infrastructure provisioning with iac

Designs, implements, and maintains infrastructure described as code using Terraform — writing configurations, reusable modules, provider plugins, and automation scripts to provision and manage infrastructure resources. Integrates Terraform with complementary tools (Ansible, Helm, CDK), and handles state management, module design/versioning, variables/outputs, lifecycle controls, testing, and automation for repeatable, auditable provisioning.

infrastructureprovisioningwithiac

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
1.2
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$191K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

A Framework for Measuring the Quality of Infrastructure-as-Code Scripts

Feb 05, 2025
PR
Pandu Ranga Reddy Konala
🏛️ University of Waikato

The rapid proliferation of Infrastructure-as-Code (IaC) scripts—particularly Ansible playbooks—lacks systematic, scalable quality assessment methodologies. Method: This paper proposes the first extensible, multi-dimensional, and quantifiable IaC code quality assessment framework. Leveraging over one thousand real-world repositories from Ansible Galaxy, it integrates static analysis, metadata mining, and empirical study to construct a weighted evaluation model across dimensions including error handling, automation level, and documentation completeness. Temporal analysis further uncovers evolutionary trends—e.g., progressive metadata improvement alongside declining automation capability. Contribution/Results: The framework establishes a theoretical foundation for IaC quality standardization and enables practitioners to precisely identify quality bottlenecks, thereby facilitating engineering-driven quality governance in IaC development and maintenance.

Analyzing trends in Ansible Galaxy repositoriesDeveloping Ansible code quality frameworkMeasuring Infrastructure-as-Code script quality

Smells-sus: Sustainability Smells in IaC

Jan 13, 2025
SA
Seif Ashraf
🏛️ Polytechnique Montréal

Infrastructure-as-Code (IaC) practices—particularly Terraform configurations—frequently induce resource waste and environmental unsustainability due to poor design choices. Method: This study systematically identifies and defines seven “sustainability code smells” in IaC through expert interviews, qualitative code analysis, and a large-scale empirical study of 28,327 open-source Terraform scripts. Contribution/Results: We reveal that smell causes are inherently multi-factorial and interdependent; all seven smells occur pervasively, with “Monolithic Infrastructure” being the most prevalent (9.67% occurrence rate), confirming widespread sustainability challenges in IaC development. Our work establishes the first taxonomy of IaC sustainability smells and provides an empirically grounded, detectable, and actionable foundation for green cloud operations and sustainable infrastructure engineering.

Cloud ComputingResource EfficiencySustainability

Existing Infrastructure-as-Code (IaC) repair approaches often rely on manual intervention or are prone to hallucination, compromising repair validity. This work proposes TerraRepair, the first large language model agent for IaC repair that incorporates a tool-anchoring mechanism. TerraRepair retrieves Terraform dependency context, queries provider schemas, and re-invokes Checkov and Trivy post-repair to ensure correctness. Crucially, when essential contextual information is missing, it proactively escalates the issue rather than generating speculative fixes. Experimental results on an AWS benchmark demonstrate that TerraRepair significantly improves verified repair rates—increasing them from 26.6% to 78.4% for Checkov and from 44.8% to 72.4% for Trivy—with the majority of repairs validated as correct through human evaluation.

automated repaircloud misconfigurationsInfrastructure-as-Code

This study addresses the security risks arising from cloud misconfigurations by presenting the first systematic evaluation of large language models (LLMs) and small language models (SLMs) in generating secure and compliant Infrastructure-as-Code (IaC). Using 17 AWS Terraform scenarios, seven prominent models—including Claude Opus 4 and Qwen2.5-Coder-14B—were benchmarked under a pass@5 protocol within a GitLab CI/CD pipeline, employing Checkov and Trivy for security scanning across three compliance tiers and two prompting strategies. The findings reveal that syntactic correctness and security compliance are largely orthogonal: WizardCoder-33B achieved a 77.8% syntactic validity rate yet zero security compliance. Even with detailed security-oriented prompts, only Claude Opus 4 attained modest pass rates of 23.1% (Checkov) and 92.5% (Trivy), demonstrating that prompt engineering alone is insufficient for ensuring IaC security and underscoring the necessity of automated, multi-tool scanning.

