# IT Wonder Lab > Step-by-step tutorials and best practices for cloud infrastructure automation: Infrastructure as Code with Terraform / OpenTofu, AWS, Kubernetes and Ansible. Written by Javier Ruiz Jiménez. IT Wonder Lab publishes free, practical tutorials: each one explains the concepts, shows complete Terraform / OpenTofu, Ansible or Kubernetes code and how to run it. Every page is also available as clean Markdown by adding `index.md` to its URL (or by requesting it with `Accept: text/markdown`). The full text of all tutorials is in [llms-full.txt](https://www.itwonderlab.com/llms-full.txt). ## AWS with Terraform: The Essential Guide (read in this order) - [AWS with Terraform Tutorial: Terraform Basics (1)](https://www.itwonderlab.com/aws-terraform-tutorial-terraform-basics/index.md): How to start building AWS infrastructure with Terraform: Terraform is an Infrastructure as Code (IaC) tool used to provision and manage infrastructure. - [AWS with Terraform Tutorial: AWS Basics (2)](https://www.itwonderlab.com/aws-terraform-tutorial-aws-basics/index.md): AWS is the world’s leading cloud platform, used by startups and large enterprises. - [AWS with Terraform Tutorial: Terraform AWS Provider (3)](https://www.itwonderlab.com/aws-terraform-tutorial-terraform-aws-provider/index.md): How the Terraform and OpenTofu AWS provider authenticates to AWS, where to store the state and which provider source to use, before creating resources. - [AWS with Terraform Tutorial: AWS VPC (4)](https://www.itwonderlab.com/aws-terraform-tutorial-aws-vpc/index.md): How to configure and use the Terraform aws_vpc resource block to create and manage an AWS VPC (Virtual Private Cloud), step by step. - [AWS with Terraform Tutorial: AWS Subnets (5)](https://www.itwonderlab.com/aws-terraform-tutorial-aws-subnets/index.md): How to configure and use the Terraform aws_subnet resource block to create and manage AWS Subnets inside a VPC. - [AWS with Terraform Tutorial: AWS Internet Gateway (6)](https://www.itwonderlab.com/aws-terraform-tutorial-aws-internet-gateway/index.md): How to configure and use the Terraform aws_internet_gateway resource block to create an AWS Internet Gateway that gives a VPC access to the Internet. - [AWS with Terraform Tutorial: AWS NAT Gateway (7)](https://www.itwonderlab.com/aws-terraform-tutorial-aws-nat-gateway/index.md): How to configure and use the Terraform aws_nat_gateway and aws_eip resources to create NAT Gateways and Elastic IPs for the private subnets of a VPC. - [AWS with Terraform Tutorial: AWS Routing Tables (8)](https://www.itwonderlab.com/aws-terraform-tutorial-aws-routing-tables/index.md): How to configure and use the Terraform aws_route_table, aws_route, and aws_main_route_table_association resource blocks to create and manage AWS Routing Tables. - [AWS with Terraform Tutorial: AWS Security Groups (9)](https://www.itwonderlab.com/aws-terraform-tutorial-aws-security-groups/index.md): How to configure and use the Terraform aws_security_group and aws_security_group_rule resources to create AWS security groups and secure the infrastructure. - [AWS with Terraform Tutorial: AWS Key Pairs (10)](https://www.itwonderlab.com/aws-terraform-tutorial-aws-key-pairs/index.md): How to configure and use the Terraform aws_key_pair resource to upload an SSH public key to AWS and use it for public key authentication on EC2 instances. - [AWS with Terraform Tutorial: AWS AMIs (11)](https://www.itwonderlab.com/aws-terraform-tutorial-aws-ami/index.md): How to use the Terraform aws_ami data source to find the AMI (root volume template with an operating system) used to launch EC2 instances. - [AWS with Terraform Tutorial: AWS EC2 Instances (12)](https://www.itwonderlab.com/aws-terraform-tutorial-aws-ec2/index.md): How to use the Terraform aws_instance resource block to configure, launch, and secure EC2 instances. - [AWS with Terraform Tutorial: AWS RDS Instances (13)](https://www.itwonderlab.com/aws-terraform-tutorial-aws-rds/index.md): Using the Terraform aws_db_instance resource block to configure, launch, and secure RDS instances. - [AWS with Terraform Tutorial: AWS Route 53 (DNS) (14)](https://www.itwonderlab.com/aws-with-terraform-tutorial-aws-route-53/index.md): Using the Terraform aws_route53_delegation_set, aws_route53_zone, and aws_route53_record resource blocks to configure DNS in AWS. - [AWS with Terraform Tutorial: AWS Auto Scaling (15)](https://www.itwonderlab.com/aws-terraform-tutorial-aws-auto-scaling/index.md): Use the Terraform aws_launch_template and aws_autoscaling_group resources to run a self-healing, scalable group of EC2 instances on AWS. - [AWS with Terraform Tutorial: AWS Load Balancers (16)](https://www.itwonderlab.com/aws-terraform-tutorial-aws-load-balancers/index.md): Use Terraform to create an Application Load Balancer with a target group, listeners and HTTPS in front of an Auto Scaling group on AWS. - [How to use Terraform, AWS, and Ansible Together](https://www.itwonderlab.com/terraform-aws-ansible/index.md): How to use Terraform to create AWS infrastructure with tags, and Ansible with its dynamic inventory plugin to configure the servers, linked by the tags. - [AWS with Terraform Tutorial: Terraform Modules (18)](https://www.itwonderlab.com/aws-terraform-tutorial-terraform-modules/index.md): Refactor the AWS network of the tutorial into a reusable Terraform module with variables and outputs, without recreating any resource. - [AWS with Terraform Tutorial: Terraform Backends (19)](https://www.itwonderlab.com/aws-terraform-tutorial-terraform-backends/index.md): Store the Terraform or OpenTofu state in an encrypted, versioned S3 bucket with native state locking, and migrate the local state to it. - [AWS with Terraform Tutorial: Terraform Tools (20)](https://www.itwonderlab.com/aws-terraform-tutorial-terraform-tools/index.md): The essential tools for Terraform and OpenTofu: fmt, validate, TFLint, Trivy, Checkov, terraform-docs, Infracost and pre-commit hooks. - [AWS with Terraform Tutorial: Terraform CI/CD (21)](https://www.itwonderlab.com/aws-terraform-tutorial-terraform-cicd/index.md): Automate Terraform and OpenTofu on AWS with GitHub Actions: checks on every pull request, plan comments, approved applies and OIDC without keys. ## AWS - [AWS Organizations](https://www.itwonderlab.com/aws-organizations/index.md): AWS Organizations lets you manage many AWS accounts centrally: organizational units, consolidated billing and service control policies to set guardrails. - [AWS Aurora](https://www.itwonderlab.com/aws-aurora/index.md): Amazon Aurora is a MySQL and PostgreSQL-compatible relational database built for the cloud, with storage replicated across three Availability Zones. - [AWS WAF](https://www.itwonderlab.com/aws-waf/index.md): AWS WAF is a web application firewall that filters HTTP requests with rules and managed rule groups to block SQL injection, XSS, bots and abusive traffic. - [AWS ElastiCache](https://www.itwonderlab.com/aws-elasticache/index.md): Amazon ElastiCache is a managed in-memory data store and cache compatible with Valkey, Redis OSS and Memcached, for microsecond latency. - [AWS CloudFormation](https://www.itwonderlab.com/aws-cloudformation/index.md): AWS CloudFormation is the native infrastructure as code service of AWS: describe resources in JSON or YAML templates and it manages them as stacks. - [AWS Systems Manager](https://www.itwonderlab.com/aws-systems-manager/index.md): AWS Systems Manager (SSM) manages servers at scale: Session Manager shell access without SSH, Parameter Store, Patch Manager, Run Command and Automation. - [AWS API Gateway](https://www.itwonderlab.com/aws-api-gateway/index.md): Amazon API Gateway is a managed service to create, publish, secure and monitor REST, HTTP and WebSocket APIs in front of Lambda functions and other backends. - [AWS SQS](https://www.itwonderlab.com/aws-sqs/index.md): Amazon Simple Queue Service (SQS) is a managed message queue that decouples the components of an application, with standard and FIFO queues. - [AWS SNS](https://www.itwonderlab.com/aws-sns/index.md): Amazon Simple Notification Service (SNS) is a managed publish/subscribe service that sends messages to email, SMS, HTTP endpoints, SQS and Lambda. - [AWS CloudTrail](https://www.itwonderlab.com/aws-cloudtrail/index.md): AWS CloudTrail records the API calls and account activity in AWS, so you can audit who did what, when and from where, and investigate security incidents. - [AWS CloudWatch](https://www.itwonderlab.com/aws-cloudwatch/index.md): Amazon CloudWatch collects metrics, logs and events from AWS resources and applications, and offers dashboards, alarms and automated actions. - [AWS ECR](https://www.itwonderlab.com/aws-ecr/index.md): Amazon Elastic Container Registry (ECR) is a managed registry to store, scan and share Docker and OCI container images with ECS, EKS and Lambda. - [AWS EKS](https://www.itwonderlab.com/aws-eks/index.md): Amazon Elastic Kubernetes Service (EKS) runs a managed, highly available Kubernetes control plane on AWS and integrates it with VPC, IAM and load balancers. - [AWS EFS](https://www.itwonderlab.com/aws-efs/index.md): Amazon Elastic File System (EFS) is a managed, elastic NFS file system that many Linux EC2 instances, containers and Lambda functions can share. - [AWS DynamoDB](https://www.itwonderlab.com/aws-dynamodb/index.md): Amazon DynamoDB is a fully managed, serverless NoSQL key-value and document database with single-digit millisecond latency at any scale. - [AWS Lambda](https://www.itwonderlab.com/aws-lambda/index.md): AWS Lambda runs your code in response to events without servers to manage, and you pay only for the time the code runs. It is the core of AWS serverless. - [AWS Certificate Manager (ACM)](https://www.itwonderlab.com/aws-acm/index.md): AWS Certificate Manager (ACM) issues, stores and automatically renews free public TLS certificates for load balancers, CloudFront and API Gateway. - [AWS Secrets Manager](https://www.itwonderlab.com/aws-secrets-manager/index.md): AWS Secrets Manager stores, retrieves and automatically rotates database credentials, API keys and other secrets, encrypted with AWS KMS. - [AWS KMS](https://www.itwonderlab.com/aws-kms/index.md): AWS Key Management Service (KMS) creates and controls the cryptographic keys that encrypt data in S3, EBS, RDS, Secrets Manager and many other AWS services. - [AWS Regions and Availability Zones](https://www.itwonderlab.com/aws-regions-availability-zones/index.md): AWS Regions are separate geographic areas, each made of several isolated Availability Zones. Choose them for latency, compliance, price and resilience. - [AWS Elastic IP](https://www.itwonderlab.com/aws-elastic-ip/index.md): An Elastic IP address is a static public IPv4 address that belongs to your AWS account and can be moved between instances or NAT Gateways. - [AWS Route Tables](https://www.itwonderlab.com/aws-route-tables/index.md): A route table contains the rules that decide where the network traffic of a VPC subnet is sent: the local network, an Internet Gateway, a NAT Gateway and more. - [AWS Network ACLs](https://www.itwonderlab.com/aws-network-acl/index.md): A network access control list (NACL) is a stateless firewall that allows or denies traffic at the subnet level of an AWS VPC, using numbered rules. - [AWS Security Groups](https://www.itwonderlab.com/aws-security-groups/index.md): A security group is a stateful virtual firewall that controls the inbound and outbound traffic of AWS resources such as EC2 instances and