Skip to main content
🎤 Luca Berton is speaking at Red Hat Summit & KubeCon EU 2026!Learn more →
Back to Blog

Ansible vs Terraform vs Puppet Guide

Compare Ansible, Terraform, and Puppet for infrastructure automation. Understand when to use each tool and how they complement each other in modern DevOps.

Luca BertonMarch 17, 20263 min read

Ansible, Terraform, and Puppet are the three most common infrastructure automation tools. They solve different problems, and the best teams use more than one.

Quick Comparison

FeatureAnsibleTerraformPuppet
Primary useConfiguration managementInfrastructure provisioningConfiguration management
ApproachProcedural (imperative)DeclarativeDeclarative
AgentAgentless (SSH/WinRM)Agentless (API calls)Agent required
LanguageYAMLHCLPuppet DSL (Ruby-based)
StateNo state fileState file (required)PuppetDB
Learning curveLowMediumHigh
CommunityVery largeVery largeShrinking
Best forConfig mgmt, app deployCloud provisioningLarge-scale config mgmt

Ansible: The Swiss Army Knife

What it does well: - Configure servers (install packages, manage files, set up services) - Deploy applications - Orchestrate multi-step workflows - Ad-hoc tasks across many servers

Example — Configure a web server:

yaml
---
- name: Configure web servers
  hosts: webservers
  become: true
  tasks:
    - name: Install Nginx
      apt:
        name: nginx
        state: present

    - name: Deploy config
      template:
        src: nginx.conf.j2
        dest: /etc/nginx/nginx.conf
      notify: Restart Nginx

  handlers:
    - name: Restart Nginx
      service:
        name: nginx
        state: restarted

Strengths: - No agent to install — works over SSH - YAML is easy to learn - Huge module library (3,000+ modules) - Good for both config management and orchestration

Weaknesses: - No state tracking — doesn't know what exists - Procedural — order of tasks matters - Slower on large fleets (SSH overhead) - Drift detection requires running playbooks

Terraform: The Infrastructure Builder

What it does well: - Create cloud resources (VMs, networks, databases, DNS) - Manage infrastructure lifecycle (create, update, destroy) - Multi-cloud provisioning

Example — Create AWS infrastructure:

hcl
resource "aws_vpc" "main" {
  cidr_block = "10.0.0.0/16"
  tags       = { Name = "production" }
}

resource "aws_instance" "web" {
  count         = 3
  ami           = "ami-0c1c30571d2dae5c9"
  instance_type = "t3.micro"
  subnet_id     = aws_subnet.public.id
  tags          = { Name = "web-${count.index}" }
}

resource "aws_rds_instance" "db" {
  engine         = "postgres"
  instance_class = "db.t3.micro"
  allocated_storage = 20
}

Strengths: - Declarative — define desired state, Terraform figures out how - State file tracks real infrastructure - Plan before apply — see what will change - Excellent multi-cloud support - Modules for code reuse

Weaknesses: - State file management is complex - Not designed for server configuration (use Ansible for that) - HCL has a learning curve - Provider-specific knowledge needed

Related Course

Master this topic with hands-on labs

Go beyond reading — build real projects in sandboxed environments with expert video guidance.

Browse Courses →

Puppet: The Enterprise Veteran

What it does well: - Enforce configuration at scale (thousands of nodes) - Continuous enforcement — agent runs every 30 minutes - Compliance and audit reporting

Example — Enforce a configuration:

puppet
class webserver {
  package { 'nginx':
    ensure => installed,
  }

  file { '/etc/nginx/nginx.conf':
    ensure  => file,
    source  => 'puppet:///modules/webserver/nginx.conf',
    require => Package['nginx'],
    notify  => Service['nginx'],
  }

  service { 'nginx':
    ensure => running,
    enable => true,
  }
}

Strengths: - Continuous enforcement prevents drift - PuppetDB provides infrastructure visibility - Strong compliance reporting - Mature, battle-tested at scale

Weaknesses: - Agent required on every node - Puppet DSL has steep learning curve - Community shrinking (Ansible took market share) - Overkill for small environments

When to Use Each

ScenarioBest ToolWhy
Create AWS VPC + EC2 + RDSTerraformAPI-driven provisioning with state
Install packages + configure servicesAnsibleAgentless, quick, easy
Enforce compliance across 5,000 nodesPuppetContinuous agent enforcement
Deploy application updateAnsibleOrchestration + app deployment
Multi-cloud infrastructureTerraformProvider ecosystem
Quick ad-hoc tasks (restart service, check logs)AnsibleAd-hoc commands, no setup

Using Them Together

The best approach combines tools:

Terraform → Creates infrastructure (VMs, networks, databases)
    ↓
Ansible → Configures servers (packages, services, users)
    ↓
Kubernetes → Runs applications (containers, scaling)
bash
# 1. Provision with Terraform
cd terraform/ && terraform apply

# 2. Configure with Ansible
cd ../ansible/ && ansible-playbook -i inventory site.yml

# 3. Deploy apps to Kubernetes
kubectl apply -f k8s/
Stay Updated

Get weekly IT automation tips

Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.

Subscribe Free →

The Trend: Ansible + Terraform

Most new projects choose Ansible + Terraform: - Terraform for infrastructure provisioning - Ansible for configuration and deployment - Puppet is declining in new adoptions (but still strong in legacy enterprises)

What's Next?

CopyPasteLearn offers hands-on courses for both: - Ansible Automation in 30 Minutes — 6 lessons, beginner friendly - Terraform for Beginners — 15 lessons covering AWS provisioning

Both include free preview lessons and lab environments.

---

Ready to go deeper? Check out our hands-on course: Ansible Quickstart — practical exercises you can follow along on your own machine.

Related reading: Terraform vs Ansible: when to use which covers this in real-world detail.

Ready to learn by doing?

Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.

Share this article
LB
Luca Berton

Docker Captain, IT automation expert, Red Hat Summit & KubeCon speaker. Building hands-on education for DevOps engineers at CopyPasteLearn.

Related Articles

Explore topics

Browse more articles on the topics covered here.