Week 7–8: Terraform IaC, Infrastructure Automation & My First Full Serverless Pipeline
DevOps & Cloud learner, currently in the deep end with Linux, Git, and AWS. BTech CSE student breaking things on purpose (and learning how to fix them). Exploring real infrastructure, automation, and the tools that keep modern systems running.
What actually went down this week
Weeks 7 and 8 were where things finally became hands-on DevOps.
I moved away from console clicking and into Terraform-driven infrastructure, modular IaC, remote state management, and building a real event-driven serverless pipeline.
Instead of learning services in isolation, I started connecting them into real systems.
This week resulted in two major, practical projects that pushed my understanding of AWS, Terraform, IAM, automation, and debugging:
Project 1 — Terraform Infrastructure Modules (EC2, VPC, S3, DynamoDB)
Project 2 — Serverless Event Pipeline (S3 → Lambda → DynamoDB → SNS)
Both significantly deepened my cloud engineering skillset.
Why I had to tackle these now
To grow in DevOps, you can’t rely on the AWS Console forever.
You need:
reproducible infrastructure
clean modules
real IAM patterns
event-driven thinking
automation instead of manual fixes
the ability to design how services interact
Terraform + Serverless forced me to understand:
Networking
Compute
Storage
IAM
Event triggers
Logging
Cloud automation
State management
All working together — which is the whole point of DevOps.
Project 1 — Terraform Infrastructure Modules
This project was focused on learning how real IaC is structured, not just writing .tf files.
I built multi-environment AWS infrastructure using Terraform modules for dev, stg, and prd.
What I learned & built
How to structure Terraform providers, variables, and outputs
How modules make infrastructure reusable and clean
EC2 provisioning with instance type, AMI, tags, and root volume
Automated Nginx installation using user-data
Security groups for SSH + HTTP
SSH keypair creation through Terraform
S3 + DynamoDB remote backend to manage Terraform state safely
How to scale infra using
countThe beginning of VPC automation (subnets, routes, IGW)


Environments covered
dev → 1 EC2, 1 S3, 1 DynamoDB, 1 VPC, 1 SG
stg → same as dev
prd → 2 EC2 instances, 1 S3, 1 DynamoDB, 1 VPC, 1 SG
This project taught me how real teams structure Terraform in repositories.
Project 2 — Serverless Event Pipeline
Pipeline » S3 → Lambda → DynamoDB → SNS → CloudWatch
This was my first real event-driven architecture, automated fully through Terraform.
What actually happens
I upload a file to S3
S3 triggers a Lambda
Lambda extracts the metadata
Lambda writes a record into DynamoDB
Lambda sends an SNS email alert
CloudWatch logs everything
It’s a real workflow — the kind used in ingestion systems, audit logging, automation, and backend event processing.
What I learned & built
Creating S3 buckets with versioning
Packaging Lambda using Terraform’s
archive_fileWriting a Lambda handler to parse S3 events and write to DynamoDB
Designing IAM roles that allow least-privilege access
Creating DynamoDB tables for logging uploads
SNS topic + email notifications
Wiring S3 events to Lambda (
aws_s3_bucket_notification)Adding CloudWatch log groups with retention
Injecting environment variables into Lambda
Using
depends_onto control deployment order


Minimal Terraform snippets
Lambda packaging
data "archive_file" "lambda_zip" {
type = "zip"
source_dir = "${path.module}/lambda"
}
Lambda logic
file = record['s3']['object']['key']
table.put_item({"file_name": file})
S3 → Lambda invoke permission
resource "aws_lambda_permission" "allow_s3" {
principal = "s3.amazonaws.com"
action = "lambda:InvokeFunction"
}
This didn’t feel like practice — it felt like building a real backend automation system.
The things that broke (and how I fixed them)
Lambda crashing on init → missing environment variables
DynamoDB rejecting writes → wrong partition key name
S3 not triggering Lambda → missing lambda_permission
Terraform state conflicts → S3 backend + DynamoDB locking
IAM trust policy errors → rewritten assume-role + policy blocks
Zip not updating Lambda → changed source hash + forced redeploy
Every mistake turned into a lesson.
What I learned the hard way
Terraform modules are how real IaC repositories work
Serverless pipelines are 90% IAM & wiring — 10% code
Remote state is essential for multi-environment setups
CloudWatch Logs are your lifeline for debugging Lambda
VPC design forces you to understand AWS networking internals
Reproducibility > manual environment tweaking
Event-driven systems need strong permission boundaries
This week made the entire DevOps roadmap feel achievable.
Resources I actually used
Terraform Registry
AWS Docs (Lambda, IAM, DynamoDB, S3 Events)
HashiCorp Learn
Deep-dive DevOps YouTube explanations
Notes from debugging Terraform errors & CloudWatch logs
Up Next: Week 9 — Plan
AWS Networking Fundamentals
VPC → Subnets → Route Tables
Internet Gateway + NAT Gateway flow
Public vs private subnet designs
CIDR block planning
Docker Foundations
Dockerfile best practices
Build → Tag → Run workflow
Docker Compose for multi-service development
Follow along
GitHub: shauryad01/cloud-devops-journey
LinkedIn: Shaurya Dhingra