Managing infrastructure manually has been the norm for decades: an administrator logs into a web panel or an SSH console, creates a virtual machine, configures the network, mounts a disk and repeats the process for every new server. The problem is that this approach does not scale, is not reproducible and is prone to human error. When you have 5 servers it is manageable; when you have 50 or 500, every manual change becomes an operational risk.
Infrastructure as Code (IaC) solves this problem by defining infrastructure in text files that can be versioned, reviewed and executed automatically. And within the IaC ecosystem, Terraform by HashiCorp has become the de facto standard for infrastructure provisioning in cloud, on-premise and hybrid environments.
In this article we explain what IaC is, how Terraform works, its HCL language, the most relevant providers, state management, modules, a comparison with other tools and best practices for automating production infrastructure.
What Is Infrastructure as Code
Infrastructure as Code is the practice of defining and managing infrastructure (servers, networks, storage, firewalls, DNS, load balancers) through source code instead of manual processes. Configuration files describe the desired state of the infrastructure, and an IaC tool takes care of creating, modifying or destroying the resources needed to reach that state.
The fundamental benefits of IaC are reproducibility (the same code produces the same environment every time), auditability (every change is recorded in version control), speed (deploying a complete environment takes minutes, not days) and drift elimination (the real infrastructure always matches what the code describes).
IaC is divided into two main approaches: declarative (you describe the final state and the tool calculates the steps) and imperative (you describe step by step what needs to be done). Terraform follows the declarative approach, which greatly simplifies the management of complex infrastructure.
What Is Terraform
Terraform is an open-source Infrastructure as Code tool created by HashiCorp in 2014. It allows you to define infrastructure in a declarative language called HCL (HashiCorp Configuration Language), plan changes before applying them, and execute them safely and repeatably against any infrastructure provider.
The Terraform workflow is based on three main commands: terraform init (initialises the working directory and downloads the required providers), terraform plan (calculates the difference between the current state and the desired state, showing which resources will be created, modified or destroyed) and terraform apply (executes the planned changes against the provider API).
What sets Terraform apart from other tools is its provider-based architecture: plugins that connect Terraform with the APIs of each platform. There are providers for AWS, Azure, GCP, Proxmox, VMware, Cloudflare, GitHub, Kubernetes and hundreds of other services. This makes Terraform a truly multi-cloud and multi-platform tool.
HCL: The Terraform Language
HCL (HashiCorp Configuration Language) is a declarative language designed to be readable by both humans and machines. Unlike JSON or YAML, HCL supports variables, functions, conditional expressions, loops and cross-resource references, enabling the definition of complex infrastructure in a concise and maintainable way.
The fundamental HCL blocks are: resource (defines an infrastructure resource such as a VM, a disk or a firewall rule), variable (reusable input parameters), output (values exported after execution), data (queries for existing data in the provider) and locals (internal computed variables). A typical Terraform file combines these blocks to describe a complete environment.
Key concept:
Terraform is declarative: you define WHAT infrastructure you want (3 VMs with 8 GB of RAM and NVMe disk) and Terraform calculates HOW to reach that state. If 2 VMs already exist, it will only create the third. If one has 4 GB, it will update it to 8 GB. You do not need to write the change logic.
Providers: Proxmox, AWS, Azure and More
Providers are the heart of Terraform's extensibility. Each provider translates HCL resource blocks into API calls against the corresponding platform. The most relevant ones for enterprise infrastructure environments are:
- dns Proxmox (bpg/proxmox): allows you to create and manage virtual machines, LXC containers, storage pools and networks on Proxmox VE clusters. Ideal for automating on-premise infrastructure with the same workflow used in public cloud.
- cloud AWS (hashicorp/aws): the most mature provider in the ecosystem, with support for EC2, S3, RDS, VPC, Lambda, EKS and hundreds of AWS services. It enables full public cloud infrastructure management from code.
- cloud Azure (hashicorp/azurerm): full support for Azure Resource Manager, including VMs, virtual networks, Azure Kubernetes Service, databases and storage services.
- settings Others: GCP, Cloudflare (DNS, WAF), Kubernetes, Helm, Vault, GitHub, GitLab, Datadog, PagerDuty. Terraform can manage not only infrastructure but also service configuration, monitoring and access control.
The ability to combine multiple providers in a single project is what makes Terraform the ideal tool for hybrid environments: you can define VMs on on-premise Proxmox, DNS records on Cloudflare and S3 buckets on AWS within the same configuration file, with automatic dependencies between resources.
State Management
Terraform maintains a state file that records the mapping between resources defined in code and the actual resources created in the provider. This state is essential for Terraform to calculate the differences between the current and desired states and plan the necessary changes.
By default, the state is stored in a local file (terraform.tfstate), but in production environments with multiple operators it is essential to use a remote backend: S3 + DynamoDB for locking, Azure Blob Storage, Google Cloud Storage or Terraform Cloud. The remote backend ensures that two people do not run terraform apply simultaneously, preventing conflicts and state corruption.
State management best practices include: never editing the state manually, using terraform state for refactoring operations, enabling encryption at rest on the backend (the state may contain credentials) and separating state by environment (dev, staging, production) using workspaces or independent directories.
Modules: Reusable Infrastructure
Terraform modules are reusable configuration packages that encapsulate a set of related resources. A module can define, for example, a complete VM with its disk, network, firewall and DNS, and expose it as a parameterisable component invoked with input variables.
