Terraform & Terragrunt Zero-to-Hero
A five-tier mastery path — Foundation to Specialist — for Terraform & Terragrunt: author modules for every service, orchestrate multi-environment infrastructure, enforce approval gates, and run an enterprise IaC platform.
Start the courseA complete, job-oriented path through Terraform and Terragrunt: HCL and the core workflow, state and remote backends, authoring and versioning reusable modules, Terragrunt DRY multi-environment orchestration, CI/CD approval gates, policy-as-code, testing, drift recovery, and enterprise IaC platforms — plus a large hands-on real-world layer that provisions actual infrastructure with Terraform on Azure (incl. Azure DevOps pipelines), AWS (VPC/EC2/ALB/RDS/SRE), and Kubernetes on AWS EKS (IRSA, the AWS Load Balancer Controller, ExternalDNS, autoscaling, CSI storage) — and alternative IaC (Pulumi, CDKTF, CloudFormation, Ansible).
What you’ll be able to do
- Write Terraform confidently — HCL, providers, the core workflow and state
- Author, test, version and publish reusable modules for any cloud
- Orchestrate dev/uat/staging/prod with Terragrunt — DRY, dependencies, remote state
- Enforce approval gates, policy-as-code and OIDC keyless auth in CI/CD
- Recover from drift and state corruption, and operate state at scale
- Architect an enterprise IaC platform and be Terraform-Associate-ready
Prerequisites
- Basic IT literacy and a terminal — no prior IaC experience required
- A free cloud account (AWS/Azure/GCP) for the hands-on labs
Who it’s for
Engineers new to IaC, cloud engineers standardising infrastructure, and people preparing for the HashiCorp Terraform Associate or real platform-engineering work.
Curriculum
Tier 1 · Foundation — Terraform Basics (Associate)
Start at zero: what IaC is, HCL, the core workflow, state, and authoring your first reusable module.
- 1 Terraform Fundamentals: HCL, Providers, State & the Core Workflow
- 2 The Terraform CLI, In Depth: Install, First Steps & the Complete Command Reference
- 3 HCL, In Depth: Blocks, Arguments, Expressions, Types & Templates
- 4 Terraform Providers, In Depth: required_providers, Versions, Aliases & the Lock File
- 5 Terraform Resources & Meta-Arguments, In Depth: count, for_each, depends_on & lifecycle
- 6 Terraform Variables, Outputs & Locals, In Depth: Types, Validation, Sensitivity & Precedence
- 7 Infrastructure as Code: Core Concepts — State, Plan/Apply, Drift & Idempotency
- 8 Authoring Terraform Modules: Structure, Inputs/Outputs, Versioning & Publishing
- 9 Consuming Terraform Modules, In Depth: Sources, Versions, Composition & the Registry
Tier 2 · Intermediate — State, Remote Backends & HCL Depth
Scale beyond a laptop: remote state, dynamic blocks & complex types, and safe refactoring.
- 10 Terraform Remote State at Scale: Backends, Locking, Splitting, and State Surgery
- 11 Terraform State, In Depth: the State File, the state Commands, Locking & Sensitive Data
- 12 Terraform Backends, In Depth: Local vs Remote, Every Backend Type, Locking & Migration
- 13 HCP Terraform (Terraform Cloud), In Depth: Workspaces, VCS-Driven Runs, Remote State & the Private Registry
- 14 Terraform Workspaces, In Depth: CLI Workspaces vs HCP Workspaces, State Isolation & When to Use Each
- 15 Mastering Terraform Dynamic Blocks, Complex Types, and Variable Validation
- 16 Terraform Built-in Functions & Expressions, In Depth: for, dynamic, conditionals & the Function Catalog
- 17 Terraform Provisioners, In Depth: local-exec, remote-exec, connection, null_resource & terraform_data
- 18 Refactoring Terraform Safely with moved, import, and removed Blocks
Tier 2 · Intermediate — Terragrunt
Stay DRY at scale: Terragrunt fundamentals, multi-account environments, and monorepo run-all.
- 19 Terragrunt Fundamentals: DRY Configurations, Remote State & Dependencies
- 20 Terragrunt Configuration, In Depth: Every Block, Function & Hook in terragrunt.hcl
- 21 Terragrunt Stacks, In Depth: Units, Stacks, values & Generating Infrastructure from a Blueprint
- 22 DRY Multi-Environment Infrastructure with Terragrunt: Stacks, Dependencies, and Promotion
- 23 Scaling Terragrunt Monorepos with Dependency Graphs and run-all
Tier 3 · Advanced — Multi-Environment & CI/CD Approval Gates
Promote dev→uat→staging→prod safely: the 3-tier pattern, OIDC PR automation, Atlantis and Spacelift.
