← all services

Terraform and Multi-Environment Infrastructure

Staging works. Production needs manual steps nobody documented, and adding another environment would take a sprint.

Design and implement a Terraform platform across dev, staging, and production: shared modules, partitioned state, environment parity, and OIDC-based deploys.

You probably need this if…

  • Staging passes CI but production requires manual steps between apply and verify
  • Developers deploy with long-lived AWS keys stored in CI secrets
  • Each environment has different resource names, not just different capacity
  • Terraform modules are copy-pasted between repos with subtle drift
  • Adding a fourth environment would take a sprint and a hero engineer

What's actually going wrong

Environments were added one at a time without a platform pattern. Configuration is duplicated, promotion is manual, and identity federation was never wired, so every deploy is a special case and every new environment starts from a fragile copy.

What I review or implement

  • Environment model: naming, tagging, account/region strategy, and promotion flow
  • Terraform module composition with shared core and environment-specific overlays
  • Remote state partitioning and workspace boundaries that match blast radius
  • OIDC federation for CI (GitHub Actions, etc.), no static AWS keys in secrets
  • Dev → staging → prod promotion with approval gates and drift detection

What you get

  • Reference environment architecture (Terraform modules + CI pipeline)
  • OIDC setup for your CI provider with least-privilege deploy roles
  • Documented promotion, rollback, and hotfix runbook
  • Working parity across environments for the resources that matter

Proof

Six-environment Terraform platform

Regulated SaaS client

Built a modular Terraform platform across multiple environments with GitHub Actions CI/CD, OIDC-federated deploys, and a manual production approval gate, so commercial and GovCloud partitions could evolve independently without copy-paste drift.

Multi-env
Terraform platform with OIDC deploys
GovCloud
Commercial + FedRAMP partitions isolated
Manual gate
Prod promotion requires explicit approval

Read: deploy with OIDC →

Request an environment assessment

Describe your symptoms, not a job spec. I'll reply within 48 hours with an honest read on whether the problem is structural, operational, or something else entirely.