StudyToCert

All certifications / Terraform Associate / Cheat sheet

Terraform Associate Terraform Associate (004) cheat sheet

Every exam tip and key term from the free Terraform Associate lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Infrastructure as Code (IaC) with Terraform (8%)

Exam tips

Key terms

Infrastructure as Code (IaC)
Managing infrastructure through machine-readable definition files that a tool applies, instead of manual changes.
Configuration
In Terraform, the set of .tf files in a directory that together describe the desired infrastructure.
HCL
HashiCorp Configuration Language, the declarative language Terraform configurations are written in.
Configuration drift
Differences that build up between environments or between the recorded design and reality, usually from untracked manual changes.
ClickOps
Informal name for provisioning infrastructure by hand through a web console.
Repeatability
The ability to produce the same infrastructure again from the same code and inputs.
Consistency
Environments built from the same definitions match each other, reducing works-in-staging-but-not-production surprises.
Audit trail
The record, from version control and pipeline logs, of who changed infrastructure, when and why.
CI/CD
Continuous integration and continuous delivery; automated pipelines that test and deploy changes.
Declarative
Describing the desired end state and letting the tool determine the steps to reach it.
Imperative
Specifying the exact sequence of commands or steps to perform.
Desired state
The infrastructure described by the configuration, which Terraform tries to make real.
Provisioner
A Terraform feature that runs scripts or commands during resource creation or destruction; recommended only as a last resort.
Idempotence
The property that repeating an operation produces the same result as doing it once, with no further changes.
Drift
A difference between real infrastructure and what the configuration and state describe, usually from manual changes.
Refresh
The part of planning where Terraform reads the current attributes of managed objects from the provider.
Perpetual diff
A change that appears in every plan because a value is non-deterministic or normalized differently by the API.
Terraform core
The main Terraform binary that parses configuration, builds the dependency graph, manages state and drives the workflow.
Provider
A plugin that lets Terraform manage a specific platform or service by translating requests into its API calls.
Plugin
A separate executable that core launches and talks to over RPC; providers are plugins.
Data source
A read-only lookup, supplied by a provider, that fetches information about existing objects.
Multi-cloud
Using two or more public cloud providers together.
Hybrid cloud
Combining public cloud services with private or on-premises infrastructure.
Native IaC tool
A cloud vendor's own provisioning tool, such as CloudFormation or ARM templates, which only manages that vendor's resources.
Cross-provider reference
An expression in one provider's resource that uses an attribute from another provider's resource, creating an implicit dependency.
Service-agnostic
Able to manage any service that exposes an API, as long as a provider exists for it.
Terraform Registry
The public catalog where providers and modules are published and from which terraform init downloads them by default.
Utility provider
A provider such as random, local, tls or http that supports configurations without managing a cloud platform.
Branch protection
Git platform rules, such as required reviews, that can be codified with a Git provider.
Provisioning
Creating and managing infrastructure resources themselves, such as servers and networks, typically through APIs.
Configuration management
Installing and maintaining software and settings inside existing servers, as done by Ansible, Chef, Puppet or Salt.
cloud-init / user_data
A mechanism for passing a first-boot script or configuration to a new virtual machine.
Immutable infrastructure
A practice where deployed components are never modified; changes are made by replacing them with new versions.
Mutable infrastructure
Servers that are updated and patched in place over their lifetime.
Snowflake server
A server whose configuration has drifted into something unique and hard to reproduce.
Golden image
A pre-built, versioned machine image containing the OS and software, used to launch identical instances.
create_before_destroy
A lifecycle setting that makes Terraform create the replacement before destroying the original.