databases. - [AWS Auto Scaling](https://www.itwonderlab.com/aws-auto-scaling/index.md): Amazon EC2 Auto Scaling keeps the right number of EC2 instances running, replaces unhealthy ones and adds or removes capacity as the load changes. - [AWS Elastic Load Balancing (ELB)](https://www.itwonderlab.com/aws-elastic-load-balancing/index.md): Elastic Load Balancing (ELB) distributes incoming traffic across healthy targets in several Availability Zones: Application, Network and Gateway load balancers. - [AWS Kinesis](https://www.itwonderlab.com/aws-kinesis/index.md): Amazon Kinesis collects, processes and analyzes real-time streaming data: Data Streams, Data Firehose and Managed Service for Apache Flink. - [AWS Step Functions](https://www.itwonderlab.com/aws-step-functions/index.md): AWS Step Functions is a serverless workflow service that coordinates Lambda functions and AWS services using state machines. - [AWS EventBridge](https://www.itwonderlab.com/aws-eventbridge/index.md): Amazon EventBridge is a serverless event bus that routes events from AWS services, SaaS applications and your own code to targets using rules. - [AWS Redshift](https://www.itwonderlab.com/aws-redshift/index.md): Amazon Redshift is a managed, columnar data warehouse for large-scale SQL analytics, available as provisioned clusters or serverless. - [AWS Athena](https://www.itwonderlab.com/aws-athena/index.md): Amazon Athena runs SQL queries directly on data stored in Amazon S3, without servers, and charges per amount of data scanned. - [AWS Transit Gateway](https://www.itwonderlab.com/aws-transit-gateway/index.md): AWS Transit Gateway is a regional network hub that connects VPCs, VPN connections and Direct Connect with transitive routing. - [AWS Config](https://www.itwonderlab.com/aws-config/index.md): AWS Config records the configuration of AWS resources over time and evaluates them against rules for compliance and auditing. - [AWS Security Hub](https://www.itwonderlab.com/aws-security-hub/index.md): AWS Security Hub aggregates security findings from AWS services and partners and checks accounts against standards such as CIS and AWS Foundational Best Practices. - [AWS PrivateLink](https://www.itwonderlab.com/aws-privatelink/index.md): AWS PrivateLink provides private connectivity between VPCs and AWS services or your own services using interface endpoints, without Internet access. - [AWS Cognito](https://www.itwonderlab.com/aws-cognito/index.md): Amazon Cognito provides user sign-up, sign-in and access control for web and mobile apps, with user pools and identity pools. - [AWS GuardDuty](https://www.itwonderlab.com/aws-guardduty/index.md): Amazon GuardDuty is a managed threat detection service that analyzes CloudTrail, VPC flow and DNS logs to find compromised resources and attacks. - [AWS Control Tower](https://www.itwonderlab.com/aws-control-tower/index.md): AWS Control Tower sets up and governs a secure multi-account AWS environment (landing zone) with guardrails, account factory and centralized logging. - [AWS IAM Identity Center](https://www.itwonderlab.com/aws-iam-identity-center/index.md): AWS IAM Identity Center (formerly AWS SSO) gives people single sign-on access to multiple AWS accounts and applications with permission sets. - [AWS Bedrock](https://www.itwonderlab.com/aws-bedrock/index.md): Amazon Bedrock is a managed service to build generative AI applications with foundation models from several providers through a single API. - [AWS Glue](https://www.itwonderlab.com/aws-glue/index.md): AWS Glue is a serverless data integration service with a data catalog, crawlers and ETL jobs to prepare data for analytics. - [Public Key Authentication](https://www.itwonderlab.com/public-key-authentication/index.md): A public key is a cryptographic key that is part of a key pair used for public key cryptography. - [Cloud-init](https://www.itwonderlab.com/cloud-init/index.md): Cloud-init is a multi-distribution package that handles the early initialization of cloud instances. - [AWS NAT Gateway](https://www.itwonderlab.com/aws-nat-gateway/index.md): An AWS NAT Gateway is a managed service that allows instances in a private subnet to connect to the Internet while keeping them secure. - [AWS IAM](https://www.itwonderlab.com/aws-iam/index.md): AWS Identity and Access Management (IAM) is a web service provided by Amazon Web Services (AWS) that enables users to securely control access to AWS… - [Amazon CloudFront](https://www.itwonderlab.com/amazon-cloudfront/index.md): Amazon CloudFront is a content delivery network (CDN) service provided by AWS. - [AWS Route 53](https://www.itwonderlab.com/aws-route-53/index.md): Amazon Route 53 is a scalable and highly available Domain Name System (DNS) web service provided by Amazon Web Services (AWS). - [AWS RDS](https://www.itwonderlab.com/aws-rds/index.md): AWS RDS is a fully managed service provided by Amazon Web Services (AWS) that simplifies the setup, operation, and scaling of relational databases in the cloud. - [AWS EBS](https://www.itwonderlab.com/aws-ebs/index.md): Block storage for persistent data for EC2 instances. Instance storage for the operating system uses EBS volumes. - [AWS Internet Gateway](https://www.itwonderlab.com/aws-internet-gateway/index.md): An AWS Internet Gateway is a component that facilitates communication between instances within an Amazon Virtual Private Cloud (VPC) and the Internet - [AWS Fargate](https://www.itwonderlab.com/aws-fargate/index.md): AWS Fargate is a serverless compute engine for containers that runs ECS and EKS workloads without managing servers or clusters of instances. - [AWS ECS](https://www.itwonderlab.com/aws-ecs/index.md): Amazon ECS is a fully managed container orchestration service to deploy, manage and scale Docker containers on