Memory hook: Provider talks; state remembers.
Must remember
- A provider is a plugin implementing resource and data-source operations for an API. Terraform Core handles language evaluation and the dependency graph; it delegates API behavior to providers.
required_providersdeclares source addresses and allowed versions. Aproviderblock supplies a configuration such as region or endpoint.required_versionconstrains Terraform itself, not a provider.terraform initinstalls providers. Commit.terraform.lock.hclso colleagues reuse selected provider versions and verified checksums. The lock file does not lock remote module versions.~> 6.2permits later 6.x releases;~> 6.2.0permits later 6.2.x patches.init -upgradereselects versions within constraints, so review the lock-file diff.- Multiple configurations of one provider use
alias; select one withprovider = aws.secondary. Child modules receive aliases through an explicitprovidersmapping and declare expected aliases. - A Terraform resource address identifies a configured instance, such as
module.web.aws_instance.node["blue"]. State connects that address to the remote object identifier. Renaming an address without a move declaration can look like delete-and-create.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Same API, two regions | Two provider configurations, one aliased, with explicit resource/module selection. |
| Reproducible plugin selection | Compatible constraints plus the committed dependency lock file. |
Traps
- A provider alias is not a separate state file.
- An omitted default provider configuration can produce an empty default configuration, which may lack required settings.
Active recall
1. What downloads a provider?
terraform init resolves the declared source and installs a compatible plugin.
2. Does required_version pin AWS?
No. It constrains the Terraform CLI; required_providers constrains the AWS provider.
3. What does the lock file record?
Selected provider versions and package checksums, not module source versions.
4. Why use an alias?
To select another configuration of the same provider, such as another region or account.
5. What identifies an object to Terraform?
The resource-instance address is bound in state to the provider’s remote object ID.