Domain 2: Terraform fundamentals (11%)

Exam tips

Key terms

terraform block
The top-level block for settings about Terraform itself, such as required_version, required_providers and backend.
required_version
A version constraint that the running Terraform CLI must satisfy, or commands fail.
terraform version
Command that prints the installed Terraform version, platform and, in an initialized directory, provider versions.
Version constraint
A string of one or more conditions, such as >= 1.12.0, < 2.0.0, that a version must meet.
required_providers
Block inside terraform that declares each provider's local name, source address and version constraint.
Source address
The HOSTNAME/NAMESPACE/TYPE identifier telling Terraform where to download a provider.
Namespace
The publisher part of a source address, such as hashicorp or a company or user name.
Local name
The module-specific name for a provider, used in provider blocks and matched to resource type prefixes.
Semantic versioning
Versioning scheme MAJOR.MINOR.PATCH where major changes may break compatibility, minor adds features and patch fixes bugs.
Pessimistic constraint (~>)
Allows only the rightmost specified version component to increase.
Exact constraint (=)
Allows only one specific version; also the only way to select a pre-release.
Exclusion (!=)
Rejects a specific version while allowing others permitted by the remaining conditions.
Dependency lock file
.terraform.lock.hcl, which records the exact provider versions and package checksums selected by terraform init.
terraform init -upgrade
Re-selects the newest provider (and module) versions allowed by constraints and updates the lock file.
Checksum (hash)
A fingerprint of a provider package used to verify that the downloaded file is the expected one.
.terraform directory
Local working directory where init stores downloaded providers and modules; not committed.
Provider schema
The provider's definition of its resource types, data sources, arguments and attributes.
Plugin cache
An optional shared directory where init stores provider packages so they can be reused across working directories.
Provider mirror
A local or network copy of provider packages used instead of the public registry, for example on isolated networks.
Computed attribute
A value set by the provider or platform after creation, such as an ID, rather than by your configuration.
Official provider
Provider owned and maintained by HashiCorp, published under the hashicorp namespace.
Partner provider
Provider written and maintained by a third-party company in HashiCorp's Technology Partner Program, published under the company's namespace.
Community provider
Provider published by individuals or groups in the community, with no HashiCorp or vendor support guarantee.
Archived provider
A provider that is no longer maintained, kept available so existing configurations still work.
provider block
Configuration for a provider, such as region, endpoint or authentication settings, normally placed in the root module.
alias
An argument that names an additional, non-default configuration of the same provider.
provider meta-argument
An argument on a resource or data block, like provider = aws.west, that selects a specific provider configuration.
Meta-argument
An argument handled by Terraform itself and usable on any resource type, such as count, for_each, depends_on, provider and lifecycle.
Resource type prefix
The part of a resource type before the first underscore, such as docker in docker_container, which selects the provider.
terraform providers
Command that shows the providers required by the configuration and its modules.
Dependency graph
Terraform's internal map of which objects depend on which, used to order operations across all providers.
Partial apply
An apply that stops after some changes succeed; state records completed work so the next run can continue.
State
Terraform's record of the real objects it manages, their attributes and metadata, stored in terraform.tfstate or a remote backend.
Resource address
The identifier of a resource in configuration and state, such as aws_instance.web or module.net.aws_vpc.main.
Backend
Where Terraform stores state, such as local disk, HCP Terraform or a cloud storage service.
State locking
A mechanism that prevents concurrent operations from writing the same state at once.
terraform.tfstate
The default local state file, a JSON document recording managed resources and their attributes.
sensitive
A flag on variables and outputs that redacts values in CLI output; the values are still stored in state.
Ephemeral value
A value that exists only during a Terraform run and is never persisted to state or plan files.
Serial and lineage
State metadata: the serial increments on each write, and the lineage identifies a single state's history.

Domain 3: Core Terraform workflow (19%)

