All tutorials and glossary
- AWS
AWS Organizations
AWS Organizations lets you manage many AWS accounts centrally: organizational units, consolidated billing and service control policies to set guardrails.
- AWS
AWS Aurora
Amazon Aurora is a MySQL and PostgreSQL-compatible relational database built for the cloud, with storage replicated across three Availability Zones.
- AWS
AWS WAF
AWS WAF is a web application firewall that filters HTTP requests with rules and managed rule groups to block SQL injection, XSS, bots and abusive traffic.
- AWS
AWS ElastiCache
Amazon ElastiCache is a managed in-memory data store and cache compatible with Valkey, Redis OSS and Memcached, for microsecond latency.
- AWS
AWS CloudFormation
AWS CloudFormation is the native infrastructure as code service of AWS: describe resources in JSON or YAML templates and it manages them as stacks.
- AWS
AWS Systems Manager
AWS Systems Manager (SSM) manages servers at scale: Session Manager shell access without SSH, Parameter Store, Patch Manager, Run Command and Automation.
- AWS
AWS API Gateway
Amazon API Gateway is a managed service to create, publish, secure and monitor REST, HTTP and WebSocket APIs in front of Lambda functions and other backends.
- AWS
AWS SQS
Amazon Simple Queue Service (SQS) is a managed message queue that decouples the components of an application, with standard and FIFO queues.
- AWS
AWS SNS
Amazon Simple Notification Service (SNS) is a managed publish/subscribe service that sends messages to email, SMS, HTTP endpoints, SQS and Lambda.
- AWS
AWS CloudTrail
AWS CloudTrail records the API calls and account activity in AWS, so you can audit who did what, when and from where, and investigate security incidents.
- AWS
AWS CloudWatch
Amazon CloudWatch collects metrics, logs and events from AWS resources and applications, and offers dashboards, alarms and automated actions.
- AWS
AWS ECR
Amazon Elastic Container Registry (ECR) is a managed registry to store, scan and share Docker and OCI container images with ECS, EKS and Lambda.
- AWS
AWS EKS
Amazon Elastic Kubernetes Service (EKS) runs a managed, highly available Kubernetes control plane on AWS and integrates it with VPC, IAM and load balancers.
- AWS
AWS EFS
Amazon Elastic File System (EFS) is a managed, elastic NFS file system that many Linux EC2 instances, containers and Lambda functions can share.
- AWS
AWS DynamoDB
Amazon DynamoDB is a fully managed, serverless NoSQL key-value and document database with single-digit millisecond latency at any scale.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: Terraform CI/CD (21)
Automate Terraform and OpenTofu on AWS with GitHub Actions: checks on every pull request, plan comments, approved applies and OIDC without keys.
- AWS
AWS Lambda
AWS Lambda runs your code in response to events without servers to manage, and you pay only for the time the code runs. It is the core of AWS serverless.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: Terraform Tools (20)
The essential tools for Terraform and OpenTofu: fmt, validate, TFLint, Trivy, Checkov, terraform-docs, Infracost and pre-commit hooks.
- AWS
AWS Certificate Manager (ACM)
AWS Certificate Manager (ACM) issues, stores and automatically renews free public TLS certificates for load balancers, CloudFront and API Gateway.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: Terraform Backends (19)
Store the Terraform or OpenTofu state in an encrypted, versioned S3 bucket with native state locking, and migrate the local state to it.
- AWS
AWS Secrets Manager
AWS Secrets Manager stores, retrieves and automatically rotates database credentials, API keys and other secrets, encrypted with AWS KMS.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: Terraform Modules (18)
Refactor the AWS network of the tutorial into a reusable Terraform module with variables and outputs, without recreating any resource.
- AWS
AWS KMS
AWS Key Management Service (KMS) creates and controls the cryptographic keys that encrypt data in S3, EBS, RDS, Secrets Manager and many other AWS services.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: AWS Load Balancers (16)
Use Terraform to create an Application Load Balancer with a target group, listeners and HTTPS in front of an Auto Scaling group on AWS.
- AWS
AWS Regions and Availability Zones
AWS Regions are separate geographic areas, each made of several isolated Availability Zones. Choose them for latency, compliance, price and resilience.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: AWS Auto Scaling (15)
Use the Terraform aws_launch_template and aws_autoscaling_group resources to run a self-healing, scalable group of EC2 instances on AWS.
- AWS
AWS Elastic IP
An Elastic IP address is a static public IPv4 address that belongs to your AWS account and can be moved between instances or NAT Gateways.
- AWS
AWS Route Tables
A route table contains the rules that decide where the network traffic of a VPC subnet is sent: the local network, an Internet Gateway, a NAT Gateway and more.
