Architecting AWS with Terraform (Erol Kavas)(Z-Library)
Other
Design resilient and secure Cloud Infrastructures with Terraform on Amazon Web Services
3
Views
Registered users can read the full content for free
Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.
Page
1
(This page has no text content)
Page
2
Architecting AWS with Terraform Copyright © 2023 Packt Publishing All rights reserved. No part of this book may be reproduced, stored in a retrieval system, or transmitted in any form or by any means, without the prior written permission of the publisher, except in the case of brief quotations embedded in critical articles or reviews. Every effort has been made in the preparation of this book to ensure the accuracy of the information presented. However, the information contained in this book is sold without warranty, either express or implied. Neither the author, nor Packt Publishing or its dealers and distributors, will be held liable for any damages caused or alleged to have been caused directly or indirectly by this book. Packt Publishing has endeavored to provide trademark information about all of the companies and products mentioned in this book by the appropriate use of capitals. However, Packt Publishing cannot guarantee the accuracy of this information. Group Product Manager: Preet Ahuja Publishing Product Manager: Niranjan Naikwadi Senior Editor: Divya Vijayan Technical Editor: Irfa Ansari Copy Editor: Safis Editing Project Coordinator: Ashwin Kharwa Proofreader: Safis Editing Indexer: Rekha Nair
Page
3
Production Designer: Prashant Ghare Marketing Coordinator: Rohan Dobhal First published: December 2023 Production reference: 1071223 Published by Packt Publishing Ltd. Grosvenor House 11 St Paul’s Square Birmingham B3 1RB ISBN 978-1-80324-856-1 www.packtpub.com
Page
4
To my incredible wife, Mihrimah, whose steadfast support and unwavering belief in me have been my guiding light through every challenge and triumph. Your selfless dedication and willingness to help, no matter the circumstances, have been the foundation upon which I have built my dreams. You are my rock, my partner, and my inspiration. This book is a testament to your love and support.
Page
5
– Erol Kavas Contributors About the author Erol Kavas is a renowned multi-cloud expert and cloud evangelist in Canada, with over 20 years of industry experience. As a Microsoft Certified Trainer (MCT) Regional Lead and an AWS Ambassador, Erol is a recognized authority in cloud computing. His career spans roles such as solutions architect, security architect, enterprise architect, and delivery lead. Erol’s passion lies in helping enterprises become future-proof, with cutting-edge cloud infrastructure and security solutions. He holds over 100 certificates in cloud, security, and project management. Currently, Erol serves as a director in the cloud and data team at PwC Canada.
Page
6
I want to thank the people who have been close to me and supported me, especially my wife, Mihrimah, my kids, Esad and Azra, and my colleagues. About the reviewers Hamza Koc has accumulated over five years of expertise in software development, cloud infrastructure, and DevOps. He stands out for his profound understanding of major cloud platforms, particularly Microsoft Azure, AWS, and GCP. As a cloud and DevOps engineer, Hamza has streamlined code delivery processes to Kubernetes clusters, architected scalable cloud solutions, and led automation efforts using tools such as Terraform. Beyond his hands-on roles, Hamza is an esteemed Microsoft Azure and Terraform trainer, guiding professionals in mastering cloud technologies and practices. His achievements are further underscored by a robust collection of certifications from industry leaders, such as Microsoft and AWS. I wish to express my deep appreciation to my mentors and colleagues for their constant guidance. My utmost gratitude goes to my family for their unwavering belief in my capabilities, and to the visionary teams I’ve collaborated with, who have been a constant source of inspiration. Dr. Ramazan Atalay is a global cloud security expert. With a B.Sc. in physics from METU and a Ph.D. in physics from Georgia State University, his education underpins his dynamic career in cybersecurity. Currently at Loblaw Inc., he is a full-time employee and a Microsoft Certified Trainer for top courses on cloud security and cybersecurity. His passion for mentoring extends to his role as a colleague in Loblaw’s cybersecurity, network, and technology risk department. Dr. Atalay is a leading figure in the cybersecurity domain, with a dedicated commitment to education and knowledge sharing.