Cloud MisconfigurationInfrastructure-as-CodeLLM

From"Worse is Better"to Better: Lessons from a Mixed Methods Study of Ansible's Challenges

Apr 11, 2025
CC
Caroline Carreira
🏛️ Carnegie Mellon University | INESC-ID | IST | University of Lisbon | INESC TEC | University of Porto

This study identifies four core challenges in Ansible’s Infrastructure-as-Code (IaC) practice: performance bottlenecks, flawed abstraction design, weak debugging and error diagnosis capabilities, and insufficient documentation and learning resources. Employing a mixed-methods empirical approach—quantitative text mining of 59,157 community forum posts and qualitative analysis of 16 in-depth practitioner interviews—it provides the first evidence-based characterization of the real-world engineering costs incurred by the “Worse is Better” philosophy in IaC tooling. The work proposes a four-dimensional improvement framework targeting maintainability, understandability, debuggability, and evolvability, yielding four actionable design recommendations—several of which have been adopted by the Ansible Core Team. These findings establish a critical empirical benchmark for advancing IaC tool design, DevOps education, and open-source community support.

Identifying pain points from 59,157 forum posts and interviewsInvestigating challenges in Ansible for Infrastructure as CodeProposing improvements for performance, debugging, and documentation

Latest Papers

What's happening recently
View more

This work addresses the prevalence of “deceptive fixes” in large language model (LLM)-assisted repair of Terraform security configurations—patches that appear successful under static analysis yet fail to eliminate vulnerabilities or inadvertently compromise infrastructure semantics. To tackle this, the authors propose TerraProbe, the first five-tier oracle framework for evaluating Terraform repairs, integrating static scanning, plan validation, behavioral consistency, security intent alignment, and human adjudication. They also introduce a four-dimensional taxonomy to characterize deceptive fixes. Evaluating 288 samples, they find that while 83.3% pass the target checker, only 10.4% satisfy comprehensive scanning, 39.6% yield valid execution plans, and 71.4% are classified as deceptive. Notably, three leading LLMs show no significant performance differences, underscoring the pervasiveness of the issue. The study provides a reproducible evaluation methodology and an open-source toolkit.

deceptive fixesInfrastructure-as-CodeLLM-assisted repair

This study addresses the lack of systematic architectural analysis in current software-intensive Asset Administration Shells (AAS), which hinders their ability to meet the pressing demands of software modeling in digital manufacturing and AI-driven environments. To bridge this gap, the work proposes the first software integration taxonomy framework specifically tailored for AAS, integrating software quality attributes with representative manufacturing use cases. By employing architectural analysis, quality attribute evaluation, and scenario mapping, the framework provides systematic guidance on how software services should be integrated within AAS. This contribution fills a critical void between academic research and industrial practice, offering actionable architectural choices and interpretive guidelines for the standardized integration of software services in digital twins.

Asset Administration Shelldigital twinmanufacturing

Current DevOps infrastructures for blockchain applications are predominantly controlled by single entities, lacking decentralized deployment and governance mechanisms. This work proposes a decentralized deployment architecture decoupled from specific governance and upgrade schemes, integrating DAO-based governance, smart contract upgradability, and DevOps best practices. By adopting an extended registry pattern, the architecture enables deterministic deployments and, for the first time, incorporates version control, testing and validation, and user interface components into a unified decentralized framework. The project provides an open-source reference implementation that substantially lowers the barrier to practical decentralized deployment. Experimental evaluation demonstrates the effectiveness and practicality of the proposed architecture.

Blockchain ApplicationsDAODecentralised Deployment

This study addresses the limited understanding of how Agent Control Files (ACFs)—instruction documents guiding autonomous coding agents—evolve, are maintained, and relate to code quality. Through large-scale repository mining, the authors reconstruct the commit-level evolutionary history of ACFs and propose, for the first time, a taxonomy of ACF changes grounded in software maintenance theory. By integrating qualitative content analysis, statistical testing, and code quality metrics, they empirically demonstrate how different types of maintenance activities differentially impact code quality and reveal dynamic patterns in these effects across the software development lifecycle. The findings provide both theoretical grounding and practical guidance for the governance of autonomous coding agents.

Agent Context Filesautonomous coding agentscode quality

Hot Scholars

JH

Jin-Hee Cho

Computer Science Department, Virginia Tech
AI-based cybersecuritydecision making under uncertaintynetwork science
HG

Hui Guan

UMass Amherst
Machine Learning Systems
AD

Anoop Deoras

Director at AWS AI
Machine LearningRecommender SystemSpeech RecognitionLanguage Modeling
DD

Davide Di Ruscio

Professor, University of L'Aquila (Italy)
Software EngineeringModel-Driven EngineeringSoftware ModelingDomain-Specific Languages