StudyToCert

All certifications / Terraform Associate / Lessons

HashiCorp Certified: Terraform Associate Terraform Associate (004) · Domain 1: Infrastructure as Code (IaC) with Terraform

What IaC is: infrastructure defined in version-controlled, machine-readable files instead of manual console changes

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

Infrastructure as Code (IaC) means you describe servers, networks, databases, DNS records and other infrastructure in text files that a tool reads and acts on, rather than building them by clicking through a cloud console or typing one-off commands. The files are the source of truth: if you want a change, you change the file, and the tool makes reality match it.

Two words in the definition carry most of the weight. Machine-readable means a program can parse the file and turn it into API calls without a human interpreting it. Version-controlled means the files live in a system such as Git, so every change has an author, a timestamp, a message and a diff you can review or roll back. A wiki page describing how a server was built is documentation; a file that a tool can execute to build that server is code.

Compare this with manual provisioning, sometimes called ClickOps. An engineer logs in to a console, creates a virtual network, picks a subnet range, launches a virtual machine and opens a firewall port. It works, but the knowledge of exactly what was done lives in that engineer's memory. Rebuilding it in another region, or explaining to an auditor why a port is open, means reconstructing the steps by hand. Small differences creep in between environments, a problem known as configuration drift.

With Terraform, the IaC files are written in the HashiCorp Configuration Language (HCL) and usually end in .tf. A directory of .tf files is a configuration. You write blocks that declare what should exist, run terraform plan to preview what Terraform would change, and run terraform apply to make those changes through the provider's API. Terraform also keeps a state file recording which real objects belong to which blocks, which you will study later.

resource "local_file" "hello" {
  filename = "hello.txt"
  content  = "Managed by Terraform"
}

This tiny example uses the local provider to manage a file on your own machine, which is a good way to learn the workflow without a cloud account. The same pattern, a resource type, a name and some arguments, is how you would declare a cloud virtual machine or a DNS record. Once infrastructure is in files, it can be reviewed in pull requests, tested in pipelines and recreated on demand.

Key terms

Infrastructure as Code (IaC)
Managing infrastructure through machine-readable definition files that a tool applies, instead of manual changes.
Configuration
In Terraform, the set of .tf files in a directory that together describe the desired infrastructure.
HCL
HashiCorp Configuration Language, the declarative language Terraform configurations are written in.
Configuration drift
Differences that build up between environments or between the recorded design and reality, usually from untracked manual changes.
ClickOps
Informal name for provisioning infrastructure by hand through a web console.
Real-world example

A team has a staging environment that someone built by hand two years ago. When they need a second copy for load testing, nobody remembers every setting. After they describe the environment in Terraform files stored in Git, creating a third copy is a matter of running plan and apply with different variable values.

Exam tip: Exam questions define IaC by its properties: code stored in version control and applied by a tool. If an answer describes documenting manual steps or scripting console clicks without a source of truth, it is not the IaC benefit being asked about.

Check yourself

Why is a runbook describing console steps not considered Infrastructure as Code?

Because a tool cannot execute it to produce the infrastructure; IaC files are machine-readable and applied automatically, so the file itself is the source of truth.

What problem does storing IaC files in version control solve that manual changes do not?

It records who changed what, when and why, allows review before changes, and lets you roll back to a known version.

Study Terraform Associate for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Terraform Associate study plan