Exam tips

Key terms

Core workflow
Terraform's Write, Plan and Apply cycle for changing infrastructure.
Speculative plan
A plan run for review only, such as on a pull request, that cannot be applied.
Remote backend
Shared state storage, such as HCP Terraform, that lets a team use one state safely with locking.
Pull request
A request to merge code changes that lets teammates review them, often with plan output attached.
terraform init
Command that initializes a working directory: configures the backend and installs modules and providers.
-migrate-state
Init option that copies existing state to a newly configured backend.
-reconfigure
Init option that configures the backend fresh, ignoring saved settings and not migrating state.
Partial configuration
Leaving backend settings out of code and supplying them with -backend-config at init time.
terraform validate
Command that checks configuration syntax and internal consistency without contacting remote services.
Internal consistency
Whether references, argument names, types and required arguments in the configuration agree with each other and with provider schemas.
Provider schema
The provider's list of resource types, arguments and types, needed by validate and obtained by terraform init.
-json
Option that outputs validation results in a machine-readable format.
Execution plan
Terraform's preview of the create, update, replace and destroy actions needed to match the configuration.
-/+ (replace)
Plan symbol meaning the existing object will be destroyed and a new one created.
(known after apply)
Plan annotation for values the provider will only determine when the change is carried out.
Saved plan
A plan written with -out=FILE that can be applied later exactly as reviewed.
-var / -var-file
Options that set input variable values on the command line or from a file; highest precedence, last one wins.
-target
Limits planning to specific resources or modules and their dependencies; for exceptional use only.
-refresh-only
Plan or apply mode that updates state to match real infrastructure without changing that infrastructure.
-replace
Forces replacement of a specific resource instance in the plan.
terraform apply
Command that carries out a plan to create, update or destroy infrastructure and records the results in state.
-auto-approve
Skips the interactive yes confirmation; intended for automation with approval elsewhere.
Stale plan
A saved plan whose state has changed since it was created; Terraform refuses to apply it.
Tainted
State marking for a resource that is known to be damaged, such as after a failed creation, so it will be replaced.
terraform destroy
Command that destroys all resources managed by the configuration; an alias for terraform apply -destroy.
plan -destroy
Creates a destroy plan to preview, and optionally save, without destroying anything.
Reverse dependency order
Destroy removes dependents before the objects they depend on.
prevent_destroy
Lifecycle setting that makes any plan that would destroy the resource fail.
terraform fmt
Command that rewrites configuration files into Terraform's canonical style without changing meaning.
-check
fmt option that reports unformatted files and exits nonzero without modifying them.
-diff
fmt option that displays the formatting differences.
-recursive
fmt option that also processes files in subdirectories.
terraform taint
Deprecated command that marked a resource in state for replacement on the next apply.
terraform untaint
Command that removes a tainted mark from a resource in state.
Tainted resource
A resource marked in state as damaged, usually after a failed create or provisioner, that will be replaced.
Dependency graph
Directed acyclic graph of configuration objects that Terraform uses to order operations.
-parallelism
Option setting the maximum number of concurrent operations during plan, apply or destroy; the default is 10.
terraform graph
Command that outputs the dependency graph in DOT format for visualization.
Cycle
A circular dependency between objects that makes the graph impossible to order; Terraform reports it as an error.

Domain 4: Terraform configuration (22%)

