todo.academy Try a free chapter

True zero to Terraform practitioner

Infrastructure Automation with Terraform

Plan infrastructure before it surprises you, then prove state.

Learn Terraform by delivering safe, reviewable infrastructure changes from configuration to verified state.

No credit card for the free chapter. Preview what the chapter covers.

By the end

Observable skills you will practice.

  • Author and validate a typed Terraform root module
  • Select providers and review version and lock-file evidence
  • Read create, update, replace, destroy, unknown, and saved-plan behavior
  • Use dependency and lifecycle controls without hiding full-workspace risk
  • Inspect state, diagnose drift, handle locks, and protect sensitive artifacts
  • Build reusable modules and stable count or for_each identities
  • Import and refactor managed objects without accidental replacement
  • Run CI checks, recover common failures, and hand off an independently reviewed change

Syllabus

35 chapters from the published course structure.

The focused path contains 89 required lessons. The advanced library remains available when your role needs more depth.

Focused path chapters14 chapters contain the required 89-lesson path.
Chapter 00Free

Free Terraform first contact

Learn configuration, resource addresses, init, validate, plan, apply, state, outputs, changed input, and proof-backed plan review.

11 focused lessons
Chapter 01Full course

HCL foundations: blocks, variables, locals, outputs

Read HCL as a typed root-module contract, repair malformed blocks, validate types, use tfvars, trace locals, check formatting, and prove outputs.

8 focused lessons + 2 advanced lessons
Chapter 02Full course

Providers, versions, lock files, and aliases

Declare provider requirements, initialize plugins, review lock files, repair version constraints, configure provider aliases, inspect schema, and prove provider routing.

7 focused lessons + 3 advanced lessons
Chapter 03Full course

Plan reading, action types, saved plans, and freshness

Read plan symbols, unknown values, create and update actions, replacement and destroy risk, saved plan artifacts, and stale-plan recovery.

8 focused lessons + 2 advanced lessons
Chapter 04Full course

Dependency graphs, cycles, and lifecycle safety

Read implicit references, explicit depends_on edges, DOT graphs, cycle failures, create-before-destroy ordering, destroy guards, ignored drift, and replacement blast radius.

7 focused lessons + 3 advanced lessons
Chapter 05Full course

State, drift, locking, and safe inspection

Understand state bindings, inspect addresses and snapshots, review refresh-only changes, reconcile drift, reinitialize backends, recover locks, and protect sensitive state.

8 focused lessons + 2 advanced lessons
Chapter 06Full course

Modules, interfaces, sources, and composition

Build reusable module boundaries, pass typed inputs, expose outputs, compose flat module graphs, pin sources, refresh the cache, and repair broken calls.

6 focused lessons + 4 advanced lessons
Chapter 07Full course

Collections, count, for_each, and stable identity

Choose numeric or keyed instances, read addresses, reject unknown collection sizes, reason about sets, chain collections, generate nested blocks, and repair unstable identity.

5 focused lessons + 5 advanced lessons
Chapter 08Full course

Workspaces, environments, backends, and promotion

Separate configuration, values, state, backends, and credentials. Use workspaces deliberately, review variable precedence, and promote one saved plan in an explicit context.

6 focused lessons + 4 advanced lessons
Chapter 09Full course

Import, moved blocks, and safe refactors

Adopt existing objects, review generated configuration, preserve identity across address changes, migrate state safely, and use explicit replacement only for recovery.

5 focused lessons + 5 advanced lessons
Chapter 10Full course

CI, tests, conditions, and policy review

Turn Terraform habits into repeatable review gates with formatting, validation, tests, custom conditions, check warnings, saved plan JSON, and policy decisions.

6 focused lessons + 4 advanced lessons
Chapter 11Full course

Troubleshooting and recovery

Recover provider failures, stale saved plans, stuck locks, partial applies, drift, missing state bindings, and replacement risk with evidence.

5 focused lessons + 5 advanced lessons
Chapter 12Full course

Final professional capstone

Safe-change handoff: preflight, preserve state, reconcile drift, import an object, refactor without replacement, reject destroy, review a saved plan with policy, and report.

