Declarative vs Imperative IaC: Describing the End State vs Scripting the Steps

Overview Declarative IaC (e.g. Terraform, CloudFormation) has you specify the desired end state of infrastructure and lets an engine figure out how to get there. Imperative IaC (e.g. shell scripts, Chef recipes, raw CLI calls) has you write the exact sequence of commands to execute. The distinction matters because it determines who — you or the tool — is responsible for ordering, idempotency, and reconciling drift. Comparison Diagram DeclarativeDesired State"3 servers, 1 LB"Engine Computes Diffplan + dependency graphInfrastructureconverges to match stateEngine decides how & in what orderImperativeStep 1: Create VPCStep 2: Launch ServersStep 3: Attach LBInfrastructureAuthor decides exact steps & order Comparison Table Aspect Declarative Imperative Authoring model Write a desired-state spec Write an ordered command list Execution engine Resolves a dependency graph Runs a sequential interpreter State tracking Maintains a state file Stateless execution Applying changes Single apply command Run the script/playbook Ordering & dependencies Auto-resolved by engine Manually sequenced by author Idempotency Guaranteed by design Developer-enforced Drift detection Built-in plan diff Not built-in Failure handling Partial apply, replan Manual rollback Key Differences Declarative code answers ‘what’, imperative code answers ‘how’. Declarative tools rely on a state file to know current vs. desired infrastructure; imperative scripts have no memory of prior runs. Idempotent re-runs are automatic in declarative tools but must be hand-coded (checks, conditionals) in imperative scripts. Declarative engines build a dependency graph to order operations; imperative code hardcodes that order line by line. Drift correction in declarative IaC is a matter of re-running plan/apply; imperative approaches require re-running or rewriting the exact script. When to Use Each Declarative ...

August 2, 2026 · 2 min · 420 words · jeonck