- 24 Multi-Environment 3-Tier Infrastructure with Terragrunt & CI/CD Approval Gates
- 25 A Production Terraform CI/CD Pipeline on GitHub Actions with OIDC
- 26 Deploy Atlantis for Pull-Request Terraform Automation with Server-Side Workflows
- 27 Configure Spacelift Stacks, OPA Policies, and Drift Detection for Terraform GitOps
Tier 3 · Advanced — Policy-as-Code & Security
Guardrails on every plan: Checkov/tfsec/Trivy, OPA/Conftest, Sentinel, and secrets in IaC.
Tier 3 · Advanced — Testing & Provider Development
Prove modules work: native testing + Terratest, and building your own provider.
Tier 3 · Advanced — State Operations, Drift & Orchestration
Operate state in anger: drift reconciliation, state surgery/recovery, and stacks orchestration.
- 34 Detecting and Reconciling Terraform Drift Without Nuking Production
- 35 Terraform State Surgery: Recovering from Corruption, Locks, and Split-Brain
- 36 Importing Existing Infrastructure into Terraform, In Depth: import Blocks, Config Generation & Brownfield Adoption
- 37 Orchestrating Multi-Environment Infrastructure with Terraform Stacks
Tier 4 · Real-World — Terraform on Azure (Infrastructure & Azure DevOps)
Apply Terraform to Azure end to end: the azurerm provider and remote state, resource groups, networking, VMs, load balancing, App Service, AKS, Key Vault/SQL/DNS, Azure DevOps CI/CD pipelines, and multi-environment landing zones — every lesson a complete, runnable demo.
- 38 Terraform on Azure: The azurerm Provider, Authentication (CLI/SPN/MSI/OIDC) & Remote State in Azure Storage
- 39 Terraform on Azure: Resource Groups, Storage Accounts, Naming Conventions & Tagging Strategy
- 40 Terraform on Azure: Virtual Networks, Subnets, NSGs, Route Tables & VNet Peering
- 41 Terraform on Azure: Linux & Windows Virtual Machines, NICs, Public IPs, cloud-init & Scale Sets
- 42 Terraform on Azure: Azure Load Balancer, Application Gateway, WAF & Health Probes
- 43 Terraform on Azure: App Service Plans, Web Apps, Deployment Slots & Custom Domains
- 44 Terraform on Azure: Key Vault (Secrets), Azure SQL Database & Azure DNS as Code
- 45 Terraform on Azure: Provisioning AKS — Node Pools, Managed Identity, RBAC, Add-ons & kubeconfig
- 46 Terraform CI/CD with Azure DevOps: YAML Pipelines, Service Connections, plan/apply Stages & Approval Gates
- 47 Terraform on Azure at Scale: Reusable Modules, Multi-Environment Landing Zones & SRE Practices
Tier 4 · Real-World — Terraform on AWS (Infrastructure & SRE)
Apply Terraform to AWS end to end: the aws provider and S3+DynamoDB remote state, VPC networking, EC2 and security groups, ALB/NLB load balancing, Auto Scaling, Route 53 and ACM, RDS/Aurora, IAM and S3, CloudWatch/SNS observability, and a full 3-tier architecture with reusable modules and SRE practices — every lesson a complete, runnable demo.
- 48 Terraform on AWS: The aws Provider, Authentication (Profiles/Assume-Role/OIDC) & Remote State in S3 + DynamoDB
- 49 Terraform on AWS: Building a VPC — Public/Private Subnets, Internet & NAT Gateways & Route Tables
- 50 Terraform on AWS: EC2 Instances, Security Groups, Key Pairs, EBS Volumes & user-data
- 51 Terraform on AWS: Application & Network Load Balancers, Target Groups, Listeners & Health Checks
- 52 Terraform on AWS: Auto Scaling Groups, Launch Templates, Scaling Policies & ALB Integration
- 53 Terraform on AWS: Route 53 DNS (Records, Alias, Failover, Weighted) & ACM SSL Certificates
- 54 Terraform on AWS: RDS & Aurora — Subnet Groups, Parameter Groups, Multi-AZ, Read Replicas & Secrets
- 55 Terraform on AWS: IAM (Users, Roles, Policies, Instance Profiles) & S3 (Buckets, Policies, Encryption, Versioning)
- 56 Terraform on AWS: CloudWatch Alarms, Dashboards & Logs, SNS Alerting & SRE Observability as Code
- 57 Terraform on AWS at Scale: A 3-Tier Web Architecture, Reusable Modules, Multi-Environment & SRE
Tier 5 · Specialist — Terraform on AWS EKS (Kubernetes Platform, 50-Demo Scope)
Provision and run a production Kubernetes platform on EKS entirely with Terraform: the cluster/VPC/node groups, IRSA, the kubernetes & helm providers and the GitOps handoff, the AWS Load Balancer Controller, ALB Ingress + ACM + ExternalDNS, Cluster Autoscaler & Karpenter, HPA/VPA, EBS & EFS CSI storage, Fargate, observability, and the end-to-end platform capstone — every lesson a runnable demo.