Exam tips

Key terms

Resource block
Declares an infrastructure object that Terraform creates, updates and destroys.
Data block (data source)
Declares a read-only lookup of existing information that Terraform reads but does not manage.
Resource address
The reference form TYPE.NAME for resources and data.TYPE.NAME for data sources, extended with module paths and instance keys.
Local name
The second label of a resource or data block, chosen by you and unique per type within a module.
Reference
An expression that uses a value from another object, such as aws_vpc.main.id or var.region.
Implicit dependency
An ordering relationship Terraform infers automatically from a reference between objects.
Computed attribute
An attribute set by the provider after creation, such as an ID, often shown as known after apply.
moved block
A block that tells Terraform a resource's address changed so it updates state instead of replacing the object.
Input variable
A module parameter declared with a variable block and referenced as var.NAME.
TF_VAR_ environment variable
An environment variable named TF_VAR_<name> that sets a root module variable; lowest precedence.
terraform.tfvars
Variable definitions file that Terraform loads automatically from the root module directory.
nullable
Variable setting (default true) controlling whether null is accepted; when false, null is replaced by the default.
sensitive
Variable setting that redacts the value in CLI output but does not keep it out of state.
Output value
A named value a module exports, printed for the root module and accessed as module.NAME.OUTPUT for child modules.
Local value
A named expression defined in a locals block and referenced as local.NAME, usable only inside its module.
terraform output
Command that reads root module output values from state, with -raw and -json options.
terraform_remote_state
Data source that reads the root module outputs of another configuration's state.
Collection type
list, map or set: many values that all share the same element type.
Structural type
object or tuple: a fixed shape whose attributes or positions may have different types.
set
An unordered collection of unique values with no index.
optional()
Modifier in an object type that makes an attribute omittable, optionally with a default.
Type conversion
Automatic or function-based changing of a value to a compatible type, such as toset() on a list.
Conditional expression
condition ? a : b, which chooses one of two values based on a boolean.
for expression
An expression that builds a list or map by transforming, and optionally filtering, another collection.
Splat expression
[*] shorthand that extracts one attribute from every element of a list, such as aws_instance.web[*].id.
String template
A string with ${...} interpolation or %{...} directives.
dynamic block
A construct that generates repeated nested blocks from a collection using for_each and content.
Built-in function
A function supplied by Terraform, such as join or cidrsubnet, callable in expressions; user-defined functions are not supported.
terraform console
Interactive command for evaluating expressions against the current configuration and state without making changes.
lookup
Function that returns a map value by key, or a default when the key is missing.
cidrsubnet
Function that calculates a subnet address range within a larger CIDR block.
count
Meta-argument that creates a number of instances addressed by integer index.
count.index
The zero-based index of the current instance in a count block.
for_each
Meta-argument that creates one instance per element of a map or set, addressed by key.
each.key / each.value
In a for_each block, the current element's key and value; identical for sets.
depends_on
Meta-argument declaring an explicit dependency that no attribute reference expresses.
create_before_destroy
Lifecycle setting that creates the replacement object before destroying the old one.
prevent_destroy
Lifecycle setting that makes any plan destroying the resource fail with an error.
ignore_changes
Lifecycle setting listing attributes whose drift Terraform should not try to correct.
replace_triggered_by
Lifecycle setting that replaces the resource when referenced resources or attributes change.
validation block
A rule inside a variable block with a condition and error_message that rejects bad input values before planning.
precondition
A lifecycle (or output) condition evaluated before an object is created or changed; failure is an error that halts the run.
postcondition
A lifecycle condition evaluated after an object is created, updated or read; it can use self to inspect the result.
check block
A top-level block of assert conditions, optionally with a scoped data source, whose failures produce warnings instead of errors.
sensitive = true
Marks a variable or output so its value is redacted in CLI output; the value is still stored in state.
Ephemeral variable
A variable declared with ephemeral = true whose value is available during a run but never written to plan or state.
Ephemeral resource
An ephemeral block that obtains a temporary value (such as a secret or token) each run without persisting it.
Write-only argument
A resource argument that accepts a value and passes it to the provider but never stores it in plan or state, usually paired with a version argument.
HashiCorp Vault
A secrets management tool that stores, controls access to, audits and dynamically generates secrets.
Dynamic secret
A credential Vault generates on demand with a lease and revokes automatically when the lease expires.
Vault provider
The Terraform provider used to configure Vault and to read secrets from it through data sources or ephemeral resources.
Lease
The time period a Vault secret is valid for before it must be renewed or is revoked.

Domain 5: Terraform modules (11%)

