Memory hook: Workspace owns a run; project groups the work.
Must remember
HCP Terraform adds a managed workflow around Terraform: shared state, run history, workspace variables, access controls and integrations. Execution can be remote, agent-based for private-network access, or local with supported state workflows. Terraform Enterprise is the self-managed product; Terraform Community supplies the CLI rather than the whole hosted collaboration system.
An HCP workspace represents a configuration, state, variables and run settings. It is not the same concept as a CLI workspace within one working directory. Projects group workspaces and help apply access and organizational controls. Variable sets share configuration across selected workspaces; carefully scope credentials and precedence.
VCS integration starts plans for proposed changes and runs after configured repository events. A speculative plan is a review preview, not an approved apply. CLI-driven and API-driven workflows support other automation models. An agent can execute runs where private infrastructure is reachable without exposing that infrastructure publicly.
Policy checks, run tasks, private modules, team permissions and cost estimation support governance; availability depends on the product edition and subscription. Policies evaluate rules; run tasks integrate external checks. Neither is a guarantee that an application is secure or its final bill matches an estimate.
Prefer workload identity/dynamic provider credentials over shared long-lived secrets where supported. Grant plan and apply permissions separately when reviewers should inspect changes without executing them.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Private APIs unreachable from hosted runners | Use a properly connected execution agent. |
| Shared approved infrastructure patterns | Use a private module registry plus versioned modules. |
| Separate review from deployment | Combine speculative plans, permissions and an approval workflow. |
Traps
- A CLI workspace and an HCP workspace are not interchangeable terms.
- Product governance features and pricing can change; exam concepts matter more than memorising plan names.
Active recall
1. What does an HCP workspace contain?
A configuration’s state, variables, run history and execution settings.
2. What is a project for?
Grouping workspaces and organizing permissions and management.
3. Does a speculative plan apply changes?
No. It previews a possible change for review.
4. Why use an agent?
To run Terraform in a network that can reach otherwise private systems.
5. Policy check or run task for an external scanning service?
A run task integrates an external check; policy checks evaluate governance rules.