Declaring infrastructure in files.
WHAT IT MEANS
Infrastructure defined in files, versioned, reviewed, and applied by tooling.
WHAT IT PROVIDES
Repeatability Review before change A record of every change Recovery by reapplying
WHAT DECLARATIVE MEANS
Describing the desired state, with the tool determining the steps.
WHY THAT IS PREFERABLE
Running it twice produces the same result.
WHAT STATE FILES ARE
The tool's record of what it created.
WHY THEY MATTER ENORMOUSLY
Losing or corrupting one leaves the tool unable to manage what exists.
WHAT TO DO
Store state remotely, with locking and versioning.
WHY LOCKING
Two people applying simultaneously corrupts it.
WHAT TO NEVER PUT IN THESE FILES
Secrets.
WHAT TO USE INSTEAD
A secret store, referenced at apply time.
WHAT TO ALWAYS REVIEW
The plan, before applying.
WHAT TO WATCH FOR IN A PLAN
Anything being destroyed and recreated.
WHY
That frequently means an outage nobody intended.
WHAT TO SEPARATE
Environments, so a change cannot affect production accidentally.