EC2 instances or AWS Fargate. - [AWS Subnets](https://www.itwonderlab.com/aws-subnets/index.md): AWS Subnets are segmented sections within an Amazon Virtual Private Cloud (VPC). - [AWS VPC](https://www.itwonderlab.com/aws-vpc/index.md): An AWS VPC (Virtual Private Cloud) is a virtual network dedicated to an AWS account. - [AWS S3](https://www.itwonderlab.com/aws-s3/index.md): Amazon S3 is a highly scalable and durable object storage service for data storage, backup, content distribution, archiving and cloud-native applications. - [AWS EC2](https://www.itwonderlab.com/aws-ec2/index.md): Amazon Elastic Compute Cloud (EC2) is a web service offered by Amazon Web Services (AWS) that provides resizable and scalable compute capacity in the cloud. - [AWS AMI](https://www.itwonderlab.com/aws-ami/index.md): AWS AMI, or Amazon Machine Image, is a pre-configured virtual machine image used to create and launch Amazon Elastic Compute Cloud (EC2) instances ## Terraform & OpenTofu Tutorials - [Estimate AWS Costs in Terraform Pull Requests with Infracost](https://www.itwonderlab.com/terraform-cost-estimation-infracost/index.md): How to see the monthly cost of Terraform and OpenTofu changes before applying them with Infracost, and how to keep AWS demo costs under control. - [AWS VPC Peering and Transit Gateway with Terraform](https://www.itwonderlab.com/terraform-aws-vpc-peering-transit-gateway/index.md): Connect AWS VPCs with Terraform or OpenTofu using VPC peering for simple cases or a Transit Gateway for many networks, with routes and a comparison of costs. - [What is OpenTofu? The Open-Source Fork of Terraform Explained](https://www.itwonderlab.com/what-is-opentofu/index.md): OpenTofu is the open-source Infrastructure as Code tool, a fork of Terraform managed by the Linux Foundation. Learn what it is, how it works and how to start. - [Terraform lifecycle: prevent_destroy, create_before_destroy, ignore_changes](https://www.itwonderlab.com/terraform-lifecycle-meta-argument/index.md): How to use the Terraform and OpenTofu lifecycle block: prevent_destroy, create_before_destroy, ignore_changes, replace_triggered_by and conditions. - [Terraform import, moved and removed Blocks: Refactor Without Destroying](https://www.itwonderlab.com/terraform-import-moved-removed/index.md): How to import existing AWS resources into Terraform or OpenTofu, rename them with moved blocks and stop managing them with removed blocks, without downtime. - [Terraform -replace, taint and -target: Recreate or Limit Resources Safely](https://www.itwonderlab.com/terraform-replace-taint-target/index.md): How to force Terraform and OpenTofu to recreate a resource with -replace (the replacement for taint), when to use -target and how to avoid its risks. - [Terraform vs OpenTofu: Differences, License and Which One to Choose](https://www.itwonderlab.com/terraform-vs-opentofu/index.md): Compare Terraform and OpenTofu: license, governance, compatibility, exclusive features such as state encryption, and how to decide which one to use. - [Terraform Variables, Outputs and Locals Explained with Examples](https://www.itwonderlab.com/terraform-variables-outputs-locals/index.md): How to use input variables, validation, outputs and local values in Terraform and OpenTofu, and how to set variables with tfvars files and environment variables. - [AWS IAM Roles and Policies with Terraform and OpenTofu](https://www.itwonderlab.com/aws-terraform-tutorial-aws-iam-roles-policies/index.md): How to create IAM roles, policies, instance profiles and assume-role trust relationships with Terraform or OpenTofu, following least privilege, with AWS examples. - [Terraform and OpenTofu with GitHub Actions and AWS OIDC (No Access Keys)](https://www.itwonderlab.com/terraform-github-actions-aws-oidc/index.md): Run Terraform or OpenTofu plan on pull requests and apply on merge with GitHub Actions, authenticating to AWS with OIDC and short-lived credentials. - [Terraform and OpenTofu Cheat Sheet: Commands and HCL Syntax](https://www.itwonderlab.com/terraform-cheat-sheet/index.md): A quick reference of the most used Terraform and OpenTofu commands (init, plan, apply, state, import, workspace) and HCL syntax, with examples to copy. - [AWS S3 Buckets with Terraform and OpenTofu: Secure Configuration](https://www.itwonderlab.com/aws-terraform-tutorial-aws-s3/index.md): Create secure AWS S3 buckets with Terraform or OpenTofu: public access block, encryption with KMS, versioning, lifecycle rules and bucket policies. - [terraform-aws-modules: Create a VPC and EKS Cluster with the Official Community Modules](https://www.itwonderlab.com/terraform-aws-modules-vpc-eks/index.md): How to use the popular terraform-aws-modules (vpc, iam, s3-bucket, eks) from the Terraform and OpenTofu registry: versions, inputs, outputs and a VPC plus EKS example. - [Terraform Multi-Region and Multi-Account AWS with Provider Aliases](https://www.itwonderlab.com/terraform-multi-region-provider-alias/index.md): How to deploy to several AWS regions and accounts from one Terraform or OpenTofu configuration using provider aliases, assume_role, modules and for_each on providers. - [AWS Lambda and API Gateway with Terraform: Serverless HTTP API](https://www.itwonderlab.com/terraform-aws-lambda-api-gateway/index.md): Deploy a serverless HTTP API with an AWS Lambda function, IAM role, CloudWatch logs and API Gateway HTTP API using Terraform or OpenTofu. - [Terraform and OpenTofu Testing: tofu test, validate and Terratest](https://www.itwonderlab.com/terraform-testing-opentofu-test/index.md): How to test infrastructure code: terraform validate, the native terraform test and tofu test framework with mock providers, plan checks and Terratest. - [AWS SQS and SNS with Terraform: Queues, Topics and Dead-Letter