Terraform vs Ansible: Provisioning vs Configuration Management

Overview Terraform and Ansible are both infrastructure-as-code tools but solve different problems: Terraform declaratively provisions and tracks cloud infrastructure using a state file, while Ansible procedurally configures and manages software on existing hosts with no persistent state. Many teams use them together — Terraform to stand up infrastructure, Ansible to configure it. Comparison Diagram Terraformdeclarativemain.tf (desired state)state file (source of truth)dependency graphVMNetworkDBconverges infra to match stateAnsibleproceduralplaybook.ymltask 1: install pkgtask 2: configuretask 3: start serviceServer AServer BServer Csequential push over SSH, no state file Comparison Table Aspect Terraform Ansible Primary purpose Provision and tear down cloud/infra resources (VMs, networks, DBs) Configure software and manage state on existing hosts Configuration language HCL (HashiCorp Configuration Language), declarative YAML playbooks, procedural task lists Execution model Builds a dependency graph and applies changes in parallel where possible Executes tasks sequentially, in order, per host State management Maintains a state file mapping config to real resources Stateless — queries live system facts on each run Idempotency approach Diffs desired config against state file before acting Each module checks current condition before making a change Connectivity/agent requirement Agentless — calls cloud/provider APIs directly Agentless — connects over SSH or WinRM to target hosts Failure & recovery handling Partial applies are resolved by re-running against the state file Reruns the playbook from the start; tasks are re-checked, not resumed Key Differences Terraform tracks infrastructure in a persistent state file; Ansible has no state store and reads live system facts each run. Terraform resolves a dependency graph to apply changes in parallel; Ansible runs tasks sequentially. Terraform talks to infrastructure through provider APIs; Ansible connects to hosts via SSH/WinRM. Terraform is built for provisioning infra; Ansible is built for configuration of what already exists. They’re commonly paired: Terraform creates the servers, then Ansible configures them. When to Use Each Terraform ...

August 2, 2026 · 3 min · 455 words · jeonck

Declarative vs Imperative IaC: Describing the End State vs Scripting the Steps

Overview Declarative IaC (e.g. Terraform, CloudFormation) has you specify the desired end state of infrastructure and lets an engine figure out how to get there. Imperative IaC (e.g. shell scripts, Chef recipes, raw CLI calls) has you write the exact sequence of commands to execute. The distinction matters because it determines who — you or the tool — is responsible for ordering, idempotency, and reconciling drift. Comparison Diagram DeclarativeDesired State"3 servers, 1 LB"Engine Computes Diffplan + dependency graphInfrastructureconverges to match stateEngine decides how & in what orderImperativeStep 1: Create VPCStep 2: Launch ServersStep 3: Attach LBInfrastructureAuthor decides exact steps & order Comparison Table Aspect Declarative Imperative Authoring model Write a desired-state spec Write an ordered command list Execution engine Resolves a dependency graph Runs a sequential interpreter State tracking Maintains a state file Stateless execution Applying changes Single apply command Run the script/playbook Ordering & dependencies Auto-resolved by engine Manually sequenced by author Idempotency Guaranteed by design Developer-enforced Drift detection Built-in plan diff Not built-in Failure handling Partial apply, replan Manual rollback Key Differences Declarative code answers ‘what’, imperative code answers ‘how’. Declarative tools rely on a state file to know current vs. desired infrastructure; imperative scripts have no memory of prior runs. Idempotent re-runs are automatic in declarative tools but must be hand-coded (checks, conditionals) in imperative scripts. Declarative engines build a dependency graph to order operations; imperative code hardcodes that order line by line. Drift correction in declarative IaC is a matter of re-running plan/apply; imperative approaches require re-running or rewriting the exact script. When to Use Each Declarative ...

August 2, 2026 · 2 min · 420 words · jeonck