Introduction
In the dynamic realm of IT and software development, Configuration Management (cfgmgmt) and Infrastructure as Code (IaC) have become pivotal for managing complex systems. Though distinct, these concepts are interconnected and form the backbone of modern IT operations. This article aims to demystify their relationship and differences, providing a deep dive into each concept.
Understanding cfgmgmt vs. IaC
Before diving into the complexities of modern IT management, let’s break down the basic concepts of Configuration Management (cfgmgmt) and Infrastructure as Code (IaC).
Basic Concepts:
- Infrastructure as Code (IaC): IaC is the practice of managing and provisioning computing infrastructure through machine-readable configuration files, rather than physical hardware configuration or interactive configuration tools. Common tools include Terraform, OpenTofu and Pulumi. Read part 1 of this blog series for an in depth look on the concept of infrastructure as code.
- Configuration Management (cfgmgmt): cfgmgmt involves maintaining and establishing consistency of a product’s performance, functional, and physical attributes with its requirements, design, and operational information throughout its life. Popular tools include Ansible, Puppet, and Chef.
Example Scenario:
Consider a team tasked with deploying a new cloud environment. Adhering to best practices, they avoid manual configuration via the cloud provider’s dashboard. Instead, they use tools to define the infrastructure state in code—this is the essence of Infrastructure as Code (IaC), where infrastructure state is codified.
Once the infrastructure, including networks and servers, is provisioned, proper configuration is essential. Servers need specific packages installed and services running—this is where Configuration Management (cfgmgmt) comes into play.
Despite IaC containing the word “code,” Configuration Management also involves coding. Code defines system configurations, managed and deployed through automated release pipelines across various environments. Similarly, IaC uses automated pipelines for infrastructure deployment.
All code, whether for IaC or cfgmgmt, should be version-controlled and managed centrally. IaC focuses on resource creation, while cfgmgmt addresses their configuration. Both utilize code and automation for promotion through environments.
When to Use What
The distinction between Infrastructure as Code (IaC) and configuration management (cfgmgmt) can sometimes be ambiguous. For example, provisioning a server for a new GitLab installation is an IaC task, while installing GitLab itself falls under cfgmgmt. But what about managing GitLab projects and repositories? Should this be done via the IaC pipeline or the cfgmgmt tool? The decision depends on the context and specific requirements, and the team should make the choice based on their needs.
To clarify how to effectively apply IaC and cfgmgmt in real-world scenarios, consider the following common best practices for each:
- Use IaC Tools if you are building an infrastructure: When setting up new servers, databases, or networks, use IaC tools. These tools help automate the provisioning of infrastructure, ensuring consistency and repeatability.
- Use Configuration Management Tools if you are configuring systems: When configuring systems such as DNS servers or web servers, use cfgmgmt tools. These tools manage the state of existing infrastructure, applying and maintaining specific configurations.
By adhering to these guidelines, teams can ensure they are using the right tool for the job, leading to more efficient and reliable infrastructure and system management.
Configuration or Data?
Large teams implementing IaC and cfgmgmt face a challenge in managing extensive configuration and code. A platform that’s revolutionized this space is Kubernetes, which has transformed resource provisioning and configuration. Teams use YAML manifests to define resources, but these manifests represent more than just configuration—they embody Configuration as Data (CaD).
Developers need diverse resources to function effectively, ideally without delving into underlying complexities. Kubernetes abstracts these complexities, allowing users to specify resources like Service without understanding the intricate routing involved.
CaD creates a standardized, serializable data model for configuration, abstracting complexity. IaC and cfgmgmt often work behind the scenes to achieve the desired state, with end-users needing only to provide data that describes the required resources.
Conclusion
We’ve explored IaC, cfgmgmt, and CaD, each playing a crucial role in modern IT management. These practices are complementary, each with unique responsibilities within the broader system.



