Home/Labs/Terraform Plan & Drift Lab
All 280 Labs
INTERACTIVE LAB🏗️

Terraform State & DAG Lab (Interactive)

Edit desired config, run plan to see the add/change/destroy diff, and collide two pipelines on the DynamoDB state lock. Walk the Terraform lifecycle: state diffing, DAG parallelization, ClickOps drift detection and remote S3 plus DynamoDB locking.

Terraform State, DAG & Drift Reconciliation Lab

Diff declarative config against the tfstate snapshot, walk the dependency graph in parallel waves, and collide two pipelines on the DynamoDB lock.

= aws_s3_bucket.tf_state= aws_vpc.main (10.0.0.0/16)= aws_subnet.private-a (az-a)= aws_subnet.private-b (az-b)= aws_security_group.eks_nodes= aws_nat_gateway.primary= aws_eks_cluster.prod= aws_eks_nodegroup.az-b= aws_db_instance.aurora

Plan: 0 to add, 0 to change, 0 to destroy.

+0 ~0 -0

DAG levels (parallel)

1 waves

Apply wall-time

240s (vs 464s serial)

DynamoDB lock

free

wave 1:s3_state (12s)vpc (18s)subnet_a (8s)sg (6s)eks (240s)rds (180s)· max 240s parallel
No plan yet. Edit the desired config, then run `terraform plan`.

How It Works Under the Hood

Terraform is a stateful declarative engine: it maps HCL resources to real cloud IDs in a tfstate JSON file and computes the difference between that state and your code. Plan refreshes reality, builds a Directed Acyclic Graph of dependencies, and lists every create, update and destroy, then apply walks the graph in parallel waves, provisioning prerequisites like the VPC before the subnets that need them. Storing state remotely in an encrypted, versioned S3 bucket with a DynamoDB lock table stops two concurrent applies from corrupting it. Drift creeps in when someone edits the console; scheduled plan runs surface it for reconciliation.

Core Architectural Principles

  • The DAG orders provisioning topologically and parallelizes independent resources within each wave.
  • A DynamoDB mutex (LockID checksum) blocks the second terraform apply to prevent state corruption.
  • Console ClickOps changes create drift that terraform plan --detailed-exitcode detects and forces to reconcile.
Interview Round Script

Anchor IaC discussion on state and locking: remote S3 with KMS encryption plus a DynamoDB lock table is what stops two pipelines from corrupting tfstate. Explain the Directed Acyclic Graph so it is clear why the VPC is created before subnets and how independent resources provision in parallel. Call out drift detection via scheduled plan --detailed-exitcode and never committing plaintext-secret state to Git. Contrast declarative Terraform with imperative CDK/Pulumi to show range.

Key Trade-Offs

Declarative IaC gives reproducible, auditable, parallel-provisioned infrastructure, but a corrupted state file risks catastrophic unintended deletion.

Related Curriculum Chapter

Infrastructure as Code (IaC): Terraform vs Pulumi vs CloudFormation

Read Full Chapter Blueprint

Explore More Interactive Labs

View All 280 Labs