Queues](https://www.itwonderlab.com/terraform-aws-sqs-sns/index.md): Create AWS SQS queues with dead-letter queues, SNS topics and subscriptions with Terraform or OpenTofu, including encryption and the access policy for fan-out. - [Terraform and OpenTofu Project Structure: Recommended Layouts](https://www.itwonderlab.com/terraform-project-structure/index.md): How to organize a Terraform or OpenTofu project: files, modules, environments, state splitting, versions and a monorepo layout that scales with the team. - [Common Terraform and OpenTofu Errors and How to Fix Them](https://www.itwonderlab.com/terraform-common-errors/index.md): Fix the most common Terraform errors: state lock, provider version, cycle, invalid count, already exists, access denied, credentials and failed apply on AWS. - [AWS VPC Endpoints and PrivateLink with Terraform: Private Access to AWS Services](https://www.itwonderlab.com/terraform-aws-vpc-endpoints/index.md): Create gateway and interface VPC endpoints with Terraform or OpenTofu to reach S3, DynamoDB and other AWS services privately and reduce NAT gateway costs. - [Terraform Secrets Management: Keep Passwords Out of Code and State](https://www.itwonderlab.com/terraform-secrets-management/index.md): How to handle secrets in Terraform and OpenTofu: sensitive variables, AWS Secrets Manager, SSM, generated passwords, ephemeral values and state encryption. - [Automate AWS with EventBridge Scheduler and Lambda: Stop and Start EC2 on a Schedule (Terraform)](https://www.itwonderlab.com/aws-eventbridge-scheduler-terraform/index.md): Automate AWS tasks with Terraform: schedule a Lambda function with EventBridge Scheduler to stop and start tagged EC2 instances and save costs outside working hours. - [Terraform and OpenTofu on Azure: Getting Started with the AzureRM Provider](https://www.itwonderlab.com/terraform-azure-getting-started/index.md): Deploy your first Azure resources with Terraform or OpenTofu: Azure CLI login, resource group, virtual network, storage account and remote state. - [Terraform Workspaces vs Directories: How to Manage Environments](https://www.itwonderlab.com/terraform-workspaces-vs-directories/index.md): Compare Terraform and OpenTofu workspaces with separate directories and tfvars files to manage dev, pre and pro environments, and learn which one to use. - [Terraform Security Scanning with tflint, Checkov and Trivy](https://www.itwonderlab.com/terraform-security-scanning-tflint-checkov-trivy/index.md): Find misconfigurations in Terraform and OpenTofu code before deploying: tflint for errors, Checkov and Trivy for AWS security issues, with CI examples. - [Terraform Conditionals and for Expressions: Ternary, count, splat and Examples](https://www.itwonderlab.com/terraform-conditionals-for-expressions/index.md): How to write conditions and loops in Terraform and OpenTofu: the ternary operator, count and for_each switches, for expressions, splat, try, lookup, merge and flatten. - [AWS Organizations and Multi-Account Setup with Terraform](https://www.itwonderlab.com/terraform-aws-organizations-multi-account/index.md): Design and create a multi-account AWS landing zone with Terraform or OpenTofu: AWS Organizations, OUs, accounts, service control policies and cross-account roles. - [Terraform depends_on and Resource Dependencies Explained](https://www.itwonderlab.com/terraform-depends-on-dependencies/index.md): How Terraform builds its dependency graph, the difference between implicit and explicit dependencies, when to use depends_on, and how to fix dependency cycles. - [AWS KMS and Secrets Manager with Terraform: Encrypt and Store Secrets](https://www.itwonderlab.com/terraform-aws-kms-secrets-manager/index.md): Create KMS keys with rotation and policies, and store and read secrets in AWS Secrets Manager and SSM Parameter Store with Terraform or OpenTofu, safely. - [AWS Security Monitoring with Terraform: CloudTrail, GuardDuty, Config and Security Hub](https://www.itwonderlab.com/terraform-aws-security-monitoring/index.md): Enable AWS security services with Terraform or OpenTofu: an organization CloudTrail, GuardDuty, AWS Config and Security Hub, with encrypted log storage. - [AWS CloudWatch Alarms, Logs and Dashboards with Terraform](https://www.itwonderlab.com/terraform-aws-cloudwatch-alarms/index.md): Monitor AWS with Terraform or OpenTofu: log groups with retention, metric filters, CloudWatch alarms that notify through SNS, and a dashboard. - [Static Website on AWS with S3, CloudFront and ACM using Terraform](https://www.itwonderlab.com/terraform-s3-static-website-cloudfront/index.md): Host a static website on AWS with a private S3 bucket, CloudFront with Origin Access Control, an ACM certificate and Route 53, using Terraform or OpenTofu. - [Terraform Provisioners and EC2 user_data: When to Use Each (and Alternatives)](https://www.itwonderlab.com/terraform-provisioners-user-data/index.md): How Terraform provisioners (local-exec, remote-exec, file) work, why they are a last resort, and how to use EC2 user_data, cloud-init and Ansible instead. - [AWS DynamoDB Tables with Terraform: Keys, Indexes, TTL and Autoscaling](https://www.itwonderlab.com/terraform-aws-dynamodb/index.md): Create AWS DynamoDB tables with Terraform or OpenTofu: partition and sort keys, global secondary indexes, on-demand or provisioned capacity, TTL, backups and encryption. - [Terraform and OpenTofu on Google Cloud: Getting Started with the Google Provider](https://www.itwonderlab.com/terraform-gcp-getting-started/index.md): Deploy your first resources on Google Cloud with Terraform or OpenTofu: authentication, enabling APIs, a VPC network, a Cloud Storage bucket and remote state in GCS. - [HashiCorp Terraform Associate Certification Study