The main advantage of modules is standardisation: instead of each team defining its resources differently, a shared module ensures that all production VMs follow the same configuration pattern (sizing, tagging, backup policies, firewall rules). Furthermore, modules are versioned, allowing the base configuration to be updated without breaking existing deployments.
The Terraform Registry hosts thousands of public modules maintained by the community and by providers themselves. It is also possible to create private registries for internal organisation modules, distributing them via Git repositories or Terraform Cloud.
Comparison Table: Terraform vs Ansible vs Pulumi vs CloudFormation
The following table compares the most widely used IaC tools in production environments:
| Criterion | Terraform | Ansible | Pulumi | CloudFormation |
|---|---|---|---|---|
| Approach | Declarative (HCL) | Imperative (YAML playbooks) | Declarative (Python, Go, TS) | Declarative (JSON/YAML) |
| Multi-cloud | Yes, 3,000+ providers | Yes, via modules | Yes, same providers as TF | No, AWS only |
| State management | State file (local or remote) | Stateless (agentless) | State file (similar to TF) | Managed by AWS |
| Primary focus | Infrastructure provisioning | Server configuration | Infrastructure provisioning | AWS provisioning |
| Learning curve | Medium (HCL is straightforward) | Low (familiar YAML) | Medium-high (requires programming) | Medium (verbose in JSON) |
| On-premise | Yes (Proxmox, VMware, bare metal) | Yes (native SSH) | Yes (same providers) | No |
In practice, Terraform and Ansible complement each other: Terraform provisions the infrastructure (creates VMs, networks, disks) and Ansible configures the software inside those machines (installs packages, configures services, manages users). Many teams use both tools together in their deployment pipeline.
Terraform Best Practices
- check_circle Version control in Git: all Terraform code should live in a Git repository. Every infrastructure change is reviewed in a pull request before being applied, just like application code.
- check_circle Remote backend with locking: use S3 + DynamoDB, Azure Blob or Terraform Cloud as a backend to prevent concurrent executions and state loss.
- check_circle Environment separation: use workspaces or independent directories for dev, staging and production, preventing a development error from affecting production.
- check_circle Versioned modules: encapsulate repeated patterns in modules with semantic versioning. A change to the base module propagates in a controlled manner.
-
check_circle
Plan before apply: always run
terraform planand review the changes before applying them. In CI/CD, the plan runs automatically on the PR and apply only after approval. - check_circle Do not hardcode secrets: use environment variables, Vault or the CI/CD secrets mechanism for credentials. Never include passwords or API keys in .tf files.
Terraform for On-Premise Infrastructure
Although Terraform is frequently associated with public cloud, its value in on-premise environments is equally significant. With the Proxmox provider, Terraform can create virtual machines, assign CPU, RAM and storage resources, configure VLAN networks and manage LXC containers directly against the Proxmox VE API, the hypervisor used by EasyDataHost on its enterprise servers.
This means a team can manage its private datacenter with the same IaC practices used on AWS or Azure: versioned code, plan before apply, reusable modules and a CI/CD pipeline. The difference between provisioning a VM on public cloud or on a local Proxmox cluster comes down to changing the provider block in the configuration file.
Furthermore, Terraform enables the management of hybrid environments in a single project: VMs on on-premise Proxmox for sensitive workloads, with automated backups to the cloud and DNS managed on Cloudflare. All defined in the same repository and executed with a single terraform apply.
Practical advantage:
With Terraform + Proxmox, you can define your entire on-premise infrastructure in code: VMs, networks, storage, firewall. A new staging environment is deployed in minutes with a single command, identical to production. No more environments that "look like" production.
EasyDataHost and Infrastructure Automation
At EasyDataHost we apply Infrastructure as Code principles in the management of our own platform and in the managed services we offer our clients. Terraform is a central piece of our automation stack, alongside Ansible for server configuration and CI/CD pipelines for continuous delivery.
For clients who need to automate their infrastructure, we offer Terraform consulting and deployment on Proxmox, including the design of custom modules, configuration of secure remote backends, CI/CD pipeline integration and training for the technical team. The goal is for every client to be able to manage their infrastructure as code, with the same reliability and repeatability demanded by a production environment.
- check_circle Proxmox automation: VM, network and storage provisioning via Terraform against the Proxmox VE API.
- check_circle Custom modules: Terraform modules tailored to each client's architecture and security policies.
- check_circle Integrated CI/CD: automated pipelines where every infrastructure change goes through plan, review and controlled apply.
- check_circle Data in Spain: all managed infrastructure resides in our Tier III+ datacenter in Madrid with guaranteed data sovereignty.
Conclusion
Infrastructure as Code is not a trend: it is the natural evolution of infrastructure management in a world where speed, reproducibility and reliability are non-negotiable requirements. Terraform has established itself as the reference tool for IaC thanks to its declarative approach, its multi-cloud provider ecosystem and its ability to manage on-premise and cloud infrastructure with the same workflow.
- arrow_right IaC defines infrastructure in versionable, reproducible and auditable code.
- arrow_right Terraform uses declarative HCL with 3,000+ providers for cloud, on-premise and hybrid.
- arrow_right State management and modules enable scaling automation safely.
- arrow_right Terraform + Proxmox brings IaC practices to the on-premise datacenter with the same workflow as public cloud.
- arrow_right EasyDataHost offers Terraform automation on Proxmox, custom modules and integrated CI/CD.
If you want to automate your infrastructure with Terraform or need help implementing IaC in your environment, contact our team to design the solution that best fits your requirements.