For AI agents: visit https://developer.jamf.com/platform-api/llms.txt for an index of all pages formatted in Markdown and endpoints in OpenAPI. Append .md to any documentation page URL to get its markdown version.
Resources: Terraform, GitHub, and Jamf Configurations
A crash course guide for Mac admins looking to move from manual configuration ("ClickOps") to automated, version-controlled infrastructure management using Terraform and GitOps workflows.
Part 1: Understanding the fundamentals
Before diving into Jamf-specific implementations, it's essential to understand the core concepts that make Infrastructure as Code valuable.
What is version control?
Version control is the foundation of modern software development — and now, infrastructure management. If you're new to these concepts, start here:
Infrastructure as Code means managing and provisioning infrastructure through code instead of manual processes. Rather than clicking through a UI to configure settings, you define your desired state in configuration files.
Why IaC matters
Benefit
Description
Version control
Every change is tracked with full history — who changed what, when, and why
Consistency
Eliminate "configuration drift" where environments slowly diverge from intended state
Repeatability
Deploy identical configurations across dev, test, and production
Rollback
Instantly revert to a previous known-good state when issues arise
Collaboration
Teams can review changes before they're applied via pull requests
Auditability
Complete audit trail for compliance and troubleshooting
GitOps extends IaC by using Git as the single source of truth for your infrastructure. All changes flow through Git — via pull requests with peer review — and automated systems ensure your live environment matches what's defined in your repository.
The GitOps workflow
1. Developer proposes change via Pull Request
2. Team reviews and discusses the change
3. Automated checks validate the configuration
4. Change is approved and merged
5. Automation applies the change to the live system
6. Continuous monitoring ensures state matches Git
Key GitOps benefits
Benefit
How it works
Pull request approvals
Changes require peer review before deployment — no more unauthorized modifications
Audit trail
Every change is a Git commit with author, timestamp, and description
Easy rollback
Revert to any previous state with git revert — the system automatically reconciles
Self-documenting
Your Git history IS your change documentation
Drift detection
Systems continuously compare live state vs. declared state and alert on differences
Collaboration
Async code review enables distributed teams to work together effectively
Terraform is HashiCorp's open-source Infrastructure as Code tool. It uses a declarative configuration language (HCL) to define resources, and works with virtually any platform that has an API — including Jamf.
Terraform concepts
Concept
Description
Provider
A plugin that enables Terraform to interact with a specific platform (e.g., AWS, Azure, Jamf)
Resource
A component of your infrastructure (e.g., a Jamf policy, configuration profile, or Smart Group)
State
Terraform's record of the current infrastructure — used to plan and apply changes
Plan
A preview of what Terraform will change before actually applying it
Apply
Execute the planned changes to bring infrastructure to the desired state
Terraform providers are plugins that enable Terraform to interact with specific platforms. Here are the providers available for Jamf products:
Terraform providers
Provider
Maintainer
Description
Link
terraform-provider-jamfplatform
Jamf
Jamf's first-party provider. Interfaces with the Jamf Platform API and, as of recent releases, also federates the full Jamf Pro surface — our recommended starting point.
Real-world Jamf environment model built on the jamfplatform provider, with example configurations and dev → test → prod workflows. Uses HCP Terraform Cloud for state management.