The engineering notebook
Beacon: build the ground it stands on
Starting with no Terraform or cloud background, you finish able to read plans, protect state, compose modules, design a small network, provision cheap compute, handle identity without long-lived keys, bootstrap hosts with Ansible and destroy every billable resource deliberately.
Your learning trail
Verified project-agent submissions only. Reading or clicking cannot unlock progress.
System design
What you are building
The course starts with desired state and a local Terraform graph, then protects the state that records ownership. It adds reusable module boundaries, an AWS network, a cheap compute target or managed-cluster option, short-lived identity for automation, Ansible bootstrap for host configuration and a teardown path that returns the account to zero Beacon resources.
Stages
9 stages, in order
Expand any stage to read what it teaches. A stage opens for work once the stage before it passes a verified submission.
Phase 1 — Terraform without a bill
Understand IaC, plans and state using local providers before any cloud account is needed.
Describe the ground first65 minutes (locked)
Why should infrastructure be described in files before it is created?
You will be able to create deploy/infra/ as the home for Terraform in Beacon.
Fork the project repository to start working through the stages.
Plan before apply90 minutes (locked)
How does Terraform turn HCL files into a safe proposed change?
You will be able to create a Terraform root under deploy/infra that requires Terraform 1.7 or newer.
Fork the project repository to start working through the stages.
Protect the ledger95 minutes (locked)
What does Terraform state know, and why does that make it dangerous?
You will be able to move local learning state to deploy/infra/state/terraform.tfstate with a backend block.
Fork the project repository to start working through the stages.
Phase 2 — Shape reusable infrastructure
Use modules and variables to define a reviewable network boundary before compute exists.
Compose without hiding90 minutes (locked)
How do modules make Terraform reusable without becoming a pile of knobs?
You will be able to create deploy/infra/modules/beacon-labels as a child module.
Fork the project repository to start working through the stages.
Lay the network bedrock2 hours (locked)
What network must exist before Beacon can run anywhere safely?
You will be able to add AWS provider configuration that reads the region from a variable.
Fork the project repository to start working through the stages.
Phase 3 — Run and authenticate safely
Provision a compute target, wire cluster access concepts and replace long-lived credentials with scoped identity.
Give Beacon a place2 hours (locked)
How does Terraform create compute and then talk to the cluster it created?
You will be able to choose the cheap VM path by default, with comments showing where a managed cluster would replace it.
Fork the project repository to start working through the stages.
Stop carrying keys90 minutes (locked)
How can automation and workloads authenticate without committed long-lived secrets?
You will be able to create Terraform files for a GitHub Actions OIDC provider and role skeleton.
Fork the project repository to start working through the stages.
Phase 4 — Configure and leave no bill
Use Ansible for host bootstrap and finish by destroying and auditing every billable Beacon resource.
Configure after provisioning85 minutes (locked)
What belongs in Ansible instead of Terraform?
You will be able to create deploy/ansible/ beside deploy/infra/.
Fork the project repository to start working through the stages.
Turn it all off75 minutes (locked)
How do you end the course with the cloud account back at zero?
You will be able to add a teardown checklist under deploy/infra/teardown.md.
Fork the project repository to start working through the stages.
About this path
Kubernetes manifests describe what should run after a cluster exists. They do not create the network, compute, identity or teardown discipline underneath it. This course teaches the provisioning layer so Beacon has somewhere real, reviewable and affordable to stand.
What you will learn: Terraform plan, apply and state, Remote state and locking, Reusable Terraform modules, Workload identity without static keys, Ansible idempotent bootstrap. Build the project through cumulative challenges with beginner explanations and local verification.
- Level
- Complete beginner to independently building and operating the project
- Format
- 9 cumulative stages. Every stage teaches the concept in full before any code, then gives you the thing to build and the run that proves it works
- Before you start
- Terraform 1.7 or newer, Git, a terminal and a cloud account. This course uses AWS because the Free Tier makes the cheap VM path realistic: a `t3.micro` EC2 instance is free for eligible new accounts up to the monthly limit, and otherwise is roughly one cent per hour before storage and data. The optional managed EKS path is not free: the control plane is about `$0.10` per hour, and a NAT Gateway is about `$0.045` per hour plus data. If you forget to destroy the default VM path for one hour, expect roughly `$0.01` to `$0.03`; if you add EKS and NAT, expect about `$0.15` to `$0.20` per hour. `terraform destroy` is mandatory, and stage 9 exists for exactly that reason. Stages 1-4 can be completed with zero cloud account and zero cost using the `local`, `random`, `tls` and `docker`-adjacent local workflow; no credential is needed there.
