Infrastructure as Code Interview Questions and Answers (Tool-Agnostic and Terraform)
Explore the top 50+ Infrastructure as Code (IaC) interview questions and answers to ace your next tech interview. Learn about Terraform, Ansible, CloudFormation, CI/CD, and more. Ideal for professionals in DevOps, cloud engineering, and IT infrastructure roles.
Quick answer: Infrastructure as code (IaC) means defining servers, networks and services in version-controlled files so environments can be created, changed and rebuilt repeatably. Interviews test declarative versus imperative approaches, state and drift, idempotence, modules, secrets handling, testing and CI/CD, plus tool specifics for Terraform and Ansible.
Key takeaways
- IaC replaces manual console clicks with reviewed, repeatable code.
- Know state and drift: what the tool believes exists versus what actually exists.
- Idempotence means running it twice gives the same result.
- Secrets, remote state locking and testing are where strong candidates stand out.
How to answer
Define the idea, say why it matters, give a short example and mention a risk. Confirm tool details in the official docs: Ansible documentation and Terraform documentation.
Concepts
1. What is infrastructure as code?
Describing infrastructure in files that live in version control, so changes are reviewed, tested and repeatable instead of done by hand.
2. What are the benefits?
Repeatability, speed, fewer manual errors, an audit trail through Git history, easy rebuilds for disaster recovery and consistent dev, test and production environments.
3. Declarative versus imperative?
Declarative code states the desired end result and the tool works out the steps (Terraform, CloudFormation). Imperative code lists the steps to run in order (shell scripts). Ansible playbooks are mostly declarative in style but execute tasks in order.
4. Mutable versus immutable infrastructure?
Mutable servers are changed in place over time. Immutable infrastructure replaces servers with new ones built from a new image, which reduces drift.
5. What is idempotence?
Applying the same configuration repeatedly produces the same result with no extra change. It makes runs safe to repeat.
6. What is configuration drift and how do you handle it?
Drift is when real infrastructure differs from what the code says, usually from manual changes. Detect it with a plan or check run, restrict manual access, and reapply or update the code.
7. Provisioning versus configuration management?
Provisioning creates resources such as networks and VMs (Terraform). Configuration management sets up software inside them (Ansible, Puppet). Teams often use both.
Terraform
8. What is the Terraform workflow?
terraform init # download providers, set up backend
terraform plan # show what would change
terraform apply # make the change
Always review the plan. See also the Terraform interview questions.
9. What is state and why is it sensitive?
State maps your code to real resources. It can contain secret values in plain text, so store it in a remote backend with encryption, locking and strict access.
10. Why use remote state with locking?
So teams share one source of truth, and two people cannot apply at once and corrupt it.
11. What are modules?
Reusable groups of resources with inputs and outputs. They reduce duplication and enforce standards. Version them.
12. What does terraform import do?
It brings an existing resource under Terraform management by adding it to state. You still need matching configuration.
13. How do you handle environments?
Separate state per environment, using separate directories or workspaces, with variable files and clear naming. Avoid sharing one state across environments.
14. What is a provider?
A plugin that lets Terraform talk to an API such as AWS, Azure or Kubernetes.
Ansible
15. How is Ansible different from Terraform?
Ansible is agentless and uses SSH or APIs to configure systems and run tasks. Terraform tracks resources in state and focuses on provisioning. They overlap, but each is stronger in its own area. See Linux automation with Ansible for training.
16. What is a playbook, inventory and role?
A playbook lists tasks to run. An inventory lists the hosts. A role packages tasks, variables and files for reuse.
17. How do you make Ansible tasks idempotent?
Prefer modules (package, service, copy) over raw shell commands, and use creates or changed_when where you must run a command.
- name: Ensure nginx is installed
ansible.builtin.package:
name: nginx
state: present
18. How do you protect secrets in Ansible?
Use Ansible Vault or an external secrets manager, and keep vault passwords out of Git.
Quality and security
19. How do you manage secrets in IaC?
Never commit them. Use a secrets manager or encrypted variables, inject at runtime, restrict state access and rotate credentials. Scan repositories for leaked secrets.
20. How do you test infrastructure code?
Validate and lint (terraform validate, ansible-lint), run plans in CI, test in a disposable environment, and use policy checks. Some teams add integration tests with tools such as Terratest.
21. What is policy as code?
Rules, such as "no public storage buckets", written as code and checked automatically before changes are applied.
22. How do you review an IaC pull request?
Read the plan output, check for destructive changes, scope of IAM permissions, public exposure and cost impact.
23. What is least privilege for pipelines?
The CI role gets only the permissions needed for the resources it manages, and production applies need approval.
Delivery and operations
24. How does IaC fit into CI/CD?
A pull request triggers validation and a plan. After approval, a pipeline applies it. See cloud automation interview questions.
25. What is GitOps?
Git holds the desired state and an agent reconciles the environment to match it, giving audit and simple rollback.
26. How do you roll back a bad change?
Revert the commit and reapply, or restore from a known good state or image. Data resources need backups, because reapplying code does not restore data.
27. What happens if someone changes a resource manually?
The next plan shows the difference. Decide whether to revert the manual change or update the code to match it, then close the gap.
28. How do you avoid destroying important resources?
Use lifecycle protections such as prevent_destroy, review every plan and restrict who can approve production applies.
29. CloudFormation, Pulumi or Terraform?
CloudFormation is AWS-native, Terraform is multi-cloud with its own language, and Pulumi uses general-purpose languages. Choose by team skills, cloud footprint and licensing; check current licence terms of each tool.
30. Tell me about an IaC problem you solved.
Prepare one real story: the problem, what you changed in code, how you tested it and what you would do differently.
Next steps
Practise by building a small network and VM from code, then destroy and rebuild it. For training, see the HashiCorp Terraform Associate course. Also read the Terraform interview questions and answers.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0