Terraform Data Engineering Infrastructure
Skill by ara.so — Data Skills collection.
This project provides Infrastructure-as-Code (IaC) patterns for data engineering teams using Terraform to provision and manage AWS resources. It demonstrates how to automate the creation of data infrastructure including S3 buckets for data lakes, EC2 instances for processing, and IAM policies for secure access.
What This Project Does
- Provisions AWS infrastructure specifically designed for data engineering workloads
- Manages S3 buckets for data storage and data lake architectures
- Creates EC2 instances for data processing and ETL jobs
- Configures IAM roles and policies for secure resource access
- Provides declarative infrastructure definitions that can be version-controlled
- Enables reproducible environment creation across dev/staging/prod
Prerequisites
Before using this project, ensure you have:
- An AWS account with root or administrative access
- Terraform installed (v1.0+)
- AWS CLI installed and configured
- IAM user with appropriate permissions (S3, EC2, IAM full access)
Installing Prerequisites
Setting Up IAM Permissions
Create an IAM user with the following permissions for Terraform:
- Full S3 access (AmazonS3FullAccess)
- Full EC2 access (AmazonEC2FullAccess)
- Full IAM access (IAMFullAccess)
Note: This is for development/learning. In production, use least-privilege policies.
Project Structure
Key Terraform Commands
Initialize Terraform
Plan and Apply Infrastructure
Inspect Infrastructure
Destroy Infrastructure
Configuration Patterns
Basic S3 Bucket for Data Lake
EC2 Instance for Data Processing
IAM Role for EC2 to Access S3
Multi-Environment Setup with Variables
Apply with variables:
Output Values for Integration
Common Workflows
Initial Setup
Verify Resources Created
Update Infrastructure
Clean Up
Advanced Patterns
Data Lake Structure with Multiple Buckets
Remote State Management
Troubleshooting
Bucket Name Already Exists
Error: BucketAlreadyExists: The requested bucket name is not available
Solution: S3 bucket names must be globally unique. Change the bucket name in main.tf:
Insufficient IAM Permissions
Error: UnauthorizedOperation or AccessDenied
Solution: Verify IAM user has required permissions:
State Lock Issues
Error: Error acquiring the state lock
Solution:
Resource Already Exists
Error: Resource already exists but not in state
Solution: Import existing resource:
Terraform State Drift
Error: Resources differ from state
Solution:
Region-Specific AMI Issues
Error: Invalid AMI ID for region
Solution: Use data source to find correct AMI:
Best Practices
- Use Remote State: Store Terraform state in S3 with versioning enabled
- Separate Environments: Use workspaces or separate state files for dev/staging/prod
- Least Privilege IAM: Use specific IAM policies instead of full access in production
- Tag Everything: Add consistent tags for cost tracking and resource management
- Version Control: Commit
.tffiles but excludeterraform.tfstateand.terraform/ - Plan Before Apply: Always run
terraform planbeforeapply - Use Variables: Parameterize configurations for reusability
- Enable Encryption: Use S3 bucket encryption and EBS encryption for EC2
- Implement Lifecycle Policies: Archive or delete old data automatically
- Document Dependencies: Use comments to explain resource relationships