Exam tips

Key terms

Module
Any directory containing Terraform configuration files; Terraform treats all .tf files in it as one unit.
Root module
The module in the working directory where Terraform commands are run; the top of the module tree.
Child module
A module called by another module through a module block.
Module address
The path to a resource through the module tree, such as module.network.aws_subnet.private.
source argument
The required module block argument that tells Terraform where to find the module code.
Registry source
A module address in the form NAMESPACE/NAME/PROVIDER, prefixed with a hostname for private registries.
Local path source
A module path beginning with ./ or ../ that Terraform reads directly from disk without downloading.
Double-slash subdirectory
The // syntax in a source address that selects a subdirectory within a downloaded repository or archive.
module block
A block that calls a child module, giving it a local name, a source and values for its input variables.
Input variable
A variable declared in the child module that callers set as an argument in the module block.
Required input
A module variable without a default; callers must supply it or Terraform reports an error.
Meta-arguments
Arguments Terraform itself handles on a module block: source, version, count, for_each, providers and depends_on.
Module scope
The rule that each module has its own namespace and sees only its own variables, locals and resources.
Output value
A value a module exports with an output block, readable by its caller as module.NAME.OUTPUT.
Re-exporting
Declaring a root module output whose value is a child module output, so it appears in terraform output.
TF_VAR_ environment variable
An environment variable that sets a root module input variable; it does not reach child modules directly.
Provider alias
An extra, named configuration of a provider created with the alias meta-argument and referenced as PROVIDER.ALIAS.
providers argument
A map on a module block that assigns the caller's provider configurations to the provider names the child module uses.
Implicit provider inheritance
The default behavior where child modules automatically use the parent's default, unaliased provider configurations.
configuration_aliases
A required_providers setting in a child module that declares additional provider configuration names the caller must pass in.
version argument
A module block argument that sets a version constraint; valid only for registry module sources.
ref parameter
A query parameter in a Git source address that selects a tag, branch or commit to check out.
Pessimistic constraint (~>)
A version operator that allows only the rightmost specified component to increase, such as ~> 1.4 allowing 1.x from 1.4 up.
Dependency lock file
.terraform.lock.hcl, which records provider versions and hashes but not module versions.
.terraform/modules
The hidden directory in the working directory where Terraform stores downloaded module code and the modules.json manifest.
terraform get
A command that downloads and updates modules only, without initializing backends or providers.
terraform init -upgrade
Re-evaluates version constraints and installs the newest allowed module and provider versions.
modules.json
A manifest in .terraform/modules that records each module call's source, version and install directory.
count on a module
Creates a number of module instances addressed by index, such as module.web[0].
for_each on a module
Creates one module instance per map key or set element, addressed by key, such as module.web["blue"].
each.key / each.value
Values available inside a for_each block that identify the current element.
Legacy module
A module containing its own provider blocks; it cannot be used with count, for_each or depends_on.
main.tf
The conventional primary file of a module, holding its main resources and module calls.
variables.tf
The conventional file holding a module's input variable declarations, forming its input interface.
outputs.tf
The conventional file holding a module's output declarations, forming its output interface.
terraform-PROVIDER-NAME
The repository naming convention required for modules published to the public Terraform Registry.

Domain 6: Terraform state management (11%)