Guide](https://www.itwonderlab.com/terraform-associate-certification-guide/index.md): A study plan for the HashiCorp Certified Terraform Associate exam: topics, what to practice, commands to know and links to hands-on tutorials with AWS. - [AWS Systems Manager Session Manager with Terraform: SSH Without Open Ports](https://www.itwonderlab.com/terraform-aws-ssm-session-manager/index.md): Connect to EC2 instances without SSH keys, bastion hosts or open port 22 using AWS Systems Manager Session Manager, configured with Terraform or OpenTofu. - [Terraform and OpenTofu Interview Questions and Answers (with AWS Examples)](https://www.itwonderlab.com/terraform-interview-questions/index.md): The most common Terraform and OpenTofu interview questions for DevOps and cloud roles, with short answers on state, modules, lifecycle, secrets, AWS and CI/CD. - [Terraform for_each vs count: Which One to Use and Why](https://www.itwonderlab.com/terraform-for-each-vs-count/index.md): Learn the difference between the Terraform and OpenTofu count and for_each meta-arguments, with AWS examples, and why for_each avoids destroying resources. - [Terragrunt with OpenTofu: Keep Your Configuration DRY](https://www.itwonderlab.com/terragrunt-opentofu/index.md): What Terragrunt is and how to use it with OpenTofu or Terraform to avoid repeating backend and provider code across environments, with a complete AWS example. - [Terraform Data Sources and terraform_remote_state with AWS Examples](https://www.itwonderlab.com/terraform-data-sources-remote-state/index.md): How to read existing infrastructure with Terraform data sources and share values between configurations with terraform_remote_state or SSM Parameter Store. - [Terraform Dynamic Blocks: Generate Nested Blocks from Variables](https://www.itwonderlab.com/terraform-dynamic-blocks/index.md): How to use dynamic blocks in Terraform and OpenTofu to generate repeated nested blocks such as security group rules, with for_each, iterator and AWS examples. - [Terraform vs CloudFormation vs CDK vs Pulumi: Which IaC Tool for AWS?](https://www.itwonderlab.com/terraform-vs-cloudformation/index.md): Compare Terraform/OpenTofu, AWS CloudFormation, AWS CDK and Pulumi for AWS infrastructure: language, state, multi-cloud, drift, learning curve and when to choose each. - [Terraform Helm Provider: Deploy Helm Charts to Kubernetes with OpenTofu](https://www.itwonderlab.com/terraform-helm-provider-kubernetes/index.md): Install Helm charts in a Kubernetes cluster with the Terraform and OpenTofu Helm provider: values, secrets, upgrades, ingress-nginx and cert-manager examples. - [How to Encrypt Terraform State with OpenTofu](https://www.itwonderlab.com/terraform-state-file-encryption/index.md): Step-by-step guide to encrypting the Terraform state file with OpenTofu state encryption and AWS KMS, with a full configuration example. - [Generating and using AWS Key Pairs with Terraform or OpenTofu](https://www.itwonderlab.com/aws-key-pairs-terraform/index.md): Generation of an Ed25519 Key Pair for SSH Authentication on AWS Linux Machines and Uploading of Key Pairs with Terraform. - [Terraform AWS EKS Cluster Deployment & Application Publishing through ALB](https://www.itwonderlab.com/terraform-eks/index.md): This how-to demonstrates how to use Terraform to create an AWS EKS cluster and deploy an application along with a Load Balancer on top. - [Terraform AWS ECS Fargate Cluster Deployment & Docker Container Publishing](https://www.itwonderlab.com/containers-aws-ecs-terraform-fargate/index.md): How-to use Terraform or OpenTofu to create an AWS ECS (Elastic Container Service) running in Fargate and deploy a Docker container. - [How to Create AWS IAM users with Terraform & OpenTofu](https://www.itwonderlab.com/terraform-aws-iam-users/index.md): Programmatically creating AWS users using IaC tools like Terraform & OpenTofu - [Using a PGP Key Pair](https://www.itwonderlab.com/installing-using-pgp/index.md): Generation of a Pretty Good Privacy (PGP) Key Pair for automated AWS IAM user access key creation with Terraform. - [How to Deploy Applications in Kubernetes using Terraform](https://www.itwonderlab.com/kubernetes-with-terraform/index.md): How to publish multiple replicas of an Application (from the Docker Registry) and create a NodePort in Kubernetes using Terraform (in 10 seconds) - [How to Migrate Infrastructure from Terraform to OpenTofu](https://www.itwonderlab.com/terraform-to-opentofu/index.md): How to migrate existing AWS Terraform-managed infrastructure that uses remote backend storage (e.g. S3) to OpenTofu. - [How to Deploy Applications in Kubernetes using OpenTofu](https://www.itwonderlab.com/kubernetes-with-opentofu/index.md): How to publish multiple replicas of an application from the Docker registry and create a NodePort or a LoadBalancer in Kubernetes using OpenTofu. - [How to Install OpenTofu](https://www.itwonderlab.com/how-to-install-opentofu/index.md): Install OpenTofu on Ubuntu with the official installer script or manually from the GitHub releases, check the installation and upgrade it. - [How To Debug Terraform](https://www.itwonderlab.com/how-to-debug-terraform/index.md): Options and techniques for debugging Terraform and OpenTofu Infrastructure plans. - [Terraform Cloud Agents in a Kubernetes Cluster](https://www.itwonderlab.com/terraform-agents-kubernetes/index.md): How Terraform Cloud agents (HCP Terraform agents) run Terraform on private infrastructure, deployed in a Kubernetes cluster with Terraform itself. - [How to disable AWS instance destroy with Terraform?](https://www.itwonderlab.com/avoiding-instance-destroy-aws-with-terraform/index.md): Techniques to prevent infrastructure destroy in Terraform by protecting selected instances and resources from being accidentally destroyed. - [How