State Architecture: Remote state (S3), State locking (DynamoDB) to prevent concurrent runs.
State Manipulation: terraform state rm (removing without deleting), terraform import (bringing manual resources into IaC), terraform taint/apply -replace.
HCL Mastery: for_each vs count, dynamic blocks, locals, data sources, depends_on, lifecycle rules (create_before_destroy).
2. Enterprise Module Design
Root vs Child Modules: Composition over inheritance. Passing variables, outputting IDs.
Multi-Account Deployments: Configuring multiple provider blocks with alias. Using assume_role to authenticate to child accounts from a central management CI/CD pipeline.
3. Policy-as-Code (Shift-Left)
Checkov / tfsec: Static analysis of Terraform code.
OPA (Open Policy Agent): Basic Rego syntax to write custom compliance rules (e.g., "All VPCs must have flow logs enabled").
π οΈ Job-Essential Exercises
The Remote Backend Setup:
Manually create an S3 bucket and DynamoDB table. Configure a Terraform backend block to use them. Verify state locking by running terraform apply in two terminal windows simultaneously.
The Cross-Account Deployer:
Write a Terraform script with two AWS providers (using aliases and assume_role). Deploy an S3 bucket in Account A and an SQS queue in Account B in a single terraform apply.
The State Import Challenge:
Go into the AWS Console and manually create an EC2 instance. Write the corresponding Terraform code, and use terraform import to map the manual instance to your code without destroying it.
Shift-Left Security Gate:
Write a Terraform module for an S3 bucket with encryption explicitly turned off. Run checkov -f main.tf and watch it fail. Fix the code, re-run, and pass.