🧱
Module 1 · Fundamentals
Variables, dependencies, outputs, state
01
Introduction to IaC + Terraform
Immutable Infrastructure
Immutable Infrastructure
What is IaC (Infrastructure as Code), and why do we need it? Your first
terraform init, plan, apply, destroy. Mini-project: deploying a static website on S3 from scratch.
02
Variables and Data Types
Parameterized Config
Parameterized Config
Parameterizing configuration: string, number, bool, list, map, object.
.tfvars files, validation. Project: an EC2 instance configured through variables.
03
Resources and Dependencies
Dependency Graph
Dependency Graph
How Terraform builds the dependency graph. Explicit (
depends_on) and implicit dependencies. Project: VPC + Subnet + Security Group + EC2 — a complete network from scratch.
04
Outputs and Data Sources
Data-Driven Lookup
Data-Driven Lookup
How to retrieve data from existing infrastructure and pass values between configurations. Project: automatically looking up the latest AMI + EC2 deployment.
05
State — How Terraform Remembers
Remote State Locking
Remote State Locking
The state file: why it is needed and why losing it is dangerous. S3 remote backend, locking for teamwork. A critical topic — mistakes in state are costly.
📈
Module 2 · Scaling
Modules, count/for_each, ALB, RDS, lifecycle
06
Modules — Reusable Code
Reusable Module Multi-AZ HA
Reusable Module Multi-AZ HA
The DRY principle in Terraform: creating and using modules. Inputs, outputs, nested modules. Project: a VPC module with a Multi-AZ NAT Gateway that is reused in later lessons.
07
Count and for_each
Fan-Out Pattern Multi-AZ HA
Fan-Out Pattern Multi-AZ HA
Creating resources dynamically: N servers across different AZs with a single block. The difference between count and for_each, and when to use which. Indexing and referencing resources.
08
ALB + Auto Scaling Group
Load-Balanced Auto-Scaling Active-Active Multi-AZ HA
Load-Balanced Auto-Scaling Active-Active Multi-AZ HA
A resilient web server: Application Load Balancer, Launch Template, Auto Scaling Group with health checks. A pattern used in 90% of production environments.
09
RDS Multi-AZ
Active-Standby Failover Active-Passive Multi-AZ HA
Active-Standby Failover Active-Passive Multi-AZ HA
A managed database: PostgreSQL with automatic failover. Parameters, subnet groups, security. Working with sensitive values and
prevent_destroy to protect data.
10
Lifecycle and Provisioners 📖 Self-study
Blue-Green Lifecycle
Blue-Green Lifecycle
Resource lifecycle rules:
create_before_destroy, ignore_changes, replace_triggered_by. Provisioners (local-exec, remote-exec) — when they are acceptable and why it is better to avoid them.
🏗️
Module 3 · Production Patterns
Dynamic blocks, functions, CDN, ECS, workspaces, Terragrunt
11
Dynamic Blocks and Conditionals
Policy-as-Code
Policy-as-Code
Generating repeated blocks from variables. Conditional operators (
count = var.enabled ? 1 : 0). Project: flexible Security Groups driven by map-type variables.
12
Functions and Expressions 📖 Self-study
Computed Network Layout
Computed Network Layout
Terraform's built-in functions: string, collection, numeric and filesystem functions. Complex expressions:
cidrsubnet(), merge(), lookup(). A reference lesson with practical examples.
13
S3 + CloudFront CDN 🔴 YouTube Live
Edge-Cached Static Hosting Edge Caching
Edge-Cached Static Hosting Edge Caching
Delivering content globally: an S3 bucket as the origin, a CloudFront distribution, an ACM certificate for HTTPS. Origin Access Control (OAC), cache policies, attaching a custom domain.
14
ECS Fargate
Serverless Containers Active-Active Serverless
Serverless Containers Active-Active Serverless
“Serverless” containers on AWS: Task Definition, Service, ALB integration. IAM roles for tasks, an ECR repository.
jsonencode() for describing containers.
15
Workspaces
Environment Isolation Multi-Environment
Environment Isolation Multi-Environment
Separating environments with a single codebase: Dev / Staging / Prod. Per-workspace variables, configuration strategies. When workspaces are enough and when you need Terragrunt.
16
Terragrunt 📖 Self-study
DRY Multi-Environment Multi-Environment
DRY Multi-Environment Multi-Environment
DRY multi-environment infrastructure:
terragrunt.hcl, configuration inheritance, dependencies between modules. A separate tool that sits on top of Terraform, for complex projects.
⚡
Module 4 · Advanced Patterns
Lambda, event pipelines, IAM, Secrets, troubleshooting
17
Lambda + API Gateway
Serverless REST API Event-Driven Serverless
Serverless REST API Event-Driven Serverless
Serverless API: packaging code with
archive_file, a Lambda function, the REST API Gateway service. IAM roles, CloudWatch Logs. The “serverless” architecture pattern.
18
SNS + SQS + Lambda
Event-Driven Pipeline Event-Driven Fan-Out / Pub-Sub Serverless
Event-Driven Pipeline Event-Driven Fan-Out / Pub-Sub Serverless
Event-driven architecture: SNS topics, SQS queues, Lambda handlers. Resource policies, dead-letter queues. Building an event pipeline with AWS services.
19
IAM Deep Dive 📖 Self-study
Least-Privilege Access
Least-Privilege Access
Secure IAM architecture: policies, roles, STS assume role, permission boundaries. The principle of least privilege. A topic where mistakes = security holes.
20
Secrets Manager + KMS
Encryption at Rest
Encryption at Rest
Managing secrets: Secrets Manager, SSM Parameter Store, KMS encryption. How to avoid storing passwords in code. Secret rotation, integration with RDS and Lambda.
21
Import, Drift, Troubleshooting 📖 Self-study
Drift Detection & Recovery
Drift Detection & Recovery
Real-world problems: importing existing resources into state, detecting drift, debugging (
TF_LOG). Recovering from mistakes, terraform state mv/rm.
🌍
Module 5 · Enterprise Scale
Multi-region, CI/CD, monitoring, final project
22
Multi-Region
Active-Passive DR Active-Passive Multi-Region DR
Active-Passive DR Active-Passive Multi-Region DR
Disaster Recovery and replication: multiple AWS providers, Route53 failover, S3 cross-region replication. An architecture that survives an entire region going down.
23
CI/CD for Terraform
GitOps Pipeline GitOps / CI-CD
GitOps Pipeline GitOps / CI-CD
Deployment automation: a GitHub Actions pipeline —
plan on pull requests and apply on merge. OIDC authentication, approval gates, artifacts.
24
Monitoring and Alerts
Observability Stack
Observability Stack
CloudWatch dashboards, metrics, alarms, SNS notifications. Building an observability layer for the entire infrastructure. A
for_each loop for templating alerts.
25
🎓 Final Project 📖 Self-study
Production-Ready Architecture Active-Active Active-Passive Edge Caching Multi-AZ HA
Production-Ready Architecture Active-Active Active-Passive Edge Caching Multi-AZ HA
Putting it all together: a production-grade stack with VPC, ECS, RDS, monitoring, CI/CD and secrets. Multi-environment and fully automated. Project defense.