to programmatically use your public Internet IP address in Terraform?](https://www.itwonderlab.com/use-your-public-internet-ip-address-terraform/index.md): Obtain your public IP address and use it in Terraform to create AWS Security Rules. - [Creating AWS RDS Database with Terraform (4/5)](https://www.itwonderlab.com/terraform-aws-mariadb-rds-database/index.md): Tutorial and source code explaining how to create and manage MariaDB (or MySQL) RDS database with Terraform in AWS. - [AWS Route 53, AMI Lookup and EC2 Creation with Terraform (3/5)](https://www.itwonderlab.com/terraform-route-53-ami-lookup/index.md): Tutorial and source code explaining how to manage AWS Route 53 DNS Service, create and register EC2 instances and find an AMI with Terraform. - [AWS VPC Subnets, Routing Tables and Internet Access using Terraform (2/5)](https://www.itwonderlab.com/using-terraform-to-create-an-aws-vpc-with-an-ec2-instance-and-a-mariadb-rds-data-base-ii/index.md): Tutorial and source code explaining how to create and manage AWS networking with Terraform. ## Terraform - [OpenTofu](https://www.itwonderlab.com/opentofu/index.md): OpenTofu is the open-source, Linux Foundation fork of Terraform for Infrastructure as Code, compatible with Terraform providers and HCL. - [Configuration Drift](https://www.itwonderlab.com/terraform-drift/index.md): Configuration drift is the difference between the real infrastructure and its Terraform code or state, caused by manual changes. Learn how to detect and fix it. - [Terraform Backend](https://www.itwonderlab.com/terraform-backend/index.md): A Terraform backend defines where the state is stored and how operations run. Learn the S3 backend, locking and how to migrate between backends. - [Terraform Workspace](https://www.itwonderlab.com/terraform-workspace/index.md): A Terraform workspace is a named state inside the same backend and configuration, used to create several copies of an infrastructure. - [Terraform State](https://www.itwonderlab.com/terraform-state/index.md): The Terraform state is the file where Terraform and OpenTofu record which real resources they manage, so they can plan and apply changes. - [Terraform Module](https://www.itwonderlab.com/terraform-module/index.md): A Terraform module is a reusable set of resources in a directory, with input variables and outputs. Learn how modules work in Terraform and OpenTofu. - [Terraform Provider](https://www.itwonderlab.com/terraform-provider/index.md): A Terraform provider is a plugin that lets Terraform and OpenTofu manage resources of a platform such as AWS, Azure or Kubernetes through its API. - [Terraform Built-in Functions](https://www.itwonderlab.com/terraform-functions/index.md): Terraform functions perform specific tasks on configuration data: numeric, string, collection, date and time, file system and more. ## AWS Best Practices - [AWS Cost Optimization and FinOps: A Practical Checklist](https://www.itwonderlab.com/aws-cost-optimization-finops/index.md): How to reduce AWS costs: budgets, tagging, right-sizing, Savings Plans, NAT gateway and data transfer savings, storage lifecycle and automation with Terraform. - [AWS Security Groups’ Best Practices](https://www.itwonderlab.com/aws-security-groups-best-practices/index.md): Best practices for AWS security groups, the virtual firewalls of EC2, RDS and other resources: naming, groups as sources, least privilege and rule descriptions. - [AWS Tagging Best Practices](https://www.itwonderlab.com/aws-resource-tagging/index.md): Effective infrastructure resource tagging can greatly improve management, IaC, monitoring and cost visibility in AWS. - [AWS Basic VPC Elements](https://www.itwonderlab.com/aws-naming-best-practices/index.md): Best practices for naming and using AWS Infrastructure with Terraform and Ansible. ## Kubernetes Tutorials - [Argo CD and GitOps on Kubernetes: Install and Deploy Your First App](https://www.itwonderlab.com/argocd-gitops-kubernetes/index.md): Learn what GitOps is and install Argo CD in a Kubernetes cluster to deploy applications automatically from Git, with an Application example, sync policies and Helm. - [How to use an external NFS Persistent Volume on Kubernetes](https://www.itwonderlab.com/kubernetes-nfs/index.md): How to use NFS Kubernetes Persistent Volumes for the storage of data. Postgres is used as an example. - [How to Install Helm](https://www.itwonderlab.com/install-kubernetes-helm/index.md): How to install Helm, the package manager for Kubernetes, and use it to deploy applications to a cluster. - [How to Install K3s as a local development Kubernetes cluster](https://www.itwonderlab.com/install-kubernetes-k3s/index.md): K3s.io is a Lightweight Kubernetes cluster perfect for development or edge deployments. K3s is a CNCF project, originally developed by Rancher. - [Istio Patterns: Traffic Splitting in Kubernetes (Canary Release)](https://www.itwonderlab.com/istio-patterns-traffic-splitting-in-kubernetes/index.md): Tutorial on how to use Istio on Kubernetes for releasing new versions of software to the Cloud. - [Kubernetes Cluster using Vagrant and Ansible with Containerd (in 3 minutes)](https://www.itwonderlab.com/ansible-kubernetes-vagrant-tutorial/index.md): Tutorial and full source code explaining how to create a Kubernetes cluster with Ansible and Vagrant for local development under 3 minutes. - [Installing Istio on Kubernetes](https://www.itwonderlab.com/istio-in-local-kubernetes/index.md): How to install Istio in a Kubernetes Cluster to use it as a service mesh for a microservices architecture. - [Installing the Kubernetes Dashboard and managing the Cluster using kubectl](https://www.itwonderlab.com/installating-kubernetes-dashboard/index.md): How to install the Kubernetes Dashboard and manage