Infrastructure as Code (IaC)
The methodology managing and provisioning cloud networks and compute units using configuration files.
Last reviewed: July 25, 2026
Infrastructure as Code (IaC) is the practice of defining and provisioning cloud infrastructure — servers, networks, databases, load balancers, and more — through machine-readable configuration files, rather than manually clicking through a cloud provider’s web console or running one-off command-line scripts.
Why It Matters
Manually configured infrastructure is difficult to reproduce reliably, easy to accidentally drift from its intended state through undocumented manual changes, and hard to review or audit, since there’s no record of exactly what changed and why. Infrastructure as code addresses all three problems: the configuration files themselves are the documentation of what infrastructure exists, they can be version-controlled in Git just like application code (enabling code review, change history, and rollback), and they can be applied repeatably and predictably to create identical environments — a critical property for maintaining consistent staging and production environments, or for quickly rebuilding infrastructure after a failure.
Declarative vs. Imperative IaC
Most modern IaC tools, including Terraform and AWS CloudFormation, are declarative: the configuration describes the desired end state of the infrastructure, and the tool figures out what specific API calls are needed to get there from the current state. This differs from imperative approaches (a shell script that runs a sequence of commands to build infrastructure step by step), which are more fragile since re-running the same script against already-existing infrastructure can produce different results or outright errors, whereas a declarative tool can safely be re-applied — it simply does nothing if the actual state already matches the desired state.
Where It Fits
IaC tools generally fall into two categories: general-purpose, multi-cloud tools like Terraform and Pulumi, and cloud-specific tools like AWS CloudFormation and Azure Resource Manager templates. It’s now considered a baseline best practice for any production cloud environment, and is a prerequisite for practices built on top of it, like GitOps.
Mutable vs. Immutable Infrastructure Patterns
IaC tools are often used in combination with a broader architectural choice between mutable infrastructure (existing servers are updated in place to reach a new desired state, which is Puppet and Chef’s traditional model) and immutable infrastructure (rather than updating existing infrastructure, an entirely new version is provisioned from scratch and the old version is discarded, which is more common with Terraform-managed cloud infrastructure and container-based deployments). Immutable infrastructure has gained favor because it eliminates configuration drift categorically — if infrastructure is never modified after creation, there’s no possibility of it drifting from its declared state over time — at the cost of requiring infrastructure that can be provisioned from scratch quickly enough to make frequent full replacement practical.
Historical figures and technical concepts for informational purposes only. Not technical, professional, legal, or financial advice. Sources: Official Documentation.