- AWS
AWS Network ACLs
A network access control list (NACL) is a stateless firewall that allows or denies traffic at the subnet level of an AWS VPC, using numbered rules.
- AWS
AWS Security Groups
A security group is a stateful virtual firewall that controls the inbound and outbound traffic of AWS resources such as EC2 instances and databases.
- AWS
AWS Auto Scaling
Amazon EC2 Auto Scaling keeps the right number of EC2 instances running, replaces unhealthy ones and adds or removes capacity as the load changes.
- AWS
AWS Elastic Load Balancing (ELB)
Elastic Load Balancing (ELB) distributes incoming traffic across healthy targets in several Availability Zones: Application, Network and Gateway load balancers.
- Terraform & OpenTofu Tutorials
How to Encrypt Terraform State with OpenTofu
Securing your Infrastructure: Encrypting Terraform State Files with OpenTofu
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: AWS Route 53 (DNS) (14)
Using the Terraform aws_route53_delegation_set, aws_route53_zone, and aws_route53_record resource blocks to configure DNS in AWS.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: AWS RDS Instances (13)
Using the Terraform aws_db_instance resource block to configure, launch, and secure RDS instances.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: AWS EC2 Instances (12)
How to use the Terraform aws_instance resource block to configure, launch, and secure EC2 instances.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: AWS AMIs (11)
How to use the Terraform aws_ami data source to find the AMI (root volume template with an operating system) used to launch EC2 instances.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: AWS Key Pairs (10)
How to configure and use the Terraform aws_key_pair resource to upload an SSH public key to AWS and use it for public key authentication on EC2 instances.
- AWS
Public Key Authentication
A public key is a cryptographic key that is part of a key pair used for public key cryptography.
- AWS
Cloud-init
Cloud-init is a multi-distribution package that handles the early initialization of cloud instances.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: AWS Security Groups (9)
How to configure and use the Terraform aws_security_group and aws_security_group_rule resources to create AWS security groups and secure the infrastructure.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: AWS Routing Tables (8)
How to configure and use the Terraform aws_route_table, aws_route, and aws_main_route_table_association resource blocks to create and manage AWS Routing Tables.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: AWS NAT Gateway (7)
How to configure and use the Terraform aws_nat_gateway and aws_eip resources to create NAT Gateways and Elastic IPs for the private subnets of a VPC.
- AWS
AWS NAT Gateway
An AWS NAT Gateway is a managed service that allows instances in a private subnet to connect to the Internet while keeping them secure.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: AWS Internet Gateway (6)
How to configure and use the Terraform aws_internet_gateway resource block to create an AWS Internet Gateway that gives a VPC access to the Internet.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: AWS Subnets (5)
How to configure and use the Terraform aws_subnet resource block to create and manage AWS Subnets inside a VPC.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: AWS VPC (4)
How to configure and use the Terraform aws_vpc resource block to create and manage an AWS VPC (Virtual Private Cloud), step by step.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: Terraform AWS Provider (3)
How the Terraform and OpenTofu AWS provider authenticates to AWS, where to store the state and which provider source to use, before creating resources.
- AWS
AWS IAM
AWS Identity and Access Management (IAM) is a web service provided by Amazon Web Services (AWS) that enables users to securely control access to AWS…
- AWS
Amazon CloudFront
Amazon CloudFront is a content delivery network (CDN) service provided by AWS.
- AWS
AWS Route 53
Amazon Route 53 is a scalable and highly available Domain Name System (DNS) web service provided by Amazon Web Services (AWS).
- AWS
AWS RDS
AWS RDS is a fully managed service provided by Amazon Web Services (AWS) that simplifies the setup, operation, and scaling of relational databases in the cloud.
- AWS
AWS EBS
Block storage for persistent data for EC2 instances. Instance storage for the operating system uses EBS volumes.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: AWS Basics (2)
AWS is the world’s leading cloud platform, used by startups and large enterprises.
- Terraform & OpenTofu Tutorials
AWS with Terraform Tutorial: Terraform Basics (1)
How to start building AWS infrastructure with Terraform: Terraform is an Infrastructure as Code (IaC) tool used to provision and manage infrastructure.
- Terraform
Terraform Built-in Functions
Terraform functions perform specific tasks on configuration data: numeric, string, collection, date and time, file system and more.
- AWS Tutorials
How to use Terraform, AWS, and Ansible Together
How to use Terraform to create AWS infrastructure with tags, and Ansible with its dynamic inventory plugin to configure the servers, linked by the tags.
- Ansible Tutorials
How to Install Ansible
How to install the Ansible control node on Ubuntu with apt or pipx, and check that Ansible works.
- Terraform Best Practices
How to Share Infrastructure in Multiple Terraform Projects?
Sharing infrastructure across multiple Terraform projects using Data Sources helps maintain consistency, reduce redundancy, and promote collaboration.