5 focused lessons + 5 advanced lessons
Chapter 13Full course

Data sources, terraform_data, and side-effect safety

Choose extension boundaries, trace data-read timing, use terraform_data, constrain provisioners, secure remote execution, prove idempotence, and migrate legacy triggers safely.

2 focused lessons + 10 advanced lessons
Explore 21 advanced library chapters

These chapters provide optional drills and reference depth. They are not required to complete the focused path.

Library 14Full course

Remote operations and team delivery

Operate Terraform across remote state, workspaces, locks, run queues, speculative plans, saved-plan freshness, VCS configuration versions, and safe remote upload packages.

10 advanced lessons
Library 15Full course

Governance, drift, and scale controls

Use policy enforcement, run tasks, cost and drift evidence, remote output boundaries, targeting exceptions, bounded parallelism, and safe refresh controls before approval.

10 advanced lessons
Library 17Full course

Terraform Stacks: components, deployments, and orchestration

Compose reusable component configurations, repeat them as isolated deployments, route providers safely, order dependencies, gate auto-approval, pass published outputs, remove components, and use the current Stacks CLI lifecycle.

11 advanced lessons
Library 18Full course

Plugin Framework and provider development

Build and verify provider servers, protocol compatibility, typed schemas, resource lifecycles, read-only data sources, diagnostics, plan modifiers, import, state upgrades, and acceptance tests.

12 advanced lessons
Library 19Full course

Advanced provider capabilities and release trust

Extend providers with functions, ephemeral resources, write-only arguments, custom types, muxed migrations, layered tests, debugging, logging, deprecation review, and signed releases.

12 advanced lessons
Library 20Full course

Provider migration, compatibility, and maintenance

Migrate SDKv2 providers safely, compare Framework behavior, stage mux routes, preserve schema and state identity, test empty plans, deprecate responsibly, publish versioned docs, and maintain a support-backed release packet.

12 advanced lessons
Library 21Full course

Provider actions, list resources, and discovery

Model explicit side effects as actions, validate invocation and recovery, then expose list-resource discovery with stable identity, paging, filters, query tests, and release support.

12 advanced lessons
Library 22Full course

Provider and module distribution, mirrors, and private registries

Verify source addresses, registry discovery, private access, CLI mirrors, lock checksums, signatures, module versioning, air-gapped recovery, troubleshooting, and clean release installs.

12 advanced lessons
Library 23Full course

Machine-readable plans, automation, and drift-safe reporting

Build version-aware JSON evidence for plans, state, outputs, policy, redaction, retention, incident recovery, and automation releases.

13 advanced lessons
Library 24Full course

HCP Terraform API, run orchestration, and event-driven operations

Operate HCP Terraform through the API: authenticate safely, address workspaces, upload configuration versions, create and follow runs, wait for state processing, protect outputs, handle pagination and idempotency, verify notifications, recover incidents, and ship a supported client contract.

13 advanced lessons
Library 25Full course

Dynamic provider credentials and workload identity

Replace long-lived cloud keys with OIDC trust, phase-aware claims, short-lived provider credentials, cloud-specific bindings, alias routing, Vault-backed leases, incident repair, and release support.

13 advanced lessons
Library 26Full course

HCP Terraform agents, agent pools, and private execution

Operate private HCP Terraform execution with explicit workspace boundaries, pool scope, token rotation, verified installation, host requirements, private network access, request forwarding, capacity, status recovery, and incident-safe operations.

13 advanced lessons
Library 27Full course

HCP Terraform governance and workspace operations

Scope projects and teams, manage variable sets and sensitive values, configure workspace settings and VCS triggers, review working directories and approvals, restrict state sharing, operate health and locks, connect run triggers, repair incidents, and ship a supportable governance packet.

13 advanced lessons
Library 28Full course

HCP Terraform private registry and no-code modules

Publish and consume private modules and providers through HCP Terraform, verify VCS and semantic releases, authenticate consumers, resolve sources, classify project tags, validate no-code contracts and upgrades, repair registry incidents, and ship a complete supply-chain packet.

13 advanced lessons
Library 29Full course

HCP Terraform policy-as-code operations

Operate Sentinel and OPA policy sets with correct scope, VCS source, enforcement levels, run results, override governance, API automation, private policy connectivity, incident repair, and release evidence.