Exam tips

Key terms

State
Terraform's record mapping resources in configuration to real objects, with their attributes and metadata.
Local backend
The default backend, which stores state in a file on the local disk.
terraform.tfstate
The JSON state file the local backend writes in the working directory.
terraform.tfstate.backup
A copy of the previous state that the local backend writes before replacing terraform.tfstate.
State locking
A backend feature that allows only one state-writing Terraform operation at a time to prevent corruption.
-lock-timeout
A flag that makes Terraform retry acquiring a held lock for a given duration before failing.
terraform force-unlock
Manually removes a stale lock using its lock ID; for use only when no operation is running.
Lock ID
The identifier shown in a lock error that force-unlock needs to release that specific lock.
Backend
The component that determines where Terraform state is stored and whether it can be locked.
backend block
A block inside terraform {} that selects a backend type and sets its arguments; only one per root module.
Remote backend
A backend that stores state in a shared service such as S3, Azure Storage, GCS, Consul or PostgreSQL.
key (s3/azurerm)
The path or blob name under which the state file is stored in the bucket or container.
Partial configuration
Leaving some backend arguments out of the backend block and supplying them at terraform init time.
-backend-config
An init flag that supplies backend settings, either as KEY=VALUE pairs or as a path to a configuration file.
Backend configuration file
An HCL file of backend arguments passed with -backend-config, often named with a .tfbackend suffix.
Early evaluation
The reason backends cannot use variables: backends are initialized before variables and locals are evaluated.
terraform init -migrate-state
Re-initializes with a changed backend and copies existing state from the old backend to the new one.
terraform init -reconfigure
Re-initializes with a changed backend while ignoring the previous backend settings and without migrating state.
-force-copy
An init flag that automatically answers yes to state migration prompts.
terraform state pull
Outputs the current state from the configured backend, useful for taking a backup before migration.
cloud block
A block inside terraform {} that connects a configuration to HCP Terraform or Terraform Enterprise for state and runs.
organization
The cloud block argument naming the HCP Terraform organization that owns the workspaces.
workspaces { name / tags }
The nested block that maps the configuration to one workspace by name or to several by tags.
Execution mode
A workspace setting that decides whether runs execute remotely in HCP Terraform, locally, or on agents.
Secrets in state
The fact that Terraform stores resource attributes, including passwords and keys, in state in plain text.
Encryption at rest
Protection of stored state by the backend's storage service, such as S3 server-side encryption.
Access control
IAM or platform permissions that restrict who can read or write the state storage.
terraform_remote_state
A data source that reads root outputs from another configuration's state, requiring access to that state.
Drift
A difference between real infrastructure and the state Terraform last recorded, usually from changes made outside Terraform.
Refresh
The step where Terraform reads the current state of managed objects from providers before planning.
-refresh-only
A plan or apply mode that only updates state to match real infrastructure, without changing any resources.
ignore_changes
A lifecycle setting that tells Terraform to ignore changes to specific attributes when planning.
CLI workspace
A named, separate state for the same configuration and backend, managed with terraform workspace commands.
default workspace
The workspace every configuration starts in; it cannot be deleted.
terraform.workspace
An expression that returns the name of the current workspace for use in configuration.
terraform.tfstate.d
The directory where the local backend stores state for non-default workspaces.

Domain 7: Maintain infrastructure with Terraform (8%)

Exam tips

Key terms

import block
A declarative block with to and id that tells Terraform to bring an existing object under a resource address during plan and apply.
Import ID
The provider-specific identifier of an existing object, such as an instance ID or bucket name.
-generate-config-out
A terraform plan flag that writes generated HCL for import targets that lack resource blocks into a new file.
Adopting infrastructure
Bringing manually created resources under Terraform management without recreating them.
terraform import
A CLI command that immediately writes an existing object into state at a given resource address.
ADDRESS
The resource address in configuration that the imported object will be bound to.
Prerequisite resource block
The resource block that must already exist in configuration before terraform import can succeed.
Post-import plan
Running terraform plan after import and adjusting configuration until no changes are shown.
terraform state list
Lists the addresses of all resources in state, optionally filtered by an address prefix.
terraform state show
Shows all recorded attributes of one resource instance in state.
terraform show
Shows the whole state, or a saved plan file, in human-readable or JSON form.
terraform output
Prints root module output values from state, with -json and -raw options for scripting.
moved block
A configuration block with from and to that records a change of address so Terraform updates state instead of replacing the object.
terraform state mv
A CLI command that immediately changes the address of an object in state.
Refactoring
Restructuring configuration (renaming, moving into modules) without changing the real infrastructure.
Resource address
The identifier Terraform uses to track an object, such as module.app.aws_instance.web[0].
removed block
A configuration block that tells Terraform to stop managing an address, destroying it or not according to lifecycle destroy.
destroy = false
The removed block lifecycle setting that removes the object from state while leaving the real infrastructure in place.
terraform state rm
A CLI command that immediately deletes a resource entry from state without affecting the real object.
Unmanaged resource
A real object that exists but is not tracked in any Terraform state.
TF_LOG
Environment variable that enables Terraform logging at TRACE, DEBUG, INFO, WARN, ERROR or JSON level.
TF_LOG_PATH
Environment variable that writes (appends) log output to a file instead of standard error.
TF_LOG_CORE
Environment variable that sets the log level for Terraform core only.
TF_LOG_PROVIDER
Environment variable that sets the log level for provider plugins only.
Provider error
A failure in a provider plugin or the remote API it calls, often diagnosed with provider logs.
Crash (panic)
An unexpected termination of Terraform or a plugin that prints a stack trace and should be reported with logs.
terraform version
Command that shows the Terraform version and installed provider versions, needed for bug reports.
Minimal reproduction
The smallest configuration that still shows the problem, included in a bug report.
terraform output -json
Prints root outputs as JSON with value, type and sensitive fields, revealing sensitive values.
terraform graph
Prints the dependency graph of the configuration or plan in DOT format.
DOT / Graphviz
A graph description language and the toolset (including the dot command) that renders it as an image.
Implicit dependency
A dependency Terraform infers from an expression referencing another resource's attributes.

