Memory hook: References connect; sensitive only conceals.
Must remember
- Resources manage object lifecycles; data sources read information. References such as
aws_subnet.app.idnormally create implicit dependencies. Usedepends_onfor real hidden ordering requirements, not every relationship. - Variables are module inputs; locals name derived expressions; outputs expose results. In the CLI, explicit
-var/-var-fileoptions override automatic variable files and environment variables. Child modules receive arguments from their caller. - Types include
string,number,bool, lists, sets, maps, tuples and objects. A set removes duplicates and has no index ordering.fortransforms values; adynamicblock generates nested blocks;countandfor_eachcreate resource/module instances. countuses numeric addresses.for_eachuses known map keys or set-of-string elements, which are more stable when items are removed. Sensitive or apply-time-unknown values cannot serve as identity keys.- Variable validation checks input constraints. Preconditions check assumptions before an operation; postconditions check results. A failed
checkassertion reports a warning rather than blocking the operation like a failed precondition. sensitive = trueredacts ordinary display but does not itself remove a value from state. Use secure remote storage and least-privilege access. Vault can supply short-lived secrets; retrieving a secret does not automatically keep it out of state.- Terraform 1.10 introduced ephemeral values; 1.11 added write-only resource arguments, where supported by providers. These reduce persistence in permitted contexts. Do not assume every normal argument accepts ephemeral data.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Stable named instances | Use for_each with nonsecret, known keys. |
| Prevent invalid input | Use a type constraint and variable validation. |
| Avoid persistent secret values | Use supported ephemeral/write-only mechanisms and protect remaining state and plans. |
Traps
- Marking an output sensitive is not encryption.
- Broad depends_on can make more values unknown and cause unnecessary conservative plans.
Active recall
1. Does a data source own the object it reads?
No. It queries information rather than managing that object’s lifecycle.
2. Why can removing the first count item cause churn?
Later numeric indices shift. Stable for_each keys avoid that identity shift.
3. What creates most dependencies?
References to attributes or outputs of other managed objects.
4. Will a failed check assertion block apply?
It reports a warning; blocking validation requires the appropriate validation or pre/postcondition.
5. Does Vault guarantee a secret never reaches state?
No. Persistence depends on the values and arguments involved; use supported nonpersistent mechanisms and protect state.