Course Outline
Module 1: Introduction to Infrastructure as Code and Terraform
- IaC concepts and their advantages for on-premises and hybrid environments.
- An overview of Terraform, covering providers, resources, state, and lifecycle.
- Installation of Terraform, Azure CLI, and other necessary tools.
- Initial practical exercise: writing and applying a basic Terraform configuration locally.
Module 2: HashiCorp Configuration Language (HCL) and Configuration Basics
- Understanding HCL syntax, resources, attributes, and expressions.
- Working with variables, outputs, locals, and type constraints.
- Using the Terraform CLI: init, plan, apply, destroy, and fmt commands.
- Practical lab: constructing a parameterized configuration for both an on-prem resource and an Azure resource.
Module 3: Providers, Resources, and Azure Provider Fundamentals
- Understanding the role of providers and configuring the AzureRM provider.
- Mapping real-world infrastructure to Terraform resources (networking, compute, storage).
- Handling Azure authentication and service principals for automation purposes.
- Practical exercise: provisioning an Azure virtual network and a basic VM using Terraform.
Module 4: State Management, Backends, and Collaboration
- Exploring Terraform state: its purpose, format, and lifecycle implications.
- Implementing remote backends using Azure Storage Accounts and applying state locking strategies.
- Managing workspaces, environments, and effective team collaboration patterns.
- Lab: setting up remote state in Azure Storage and executing a multi-user workflow.
Module 5: Modularization, Reusability, and Best Practices
- Creating and utilizing Terraform modules.
- Managing module inputs/outputs, versioning, and registry patterns.
- Establishing folder structures, naming conventions, and maintainable repository layouts.
- Practical exercise: developing a reusable module for an Azure VM, disk, and network, then testing it across different environments.
Module 6: Managing Azure Virtual Devices and On-Prem Integration
- Controlling Azure Virtual Machines, Virtual Desktop components, and device lifecycles via Terraform.
- Strategies for hybrid device management: linking on-prem resources with Azure-managed devices.
- Integrating volumetric or device management systems using data sources and external providers.
- Lab: deploying a fleet of Azure VMs to represent operator units, including inventory tagging and basic monitoring setup.
Module 7: CI/CD, Automation, and Deployment Pipelines
- Connecting Terraform with CI/CD tools (such as GitHub Actions and Azure DevOps pipelines).
- Automating plan/apply processes with secured secrets and service principals.
- Basics of Policy as Code (using Sentinel or Open Policy Agent patterns) and pre-deployment checks.
- Practical exercise: creating a simple GitHub Actions workflow to plan and apply Terraform against a sandbox subscription.
Module 8: Security, Secrets, and Operational Practices
- Securing secrets through Azure Key Vault integration and preventing sensitive data from entering state files.
- Managing access control, RBAC, and enforcing least privilege for automation accounts.
- Detecting drift, reconciling state, and applying basic remediation practices.
- Checklist for backup, auditing, and governance of Terraform-managed infrastructure.
Module 9: Testing, Debugging, and Troubleshooting
- Debugging Terraform configurations and interpreting plan diffs effectively.
- Approaches to unit and integration testing (using terraform validate, tflint, kitchen-terraform).
- Identifying common error patterns and strategies for resolving them.
- Lab: executing validation and linting tools and correcting identified issues.
Module 10: Capstone Project — Hybrid Deployment Scenario
- Design challenge: planning an on-prem and Azure device deployment using the patterns learned in the course.
- Implementing core components using modules, remote state, and CI/CD pipeline snippets.
- Presenting the solution, discussing trade-offs, and reviewing the operational runbook.
Summary and Next Steps
Requirements
- A solid grasp of fundamental networking and virtualization principles.
- Proficiency with Windows or Linux command-line interfaces.
- Foundational knowledge of cloud or on-premises infrastructure concepts.
Target Audience
- System administrators and platform engineers.
- DevOps professionals starting their journey with Infrastructure as Code.
- IT teams responsible for managing hybrid infrastructure (combining on-prem and Azure).
Testimonials (3)
pacing for the most part was fantastic. Michal was very good at ensuring the audience were engaged and ensured everyone was following along for the most part
Asif Shaikh - Carpmaels & Ransford
Course - Terraform on Microsoft Azure
Checking all the details in practice - by writing real code
Michal Pipala - EY
Course - Advanced Terraform: Efficient Infrastructure as Code
the instructor was very well prepared