☁️ Practical Course

AWS + Terraform

From your first terraform apply to production-ready infrastructure. 25 topics (18 lectures, +6 self-study topics, +1 topic on YouTube LIVE).

25Topics
5Modules
L1→L5Levels
47K+Lines of Code
🧱

Module 1 · Fundamentals

Variables, dependencies, outputs, state

01
Introduction to IaC + Terraform
Immutable Infrastructure
What is IaC (Infrastructure as Code), and why do we need it? Your first terraform init, plan, apply, destroy. Mini-project: deploying a static website on S3 from scratch.
S3initapply
02
Variables and Data Types
Parameterized Config
Parameterizing configuration: string, number, bool, list, map, object. .tfvars files, validation. Project: an EC2 instance configured through variables.
EC2variablestfvars
03
Resources and Dependencies
Dependency Graph
How Terraform builds the dependency graph. Explicit (depends_on) and implicit dependencies. Project: VPC + Subnet + Security Group + EC2 — a complete network from scratch.
VPCEC2depends_on
04
Outputs and Data Sources
Data-Driven Lookup
How to retrieve data from existing infrastructure and pass values between configurations. Project: automatically looking up the latest AMI + EC2 deployment.
EC2outputsdata
05
State — How Terraform Remembers
Remote State Locking
The state file: why it is needed and why losing it is dangerous. S3 remote backend, locking for teamwork. A critical topic — mistakes in state are costly.
S3DynamoDBstatebackends
📈

Module 2 · Scaling

Modules, count/for_each, ALB, RDS, lifecycle

06
Modules — Reusable Code
Reusable Module Multi-AZ HA
The DRY principle in Terraform: creating and using modules. Inputs, outputs, nested modules. Project: a VPC module with a Multi-AZ NAT Gateway that is reused in later lessons.
VPCNATmodules
07
Count and for_each
Fan-Out Pattern Multi-AZ HA
Creating resources dynamically: N servers across different AZs with a single block. The difference between count and for_each, and when to use which. Indexing and referencing resources.
EC2countfor_each
08
ALB + Auto Scaling Group
Load-Balanced Auto-Scaling Active-Active Multi-AZ HA
A resilient web server: Application Load Balancer, Launch Template, Auto Scaling Group with health checks. A pattern used in 90% of production environments.
ALBASGlifecycletemplatefile
09
RDS Multi-AZ
Active-Standby Failover Active-Passive Multi-AZ HA
A managed database: PostgreSQL with automatic failover. Parameters, subnet groups, security. Working with sensitive values and prevent_destroy to protect data.
RDSsensitiveprevent_destroy
10
Lifecycle and Provisioners 📖 Self-study
Blue-Green Lifecycle
Resource lifecycle rules: create_before_destroy, ignore_changes, replace_triggered_by. Provisioners (local-exec, remote-exec) — when they are acceptable and why it is better to avoid them.
EC2EBSlifecycleprovisioners
🏗️

Module 3 · Production Patterns

Dynamic blocks, functions, CDN, ECS, workspaces, Terragrunt

11
Dynamic Blocks and Conditionals
Policy-as-Code
Generating repeated blocks from variables. Conditional operators (count = var.enabled ? 1 : 0). Project: flexible Security Groups driven by map-type variables.
SGdynamicconditionals
12
Functions and Expressions 📖 Self-study
Computed Network Layout
Terraform's built-in functions: string, collection, numeric and filesystem functions. Complex expressions: cidrsubnet(), merge(), lookup(). A reference lesson with practical examples.
VPCfunctions
13
S3 + CloudFront CDN 🔴 YouTube Live
Edge-Cached Static Hosting Edge Caching
Delivering content globally: an S3 bucket as the origin, a CloudFront distribution, an ACM certificate for HTTPS. Origin Access Control (OAC), cache policies, attaching a custom domain.
S3CloudFrontACM
14
ECS Fargate
Serverless Containers Active-Active Serverless
“Serverless” containers on AWS: Task Definition, Service, ALB integration. IAM roles for tasks, an ECR repository. jsonencode() for describing containers.
ECSECRjsonencode
15
Workspaces
Environment Isolation Multi-Environment
Separating environments with a single codebase: Dev / Staging / Prod. Per-workspace variables, configuration strategies. When workspaces are enough and when you need Terragrunt.
workspaces
16
Terragrunt 📖 Self-study
DRY Multi-Environment Multi-Environment
DRY multi-environment infrastructure: terragrunt.hcl, configuration inheritance, dependencies between modules. A separate tool that sits on top of Terraform, for complex projects.
terragruntDRY
⚡

Module 4 · Advanced Patterns

Lambda, event pipelines, IAM, Secrets, troubleshooting

17
Lambda + API Gateway
Serverless REST API Event-Driven Serverless
Serverless API: packaging code with archive_file, a Lambda function, the REST API Gateway service. IAM roles, CloudWatch Logs. The “serverless” architecture pattern.
LambdaAPI GW
18
SNS + SQS + Lambda
Event-Driven Pipeline Event-Driven Fan-Out / Pub-Sub Serverless
Event-driven architecture: SNS topics, SQS queues, Lambda handlers. Resource policies, dead-letter queues. Building an event pipeline with AWS services.
SNSSQSpolicies
19
IAM Deep Dive 📖 Self-study
Least-Privilege Access
Secure IAM architecture: policies, roles, STS assume role, permission boundaries. The principle of least privilege. A topic where mistakes = security holes.
IAMSTSpolicies
20
Secrets Manager + KMS
Encryption at Rest
Managing secrets: Secrets Manager, SSM Parameter Store, KMS encryption. How to avoid storing passwords in code. Secret rotation, integration with RDS and Lambda.
KMSSecretssensitive
21
Import, Drift, Troubleshooting 📖 Self-study
Drift Detection & Recovery
Real-world problems: importing existing resources into state, detecting drift, debugging (TF_LOG). Recovering from mistakes, terraform state mv/rm.
importstatedebug
🌍

Module 5 · Enterprise Scale

Multi-region, CI/CD, monitoring, final project

22
Multi-Region
Active-Passive DR Active-Passive Multi-Region DR
Disaster Recovery and replication: multiple AWS providers, Route53 failover, S3 cross-region replication. An architecture that survives an entire region going down.
Route53multi-provider
23
CI/CD for Terraform
GitOps Pipeline GitOps / CI-CD
Deployment automation: a GitHub Actions pipeline — plan on pull requests and apply on merge. OIDC authentication, approval gates, artifacts.
IAMautomation
24
Monitoring and Alerts
Observability Stack
CloudWatch dashboards, metrics, alarms, SNS notifications. Building an observability layer for the entire infrastructure. A for_each loop for templating alerts.
CloudWatchSNSfor_each
25
🎓 Final Project 📖 Self-study
Production-Ready Architecture Active-Active Active-Passive Edge Caching Multi-AZ HA
Putting it all together: a production-grade stack with VPC, ECS, RDS, monitoring, CI/CD and secrets. Multi-environment and fully automated. Project defense.
Full stackall together