Catalog / IAC-600
IAC-600Infrastructure as Code
Terraform and Bicep at organizational scale: module design, state strategy, policy-as-code, and multi-team governance.
About this program
Writing Terraform is easy; running infrastructure-as-code across an organization is not. This program addresses the hard parts: module and composition design, state and environment strategy, plan-review pipelines with policy-as-code, drift management, and the governance patterns - registries, versioning, ownership - that let many teams share one IaC practice without chaos. Terraform, OpenTofu, and Bicep are covered with clear selection guidance.
Who this is for
- Engineers who own shared Terraform or Bicep estates
- Platform teams building IaC standards and module libraries
- Leads untangling state sprawl and copy-paste infrastructure
What you will be able to do
- Design module libraries with clean interfaces and versioning discipline
- Implement state and environment strategy that isolates blast radius
- Build plan-review pipelines with policy-as-code and drift detection
- Establish governance for multi-team IaC: registries, ownership, and standards
Program modules
Delivered over 5 weeks of live tutor-led sessions, applied work, and structured review.
IaC strategy and tool landscape
- Terraform, OpenTofu, and Bicep: licensing, ecosystems, selection
- Declarative discipline: what belongs in code and what does not
- Repository topology: monorepo, polyrepo, and hybrid patterns
- Adopting IaC over an existing hand-built estate
Module design and composition
- Module interfaces: inputs, outputs, and sensible defaults
- Composition patterns: layers, stacks, and dependency flow
- Testing modules: validation, plan tests, and example roots
- Anti-patterns: god modules and leaky abstractions
State, environments, and workspaces
- State isolation strategy and blast-radius thinking
- Backends, locking, and state security
- Environment promotion: same code, different data
- Refactoring state safely: moves, imports, and splits
Pipelines and policy-as-code
- Plan-review workflows: humans approve diffs, not hope
- Policy-as-code checks: cost, tagging, security rules
- Drift detection and reconciliation cadence
- Identity for pipelines: OIDC and short-lived credentials
Scaling IaC across teams
- Private registries and module distribution
- Versioning, upgrade waves, and deprecation policy
- Ownership models: platform-owned versus team-owned code
- Capstone: IaC operating-model design with structured review
Hands-on components
- Guided lab building a versioned module library against Azure
- Plan-review pipeline with policy checks and drift exercises
- IaC operating-model capstone with instructor critique
Ready to apply?
Apply any time. Admissions reviews your fit, confirms the next available cohort, and issues an invoice. Your seat is confirmed on payment.