds a dependency graph from your code, it knows that a subnet must exist before the server placed inside it, and it creates independent resources in parallel. This ordering is covered in detail in Understanding Resource Dependencies and Ordering in Terraform.
Your first Terraform configuration
Here is a complete, working example that creates a private S3 bucket in the AWS Mumbai region. Save it as main.tf.
terraform {
required_version = ">= 1.5.0"
required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 5.0"
}
}
}
provider "aws" {
region = "ap-south-1" # Mumbai
}
resource "aws_s3_bucket" "site_assets" {
bucket = "tkh-site-assets-2026"
tags = {
Project = "techknowledgehub-site"
Environment = "dev"
ManagedBy = "terraform"
}
}
resource "aws_s3_bucket_public_access_block" "site_assets" {
bucket = aws_s3_bucket.site_assets.id
block_public_acls = true
block_public_policy = true
ignore_public_acls = true
restrict_public_buckets = true
}
output "bucket_name" {
value = aws_s3_bucket.site_assets.bucket
}
Then run:
terraform init # downloads the AWS provider
terraform plan # shows: 2 to add, 0 to change, 0 to destroy
terraform apply # type "yes" to create the resources
terraform destroy # clean up when you are done
Notice the reference aws_s3_bucket.site_assets.id in the second resource. That single line tells Terraform the access block depends on the bucket, so it will always create them in the right order. There are no credentials in the file; the provider reads them from environment variables or the AWS CLI configuration.
Making it reusable with variables
Hard-coding a bucket name is fine for a demo but not for real projects. Variables let the same code serve multiple environments:
variable "environment" {
description = "Deployment environment name"
type = string
default = "dev"
}
resource "aws_s3_bucket" "site_assets" {
bucket = "tkh-site-assets-${var.environment}"
}
Run terraform apply -var="environment=prod" and you get a second, independent bucket. Our guide on using variables and expressions in Terraform goes much deeper into this.
Why teams choose Terraform
| Advantage | What it means in practice |
|---|---|
| Declarative and readable | You describe the end state in HCL; Terraform works out the steps. New team members can read a .tf file on day one. |
| Multi-cloud | One tool and one workflow for AWS, Azure, Google Cloud, Kubernetes, Cloudflare, GitHub, Datadog and 4,000+ other providers. |
| Plan before apply | You see every change before it happens, which prevents the “I did not expect it to delete that” moment. |
| Dependency graph | Resources are created in a safe order and in parallel wherever possible. |
| Drift detection | If someone changes a setting in the console, the next plan shows the difference and lets you correct it. |
| Modules | Package a VPC, a cluster or a whole application stack once and reuse it across teams. |
| Huge ecosystem and job market | Terraform is a baseline skill in almost every DevOps, cloud and platform engineering job description. |
What Terraform means for a production website
The original version of this article framed Terraform’s value in terms of SEO. The honest version is this: search engines reward sites that are up, fast and secure, and Terraform helps you deliver all three consistently.
- Availability. Load balancers, auto-scaling groups and multi-zone databases are defined once in code, so every environment gets the same resilient architecture instead of a hand-built one that nobody dares touch.
- Performance. CDNs, caching layers and right-sized instances can be rolled out identically across regions. When traffic grows, you change a number in a variable rather than rebuilding servers.
- Security. Security groups, IAM policies, encryption settings and public-access blocks are reviewed in pull requests and enforced on every apply. Misconfigurations are caught before they reach production, not after a breach.
In short, Terraform does not optimise your pages, but it makes the infrastructure underneath them predictable β and predictable infrastructure is what keeps a site fast and online.
Common beginner mistakes
- Keeping state on a laptop.
terraform.tfstateon one developer’s machine means nobody else can run Terraform safely. Use a remote backend (S3 with DynamoDB locking, Azure Blob, Terraform Cloud) from the very first project. - Committing state or secrets to Git. State can contain passwords and keys in plain text. Add
*.tfstateand*.tfvarswith secrets to.gitignore. - Skipping
terraform plan. Runningapplydirectly in production is how resources get deleted by surprise. Always read the plan. - No version constraints. Pin the Terraform version and provider versions, and commit
.terraform.lock.hcl, so a teammate’s run six months later behaves identically. - Editing resources in the console. Manual changes cause drift. Make every change through code, or import the manual change with
terraform import. - One giant configuration. Split by environment and by component. A small blast radius makes mistakes cheap.
Frequently asked questions
Is Terraform free?
The Terraform CLI is free to download and use. HashiCorp moved its licence from MPL to the Business Source Licence in 2023, which restricts building competing products but does not affect normal users. HCP Terraform (formerly Terraform Cloud) has a free tier and paid plans for teams. OpenTofu is a fully open-source, drop-in compatible alternative.
Do I need to know programming to learn Terraform?
No. HCL is a configuration language, not a programming language, and most beginners are productive within a week. Basic comfort with the command line and one cloud provider’s concepts (what a VPC or a storage account is) helps far more than coding experience.
Terraform vs Ansible β which should I learn?
They solve different problems. Terraform provisions infrastructure (create the server). Ansible configures it (install Nginx on the server). Many teams use both, running Ansible after Terraform has created the machines.
Is Terraform only for the cloud?
No. Providers exist for VMware vSphere, on-premises Kubernetes, network devices, DNS, monitoring tools, GitHub repositories and SaaS products. Anything with an API can be managed with Terraform.
Key takeaways
- Terraform is an open-source IaC tool that turns infrastructure into version-controlled HCL files.
- The workflow is write β
initβplanβapply, with state tracking what exists. - Providers make it work across AWS, Azure, Google Cloud and thousands of other platforms with one consistent syntax.
- The
planstep, dependency graph and drift detection are what make Terraform safe to use in production. - Use remote state, pin versions, keep secrets out of Git and never edit managed resources by hand.
Ready to go from reading about Terraform to deploying real infrastructure on AWS and Azure? Our DevOps course covers Terraform end to end alongside Docker, Kubernetes and CI/CD, with live projects, mentor support and placement assistance. Prefer video? Follow along on our YouTube channel.


