All courses

Terraform security and compliance

Infrastructure code is an attack surface, and the pipeline that applies it holds the keys to your cloud. Secure the state file and the backend that stores it, get long-lived provider credentials out of CI, keep secrets out of variables and outputs, scan both the HCL and the plan, encode policy as code and gate the pipeline on it, detect drift before an auditor does, and pin the modules you inherit. Twelve lessons, each with real commands and output, ending in a secure Terraform pipeline built end to end.

Intermediate3 sections · 12 lessons · ~4.5h total · 18-question self-test

Progress is saved in this browser only — no account required.

Final exam
Test yourself on everything
18 questions drawn from all 2 sections — every answer explained as you pick.
Start final exam