- Glossary
SSH
SSH, which stands for Secure Shell, is a cryptographic network protocol that allows for secure communication and data transfer between two computers over an…
- Terraform & OpenTofu Tutorials
Generating and using AWS Key Pairs with Terraform or OpenTofu
Generation of an Ed25519 Key Pair for SSH Authentication on AWS Linux Machines and Uploading of Key Pairs with Terraform.
- Terraform & OpenTofu Tutorials
Terraform AWS EKS Cluster Deployment & Application Publishing through ALB
This how-to demonstrates how to use Terraform to create an AWS EKS cluster and deploy an application along with a Load Balancer on top.
- AWS
AWS Internet Gateway
An AWS Internet Gateway is a component that facilitates communication between instances within an Amazon Virtual Private Cloud (VPC) and the Internet
- AWS
AWS Fargate
AWS Fargate is a serverless compute engine for containers that runs ECS and EKS workloads without managing servers or clusters of instances.
- AWS
AWS ECS
Amazon ECS is a fully managed container orchestration service to deploy, manage and scale Docker containers on EC2 instances or AWS Fargate.
- AWS
AWS Subnets
AWS Subnets are segmented sections within an Amazon Virtual Private Cloud (VPC).
- AWS
AWS VPC
An AWS VPC (Virtual Private Cloud) is a virtual network dedicated to an AWS account.
- AWS Tutorials
How to Install AWS CLI V2
How to install the AWS CLI (Command Line Interface) to interact with Amazon Web Services through the command line.
- Terraform & OpenTofu Tutorials
Terraform AWS ECS Fargate Cluster Deployment & Docker Container Publishing
How-to use Terraform or OpenTofu to create an AWS ECS (Elastic Container Service) running in Fargate and deploy a Docker container.
- Terraform & OpenTofu Tutorials
How to Create AWS IAM users with Terraform & OpenTofu
Programmatically creating AWS users using IaC tools like Terraform & OpenTofu
- Terraform & OpenTofu Tutorials
Using a PGP Key Pair
Generation of a Pretty Good Privacy (PGP) Key Pair for automated AWS IAM user access key creation with Terraform.
- Terraform & OpenTofu Tutorials
How to Deploy Applications in Kubernetes using Terraform
How to publish multiple replicas of an Application (from the Docker Registry) and create a NodePort in Kubernetes using Terraform (in 10 seconds)
- Terraform & OpenTofu Tutorials
How to Migrate Infrastructure from Terraform to OpenTofu
How to migrate existing AWS Terraform-managed infrastructure that uses remote backend storage (e.g. S3) to OpenTofu.
- Kubernetes Tutorials
How to use an external NFS Persistent Volume on Kubernetes
How to use NFS Kubernetes Persistent Volumes for the storage of data. Postgres is used as an example.
- Kubernetes Tutorials
How to Install Helm
How to install Helm, the package manager for Kubernetes, and use it to deploy applications to a cluster.
- Kubernetes Tutorials
How to Install K3s as a local development Kubernetes cluster
K3s.io is a Lightweight Kubernetes cluster perfect for development or edge deployments. K3s is a CNCF project, originally developed by Rancher.
- Terraform & OpenTofu Tutorials
How to Deploy Applications in Kubernetes using OpenTofu
How to publish multiple replicas of an application from the Docker registry and create a NodePort or a LoadBalancer in Kubernetes using OpenTofu.
- Terraform & OpenTofu Tutorials
How to Install OpenTofu
Install OpenTofu on Ubuntu with the official installer script or manually from the GitHub releases, check the installation and upgrade it.
- Kubernetes Tutorials
Istio Patterns: Traffic Splitting in Kubernetes (Canary Release)
Tutorial on how to use Istio on Kubernetes for releasing new versions of software to the Cloud.
- AWS Best Practices
AWS Security Groups’ Best Practices
Best practices for AWS security groups, the virtual firewalls of EC2, RDS and other resources: naming, groups as sources, least privilege and rule descriptions.
- Terraform Best Practices
AWS and Terraform Naming Best Practices
Terraform and AWS resource naming should follow a company standard. Each company has different requirements and the standard should be adjusted.
- Terraform & OpenTofu Tutorials
How To Debug Terraform
Options and techniques for debugging Terraform and OpenTofu Infrastructure plans.
- Ansible Best Practices
Ansible Multiple Environment Best Practices
Handling multiple infrastructure environments with Ansible by targeting the environment tag that is included in the mandatory AWS tags
- Ansible Best Practices
Ansible Roles Best Practices
How granular Ansible roles should be: highly reusable by configuration, but pragmatic for stateful applications that are not cloud native.
