Terraform State & DAG Lab (Interactive)
Edit desired config, run plan to see the add/change/destroy diff, and collide two pipelines on the DynamoDB state lock. Walk the Terraform lifecycle: state diffing, DAG parallelization, ClickOps drift detection and remote S3 plus DynamoDB locking.
Terraform State, DAG & Drift Reconciliation Lab
Diff declarative config against the tfstate snapshot, walk the dependency graph in parallel waves, and collide two pipelines on the DynamoDB lock.
Plan: 0 to add, 0 to change, 0 to destroy.
+0 ~0 -0
DAG levels (parallel)
1 waves
Apply wall-time
240s (vs 464s serial)
DynamoDB lock
free
No plan yet. Edit the desired config, then run `terraform plan`.
How It Works Under the Hood
Terraform is a stateful declarative engine: it maps HCL resources to real cloud IDs in a tfstate JSON file and computes the difference between that state and your code. Plan refreshes reality, builds a Directed Acyclic Graph of dependencies, and lists every create, update and destroy, then apply walks the graph in parallel waves, provisioning prerequisites like the VPC before the subnets that need them. Storing state remotely in an encrypted, versioned S3 bucket with a DynamoDB lock table stops two concurrent applies from corrupting it. Drift creeps in when someone edits the console; scheduled plan runs surface it for reconciliation.
Core Architectural Principles
- The DAG orders provisioning topologically and parallelizes independent resources within each wave.
- A DynamoDB mutex (LockID checksum) blocks the second terraform apply to prevent state corruption.
- Console ClickOps changes create drift that terraform plan --detailed-exitcode detects and forces to reconcile.
Anchor IaC discussion on state and locking: remote S3 with KMS encryption plus a DynamoDB lock table is what stops two pipelines from corrupting tfstate. Explain the Directed Acyclic Graph so it is clear why the VPC is created before subnets and how independent resources provision in parallel. Call out drift detection via scheduled plan --detailed-exitcode and never committing plaintext-secret state to Git. Contrast declarative Terraform with imperative CDK/Pulumi to show range.
Declarative IaC gives reproducible, auditable, parallel-provisioned infrastructure, but a corrupted state file risks catastrophic unintended deletion.