Infrastructure as code (IaC) means describing firewall configuration in text files kept in version control, then letting a tool apply it. The benefits are repeatability, peer review of changes, easy rollback to a known version, and consistency across many firewalls. All three tools in this topic talk to the PAN-OS XML API underneath, so everything from the API lesson still applies: API keys, API-only admin roles, and the difference between candidate and running configuration. The tools differ mainly in style: whether you describe an end state, a sequence of steps, or write your own program. Terraform, from HashiCorp, is declarative: you write the desired end state in HCL (HashiCorp Configuration Language) files and Terraform works out what to create, change or delete. The Palo Alto Networks panos provider supplies resources for objects, policies, network settings and more, for firewalls and Panorama. Terraform records what it manages in a state file, terraform plan shows the changes before terraform apply makes them, and terraform destroy removes what it created. Terraform is excellent at building configuration, for example creating address objects and rules alongside cloud VM-Series deployments. Committing is handled separately from the resource changes, and how depends on the provider version, so check its documentation; pushed configuration is not live until committed. Protect the state file, because it can contain sensitive values.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.