Page
7
Table of Contents Preface
Page
8
Part 1: Introduction to IAC and Terraform in AWS 1 Understanding Patterns and Antipatterns of IaC and Terraform Introducing IaC Key principles of IaC Patterns and practices of IaC Source control and VCS Modules and versions Documentation Testing Security and compliance How to handle IaC projects IaC principles Version control systems for IaC Some common use cases of IaC Challenges and best practices with IaC How to make decisions about IaC projects The decision about where to store your code Summary 2
Page
9
How Not to Use IaC and Terraform Terraform architecture and workflow Architecture Workflow To Compare with the Other IaC Tools Terraform versus CloudFormation What is AWS CloudFormation? Comparison and differences between Terraform and CloudFormation Terraform or CloudFormation – which should I choose? Summary 3 Building Your First Terraform Project How to install Terraform Manual installation Popular package managers Verifying the installation How to install/prepare Terraform for AWS Prerequisites AWS CLI installation
Page
10
Creating an IAM user and credentials for Terraform Building your first Terraform configuration Building your first Terraform template Provisioning and testing your template Summary 4 Discovering Best Practices for Terraform IaC Projects How to maintain IaC projects with Terraform Follow a standard module structure Adopt a naming convention Use variables carefully Expose outputs Use data sources Leverage tfvars files Separate variables and inputs based on their functionality Limit the use of custom scripts Include helper scripts in a separate directory Put static files in a separate directory Protect stateful resources Use built-in formatting
Page
11
Limit the complexity of expressions Use count for conditional values Use for_each for iterated resources Publish modules to a registry How to execute IaC projects with Terraform How to secure IaC projects with Terraform Implementing Terraform in DevOps or cloud teams Summary
Page
12
Part 2: Become an Expert in Terraform with AWS 5 Planning and Designing Infrastructure Projects in AWS Terraform infrastructure project planning basics The speed benefits The risk management benefits Security, reusability, and governance Team skill sets The best candidates for automation The types of applications you’ll be running The cost of automating too many tasks The critical nature of the code The need for software expertise The impact on agility Integration with existing infrastructure Goals and available resources The long-term plan Quality control and security How to design your first Terraform template in AWS Authentication with AWS
Page
13
Setting up programmatic access Create your first AWS infrastructure with Terraform Understanding AWS Providers What are AWS Providers and why are they important in Terraform? How to configure an AWS Provider in your Terraform code Understanding the different versions of the AWS Provider and their compatibility with Terraform Best practices for working with AWS Providers in Terraform Understanding Terraform modules What is a Terraform module? Using modules Local and remote modules Module best practices What problems do Terraform modules solve? How to implement best practices with Terraform AWS modules Terraform configurations file separation Follow a standard module structure Use opinionated modules to do exactly what you need Leverage official open source modules
Page
14
Make extensive use of convention over configuration Make modules flexible with multiple optional inputs Refer to modules by version Consider bundling modules together if they serve a common purpose Consider using variable and naming validation Use locals correctly Keep the code in your module logically separated Separate required and optional variables Always have an example folder within your module folder Summary 6 Making Decisions for Terraform Projects with AWS AWS infrastructure and fundamentals What is AWS infrastructure? What are the main AWS product and service categories? How to make decisions to start a Terraform project in AWS
Page
15
How to start designing your first AWS infrastructure AWS Organizations and network fundamentals AWS resources fundamentals AWS shared responsibility model How to select AWS resources AWS environments, projects, workloads What is an environment? How to define environments or projects in AWS Summary 7 Implementing Terraform in Projects Terraform basics for developing AWS infrastructure projects Resources Providers State Modules Variables Outputs Provisioners Selecting AWS Providers
Page
16
Selecting AWS public modules for your needs How to decide on Terraform module selection How to write custom Terraform AWS modules Summary 8 Deploying Serverless Projects with Terraform What are landing zones and why do we need them? AWS Foundations How to build landing zones with Terraform in AWS What is serverless? What are AWS serverless patterns? What is AWS Lambda? What is AWS Fargate? How to design a serverless infrastructure with Terraform How to develop a serverless infrastructure How to deploy a serverless infrastructure using Terraform Summary 9
Page
17
Deploying Containers in AWS with Terraform What are containers? Containers in AWS The reasons for using containers How to containerize applications AWS containers How to choose the best containerization platform in AWS How to utilize Terraform for containers Deploying containers with Terraform How to use Terraform for AWS container resources How to deploy AWS ECR with Terraform Deploying container images to AWS container platforms with Terraform Creating an AWS EKS cluster with Terraform Deploying an application to an AWS EKS cluster with Terraform Summary
Page
18
Part 3: How to Structure and Advance Terraform in Enterprises 10 Leveraging Terraform for the Enterprise What is an enterprise infrastructure project? What is an AWS enterprise project? How to define needs and solutions for an AWS enterprise project Defining success in AWS enterprise projects How to discuss AWS enterprise projects How to leverage Terraform in AWS enterprise projects Some recommendations for AWS enterprise projects Summary 11 Building Git Workflows for IaC and Terraform Projects Why do we need a Git workflow? Implementing a Git workflow Tools and flows to use with AWS Terraform projects
Page
19
How to secure a Terraform project Streamlining AWS Terraform projects Summary 12 Automating the Deployment of Terraform Projects What is deployment in Terraform? What is CI/CD for Terraform? Why do we need CI/CD tool for Terraform? What is the best CI/CD for Terraform? How to build the governance and auditability of provisioning infrastructure How to provision infrastructure securely Summary 13 Governing AWS with Terraform What is infrastructure governance? The importance of infrastructure governance Key elements of infrastructure governance Benefits of infrastructure governance Why do we need infrastructure governance? Security and compliance
Page
20
Cost optimization Standardization and consistency Risk management How to govern infrastructure with Terraform Resource provisioning with Terraform Summary 14 Building a Secure Infrastructure with AWS Terraform What is security in infrastructure? Threats to infrastructure security The importance of infrastructure security Basic principles of infrastructure security Types of security measures for infrastructure The role of governance in infrastructure security How to govern security in AWS AWS security services and features AWS security compliance and certifications AWS security governance frameworks Monitoring and logging for AWS security Incident response for AWS security How to build secure infrastructure in Terraform Implementing least privilege using IAM policies
The above is a preview of the first 20 pages. Register to read the complete e-book.