Domain 8: HCP Terraform (10%)

Exam tips

Key terms

HCP Terraform
HashiCorp's hosted service (formerly Terraform Cloud) for remote state, remote runs and team collaboration with Terraform.
Terraform Enterprise
The self-hosted distribution of HCP Terraform for organizations that run it on their own infrastructure.
Remote run
A Terraform plan or apply executed on HCP Terraform workers, with output shown in the UI and CLI.
State version history
The record of every state saved in a workspace, which can be viewed and used for recovery.
terraform login
A command that obtains an HCP Terraform API token through the browser and stores it locally for the CLI.
credentials.tfrc.json
The local file where terraform login stores API tokens in plain text.
TF_TOKEN_hostname
An environment variable that supplies an API token for a given host, such as TF_TOKEN_app_terraform_io.
Workspace tags mapping
Using tags in the cloud block so one configuration maps to multiple HCP Terraform workspaces.
VCS-driven workflow
A workspace connected to a repository branch, where commits trigger runs and pull requests trigger speculative plans.
CLI-driven workflow
Runs started from the local terraform CLI that upload configuration and execute remotely in HCP Terraform.
API-driven workflow
Runs started by external tools that upload configuration versions and create runs through the HCP Terraform API.
Speculative plan
A plan-only run that shows proposed changes but can never be applied, used for pull request checks.
HCP Terraform workspace
A container for one infrastructure collection with its own state, variables, run history, settings and permissions.
Run history
The recorded list of a workspace's plans and applies with logs, triggers and resulting state versions.
Auto-apply
A workspace setting that applies successful plans automatically instead of waiting for manual confirmation.
Remote state sharing
A workspace setting that controls which other workspaces may read its outputs.
Project
An HCP Terraform container that groups related workspaces for organization and access control.
Default project
The project new workspaces are placed in when no other project is specified.
Project-level team access
Permissions granted to a team on a project that apply to all its current and future workspaces.
Organization
The top-level HCP Terraform container that holds projects, workspaces, teams and settings.
Terraform variable (category)
A workspace variable that sets a Terraform input variable declared in the configuration.
Environment variable (category)
A workspace variable exported into the run's shell, used for provider credentials and Terraform settings.
Sensitive variable
A write-only variable whose value cannot be viewed after saving but is available to runs.
Variable set
A reusable group of variables applied to selected workspaces, projects or the whole organization.
Owners team
The built-in team with full administrative control of an HCP Terraform organization.
Sentinel
HashiCorp's policy-as-code framework with advisory, soft-mandatory and hard-mandatory enforcement levels.
OPA (Open Policy Agent)
An open-source policy engine using the Rego language, supported in HCP Terraform with advisory and mandatory levels.
Private registry
An organization-only registry for sharing approved modules and providers with versioning.
Health assessment
An automatic, scheduled HCP Terraform check of a workspace for drift and failing conditions.
Drift detection
The part of health assessments that uses refresh-only plans to find changes made outside Terraform.
Continuous validation
The part of health assessments that re-evaluates check blocks and pre/postconditions between runs.
Drifted workspace
A workspace whose real infrastructure no longer matches its stored state.
Run trigger
A link that automatically queues a run in a workspace after a source workspace applies successfully.
Run task
An integration that sends run data to an external service at a set stage and can block the run on failure.
Notification configuration
A workspace setting that sends run and health events to email, chat tools or webhooks.
Dynamic provider credentials
Short-lived cloud credentials obtained per run by exchanging an HCP Terraform OIDC workload identity token.
Study Terraform Associate for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Terraform Associate study plan