certslothcertsloth
004/Topic 04

HashiCorp / Associate

Configuration and Sensitive Values

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: References connect; sensitive only conceals.

Must remember

  • Resources manage object lifecycles; data sources read information. References such as aws_subnet.app.id normally create implicit dependencies. Use depends_on for real hidden ordering requirements, not every relationship.
  • Variables are module inputs; locals name derived expressions; outputs expose results. In the CLI, explicit -var/-var-file options override automatic variable files and environment variables. Child modules receive arguments from their caller.
  • Types include string, number, bool, lists, sets, maps, tuples and objects. A set removes duplicates and has no index ordering. for transforms values; a dynamic block generates nested blocks; count and for_each create resource/module instances.
  • count uses numeric addresses. for_each uses known map keys or set-of-string elements, which are more stable when items are removed. Sensitive or apply-time-unknown values cannot serve as identity keys.
  • Variable validation checks input constraints. Preconditions check assumptions before an operation; postconditions check results. A failed check assertion reports a warning rather than blocking the operation like a failed precondition.
  • sensitive = true redacts ordinary display but does not itself remove a value from state. Use secure remote storage and least-privilege access. Vault can supply short-lived secrets; retrieving a secret does not automatically keep it out of state.
  • Terraform 1.10 introduced ephemeral values; 1.11 added write-only resource arguments, where supported by providers. These reduce persistence in permitted contexts. Do not assume every normal argument accepts ephemeral data.

Choose under exam pressure

Requirement Choice and reason
Stable named instances Use for_each with nonsecret, known keys.
Prevent invalid input Use a type constraint and variable validation.
Avoid persistent secret values Use supported ephemeral/write-only mechanisms and protect remaining state and plans.

Traps

  • Marking an output sensitive is not encryption.
  • Broad depends_on can make more values unknown and cause unnecessary conservative plans.

Active recall

1. Does a data source own the object it reads?

No. It queries information rather than managing that object’s lifecycle.

2. Why can removing the first count item cause churn?

Later numeric indices shift. Stable for_each keys avoid that identity shift.

3. What creates most dependencies?

References to attributes or outputs of other managed objects.

4. Will a failed check assertion block apply?

It reports a warning; blocking validation requires the appropriate validation or pre/postcondition.

5. Does Vault guarantee a secret never reaches state?

No. Persistence depends on the values and arguments involved; use supported nonpersistent mechanisms and protect state.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.