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
AI guide
【One-Line Pitch】
A hands-on guide to designing, automating, and operating resilient AWS infrastructure with Terraform, aimed at cloud, DevOps, and platform engineers who want to move from clicking in the console to codifying their infrastructure. It pairs Terraform fundamentals with AWS-specific patterns for containers, operations, and enterprise-scale governance.
【Book Arc】
- **Opening (~0%–10%)**: Frames the case for Infrastructure as Code, covering its core principles—idempotency and testing—and why declarative, stateful tooling like Terraform changes how teams provision and manage cloud resources.
- **Early (~10%–32%)**: Moves into practical setup: installing Terraform across Linux distributions, creating IAM users and credentials, and understanding the provider/plan/apply workflow alongside comparisons to AWS CloudFormation.
- **Middle (~32%–50%)**: Shifts to project planning and design—choosing what to automate, structuring modules, naming conventions, protecting stateful resources, and managing secrets and CI/CD pipelines.
- **Late (~50%–80%)**: Applies Terraform to concrete AWS workloads, notably containers: containerizing applications, deploying ECR and EKS clusters, and running applications on them with Terraform.
- **Ending (~80%–100%)**: Covers operations and enterprise concerns—SLIs/SLOs/SLAs, monitoring, logging, troubleshooting, scaling, and best practices for large-scale, reusable, governed Terraform projects.
【Key Takeaways】
- **IaC rests on idempotency and testing** (Opening): Terraform's stateful model guarantees the same end state regardless of starting point or run count, while static analysis and layered testing catch issues early.
- **Providers are the bridge to AWS** (Early): Terraform's plugin architecture lets one consistent syntax manage AWS and other platforms, with `terraform plan` previewing changes before apply.
- **Secure credentials from day one** (Early): Create a dedicated IAM user with programmatic access, and never store secrets in repositories—use a vault and inject them at pipeline runtime.
- **Module structure drives maintainability** (Middle): Start modules with `main.tf`, add READMEs and examples, group resources by purpose, and adopt consistent naming conventions.
- **Protect stateful resources** (Middle): Enable deletion protection and `prevent_destroy` lifecycles for databases and other critical infrastructure to avoid accidental loss.
- **Containers are a first-class AWS target** (Late): Terraform can provision ECR, build EKS clusters, and deploy applications onto them, tying container platforms into the same IaC workflow.
- **Operations belong in code too** (Ending): Automate routine tasks, manage changes, monitor, log, and scale infrastructure through Terraform rather than manual console work.
- **Enterprise scale needs governance** (Ending): Large projects demand reusability, clear ownership, and processes for managing complexity across teams.
【Reading Tips】
- Deep-read the Opening and Early chapters if you're new to IaC; the idempotency and provider/plan/apply concepts underpin everything later.
- Skim the installation commands (yum/dnf/Amazon Linux) unless you're setting up a specific distro—the value is in the workflow, not the exact package manager.
- Treat the Middle chapters on module structure and naming as a reference checklist you can apply directly to your own repositories.
- The Late container chapters (ECR/EKS) are the most hands-on; work through them with a real AWS account to internalize the patterns.
- Don't skip the Ending's operations and enterprise material—it's where the book connects day-to-day Terraform use to long-term governance.
【Coverage Limits】
The excerpts cover the book's structure and early-to-middle conceptual material in detail, but the Late container and Ending operations/enterprise chapters are represented mainly through table-of-contents entries rather than full content. Specific code examples, figures, and chapter-level depth for those later sections are not fully reflected here.
Passage locations
Page 12
e sharing. Part 2: Become an Expert in Terraform with AWS 5 Planning and Designing Infrastructure Projects in AWS Terraform infrastructure project planning b...
View in text
Excerpt 2
e automation, security, and compliance. Configuration drift At the start of an IaC journey, developers may not always know what changes are required for infr...
View in text
Excerpt 3
dd users. 3. Use terraform as the username for the new user. This is the sign-in name for AWS. 4. Select the type of access this user will have. You can sele...
View in text
Excerpt 4
ement a VCS to manage changes to the infrastructure code. 5. Implement a CI/CD pipeline: Automate the testing, building, and deployment of Terraform code usi...
View in text
Recommended for You
{{#thumbnailUrl}}
{{/thumbnailUrl}}
{{^thumbnailUrl}}
{{/thumbnailUrl}}
Loading recommended books...
Failed to load, please try again later
Tip the Site
Scan the WeChat Pay or Alipay code to tip. No login required.
WeChat Pay
Alipay