VOOZH about

URL: https://thenewstack.io/beyond-orchestration-a-comprehensive-approach-to-iac-strategy/

⇱ Beyond Orchestration: A Comprehensive Approach to IaC Strategy - The New Stack


TNS
SUBSCRIBE
Join our community of software engineering leaders and aspirational developers. Always stay in-the-know by getting the most important news and exclusive content delivered fresh to your inbox to learn more about at-scale software development.
REQUIRED
It seems that you've previously unsubscribed from our newsletter in the past. Click the button below to open the re-subscribe form in a new tab. When you're done, simply close that tab and continue with this form to complete your subscription.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.
Welcome and thank you for joining The New Stack community!
Please answer a few simple questions to help us deliver the news and resources you are interested in.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Great to meet you!
Tell us a bit about your job so we can cover the topics you find most relevant.
REQUIRED
REQUIRED
REQUIRED
REQUIRED
REQUIRED
Welcome!

We’re so glad you’re here. You can expect all the best TNS content to arrive Monday through Friday to keep you on top of the news and at the top of your game.

What’s next?

Check your inbox for a confirmation email where you can adjust your preferences and even join additional groups.

Follow TNS on your favorite social media networks.

Become a TNS follower on LinkedIn.

Check out the latest featured and trending stories while you wait for your first TNS newsletter.

PREV
1 of 2
NEXT
VOXPOP
As a JavaScript developer, what non-React tools do you use most often?
Angular
0%
Astro
0%
Svelte
0%
Vue.js
0%
Other
0%
I only use React
0%
I don't use JavaScript
0%
Thanks for your opinion! Subscribe below to get the final results, published exclusively in our TNS Update newsletter:
NEW! Try Stackie AI
From clobbered drafts to real-time sync
Apr 14th 2026 10:00am, by David Moore
TypeScript 6.0 RC arrives as a bridge to a faster future
Mar 14th 2026 9:00am, by Darryl K. Taft
Mastra empowers web devs to build AI agents in TypeScript
Jan 28th 2026 11:00am, by Loraine Lawson
2024-08-20 09:19:30
Beyond Orchestration: A Comprehensive Approach to IaC Strategy
sponsor-firefly,sponsored-post-contributed,
CI/CD / Infrastructure as Code

Beyond Orchestration: A Comprehensive Approach to IaC Strategy

To truly channel the power of IaC, organizations need to look beyond tool selection and orchestration to vital, yet oft-overlooked aspects.
Aug 20th, 2024 9:19am by Eran Bibi
👁 Featued image for: Beyond Orchestration: A Comprehensive Approach to IaC Strategy
Photo via Firefly.
Firefly sponsored this post.

In the past decade since the large-scale adoption of cloud (native) technologies, Infrastructure as Code (IaC) has been the core of enabling the unprecedented growth and manageability of very complex systems. However, much like other domains with their evolutions and intrigues, the IaC landscape has also undergone quite a bit of change.

In this year alone HashiCorp replaced its open source license for Terraform with a more restrictive one, and the community forked this most ubiquitous tool. (I spoke about this recently at a panel at KubeCon Paris called “The Evolution of IaC: On Open Source and Everything Else”).

This leaves us, as platform engineers and DevOps professionals, grappling with two primary dilemmas when crafting our IaC strategy:

  1. Which IaC tool should we use? Terraform, OpenTofu, cloud-specific solutions like AWS CloudFormation or Kubernetes controllers like Crossplane?
  2. How should we handle orchestration? Should we build our own IaC provisioning pipeline in our CI/CD tools or invest in IaC automation products like Terraform Cloud?

While these questions are undoubtedly crucial, they only scratch the surface of what a comprehensive IaC strategy should encompass. With IaC now serving as the backbone to the way we deliver software and the critical systems they run on — the CrowdStrike outage is just one example of how this can go very wrong — our IaC strategy will have a direct impact on our business operations. To truly channel the power of IaC, organizations need to look beyond just tool selection and orchestration. These are honestly just implementation details. Let’s explore the often-overlooked aspects that can make or break your IaC operations and systems engineering.

The Missing Pieces in Your IaC Strategy

1. IaC Coverage: The Critical KPI You’re Not Measuring

IaC coverage represents the percentage of your cloud resources managed through IaC. This crucial metric provides insight into the health and maturity of your cloud infrastructure management.

Why is IaC coverage so important?

  • It indicates how much of your infrastructure is consistently managed and version-controlled.
  • It helps identify areas of potential risk (unmanaged resources are not DR-Compliant).
  • It serves as a benchmark for continuous improvement in your cloud governance.

Despite its significance, most cloud providers don’t offer visibility into this metric. Without understanding your IaC coverage, you’re essentially flying blind in your cloud management efforts.

👁 Image

We’ve learned over many years of writing infrastructure code that all of these combined lead to greater system health and stability over time through better guardrails, governance and maintainability. When systems aren’t codified — and much of this leads to the next point — which at times is a byproduct of older and legacy systems, it is much harder to visualize, manage and maintain systems, and even recover from failure.

2. Dealing with Existing Resources: The Legacy Challenge

Lambda is celebrating its 10th anniversary this year, so let’s not talk about Amazon Elastic Compute Cloud (EC2) which will be celebrating two decades in 2026. For young engineers now entering the trade, the cloud has been around forever — there was no time before the cloud. However, for more seasoned engineers, we know what came before (and it ain’t pretty).

