Q: How do you structure a large Terraform codebase for a multi-environment setup?
Recommended structure:
#Terraform #Modules & Structure #L2 #IaC #Cloud Infrastructure #IAM
🎙️ Candidate Opening & Architectural Context
""When terraform plan shows unexpected changes, my golden rule is: never apply blindly. Investigate the diff first. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
Recommended structure:
- Has its own
terraform.tfstate(separate remote backend key per env). - Calls the same modules with different variable values.
- Can be planned/applied independently.
2️⃣
Remediation & Permanent Safeguards
Each environment directory: Terragrunt simplifies this further by handling backend config, module sourcing, and dependency between environments.
infrastructure/
├── modules/ # reusable modules
│ ├── networking/
│ ├── eks/
│ └── rds/
├── environments/
│ ├── dev/
│ │ ├── main.tf # calls modules with dev vars
│ │ ├── variables.tf
│ │ └── terraform.tfvars
│ ├── staging/
│ └── production/
└── global/ # shared resources (IAM, Route53)
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Has its own terraform.tfstate (separate remote backend key per env).."
⚡ 60-Second Elevator Pitch Talking Points
- Has its own terraform.tfstate (separate remote backend key per env).
- Calls the same modules with different variable values.
- Can be planned/applied independently.
Advertisement