certslothcertsloth
← 004 overview

Terraform Associate / STUDY TOOLS

004 quick review

Reviewed 10 October 2026 against the linked published scope. Associate 004 targets Terraform 1.12. Multiple-choice knowledge exam; keep the tested version separate from the latest CLI.

Memory hook: Configuration declares intent; state binds identity; the plan explains the change.

Read the essentials, cover the answers and explain the decision aloud. Open the topic summaries below whenever a distinction is unclear.

Workflow and provider rules

  • Terraform is declarative infrastructure provisioning. Its dependency graph orders API operations; providers implement resource/data-source behavior. Multi-cloud support does not translate one vendor's resource schema into another.
  • required_version constrains the CLI; required_providers declares provider sources and constraints; provider configures API access/region. An alias selects another configuration, not another state. Reusable modules receive aliases through explicit mappings.
  • init prepares backend, providers and modules; fmt formats; validate checks configuration consistency; plan compares intent and observations; apply executes; destroy removes managed objects in the selected state.
  • A saved plan captures proposed actions and inputs. apply FILE executes it without the normal approval prompt. Plans can contain secrets. A plan without -out is a preview; later apply creates another plan.
  • Commit .terraform.lock.hcl for provider selections/checksums. It does not pin module versions. ~> 6.2 permits 6.x from 6.2; ~> 6.2.0 stays in 6.2.x. init -upgrade reselects within constraints.

Configuration and modules

  • Resources manage lifecycles; data sources read. References create implicit dependencies; depends_on handles genuine hidden relationships. Variables are inputs, locals derived names and outputs exposed results.
  • Lists are ordered, sets deduplicate without index order, maps have string keys, tuples and objects can combine types. for transforms values; dynamic emits nested blocks; count/for_each create instances.
  • count uses numeric addresses; for_each uses known nonsecret keys. Removing an early list entry can shift count identities. Unknown or sensitive identity keys are invalid for for_each.
  • In the CLI, explicit -var/-var-file inputs outrank automatic variable files and environment values. Child modules have their own scope; pass inputs and consume declared outputs. An HCP workflow adds its documented variable precedence rules.
  • Validation rejects unsuitable inputs. Preconditions and postconditions can block operations; failed check assertions report warnings. Lifecycle options alter behavior: create_before_destroy, prevent_destroy, ignore_changes and replace_triggered_by are not interchangeable safety guarantees.
  • sensitive redacts display; it does not encrypt or remove state values. Supported ephemeral values and write-only arguments reduce persistence in permitted contexts. Protect state, saved plans, logs and credentials regardless.
  • A module is a configuration directory. Pin registry versions or Git commits; local modules share the checked-out project version. Module boundaries do not automatically isolate state or credentials.

State, recovery and collaboration

  • State maps resource addresses to remote IDs. Backends determine storage, supported locking and access. Remote storage does not necessarily mean remote execution. Backend configuration cannot use ordinary input variables.
  • init -migrate-state migrates an existing backend's state; -reconfigure reinitializes configuration without that migration behavior. Locking prevents concurrent writers; force-unlock is only for a verified stale lock, not a convenient bypass.
  • Drift is real infrastructure differing from desired/recorded state. A refresh-only plan proposes state/output changes without changing remote objects; applying it still writes state. Decide deliberately whether to accept drift or restore configuration.
  • Import binds an existing object to a managed address. CLI import does not generate full matching configuration. A moved block preserves identity through address refactoring. state rm forgets an object without deleting it; leftover configuration may recreate it.
  • CLI workspaces select separate states for one configuration, not strong account isolation. HCP workspaces bundle state, configuration, variables and run settings; projects group them. HCP agents reach private infrastructure; speculative plans support review without applying.
  • Policies, run tasks, private modules and permissions support team governance. Prefer scoped short-lived provider credentials. Inspect state list, state show and protected TF_LOG output before attempting recovery.

Traps

  • validate cannot prove service capacity or production permissions.
  • prevent_destroy is not an account-wide safeguard and cannot protect a resource whose configuration has been removed.
  • State deletion is neither infrastructure teardown nor a backup strategy.

Final active recall

1. What does sensitive=true guarantee?

Display redaction in ordinary output; not encryption or omission from state.