the cluster after installation. - [Running Postgres in Kubernetes with a Persistent NFS Volume](https://www.itwonderlab.com/postgres-kubernetes-nfs-volume/index.md): How to create a Kubernetes persistent volume for Postgres long term storage of data using a NFS Volume - [Using a NodePort in a Kubernetes Cluster on top of VirtualBox](https://www.itwonderlab.com/nodeport-kubernetes-cluster/index.md): Kubernetes tutorial explaining how to use a NodePort to publish applications in a Kubernetes cluster running in VirtualBox with Vagrant and Ansible - [Istio Patterns: Traffic Splitting in Kubernetes (Header/Cookie Based)](https://www.itwonderlab.com/istio-patterns-traffic-splitting-in-kubernetes-header-based/index.md): How to split traffic in Kubernetes with Istio based on request headers, tutorial, and examples with source code. ## AWS Tutorials - [AWS Three-Tier Web Architecture: Reference Design with Terraform](https://www.itwonderlab.com/aws-three-tier-architecture-terraform/index.md): A reference architecture for a highly available three-tier web application on AWS: VPC, ALB, EC2 auto scaling and RDS, with the Terraform modules to build each layer. - [AWS CLI Cheat Sheet: Profiles, SSO, S3, EC2, IAM and Useful Queries](https://www.itwonderlab.com/aws-cli-cheat-sheet/index.md): A quick reference for the AWS CLI: profiles and SSO, plus the most used commands for S3, EC2, IAM, Lambda and logs, with --query and --output examples. - [How to Install AWS CLI V2](https://www.itwonderlab.com/install-aws-cli/index.md): How to install the AWS CLI (Command Line Interface) to interact with Amazon Web Services through the command line. - [Creating AWS EC2 Instances and Security Rules with Terraform (5/5)](https://www.itwonderlab.com/terraform-aws-ec2-security-rules/index.md): Tutorial and source code explaining how to manage AWS EC2 Instances and Security with Terraform. - [AWS VPC, Route 53, RDS MariaDB, EC2 using Ansible and Terraform (1/5)](https://www.itwonderlab.com/terraform-ansible-aws-howto/index.md): Tutorial and source code explaining how to provision and configure a VPC, Route 53, RDS MariaDB, Instances and security groups using Ansible and Terraform… - [Create an AWS IAM User for Demos](https://www.itwonderlab.com/create-an-aws-iam-user-for-demos/index.md): How to create AWS IAM users for programmatic access to the AWS Cloud API, to be used with Terraform / OpenTofu and Ansible demos. - [Create an AWS Account for Demos](https://www.itwonderlab.com/create-an-aws-account-for-demos/index.md): In order to run the examples presented in IT Wonder Lab you will need accounts in different cloud providers. ## Terraform Best Practices - [Terraform and OpenTofu Best Practices for AWS and the Cloud](https://www.itwonderlab.com/terraform-best-practices/index.md): A practical checklist of Terraform and OpenTofu best practices: state, modules, versions, security, CI/CD, naming, testing and cost control. - [How to Share Infrastructure in Multiple Terraform Projects?](https://www.itwonderlab.com/share-terraform-projects/index.md): Sharing infrastructure across multiple Terraform projects using Data Sources helps maintain consistency, reduce redundancy, and promote collaboration. - [AWS and Terraform Naming Best Practices](https://www.itwonderlab.com/aws-and-terraform-naming-best-practices/index.md): Terraform and AWS resource naming should follow a company standard. Each company has different requirements and the standard should be adjusted. ## Ansible Tutorials - [How to Install Ansible](https://www.itwonderlab.com/how-to-install-ansible/index.md): How to install the Ansible control node on Ubuntu with apt or pipx, and check that Ansible works. ## Glossary - [SSH](https://www.itwonderlab.com/ssh/index.md): SSH, which stands for Secure Shell, is a cryptographic network protocol that allows for secure communication and data transfer between two computers over an… - [HCL](https://www.itwonderlab.com/hcl/index.md): HCL is a domain-specific language developed by HashiCorp, a company known for its infrastructure automation tools such as Terraform, Vault, Consul, and Nomad. - [IaC](https://www.itwonderlab.com/iac/index.md): IaC is an approach to managing and provisioning computing infrastructure through machine-readable code and automation, rather than manual processes. - [OSI model](https://www.itwonderlab.com/osi-model/index.md): The OSI model is a conceptual framework that describes how a network functions, split into seven layers. ## Ansible Best Practices - [Ansible Multiple Environment Best Practices](https://www.itwonderlab.com/ansible-multiple-environment-best-practices/index.md): Handling multiple infrastructure environments with Ansible by targeting the environment tag that is included in the mandatory AWS tags - [Ansible Roles Best Practices](https://www.itwonderlab.com/ansible-roles-best-practices/index.md): How granular Ansible roles should be: highly reusable by configuration, but pragmatic for stateful applications that are not cloud native. - [Ansible Playbook Structure Best Practices](https://www.itwonderlab.com/ansible-playbook-structure-best-practices/index.md): Define and apply a company-wide consistent structure for all your Ansible Playbooks that allows for easy understanding and maximum reuse ## Ansible - [Ansible Dynamic Inventory](https://www.itwonderlab.com/ansible-dynamic-inventory/index.md): Generate inventory (host and group information) dynamically rather than statically defining it in a static inventory file ## Optional - [About](https://www.itwonderlab.com/about/index.md): who writes IT Wonder Lab - [All tutorials](https://www.itwonderlab.com/archive/): complete index - [Sitemap](https://www.itwonderlab.com/sitemap.xml) - [RSS feed](https://www.itwonderlab.com/feed.xml)