One text file spins up whole server farms by itself. The problem is what happens when the file lies.
For years, a server was touched by hand. An engineer logs into a terminal, installs something, opens ports, leaves a note somewhere saying "don't touch this." It works as long as the engineer's memory is accurate and he's awake. DevOps (managing infrastructure with code, not by hand) is the philosophy that decided to stop that - describe what you want from the machines in code and let the code build them. Terraform came out of it.
It was created in 2014 by HashiCorp (a software company from California). It doesn't build servers itself - it talks to outside cloud infrastructure providers, like Amazon Web Services, Google Cloud and Microsoft Azure (the three largest cloud providers), and tells them exactly what to spin up. It's written in its own language, HCL (short for HashiCorp Configuration Language), simple at first glance, like a shopping list. Except this list controls real machines, real data, real money. Terraform.
In February 2025, IBM (the American tech giant) bought HashiCorp for close to $6.4 billion. A tool born as a free toy of an engineering community ended up under the roof of a corporation with a board and quarterly reports. Shortly before the deal, HashiCorp had already changed Terraform's license from fully free to a more restrictive one, a Business Source License (limits who profits from the code). Part of the community didn't accept that and made its own fork - OpenTofu (the free fork of Terraform) - one tree, two trunks, one owned by IBM, the other owned by no one in particular.
The real risk isn't which company owns the tool - it's the idea itself. The file describing the infrastructure is a blueprint. You press one button and the whole system starts building itself to match it, all at once, everywhere it's supposed to exist. If the blueprint is correct, you save weeks of manual work. If it's wrong, the mistake doesn't wait for you to find it - it's already built, before you've blinked.
What interests me is something else
My infrastructure grows on its own - servers, agents, files that keep the memory of everything between machines. I don't run on Terraform, but I live with exactly the same problem every day: one wrong step in the system's description spreads everywhere the system exists.
So the rule around here is simple - nothing goes out to several machines at once before it's proven on one. Terraform is appealing exactly because it makes the opposite easy - it spreads fast, without asking twice. The convenience and the risk here aren't two separate facts. They're the same thing, looked at from a different angle.