Terraform & OpenTofu HCL Infrastructure Architect & Security Linter
Synthesize enterprise-grade, CIS-hardened Terraform and OpenTofu HCL manifests for AWS, GCP, and Azure. Audit configurations against 10 critical security rules (open ingress, unencrypted storage, missing remote locks, wildcard IAM policies), visualize resource dependency DAGs, and calculate monthly infrastructure cost budgets in browser memory.
Cloud Provider & Remote Backend Architecture
Remote State Backend & Locking
VPC Network Fabric & Managed Compute Architecture
Provisions public subnets for ingress, isolated private subnets for compute, and database subnets with zero internet ingress routes.
Creates control plane with private endpoint access, managed node groups, envelope KMS secret encryption, and IRSA OIDC identity provider.
Storage Volumes, Relational Database & IAM Hardening
Deploys PostgreSQL in isolated database subnets with automated backup retention, storage encryption, and deletion protection.
Enforces aws_s3_bucket_public_access_block, TLS 1.2+ enforce policy, AES-256/KMS encryption, and versioning.
CIS Benchmark & Static Security Analysis Linter
Every generated resource is continuously validated against 10 critical security invariants. You can also paste your own external HCL in the code tab to audit for vulnerabilities.
Resource Directed Acyclic Graph (DAG) Execution Topology
Terraform parses explicit depends_on and implicit resource attribute references to construct a Directed Acyclic Graph (DAG). Resources on parallel branches are provisioned concurrently using worker threads.
Estimated Monthly Cloud Infrastructure Budget
Infrastructure as Code Architectural Showdowns
Critical engineering evaluations comparing infrastructure provisioning runtimes, state isolation patterns, and declarative versus imperative compilation models.
Terraform (HashiCorp BSL) vs OpenTofu (Linux Foundation MPL 2.0)
The Licensing Schism: In August 2023, HashiCorp migrated Terraform from open-source MPL 2.0 to the Business Source License (BSL 1.1), which prohibits using Terraform code in products competitive with HashiCorp Cloud Platform (HCP). In response, the Linux Foundation launched OpenTofu as a perpetually open fork.
Technical Innovations: While maintaining strict syntax compatibility, OpenTofu 1.7+ introduced native client-side state file encryption using AES-GCM or RSA key pairs directly in HCL. This eliminates the decade-old vulnerability where Terraform writes plaintext secrets into S3 backends. OpenTofu also ships enhanced testing mocking and early variable evaluation in backend definitions.
Declarative HCL (Terraform/OpenTofu) vs Imperative Code (Pulumi / AWS CDK)
Declarative Reconciliation: HCL describes the desired terminal state of infrastructure. Terraform calculates the mathematical graph difference between current state and desired state before mutating cloud APIs. This guarantees that plans are deterministic and reproducible without hidden side effects.
Imperative Abstraction: Pulumi and AWS CDK execute standard programming languages (TypeScript, Python, Go) that synthesize into state or CloudFormation templates. While imperative code enables loops and shared package ecosystems, it introduces runtime debugging complexity, unmockable network calls during compilation, and unpredictable diffs.
Monolithic State vs Modular State Tiers (Terragrunt / Stacks)
Monolithic Blast Radius: Storing VPC, database, Kubernetes, and DNS records in a single root state creates an existential liability. A network timeout during a minor Route53 record update locks the entire state, preventing any engineer across the company from deploying hotfixes.
Tiered Decoupling: Enterprise architectures isolate state into distinct layers: Network Layer (VPC, Subnets) modified quarterly; Data Layer (Aurora, Redis, S3) modified monthly; and Application Layer (EKS, IAM, Ingress) modified multiple times per day. Decoupling state files drops plan durations from 8 minutes to 4 seconds, and catastrophic destruction is physically isolated.
Remote S3 + DynamoDB Locking vs Terraform Cloud / Spacelift Run Tasks
Self-Hosted S3/DynamoDB: Minimal cost (less than $1/month for S3 storage and DynamoDB pay-per-request), zero external SaaS dependencies, and full data sovereignty within your own AWS account boundaries.
Managed Orchestration (Spacelift/Terraform Cloud): Provides remote execution agents, automated OPA (Open Policy Agent) Rego policy enforcement, ephemeral PR preview environments, and structured drift detection schedules.
State Drift vs Tainted State vs Configuration Drift
State Drift: Occurs when human operators alter cloud resources out-of-band directly via the AWS/GCP Console or CLI. During the next refresh or plan, Terraform queries live APIs and flags disparities.
Tainted Resources: When a resource creation succeeds partially but fails during a provisioner step, Terraform marks the object as "tainted" in the state file. On the subsequent apply, Terraform forcefully destroys and recreates the tainted resource to restore known-good integrity.
5 Fatal Infrastructure as Code Disasters in Production
Post-mortem analyses of real-world cloud outages caused by state synchronization failures, missing destruction safeguards, and unencrypted credentials.
1. Plaintext Database Passwords in Remote State
An engineering team generated RDS master credentials using random_password and pushed state to S3. Because developer IAM roles had read access to the bucket, an attacker who compromised a junior developer laptop downloaded the state JSON and extracted plaintext RDS root credentials within 60 seconds.
2. The Unlocked State Apply Race Condition
Two GitHub Actions workflows triggered concurrently on separate merge commits without DynamoDB locking configured. Both jobs read the state simultaneously, computed incompatible plans, and wrote conflicting updates. Half of the production VPC subnets were wiped from the state file, stranding live database instances.
3. Refactoring-Induced Cascading Destruction
A developer renamed an HCL resource block from aws_db_instance.db to aws_db_instance.main without running terraform state mv. Terraform interpreted the change as deleting the old database and provisioning an empty one, destroying 8TB of customer data in production.
4. Wildcard Security Group Ingress Poisoning
During debugging, an engineer added 0.0.0.0/0 to a security group on port 5432 (PostgreSQL) and committed it to Git. Automated CI applied the manifest without security linting. Within 18 minutes, automated internet bots detected the open port and initiated brute-force attacks.
5. Circular Module Graph Deadlock
Two nested modules cross-referenced each other's outputs (VPC module requiring Security Group ID, and Security Group module requiring VPC CIDR). Terraform's DAG compiler crashed with a "Cycle in graph" error, preventing updates until the cycle was resolved.
Graph Theory, DAG Topological Ordering & Concurrency Mathematics
Terraform models cloud infrastructure as a Directed Acyclic Graph \( G = (V, E) \), where vertices \( V \) represent resources and directed edges \( E = (u, v) \) represent dependency constraints.
\( L \leftarrow \text{Empty list}, \quad S \leftarrow \{ v \in V \mid \deg^-(v) = 0 \} \)
While \( S \neq \emptyset \): Remove \( u \in S \), append \( u \) to \( L \). For each edge \( (u, v) \), decrement \( \deg^-(v) \); if \( \deg^-(v) = 0 \), insert \( v \) into \( S \). Time complexity: \( \mathcal{O}(|V| + |E|) \).
Actions: \( \text{Create} \iff r \notin S_{\text{actual}} \), \( \text{Destroy} \iff r \notin S_{\text{desired}} \), \( \text{Update} \iff r_{\text{desired}} \neq r_{\text{actual}} \land \text{immutable}(r) = \text{false} \).