Skip to main content

Command Palette

Search for a command to run...

Week 7–8: Terraform IaC, Infrastructure Automation & My First Full Serverless Pipeline

Published
•4 min read•View as Markdown
S

DevOps & Cloud learner, currently in the deep end with Linux, Git, and AWS. BTech CSE student breaking things on purpose (and learning how to fix them). Exploring real infrastructure, automation, and the tools that keep modern systems running.

What actually went down this week

Weeks 7 and 8 were where things finally became hands-on DevOps.
I moved away from console clicking and into Terraform-driven infrastructure, modular IaC, remote state management, and building a real event-driven serverless pipeline.

Instead of learning services in isolation, I started connecting them into real systems.

This week resulted in two major, practical projects that pushed my understanding of AWS, Terraform, IAM, automation, and debugging:

  • Project 1 — Terraform Infrastructure Modules (EC2, VPC, S3, DynamoDB)

  • Project 2 — Serverless Event Pipeline (S3 → Lambda → DynamoDB → SNS)

Both significantly deepened my cloud engineering skillset.


Why I had to tackle these now

To grow in DevOps, you can’t rely on the AWS Console forever.
You need:

  • reproducible infrastructure

  • clean modules

  • real IAM patterns

  • event-driven thinking

  • automation instead of manual fixes

  • the ability to design how services interact

Terraform + Serverless forced me to understand:

  • Networking

  • Compute

  • Storage

  • IAM

  • Event triggers

  • Logging

  • Cloud automation

  • State management

All working together — which is the whole point of DevOps.


Project 1 — Terraform Infrastructure Modules

This project was focused on learning how real IaC is structured, not just writing .tf files.

I built multi-environment AWS infrastructure using Terraform modules for dev, stg, and prd.

What I learned & built

  • How to structure Terraform providers, variables, and outputs

  • How modules make infrastructure reusable and clean

  • EC2 provisioning with instance type, AMI, tags, and root volume

  • Automated Nginx installation using user-data

  • Security groups for SSH + HTTP

  • SSH keypair creation through Terraform

  • S3 + DynamoDB remote backend to manage Terraform state safely

  • How to scale infra using count

  • The beginning of VPC automation (subnets, routes, IGW)

Environments covered

  • dev → 1 EC2, 1 S3, 1 DynamoDB, 1 VPC, 1 SG

  • stg → same as dev

  • prd → 2 EC2 instances, 1 S3, 1 DynamoDB, 1 VPC, 1 SG

This project taught me how real teams structure Terraform in repositories.


Project 2 — Serverless Event Pipeline

Pipeline » S3 → Lambda → DynamoDB → SNS → CloudWatch

This was my first real event-driven architecture, automated fully through Terraform.

What actually happens

  • I upload a file to S3

  • S3 triggers a Lambda

  • Lambda extracts the metadata

  • Lambda writes a record into DynamoDB

  • Lambda sends an SNS email alert

  • CloudWatch logs everything

It’s a real workflow — the kind used in ingestion systems, audit logging, automation, and backend event processing.

What I learned & built

  • Creating S3 buckets with versioning

  • Packaging Lambda using Terraform’s archive_file

  • Writing a Lambda handler to parse S3 events and write to DynamoDB

  • Designing IAM roles that allow least-privilege access

  • Creating DynamoDB tables for logging uploads

  • SNS topic + email notifications

  • Wiring S3 events to Lambda (aws_s3_bucket_notification)

  • Adding CloudWatch log groups with retention

  • Injecting environment variables into Lambda

  • Using depends_on to control deployment order

Minimal Terraform snippets

Lambda packaging

data "archive_file" "lambda_zip" {
  type        = "zip"
  source_dir  = "${path.module}/lambda"
}

Lambda logic

file = record['s3']['object']['key']
table.put_item({"file_name": file})

S3 → Lambda invoke permission

resource "aws_lambda_permission" "allow_s3" {
  principal = "s3.amazonaws.com"
  action    = "lambda:InvokeFunction"
}

This didn’t feel like practice — it felt like building a real backend automation system.


The things that broke (and how I fixed them)

  • Lambda crashing on init → missing environment variables

  • DynamoDB rejecting writes → wrong partition key name

  • S3 not triggering Lambda → missing lambda_permission

  • Terraform state conflicts → S3 backend + DynamoDB locking

  • IAM trust policy errors → rewritten assume-role + policy blocks

  • Zip not updating Lambda → changed source hash + forced redeploy

Every mistake turned into a lesson.


What I learned the hard way

  • Terraform modules are how real IaC repositories work

  • Serverless pipelines are 90% IAM & wiring — 10% code

  • Remote state is essential for multi-environment setups

  • CloudWatch Logs are your lifeline for debugging Lambda

  • VPC design forces you to understand AWS networking internals

  • Reproducibility > manual environment tweaking

  • Event-driven systems need strong permission boundaries

This week made the entire DevOps roadmap feel achievable.


Resources I actually used

  • Terraform Registry

  • TrainWithShubham Terraform Tutorial

  • AWS Docs (Lambda, IAM, DynamoDB, S3 Events)

  • HashiCorp Learn

  • Deep-dive DevOps YouTube explanations

  • Notes from debugging Terraform errors & CloudWatch logs


Up Next: Week 9 — Plan

AWS Networking Fundamentals

  • VPC → Subnets → Route Tables

  • Internet Gateway + NAT Gateway flow

  • Public vs private subnet designs

  • CIDR block planning

Docker Foundations

  • Dockerfile best practices

  • Build → Tag → Run workflow

  • Docker Compose for multi-service development


Follow along

GitHub: shauryad01/cloud-devops-journey
LinkedIn: Shaurya Dhingra