2. Rename a resource without replacing it?

Use an appropriate moved block and inspect the resulting plan.

3. Does a lock file freeze remote module versions?

No. Pin module sources/versions separately.

4. When is for_each preferable to count?

When stable named identities should survive removing other instances.

5. A colleague changed a setting manually. What next?

Review drift in a plan and decide whether configuration should restore or accept the change.

Sources and further practice

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · Infrastructure as Code

Memory hook: Describe the destination; review the journey.

Must remember

  • Declarative configuration describes the desired infrastructure. Terraform compares configuration, recorded identity and provider observations to propose changes. Reapplying unchanged configuration should converge without unnecessary replacement.
  • Version control makes changes reviewable. A pull request can show a plan before approval; reusable modules make standards easier to repeat. Configuration still needs testing, credentials and operational ownership.
  • Multi-cloud means providers can manage several APIs in one workflow. It does not translate an AWS resource into an equivalent Azure resource. Resource schemas and architecture remain platform-specific.
  • Hybrid infrastructure can combine cloud services, DNS, SaaS and supported on-premises APIs. Terraform is primarily a provisioning tool; image building and application configuration may use Packer or a configuration-management system.
  • Immutable replacement creates a new object when an attribute cannot change in place. A small code change can therefore have a large availability or data impact. Read the actual plan, including deletions.

Recall drill: explain how a hand-edited production setting becomes drift and why rerunning an imperative script is not the same as comparing desired state.

Choose under exam pressure

Requirement Choice and reason
Repeatable environments Version configuration, inputs and module versions; review differences.
One workflow across cloud vendors Use the appropriate provider for each API; design each resource explicitly.

Traps

  • A successful plan is not proof that the application will function.
  • Code review does not replace review of replacements and destructive actions.

Practise this topic

02 · Providers and Resource Identity

Memory hook: Provider talks; state remembers.

Must remember

  • A provider is a plugin implementing resource and data-source operations for an API. Terraform Core handles language evaluation and the dependency graph; it delegates API behavior to providers.
  • required_providers declares source addresses and allowed versions. A provider block supplies a configuration such as region or endpoint. required_version constrains Terraform itself, not a provider.
  • terraform init installs providers. Commit .terraform.lock.hcl so colleagues reuse selected provider versions and verified checksums. The lock file does not lock remote module versions.
  • ~> 6.2 permits later 6.x releases; ~> 6.2.0 permits later 6.2.x patches. init -upgrade reselects versions within constraints, so review the lock-file diff.
  • Multiple configurations of one provider use alias; select one with provider = aws.secondary. Child modules receive aliases through an explicit providers mapping and declare expected aliases.
  • A Terraform resource address identifies a configured instance, such as module.web.aws_instance.node["blue"]. State connects that address to the remote object identifier. Renaming an address without a move declaration can look like delete-and-create.

Choose under exam pressure

Requirement Choice and reason
Same API, two regions Two provider configurations, one aliased, with explicit resource/module selection.
Reproducible plugin selection Compatible constraints plus the committed dependency lock file.

Traps

  • A provider alias is not a separate state file.
  • An omitted default provider configuration can produce an empty default configuration, which may lack required settings.

Practise this topic

03 · The Terraform CLI Workflow

Memory hook: Format, initialise, validate, plan, then approve.

Must remember

Command What to remember
terraform fmt -check -recursive Checks canonical formatting; does not contact a cloud API.
terraform init Prepares the backend, modules and providers; rerun after their configuration changes.
terraform validate Checks configuration consistency and types using installed dependencies. It does not prove API authorization or service capacity.
terraform plan -out=review.tfplan Refreshes observations by default and saves proposed actions and input values. Treat the file as sensitive.
terraform show review.tfplan Inspects the saved plan.
terraform apply review.tfplan Executes the saved plan without the usual interactive approval prompt. Protect this step in automation.
terraform destroy Plans destruction of objects managed by the current state; it is not an account-wide cleanup.

+ means create, ~ update, - destroy and a combined delete/create marker means replacement. Values marked unknown become known later. A plan without -out is a preview; a later apply creates a fresh plan.

Practice on paper: trace a provider upgrade, a module-source change and an input change through this sequence. These notes do not ask you to run apply or destroy against a cloud account.