- 58 Terraform on AWS EKS: Provisioning the Cluster, VPC & Managed Node Groups from Scratch
- 59 Terraform on AWS EKS: OIDC Provider & IRSA — IAM Roles for Service Accounts (the Core Security Pattern)
- 60 Terraform on AWS EKS: the kubernetes & helm Providers, App Deployment & the GitOps Handoff
- 61 Terraform on AWS EKS: Installing the AWS Load Balancer Controller (IRSA + Helm)
- 62 Terraform on AWS EKS: ALB Ingress, ACM SSL, ExternalDNS & Route 53 Automation
- 63 Terraform on AWS EKS: Node Autoscaling with Cluster Autoscaler & Karpenter
- 64 Terraform on AWS EKS: Metrics Server, Horizontal & Vertical Pod Autoscaling
- 65 Terraform on AWS EKS: the EBS CSI Driver, StorageClasses & Persistent Volumes for Stateful Workloads
- 66 Terraform on AWS EKS: the EFS CSI Driver & Shared ReadWriteMany Storage
- 67 Terraform on AWS EKS: Fargate Profiles — Serverless Pods Without Managing Nodes
- 68 Terraform on AWS EKS: Observability — CloudWatch Container Insights, Prometheus & Grafana
- 69 Terraform on AWS EKS: Assembling a Production Platform — the End-to-End Capstone
Tier 4 · Expert — IaC Tool Selection
Choose the right tool: Terraform vs Terragrunt vs Ansible vs Pulumi.
Tier 5 · Specialist — Alternative IaC & Multi-Cloud
Beyond Terraform: Pulumi, CDKTF, CloudFormation, Crossplane and Bicep.
- 71 Programmatic IaC with Pulumi and TypeScript: Component Resources and the Automation API
- 72 Advanced Pulumi in Python: Dynamic Providers and Stack References
- 73 Programmatic Infrastructure with CDK for Terraform in TypeScript
- 74 Advanced CloudFormation: StackSets, Custom Resources, Hooks, and Drift at Org Scale
- 75 Extending CloudFormation with Macros, Transforms, and CDK Escape Hatches
- 76 Building an Internal Cloud API with Crossplane Compositions and XRDs
- 77 Shipping Azure Workloads with Bicep: Deployment Stacks, what-if, and a CI Pipeline
- 78 Operating a Bicep Private Module Registry and Templating at Scale
Tier 5 · Specialist — Configuration Management (Ansible)
Configure servers idempotently: Ansible collections/testing and dynamic inventory.
Tier 5 · Specialist — 3rd-Party Integrations & On-Prem Provisioning
Terraform everywhere: Datadog, Snowflake, vSphere/Packer, Nutanix and OpenStack.
- 81 Configure Datadog Monitors, SLOs, and Synthetic Browser Tests as Code with Terraform
- 82 Set Up Snowflake RBAC, Resource Monitors, and Warehouse Auto-Suspend with Terraform
- 83 Provision VMware vSphere Clusters with Packer and Terraform Golden Images
- 84 Set Up Nutanix AHV Clusters with Prism Central and the Terraform NX Provider
- 85 Provision OpenStack Compute and Networking with Terraform and Heat Templates
Track · Troubleshooting (Easy → Complex)
Diagnose anything: state, providers, drift, dependencies and CI/CD failures.
Track · Architecting (Easy → Complex)
Turn requirements into IaC platforms: a six-rung ladder from a single module to an enterprise platform.
Track · Certification Center
Pass the exam: the HashiCorp Terraform Associate (003) prep kit.
Track · Job-Ready — Projects
Get hired: a six-project portfolio ladder from a first module to a multi-cloud platform.