We’ve found that when adopting IaC, organizations often focus on new deployments while neglecting existing infrastructure — some pre-cloud or early cloud days when everything was managed through the console. This oversight can lead to a hybrid state where some resources are managed via IaC while others remain as “ClickOps” console creations (unmanaged by IaC, and not deriving the benefits of IaC noted above).

The ClickOps challenge lies in:

  • Identifying which resources are not currently managed by IaC
  • Determining the effort required to “codify” these existing resources
  • Prioritizing which resources to bring under IaC management first

Without a strategy for addressing existing resources, organizations risk perpetuating a divided infrastructure, undermining the benefits of IaC adoption. In addition, we’ve all learned that sometimes our most legacy systems are our business “cash cows” and mission-critical systems. It’s not just a matter of letting them remain uncodified and unmanaged. These are usually the primary systems that will hurt the most when they go down and cause the most pain when not rapidly recovered.

3. Multi-IaC Reality: One Tool Doesn’t Fit All

In large organizations, enforcing a single IaC tool across all departments is often impractical. Today, there are a diversity of tools that cater to different stacks, strengths and collaboration with developers — from those that are native to a specific platform (CloudFormation or ARM for Azure), and those for multicloud or cloud native, from Terraform and OpenTofu, to Helm and Crossplane, and those that cater to developers like Pulumi or AWS Cloud Development Kit (CDK). Different teams may prefer different tools based on their expertise, use cases or specific project requirements.

A robust IaC strategy must account for:

  • The coexistence of multiple IaC tools within the organization
  • Visibility across various IaC implementations
  • Governance and compliance across diverse IaC ecosystems

Ignoring this multi-IaC reality can lead to silos, reduced visibility and governance challenges. In the same way that many teams today select their clouds, programming languages and stacks based upon a diversity of criteria from performance to complexity, overhead maintenance and more, the same goes for IaC. With different tools optimized for different stacks and use cases, understanding how to manage the many tools in this landscape is part and parcel to a robust IaC strategy.

Comprehensive IaC Management

As DevOps and platform engineers, we’ve developed a platform that we ourselves have needed over many years of managing cloud fleets at scale. A platform that addresses not just tooling and orchestration, but all aspects of a comprehensive IaC strategy can be the difference between 2 a.m. downtime and a good night’s sleep.

Such a single platform can transform the engineering team’s approach to IaC and evolve with a continuously changing cloud landscape:

  • Complete visibility — automatically discovers all assets across your multicloud accounts, providing a clear inventory of managed and unmanaged resources in a single dashboard, no matter what cloud your resources and assets are running on.
  • IaC coverage insights — offers real-time metrics on your IaC coverage, helping you understand which resources are managed by IaC and which aren’t, and the risk severity helping to optimize planning for codification of critical resources and assets.
  • Multi-IaC support — recognizes and supports various IaC tools, giving you a unified view of your infrastructure regardless of the IaC solution used. In this way, the tool selection is decoupled from the management and maintenance, and teams are able to choose the right tool for the workload.
  • Automated codification (such as reverse IaC) — can automatically “codify” existing resources into your preferred IaC format, significantly reducing the manual effort required to bring legacy resources under IaC management, and migrate between IaC tools.
  • Drift detection — identifies resources that have deviated from their IaC-defined state, helping maintain consistency and security. Drift is a growing problem in large-scale systems, where cloud assets are still changed via console and ClickOps.
  • Governance and compliance — ensure that all resources, regardless of how they were created, adhere to your organization’s standards without hindering real-time incident response.
  • Orchestration and beyond — Beyond robust orchestration, it offers a comprehensive suite of tools for managing your entire IaC life cycle.

Elevate Your IaC Strategy

As the cloud continues to grow in complexity and evolve, so too must our approach to managing it. By looking beyond just tool selection and orchestration, and ensuring your IaC strategy focuses on additional and critical aspects that include IaC coverage, legacy resource management and multi-IaC support, organizations can unlock the full potential of their cloud infrastructure.

Ready to take your IaC strategy to the next level? Book a demo or start using Firefly for free today and experience the future of cloud asset management.

Firefly is a Cloud Control Plane that enables DevOps and Platform Engineering teams to scan and discover their entire cloud footprint, detect cloud configuration drifts, classify assets using Policy-as-Code, and manage a single inventory of cloud resources across Multi-Cloud and Kubernetes clusters.
Learn More
The latest from Firefly
TRENDING STORIES
Eran Bibi is co-founder and chief product officer at Firefly. With years of experience in anything DevOps/SRE and security, he has earned a reputation as a CI/CD and SRE expert and an avid admin of cloud platforms and containerized environments....
Read more from Eran Bibi
Firefly sponsored this post.
SHARE THIS STORY
TRENDING STORIES
AWS is a sponsor of The New Stack.
SHARE THIS STORY
TRENDING STORIES
TNS DAILY NEWSLETTER Receive a free roundup of the most recent TNS articles in your inbox each day.
The New Stack does not sell your information or share it with unaffiliated third parties. By continuing, you agree to our Terms of Use and Privacy Policy.