Choose under exam pressure

Requirement Choice and reason
Review precisely what automation executes Save the plan, protect it and apply that artifact.
Catch syntax/type errors early Initialise dependencies, then validate; also plan in the intended environment.

Traps

  • Plan can read remote APIs and acquire a lock; it is not always offline.
  • Destroy cannot remove resources that Terraform has forgotten or never managed.

Practise this topic

04 · Configuration and Sensitive Values

Memory hook: References connect; sensitive only conceals.

Must remember

  • Resources manage object lifecycles; data sources read information. References such as aws_subnet.app.id normally create implicit dependencies. Use depends_on for real hidden ordering requirements, not every relationship.
  • Variables are module inputs; locals name derived expressions; outputs expose results. In the CLI, explicit -var/-var-file options override automatic variable files and environment variables. Child modules receive arguments from their caller.
  • Types include string, number, bool, lists, sets, maps, tuples and objects. A set removes duplicates and has no index ordering. for transforms values; a dynamic block generates nested blocks; count and for_each create resource/module instances.
  • count uses numeric addresses. for_each uses known map keys or set-of-string elements, which are more stable when items are removed. Sensitive or apply-time-unknown values cannot serve as identity keys.
  • Variable validation checks input constraints. Preconditions check assumptions before an operation; postconditions check results. A failed check assertion reports a warning rather than blocking the operation like a failed precondition.
  • sensitive = true redacts ordinary display but does not itself remove a value from state. Use secure remote storage and least-privilege access. Vault can supply short-lived secrets; retrieving a secret does not automatically keep it out of state.
  • Terraform 1.10 introduced ephemeral values; 1.11 added write-only resource arguments, where supported by providers. These reduce persistence in permitted contexts. Do not assume every normal argument accepts ephemeral data.

Choose under exam pressure

Requirement Choice and reason
Stable named instances Use for_each with nonsecret, known keys.
Prevent invalid input Use a type constraint and variable validation.
Avoid persistent secret values Use supported ephemeral/write-only mechanisms and protect remaining state and plans.

Traps

  • Marking an output sensitive is not encryption.
  • Broad depends_on can make more values unknown and cause unnecessary conservative plans.

Practise this topic

05 · Modules and Composition

Memory hook: Inputs in; outputs out; versions explicit.

Must remember

A module is a directory of Terraform configuration. The directory where you execute Terraform is the root module; its module blocks call child modules. File names such as main.tf are conventions: Terraform loads the directory’s configuration together.

A child module has its own variable scope. It cannot read a root variable simply because the name matches. Pass region = var.region or another explicit argument; read results through module.network.subnet_ids when the child declares that output.

Module sources may be local paths, registry addresses, version-controlled repositories or supported archives. Registry modules support the version argument. A Git source can pin a tag or commit with ?ref=...; a local module has no independently downloaded version. Rerun init after changing module sources or selected versions.

Prefer small modules that expose useful architecture choices and compose through outputs. Do not put provider configuration inside a reusable module when the caller should control accounts and regions. Provider requirements belong in the child; provider configurations normally come from the root.

Recall drill: sketch two calls to the same VPC module, with different CIDRs. Explain why their resource addresses differ and why their input values do not leak into each other.

Choose under exam pressure

Requirement Choice and reason
Reuse a network pattern Call a module with explicit inputs and consume its outputs.
Repeatable remote module source Pin a registry version or immutable Git commit.

Traps

  • The provider lock file does not pin a registry module.
  • A module is a code boundary, not automatically a state or security boundary.

Practise this topic

06 · State, Backends and Drift

Memory hook: One binding, one writer, protected history.

Must remember

State maps configured instances to remote object IDs and stores attributes needed for planning. The default local backend uses a local state file. Remote backends place state in shared storage; locking, encryption and access-control behavior depend on the selected backend.

Locking prevents concurrent writers corrupting a state snapshot. Do not disable locks just to get past a busy run. Force-unlock is a recovery operation for your own stale lock after confirming no writer remains. It does not roll back infrastructure.

Configure storage in a backend block; backend configuration cannot refer to normal variables or resource outputs. Supply authentication through the recommended external credential mechanism. Hard-coded or command-line backend secrets may be cached or captured in plans. init -migrate-state transfers state after a reviewed backend change; -reconfigure treats the configuration as new rather than migrating existing state.

