↓ Skip to main content

Terraform Inside Out

Most Terraform tutorials hand you a main.tf, tell you to run apply, and a bucket appears. Then something drifts, the state file does something “weird,” and you’re stuck — because nobody explained the machine underneath.

This series goes the other way. The thesis is in the name: we go inside — the state file, the reconcile loop, the dependency graph — the mechanics that explain 90% of Terraform’s surprising behavior. And we do it hands-on, on a free local AWS (LocalStack, no account, no bill), where you can safely build real aws_* resources, break them on purpose, and watch how Terraform responds.

One load-bearing idea carries the whole thing: Terraform is a reconcile loop. You declare desired state; Terraform diffs it against reality and converges. If you’ve met Kubernetes or GitOps, you already know this shape — Terraform just points it at your whole cloud.

Three labs, each combining a couple of ideas:

  • Lab 1 · The Ledger & The Loop — the reconcile loop, the core commands, and the state file as a ledger. We build a bucket, reach equilibrium, then delete it behind Terraform’s back and watch drift detection catch it. The mental model everything else hangs on.
  • Lab 2 · Dependencies & Modules — how resources relate (the dependency graph Terraform builds) and how you compose them into reusable modules. From one file to real structure.
  • Lab 3 · Surgery & Blast Radius — operating on live state safely: import existing infra, -replace a resource, state mv, and the dangerous operations — targeted and guarded destroy. The advanced, don’t-break-prod lab.

The whole rig is free and local, so you can follow every command yourself. Let’s open it up.

2026