- Ansible Best Practices
Ansible Playbook Structure Best Practices
Define and apply a company-wide consistent structure for all your Ansible Playbooks that allows for easy understanding and maximum reuse
- Ansible
Ansible Dynamic Inventory
Generate inventory (host and group information) dynamically rather than statically defining it in a static inventory file
- AWS Best Practices
AWS Tagging Best Practices
Effective infrastructure resource tagging can greatly improve management, IaC, monitoring and cost visibility in AWS.
- Glossary
HCL
HCL is a domain-specific language developed by HashiCorp, a company known for its infrastructure automation tools such as Terraform, Vault, Consul, and Nomad.
- Glossary
IaC
IaC is an approach to managing and provisioning computing infrastructure through machine-readable code and automation, rather than manual processes.
- AWS
AWS S3
Amazon S3 is a highly scalable and durable object storage service for data storage, backup, content distribution, archiving and cloud-native applications.
- AWS
AWS EC2
Amazon Elastic Compute Cloud (EC2) is a web service offered by Amazon Web Services (AWS) that provides resizable and scalable compute capacity in the cloud.
- AWS
AWS AMI
AWS AMI, or Amazon Machine Image, is a pre-configured virtual machine image used to create and launch Amazon Elastic Compute Cloud (EC2) instances
- Glossary
OSI model
The OSI model is a conceptual framework that describes how a network functions, split into seven layers.
- Terraform & OpenTofu Tutorials
Terraform Cloud Agents in a Kubernetes Cluster
How Terraform Cloud agents (HCP Terraform agents) run Terraform on private infrastructure, deployed in a Kubernetes cluster with Terraform itself.
- Kubernetes Tutorials
Kubernetes Cluster using Vagrant and Ansible with Containerd (in 3 minutes)
Tutorial and full source code explaining how to create a Kubernetes cluster with Ansible and Vagrant for local development under 3 minutes.
- Kubernetes Tutorials
Installing Istio on Kubernetes
How to install Istio in a Kubernetes Cluster to use it as a service mesh for a microservices architecture.
- Kubernetes Tutorials
Installing the Kubernetes Dashboard and managing the Cluster using kubectl
How to install the Kubernetes Dashboard and manage the cluster after installation.
- Kubernetes Tutorials
Running Postgres in Kubernetes with a Persistent NFS Volume
How to create a Kubernetes persistent volume for Postgres long term storage of data using a NFS Volume
- Terraform & OpenTofu Tutorials
How to disable AWS instance destroy with Terraform?
Techniques to prevent infrastructure destroy in Terraform by protecting selected instances and resources from being accidentally destroyed.
- Terraform & OpenTofu Tutorials
How to programmatically use your public Internet IP address in Terraform?
Obtain your public IP address and use it in Terraform to create AWS Security Rules.
- Terraform & OpenTofu Tutorials
Creating AWS RDS Database with Terraform (4/5)
Tutorial and source code explaining how to create and manage MariaDB (or MySQL) RDS database with Terraform in AWS.
- Terraform & OpenTofu Tutorials
AWS Route 53, AMI Lookup and EC2 Creation with Terraform (3/5)
Tutorial and source code explaining how to manage AWS Route 53 DNS Service, create and register EC2 instances and find an AMI with Terraform.
- AWS Tutorials
Creating AWS EC2 Instances and Security Rules with Terraform (5/5)
Tutorial and source code explaining how to manage AWS EC2 Instances and Security with Terraform.
- Terraform & OpenTofu Tutorials
AWS VPC Subnets, Routing Tables and Internet Access using Terraform (2/5)
Tutorial and source code explaining how to create and manage AWS networking with Terraform.
- AWS Tutorials
AWS VPC, Route 53, RDS MariaDB, EC2 using Ansible and Terraform (1/5)
Tutorial and source code explaining how to provision and configure a VPC, Route 53, RDS MariaDB, Instances and security groups using Ansible and Terraform…
- Kubernetes Tutorials
Using a NodePort in a Kubernetes Cluster on top of VirtualBox
Kubernetes tutorial explaining how to use a NodePort to publish applications in a Kubernetes cluster running in VirtualBox with Vagrant and Ansible
- AWS Best Practices
AWS Basic VPC Elements
Best practices for naming and using AWS Infrastructure with Terraform and Ansible.
- Kubernetes Tutorials
Istio Patterns: Traffic Splitting in Kubernetes (Header/Cookie Based)
How to split traffic in Kubernetes with Istio based on request headers, tutorial, and examples with source code.
- AWS Tutorials
Create an AWS IAM User for Demos
How to create AWS IAM users for programmatic access to the AWS Cloud API, to be used with Terraform / OpenTofu and Ansible demos.
- AWS Tutorials
Create an AWS Account for Demos
In order to run the examples presented in IT Wonder Lab you will need accounts in different cloud providers.