Infrastructure Automation Best Practices
Idempotent, versioned, auditable infrastructure keeps production changes predictable. These rules apply whether you use Ansible, Pulumi, Terraform/CDKTF, or boto3 ensure scripts.
Search across all documentation pages
Idempotent, versioned, auditable infrastructure keeps production changes predictable. These rules apply whether you use Ansible, Pulumi, Terraform/CDKTF, or boto3 ensure scripts.
pulumi, cdktf, ansible, and provider packages install from uv/pip locks in CI.prod stack to wrong AWS account.terraform apply tfplan - not a fresh implicit plan at apply time.0600 for files containing credentials.changed=0 reporting and convergence semantics.AWS_ACCESS_KEY_ID in GitHub/GitLab secrets.ruff and pytest on infra Python packages. Same quality bar as application code.Git repo, plan on PR, isolated state per env, mandatory tags, and secrets outside git. Add Molecule/OPA as you mature.
Pulumi Python or disciplined boto3 ensure scripts work for small footprints - still require plan-like review and state tracking.
pytest policy on plan JSON, AWS Config rules, or Service Control Policies - defense in depth beats one check.
Break-glass incidents only. Open a ticket to import or revert the change in IaC before the next scheduled apply.
Daily for prod-critical resources, weekly for lower tiers - tune based on incident history and change velocity.
Prefer CI promotion with approval gates. Direct prod applies from laptops multiply audit and mis-account risk.
Pulumi/Terraform for cloud primitives; Ansible for OS-level config on instances. Document handoff in runbooks.
Simple org rules (tags, naming) in pytest for speed. Complex graph policies (no public SG rules) in OPA on full plan JSON.
Revert git commit and re-apply, or restore state snapshot if backend supports it - practice rollback in sandbox first.
Incidents need who changed what and when. Plain print("done") does not survive centralized log search.
Stack versions: This page was written for Python 3.14.0 (stable 3.14, maintenance 3.13), FastAPI 0.115+, Django 5.2, Flask 3.1, Pydantic 2, PyTorch 2.6+, pandas 2.2+, Polars 1.x, ruff 0.9+, and uv 0.6+.
Reviewed by Chris St. John·Last updated Jul 16, 2026