Drift is found when providers read real objects during planning. Decide whether configuration should restore the intended value or be updated to accept the external change. A refresh-only plan proposes state/output updates without proposing remote infrastructure changes; applying it still writes state.

CLI workspaces provide separate state instances for one configuration, but shared credentials/backend access can remain. Use separate roots and permissions when environments need strong isolation. Consumers of terraform_remote_state need access to the underlying snapshot, even though the data source exposes only root outputs.

Choose under exam pressure

Requirement Choice and reason
Team collaboration Shared protected state with supported locking and a controlled apply process.
Deliberate external change Review drift and update configuration or deliberately reconcile state.

Traps

  • Remote state storage does not always mean remote execution.
  • Copying state into Git exposes historical secrets and provides poor locking.

Practise this topic

07 · Import, Refactoring and Troubleshooting

Memory hook: Import adopts; move renames; remove forgets.

Must remember

  • Import associates an existing remote object with a resource address. The CLI import command updates state but does not write a complete matching configuration. Configuration-driven import blocks allow adoption to appear in a plan; review any generated configuration before applying it.
  • Import one real object into one managed address. After adoption, plan again: missing or different arguments can propose changes or replacement. Import is not a backup and does not discover an entire application automatically.
  • A moved block records an address change, such as moving a resource into a module, so Terraform can retain its identity. Keep historical moves for consumers who upgrade from older module versions.
  • terraform state list shows addresses; state show ADDRESS shows a recorded object; terraform show displays state or a saved plan. State inspection can reveal secrets.
  • terraform state rm ADDRESS forgets the binding without deleting the remote object. If its configuration remains, a later plan may try to create another object. A reviewed removed block with destruction disabled provides a declarative alternative.
  • Set TF_LOG to a diagnostic level such as DEBUG or TRACE when troubleshooting; TF_LOG_PATH writes logs to a file. Disable logging afterward and protect logs because provider requests may contain sensitive data. Inspect initialization, authentication, provider diagnostics and the exact address before changing state.

Choose under exam pressure

Requirement Choice and reason
Rename without recreation Use a moved block and review the plan.
Adopt manually created infrastructure Import the correct ID into matching configuration.
Investigate a recorded instance Use state list/show before attempting recovery.

Traps

  • Removing state is not resource cleanup.
  • Import may succeed while the next plan still proposes destructive changes.

Practise this topic

08 · HCP Terraform and Team Workflows

Memory hook: Workspace owns a run; project groups the work.

Must remember

HCP Terraform adds a managed workflow around Terraform: shared state, run history, workspace variables, access controls and integrations. Execution can be remote, agent-based for private-network access, or local with supported state workflows. Terraform Enterprise is the self-managed product; Terraform Community supplies the CLI rather than the whole hosted collaboration system.

An HCP workspace represents a configuration, state, variables and run settings. It is not the same concept as a CLI workspace within one working directory. Projects group workspaces and help apply access and organizational controls. Variable sets share configuration across selected workspaces; carefully scope credentials and precedence.

VCS integration starts plans for proposed changes and runs after configured repository events. A speculative plan is a review preview, not an approved apply. CLI-driven and API-driven workflows support other automation models. An agent can execute runs where private infrastructure is reachable without exposing that infrastructure publicly.

Policy checks, run tasks, private modules, team permissions and cost estimation support governance; availability depends on the product edition and subscription. Policies evaluate rules; run tasks integrate external checks. Neither is a guarantee that an application is secure or its final bill matches an estimate.

Prefer workload identity/dynamic provider credentials over shared long-lived secrets where supported. Grant plan and apply permissions separately when reviewers should inspect changes without executing them.

Choose under exam pressure

Requirement Choice and reason
Private APIs unreachable from hosted runners Use a properly connected execution agent.
Shared approved infrastructure patterns Use a private module registry plus versioned modules.
Separate review from deployment Combine speculative plans, permissions and an approval workflow.

Traps

  • A CLI workspace and an HCP workspace are not interchangeable terms.
  • Product governance features and pricing can change; exam concepts matter more than memorising plan names.

Practise this topic

Search across every published topic.