Part 1 — Foundations · wrap-up
Cheat sheet & self-check
Every command from this section on one page.
Working in a layer
terraform -chdir=live/prod/20-cluster init | Initialise one layer of one environment |
terraform -chdir=live/prod/20-cluster plan -out=tfplan | Plan and save it |
terraform -chdir=live/prod/20-cluster apply tfplan | Apply exactly what was reviewed |
terraform providers lock -platform=linux_amd64 -platform=darwin_arm64 | Lock provider hashes for all platforms your team uses |
terraform fmt -recursive && terraform validate | Formatting and static checks |
Across layers
for l in 10-network 20-cluster 30-platform; do terraform -chdir=live/prod/$l apply; done | Create in order |
for l in 30-platform 20-cluster 10-network; do terraform -chdir=live/prod/$l destroy; done | Destroy in reverse order |
aws ssm get-parameter --name /platform/prod/vpc_id | Read an output another layer published |
State
terraform init -backend-config=backend-prod.hcl | Initialise against an environment's backend |
terraform state list | Resources tracked in state |
terraform state show module.eks.aws_eks_cluster.this[0] | One resource's recorded attributes |
terraform force-unlock <lock-id> | Remove a stale lock (only when sure nobody is running!) |
Plans & drift
terraform plan -var-file=prod.tfvars -out=prod.plan | Plan and save it |
terraform apply prod.plan | Apply exactly what was planned |
terraform plan -detailed-exitcode | Exit 0 = no changes, 2 = changes (drift), 1 = error |
Patterns
exec { command = "aws" args = ["eks", "get-token", …] } | Fresh tokens during long applies |
data "terraform_remote_state" "cluster" { … } | Read the cluster layer's outputs from another stack |
terraform apply -target=module.eks | Emergency only: bootstrap one part first |
Useful commands
aws eks get-token --cluster-name prod | jq -r .status.expirationTimestamp | When does this token expire? |
terraform providers | Which providers each module uses |