Draw the boundary clearly
Use Terraform to declare infrastructure that exists — networks, subnets, compute, load balancers, managed databases, identity roles — and let its state track the desired shape of the estate. Use Ansible for configuration inside those resources and for procedural operations that have an order: package installation, service configuration, rolling restarts, patch orchestration.
Provisioners that shell out from within a declarative plan are a warning sign. If you find yourself scripting imperative steps inside infrastructure code, hand that work to the configuration tool instead.
Treat state as production data
Remote state with locking, encryption at rest, versioning, and restricted access is not optional once more than one engineer runs plans. Split state by environment and by blast radius so a mistake in a sandbox cannot corrupt the production estate.
Establish a drift routine. Scheduled plan runs that report differences without applying them catch console changes early, when reconciliation is cheap.
Design modules and roles for reuse
Modules and roles should be versioned, documented, and narrow. A module that provisions a landing zone, a database, and a monitoring stack cannot be adopted piecemeal and will be copied instead of reused.
Keep environment differences in variable files rather than in forked code. Idempotency is the acceptance criterion for both tools: a second run should change nothing.
Secrets, review, and the pipeline
Secrets belong in a managed vault with short-lived credentials issued to the pipeline, never in repositories, variable defaults, or inventory files. Encrypt any sensitive value that must live in the repository and scan commits for leaks.
Run everything through the same path: pull request, static analysis, policy checks, a plan posted for human review, then an applied change from a controlled runner. Grant engineers read access to production and write access only through the pipeline, and the audit trail becomes a by-product of normal work rather than a separate chore.
Key takeaways
- Declarative provisioning for resources; configuration management for what runs inside them.
- Remote, locked, encrypted, environment-split state with scheduled drift detection.
- Version narrow modules and roles; keep differences in variables, not forks.
- Short-lived vault credentials and pipeline-only write access to production.
Working through this in your own estate?
TalentOp Systems designs, provisions, and operates hybrid infrastructure for regulated, multi-site enterprises.
Start an infrastructure assessment