As of 2026, "Infrastructure as Code" (IaC) approaches have established theirselves as a new technique for infrastructure provisioning. One of the most popular IaC tools is Terraform, which allows to describe needed "data center based" infrastructure (e.g. fleets of virtual machines) through declarative configuration files. Abstracting over cloud providers' resource management web APIs in a standardized way and leveraging a declarative syntax, Terraform emerges as the "Holy Grail" of IaC. Terraform's focus is mostly on infrastructural objects rather than on what actually gets executed on them. For example, despite being able to describe virtual machines, Terraform can't fully manage configuration for their running software. This is, however, a voluntary limitation of the tool, which can be addressed by integrating Terraform with ad hoc solutions suitable for more "imperative like" operations. Cloud-init represents one of the aforementioned solutions and, in combination with Terraform, realizes a complete IaC system. In any case the resulting system still presents certain limitations and weaknesses, both considering its two components individually and the way they interact with one another. One method for bringing to light these faults is conducting "in-depth" experiments with both tools together, employing them under practical use cases in order to achieve a sufficient level of representativeness. From November 2025 to March 2026 I've been participating to an internship at Nucleus S.R.L., a network and IT consulting company based in Udine: during the experience I had the opportunity to perform the needed experiments in that sense. Both Terraform and cloud-init were leveraged, using versions 1.13 and 24.3 respectively. A wide percentage of their known functionalities was unleashed, especially considering the former tool, which gave me the opportunity to assess a series of interesting limitations and weaknesses of the "Terraform - cloud-init duo". The aim of this thesis is therefore to provide the reader with the achieved results: although deriving from domain specific use cases, such results may anyway serve as a base to highlight some IaC shortcomings which still have to be widely acknowledged.

As of 2026, "Infrastructure as Code" (IaC) approaches have established theirselves as a new technique for infrastructure provisioning. One of the most popular IaC tools is Terraform, which allows to describe needed "data center based" infrastructure (e.g. fleets of virtual machines) through declarative configuration files. Abstracting over cloud providers' resource management web APIs in a standardized way and leveraging a declarative syntax, Terraform emerges as the "Holy Grail" of IaC. Terraform's focus is mostly on infrastructural objects rather than on what actually gets executed on them. For example, despite being able to describe virtual machines, Terraform can't fully manage configuration for their running software. This is, however, a voluntary limitation of the tool, which can be addressed by integrating Terraform with ad hoc solutions suitable for more "imperative like" operations. Cloud-init represents one of the aforementioned solutions and, in combination with Terraform, realizes a complete IaC system. In any case the resulting system still presents certain limitations and weaknesses, both considering its two components individually and the way they interact with one another. One method for bringing to light these faults is conducting "in-depth" experiments with both tools together, employing them under practical use cases in order to achieve a sufficient level of representativeness. From November 2025 to March 2026 I've been participating to an internship at Nucleus S.R.L., a network and IT consulting company based in Udine: during the experience I had the opportunity to perform the needed experiments in that sense. Both Terraform and cloud-init were leveraged, using versions 1.13 and 24.3 respectively. A wide percentage of their known functionalities was unleashed, especially considering the former tool, which gave me the opportunity to assess a series of interesting limitations and weaknesses of the "Terraform - cloud-init duo". The aim of this thesis is therefore to provide the reader with the achieved results: although deriving from domain specific use cases, such results may anyway serve as a base to highlight some IaC shortcomings which still have to be widely acknowledged.

On the limitations of Infrastructure as Code: some practical case studies

ZENEZINI, PIETRO
2025/2026

Abstract

As of 2026, "Infrastructure as Code" (IaC) approaches have established theirselves as a new technique for infrastructure provisioning. One of the most popular IaC tools is Terraform, which allows to describe needed "data center based" infrastructure (e.g. fleets of virtual machines) through declarative configuration files. Abstracting over cloud providers' resource management web APIs in a standardized way and leveraging a declarative syntax, Terraform emerges as the "Holy Grail" of IaC. Terraform's focus is mostly on infrastructural objects rather than on what actually gets executed on them. For example, despite being able to describe virtual machines, Terraform can't fully manage configuration for their running software. This is, however, a voluntary limitation of the tool, which can be addressed by integrating Terraform with ad hoc solutions suitable for more "imperative like" operations. Cloud-init represents one of the aforementioned solutions and, in combination with Terraform, realizes a complete IaC system. In any case the resulting system still presents certain limitations and weaknesses, both considering its two components individually and the way they interact with one another. One method for bringing to light these faults is conducting "in-depth" experiments with both tools together, employing them under practical use cases in order to achieve a sufficient level of representativeness. From November 2025 to March 2026 I've been participating to an internship at Nucleus S.R.L., a network and IT consulting company based in Udine: during the experience I had the opportunity to perform the needed experiments in that sense. Both Terraform and cloud-init were leveraged, using versions 1.13 and 24.3 respectively. A wide percentage of their known functionalities was unleashed, especially considering the former tool, which gave me the opportunity to assess a series of interesting limitations and weaknesses of the "Terraform - cloud-init duo". The aim of this thesis is therefore to provide the reader with the achieved results: although deriving from domain specific use cases, such results may anyway serve as a base to highlight some IaC shortcomings which still have to be widely acknowledged.
2025
On the limitations of Infrastructure as Code: some practical case studies
As of 2026, "Infrastructure as Code" (IaC) approaches have established theirselves as a new technique for infrastructure provisioning. One of the most popular IaC tools is Terraform, which allows to describe needed "data center based" infrastructure (e.g. fleets of virtual machines) through declarative configuration files. Abstracting over cloud providers' resource management web APIs in a standardized way and leveraging a declarative syntax, Terraform emerges as the "Holy Grail" of IaC. Terraform's focus is mostly on infrastructural objects rather than on what actually gets executed on them. For example, despite being able to describe virtual machines, Terraform can't fully manage configuration for their running software. This is, however, a voluntary limitation of the tool, which can be addressed by integrating Terraform with ad hoc solutions suitable for more "imperative like" operations. Cloud-init represents one of the aforementioned solutions and, in combination with Terraform, realizes a complete IaC system. In any case the resulting system still presents certain limitations and weaknesses, both considering its two components individually and the way they interact with one another. One method for bringing to light these faults is conducting "in-depth" experiments with both tools together, employing them under practical use cases in order to achieve a sufficient level of representativeness. From November 2025 to March 2026 I've been participating to an internship at Nucleus S.R.L., a network and IT consulting company based in Udine: during the experience I had the opportunity to perform the needed experiments in that sense. Both Terraform and cloud-init were leveraged, using versions 1.13 and 24.3 respectively. A wide percentage of their known functionalities was unleashed, especially considering the former tool, which gave me the opportunity to assess a series of interesting limitations and weaknesses of the "Terraform - cloud-init duo". The aim of this thesis is therefore to provide the reader with the achieved results: although deriving from domain specific use cases, such results may anyway serve as a base to highlight some IaC shortcomings which still have to be widely acknowledged.
Terraform
Cloud-Init
IaC
File in questo prodotto:
File Dimensione Formato  
thesis.pdf

Accesso riservato

Dimensione 1.49 MB
Formato Adobe PDF
1.49 MB Adobe PDF

The text of this website © Università degli studi di Padova. Full Text are published under a non-exclusive license. Metadata are under a CC0 License

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/20.500.12608/110964