Infrastructure as Code Interview Questions and Answers (Tool-Agnostic and Terraform)

Explore the top 50+ Infrastructure as Code (IaC) interview questions and answers to ace your next tech interview. Learn about Terraform, Ansible, CloudFormation, CI/CD, and more. Ideal for professionals in DevOps, cloud engineering, and IT infrastructure roles.

Aug 13, 2024 - 14:08
Updated: 10 days ago
105.1k
Infrastructure as Code Interview Questions and Answers (Tool-Agnostic and Terraform)

Quick answer: Infrastructure as code (IaC) means defining servers, networks and services in version-controlled files so environments can be created, changed and rebuilt repeatably. Interviews test declarative versus imperative approaches, state and drift, idempotence, modules, secrets handling, testing and CI/CD, plus tool specifics for Terraform and Ansible.

Key takeaways

  • IaC replaces manual console clicks with reviewed, repeatable code.
  • Know state and drift: what the tool believes exists versus what actually exists.
  • Idempotence means running it twice gives the same result.
  • Secrets, remote state locking and testing are where strong candidates stand out.

How to answer

Define the idea, say why it matters, give a short example and mention a risk. Confirm tool details in the official docs: Ansible documentation and Terraform documentation.

Concepts

1. What is infrastructure as code?

Describing infrastructure in files that live in version control, so changes are reviewed, tested and repeatable instead of done by hand.

2. What are the benefits?

Repeatability, speed, fewer manual errors, an audit trail through Git history, easy rebuilds for disaster recovery and consistent dev, test and production environments.

3. Declarative versus imperative?

Declarative code states the desired end result and the tool works out the steps (Terraform, CloudFormation). Imperative code lists the steps to run in order (shell scripts). Ansible playbooks are mostly declarative in style but execute tasks in order.

4. Mutable versus immutable infrastructure?

Mutable servers are changed in place over time. Immutable infrastructure replaces servers with new ones built from a new image, which reduces drift.

5. What is idempotence?

Applying the same configuration repeatedly produces the same result with no extra change. It makes runs safe to repeat.

6. What is configuration drift and how do you handle it?

Drift is when real infrastructure differs from what the code says, usually from manual changes. Detect it with a plan or check run, restrict manual access, and reapply or update the code.

7. Provisioning versus configuration management?

Provisioning creates resources such as networks and VMs (Terraform). Configuration management sets up software inside them (Ansible, Puppet). Teams often use both.

Terraform

8. What is the Terraform workflow?

terraform init # download providers, set up backend
terraform plan # show what would change
terraform apply # make the change

Always review the plan. See also the Terraform interview questions.

9. What is state and why is it sensitive?

State maps your code to real resources. It can contain secret values in plain text, so store it in a remote backend with encryption, locking and strict access.

10. Why use remote state with locking?

So teams share one source of truth, and two people cannot apply at once and corrupt it.

11. What are modules?

Reusable groups of resources with inputs and outputs. They reduce duplication and enforce standards. Version them.

12. What does terraform import do?

It brings an existing resource under Terraform management by adding it to state. You still need matching configuration.

13. How do you handle environments?

Separate state per environment, using separate directories or workspaces, with variable files and clear naming. Avoid sharing one state across environments.

14. What is a provider?

A plugin that lets Terraform talk to an API such as AWS, Azure or Kubernetes.

Ansible

15. How is Ansible different from Terraform?

Ansible is agentless and uses SSH or APIs to configure systems and run tasks. Terraform tracks resources in state and focuses on provisioning. They overlap, but each is stronger in its own area. See Linux automation with Ansible for training.

16. What is a playbook, inventory and role?

A playbook lists tasks to run. An inventory lists the hosts. A role packages tasks, variables and files for reuse.

17. How do you make Ansible tasks idempotent?

Prefer modules (package, service, copy) over raw shell commands, and use creates or changed_when where you must run a command.

- name: Ensure nginx is installed
 ansible.builtin.package:
 name: nginx
 state: present

18. How do you protect secrets in Ansible?

Use Ansible Vault or an external secrets manager, and keep vault passwords out of Git.

Quality and security

19. How do you manage secrets in IaC?

Never commit them. Use a secrets manager or encrypted variables, inject at runtime, restrict state access and rotate credentials. Scan repositories for leaked secrets.

20. How do you test infrastructure code?

Validate and lint (terraform validate, ansible-lint), run plans in CI, test in a disposable environment, and use policy checks. Some teams add integration tests with tools such as Terratest.

21. What is policy as code?

Rules, such as "no public storage buckets", written as code and checked automatically before changes are applied.

22. How do you review an IaC pull request?

Read the plan output, check for destructive changes, scope of IAM permissions, public exposure and cost impact.

23. What is least privilege for pipelines?

The CI role gets only the permissions needed for the resources it manages, and production applies need approval.

Delivery and operations

24. How does IaC fit into CI/CD?

A pull request triggers validation and a plan. After approval, a pipeline applies it. See cloud automation interview questions.

25. What is GitOps?

Git holds the desired state and an agent reconciles the environment to match it, giving audit and simple rollback.

26. How do you roll back a bad change?

Revert the commit and reapply, or restore from a known good state or image. Data resources need backups, because reapplying code does not restore data.

27. What happens if someone changes a resource manually?

The next plan shows the difference. Decide whether to revert the manual change or update the code to match it, then close the gap.

28. How do you avoid destroying important resources?

Use lifecycle protections such as prevent_destroy, review every plan and restrict who can approve production applies.

29. CloudFormation, Pulumi or Terraform?

CloudFormation is AWS-native, Terraform is multi-cloud with its own language, and Pulumi uses general-purpose languages. Choose by team skills, cloud footprint and licensing; check current licence terms of each tool.

30. Tell me about an IaC problem you solved.

Prepare one real story: the problem, what you changed in code, how you tested it and what you would do differently.

Next steps

Practise by building a small network and VM from code, then destroy and rebuild it. For training, see the HashiCorp Terraform Associate course. Also read the Terraform interview questions and answers.

Related reading

Frequently Asked Questions

Declarative IaC describes the desired end state and the tool works out the steps, as in Terraform. Imperative IaC lists the steps to run in order, as in a shell script. Many tools mix both styles.

Drift is when real infrastructure no longer matches the code, usually after manual changes. Detect it with plan or check runs, limit manual access, and either revert the change or update the code.

Terraform provisions resources and tracks them in state. Ansible is agentless and configures systems and runs tasks over SSH or APIs. Teams often use Terraform to create infrastructure and Ansible to configure it.

Never commit secrets to Git. Use a secrets manager or encrypted variables, inject values at runtime, protect and encrypt state files, restrict access with least privilege and rotate credentials.

State maps code to real resources and can contain secret values in plain text. Store it in an encrypted remote backend with locking and tight access control, and never commit it to Git.

Validate and lint the code, run plans in CI, deploy to a disposable environment, add policy checks and optionally integration tests. Review plan output for destructive changes before applying.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Anjali

I am passionate about technology, invention and big challenging tasks on my to- do list. In terms of the work I am doing also at Bunnyshell, I am most passionate about the technologies that we are using., I'm devoted to delivering content that not only informs but also inspires. Whether you need in- depth analysis pieces, educational attendants, or study- provoking opinion pieces, I draft content that resonates with tech suckers and professionals likewise.