13 advanced lessons
Library 30Full course

HCP Terraform audit trails and security evidence

Operate organization audit trails with correct token scope, retention-aware queries, event schema preservation, team, run, registry, and login event review, SIEM export, entitlement checks, incident repair, and release evidence.

13 advanced lessons
Library 31Full course

HCP Terraform SSO and identity operations

Operate SAML SSO with correct access boundaries, break glass recovery, tested enablement, account linking, NameID validation, team mapping, SSO Team IDs, IdP-specific claims, entitlement checks, incident repair, and release evidence.

13 advanced lessons
Library 32Full course

HCP Terraform team access and permission design

Design auditable team access with organization membership, owners, team lifecycle, visibility, organization, project, and workspace permissions, effective access, team tokens, API review, incident repair, and release evidence.

13 advanced lessons
Library 33Full course

HCP Terraform security perimeter and token governance

Harden account and API access with 2FA, user, team, and organization token boundaries, one-time token visibility, user-token disablement, VCS impact review, IP allowlist CIDR and scope, exception handling, incident repair, and final evidence.

13 advanced lessons
Library 34Full course

HCP Terraform notifications, webhooks, and run-event response

Design operational signal paths with workspace, project, and team notifications, event selection, destinations, webhook authenticity, configuration verification, delivery responses, VCS status checks, static outbound IP ranges, incident repair, and final evidence.

13 advanced lessons
Library 35Full course

HCP Terraform organization usage, entitlements, billing, and capacity

Operate HCP Terraform at the organization layer with plan and billing review, subscriptions, entitlements, managed resource counting, usage review, cost estimation, concurrency, API rate limits, HCP Europe differences, incident repair, and final evidence.

13 advanced lessons

Full access

Choose access for Infrastructure Automation with Terraform

Every available offer is shown with its exact CAD price and billing model. Checkout opens only after you choose an offer and enter the receipt email.

Available access options

The selected offer and exact total remain visible before payment.

Already purchased? Restore access

Payments are processed by Lemon Squeezy for Phoenix Soft Inc. Paid access can be restored after secure sign-in.

Questions

Know what to expect before you start.

What can I try for free?

Free Terraform first contact is free and contains 11 lessons. No credit card is requested before the free workspace opens.

What experience do I need?

No Terraform experience is required. Basic command-line familiarity is helpful.

What does the focused path include?

89 required lessons, with 11 free and 78 included in paid access.

Is there material beyond the focused path?

Yes. The course also includes 314 advanced practice and reference resources. They are available when you need more depth, but they do not lengthen the required path.

Which paid options are available?

Academy Founder Annual: CA$139 per year. Founder Vault: CA$279 one-time.

How is paid access billed?

Academy Founder Annual: Access continues while the annual subscription remains active. Founder Vault: No recurring charge. Coverage includes courses launched during the first 24 months.

How long does it take?

The published estimate is 18 to 24 active hours. Your pace will depend on how much you repeat the practice.

Do I need to install anything?

No installation is required to start the guided free chapter. Later lessons explain the real tools, files, and operating boundaries relevant to the skill.

What technology is covered?

The syllabus and these stated outcomes are the source of truth: Author and validate a typed Terraform root module; Select providers and review version and lock-file evidence; Read create, update, replace, destroy, unknown, and saved-plan behavior; Use dependency and lifecycle controls without hiding full-workspace risk; Inspect state, diagnose drift, handle locks, and protect sensitive artifacts; Build reusable modules and stable count or for_each identities; Import and refactor managed objects without accidental replacement; Run CI checks, recover common failures, and hand off an independently reviewed change.

Which browsers are supported?

Use a current browser with JavaScript enabled. The free chapter is the quickest compatibility check for your device.

Does the workspace work on mobile?

The reading pages reflow for small screens. Command-heavy practice is more comfortable with a physical keyboard and a larger display.

What happens when I make a mistake?

The practice state is isolated from production systems. Read the resulting evidence, revise the action, and try again.

How do I restore access?

Use the receipt email on the restore-access page. The sign-in link verifies the account before paid entitlements are loaded.