Project challenges / verified progress
Engineering project paths

The engineering notebook

Beacon: build the ground it stands on

Starting with no Terraform or cloud background, you finish able to read plans, protect state, compose modules, design a small network, provision cheap compute, handle identity without long-lived keys, bootstrap hosts with Ansible and destroy every billable resource deliberately.

Your learning trail

0 / 9 complete

Verified project-agent submissions only. Reading or clicking cannot unlock progress.

System design

What you are building

The course starts with desired state and a local Terraform graph, then protects the state that records ownership. It adds reusable module boundaries, an AWS network, a cheap compute target or managed-cluster option, short-lived identity for automation, Ansible bootstrap for host configuration and a teardown path that returns the account to zero Beacon resources.

BEACON / THE GROUNDYour HCLwhat should existTHE WORKFLOW YOU OWNResource graphdependencies, inferredPlanread every replace twiceApplythe only step that costsStateremote, locked, secretOUTSIDE YOUR REPOSITORYCloud providernetwork, cluster, identityDestroyback to zero, on purposeplan refreshes state first, which is how drift is foundAN ENVIRONMENT YOU CAN DELETE IS AN ENVIRONMENT YOU UNDERSTAND

Stages

9 stages, in order

Expand any stage to read what it teaches. A stage opens for work once the stage before it passes a verified submission.

Phase 1Stages 1–30 of 3 stages verified

Phase 1 — Terraform without a bill

Understand IaC, plans and state using local providers before any cloud account is needed.

  • Describe the ground first65 minutes (locked)

    Why should infrastructure be described in files before it is created?

    You will be able to create deploy/infra/ as the home for Terraform in Beacon.

    Fork the project repository to start working through the stages.

  • Plan before apply90 minutes (locked)

    How does Terraform turn HCL files into a safe proposed change?

    You will be able to create a Terraform root under deploy/infra that requires Terraform 1.7 or newer.

    Fork the project repository to start working through the stages.

  • Protect the ledger95 minutes (locked)

    What does Terraform state know, and why does that make it dangerous?

    You will be able to move local learning state to deploy/infra/state/terraform.tfstate with a backend block.

    Fork the project repository to start working through the stages.

Phase 2Stages 4–50 of 2 stages verified

Phase 2 — Shape reusable infrastructure

Use modules and variables to define a reviewable network boundary before compute exists.

  • Compose without hiding90 minutes (locked)

    How do modules make Terraform reusable without becoming a pile of knobs?

    You will be able to create deploy/infra/modules/beacon-labels as a child module.

    Fork the project repository to start working through the stages.

  • Lay the network bedrock2 hours (locked)

    What network must exist before Beacon can run anywhere safely?

    You will be able to add AWS provider configuration that reads the region from a variable.

    Fork the project repository to start working through the stages.

Phase 3Stages 6–70 of 2 stages verified

Phase 3 — Run and authenticate safely

Provision a compute target, wire cluster access concepts and replace long-lived credentials with scoped identity.

  • Give Beacon a place2 hours (locked)

    How does Terraform create compute and then talk to the cluster it created?

    You will be able to choose the cheap VM path by default, with comments showing where a managed cluster would replace it.

    Fork the project repository to start working through the stages.

  • Stop carrying keys90 minutes (locked)

    How can automation and workloads authenticate without committed long-lived secrets?

    You will be able to create Terraform files for a GitHub Actions OIDC provider and role skeleton.

    Fork the project repository to start working through the stages.

Phase 4Stages 8–90 of 2 stages verified

Phase 4 — Configure and leave no bill

Use Ansible for host bootstrap and finish by destroying and auditing every billable Beacon resource.

  • Configure after provisioning85 minutes (locked)

    What belongs in Ansible instead of Terraform?

    You will be able to create deploy/ansible/ beside deploy/infra/.

    Fork the project repository to start working through the stages.

  • Turn it all off75 minutes (locked)

    How do you end the course with the cloud account back at zero?

    You will be able to add a teardown checklist under deploy/infra/teardown.md.

    Fork the project repository to start working through the stages.

About this path

Kubernetes manifests describe what should run after a cluster exists. They do not create the network, compute, identity or teardown discipline underneath it. This course teaches the provisioning layer so Beacon has somewhere real, reviewable and affordable to stand.

What you will learn: Terraform plan, apply and state, Remote state and locking, Reusable Terraform modules, Workload identity without static keys, Ansible idempotent bootstrap. Build the project through cumulative challenges with beginner explanations and local verification.

Level
Complete beginner to independently building and operating the project
Format
9 cumulative stages. Every stage teaches the concept in full before any code, then gives you the thing to build and the run that proves it works
Before you start
Terraform 1.7 or newer, Git, a terminal and a cloud account. This course uses AWS because the Free Tier makes the cheap VM path realistic: a `t3.micro` EC2 instance is free for eligible new accounts up to the monthly limit, and otherwise is roughly one cent per hour before storage and data. The optional managed EKS path is not free: the control plane is about `$0.10` per hour, and a NAT Gateway is about `$0.045` per hour plus data. If you forget to destroy the default VM path for one hour, expect roughly `$0.01` to `$0.03`; if you add EKS and NAT, expect about `$0.15` to `$0.20` per hour. `terraform destroy` is mandatory, and stage 9 exists for exactly that reason. Stages 1-4 can be completed with zero cloud account and zero cost using the `local`, `random`, `tls` and `docker`-adjacent local workflow; no credential is needed there.
Official documentation (opens in a new tab)