All certifications / Terraform Associate / Cheat sheet
Terraform Associate Terraform Associate (004) cheat sheet
Domain 1: Infrastructure as Code (IaC) with Terraform (8%)
Exam tips
- Exam questions define IaC by its properties: code stored in version control and applied by a tool. If an answer describes documenting manual steps or scripting console clicks without a source of truth, it is not the IaC benefit being asked about.
- If a question asks which IaC benefit lets you see who changed infrastructure and when, the answer is version control and audit history; if it asks about identical dev and prod, the answer is consistency.
- The exam words it as 'Terraform is declarative: you describe the desired end state.' If an answer says Terraform executes your steps in the order you wrote them, it is wrong; block order in files does not matter.
- Expect a true/false question along the lines of 'running terraform apply twice with no configuration changes will create duplicate resources.' That is false: Terraform is idempotent and the second run makes no changes.
- If asked which component contains the code that talks to a cloud API, the answer is the provider, not Terraform core. Core handles language, graph, state and workflow.
- Exam questions contrast Terraform with CloudFormation or ARM templates: the Terraform advantage is managing many providers, including multiple clouds, with one workflow. It is not that the same resource block works on every cloud.
- If a question asks whether Terraform can manage things like GitHub teams, DNS records or monitoring dashboards, the answer is yes, provided a provider exists for the service's API.
- When the exam asks which tool is best for creating cloud networks and instances, pick Terraform; for managing packages and files inside running servers, pick configuration management. Provisioners are a last resort.
- Know that Terraform's default replacement order is destroy then create, and that
create_before_destroyreverses it. In plan output,-/+means replace (destroy then create), while+/-means create then destroy.
Key terms
- Infrastructure as Code (IaC)
- Managing infrastructure through machine-readable definition files that a tool applies, instead of manual changes.
- Configuration
- In Terraform, the set of
.tffiles in a directory that together describe the desired infrastructure. - HCL
- HashiCorp Configuration Language, the declarative language Terraform configurations are written in.
- Configuration drift
- Differences that build up between environments or between the recorded design and reality, usually from untracked manual changes.
- ClickOps
- Informal name for provisioning infrastructure by hand through a web console.
- Repeatability
- The ability to produce the same infrastructure again from the same code and inputs.
- Consistency
- Environments built from the same definitions match each other, reducing works-in-staging-but-not-production surprises.
- Audit trail
- The record, from version control and pipeline logs, of who changed infrastructure, when and why.
- CI/CD
- Continuous integration and continuous delivery; automated pipelines that test and deploy changes.
- Declarative
- Describing the desired end state and letting the tool determine the steps to reach it.
- Imperative
- Specifying the exact sequence of commands or steps to perform.
- Desired state
- The infrastructure described by the configuration, which Terraform tries to make real.
- Provisioner
- A Terraform feature that runs scripts or commands during resource creation or destruction; recommended only as a last resort.
- Idempotence
- The property that repeating an operation produces the same result as doing it once, with no further changes.
- Drift
- A difference between real infrastructure and what the configuration and state describe, usually from manual changes.
- Refresh
- The part of planning where Terraform reads the current attributes of managed objects from the provider.
- Perpetual diff
- A change that appears in every plan because a value is non-deterministic or normalized differently by the API.
- Terraform core
- The main Terraform binary that parses configuration, builds the dependency graph, manages state and drives the workflow.
- Provider
- A plugin that lets Terraform manage a specific platform or service by translating requests into its API calls.
- Plugin
- A separate executable that core launches and talks to over RPC; providers are plugins.
- Data source
- A read-only lookup, supplied by a provider, that fetches information about existing objects.
- Multi-cloud
- Using two or more public cloud providers together.
- Hybrid cloud
- Combining public cloud services with private or on-premises infrastructure.
- Native IaC tool
- A cloud vendor's own provisioning tool, such as CloudFormation or ARM templates, which only manages that vendor's resources.
- Cross-provider reference
- An expression in one provider's resource that uses an attribute from another provider's resource, creating an implicit dependency.
- Service-agnostic
- Able to manage any service that exposes an API, as long as a provider exists for it.
- Terraform Registry
- The public catalog where providers and modules are published and from which
terraform initdownloads them by default. - Utility provider
- A provider such as
random,local,tlsorhttpthat supports configurations without managing a cloud platform. - Branch protection
- Git platform rules, such as required reviews, that can be codified with a Git provider.
- Provisioning
- Creating and managing infrastructure resources themselves, such as servers and networks, typically through APIs.
- Configuration management
- Installing and maintaining software and settings inside existing servers, as done by Ansible, Chef, Puppet or Salt.
- cloud-init / user_data
- A mechanism for passing a first-boot script or configuration to a new virtual machine.
- Immutable infrastructure
- A practice where deployed components are never modified; changes are made by replacing them with new versions.
- Mutable infrastructure
- Servers that are updated and patched in place over their lifetime.
- Snowflake server
- A server whose configuration has drifted into something unique and hard to reproduce.
- Golden image
- A pre-built, versioned machine image containing the OS and software, used to launch identical instances.
- create_before_destroy
- A lifecycle setting that makes Terraform create the replacement before destroying the original.
Domain 2: Terraform fundamentals (11%)
Exam tips
- Remember the split:
required_versionpins the Terraform CLI;required_providerspins providers. Neither accepts variables, because theterraformblock only takes literal values. - If a question shows
source = "hashicorp/aws"and asks for the full address, the hidden default hostname isregistry.terraform.io. - Upper bound rule for
~>: remove the last written component and add one to the new last component.~> 2.1.3means < 2.2.0;~> 2.1means < 3.0. - Lock file: commit it.
.terraform/directory: do not commit it. And the lock file covers providers, not modules. - Providers are installed by
terraform init, not by plan or apply, and by default come from the public Terraform Registry. Adding or changing a provider always requires running init again. - The namespace is the quick clue:
hashicorp/...means official. Partner providers are maintained by the technology company that owns the API; community providers by individuals or groups. - The reference is
aws.west, not"aws.west"and notaws-west. Resources without aproviderargument use the default (unaliased) configuration. - You do not need a separate configuration or command per provider. One configuration, one init and one apply can manage all of them, and references between them create dependencies automatically.
- If asked for the primary purpose of state, choose mapping resources in configuration to real-world objects. Metadata such as dependencies and performance caching are the other listed purposes.
sensitive = truehides values from output, not from state. The correct protection for secrets in state is a secure, encrypted, access-controlled backend, plus ephemeral values or write-only arguments where available.
Key terms
- terraform block
- The top-level block for settings about Terraform itself, such as
required_version,required_providersandbackend. - required_version
- A version constraint that the running Terraform CLI must satisfy, or commands fail.
- terraform version
- Command that prints the installed Terraform version, platform and, in an initialized directory, provider versions.
- Version constraint
- A string of one or more conditions, such as
>= 1.12.0, < 2.0.0, that a version must meet. - required_providers
- Block inside
terraformthat declares each provider's local name, source address and version constraint. - Source address
- The
HOSTNAME/NAMESPACE/TYPEidentifier telling Terraform where to download a provider. - Namespace
- The publisher part of a source address, such as
hashicorpor a company or user name. - Local name
- The module-specific name for a provider, used in provider blocks and matched to resource type prefixes.
- Semantic versioning
- Versioning scheme MAJOR.MINOR.PATCH where major changes may break compatibility, minor adds features and patch fixes bugs.
- Pessimistic constraint (~>)
- Allows only the rightmost specified version component to increase.
- Exact constraint (=)
- Allows only one specific version; also the only way to select a pre-release.
- Exclusion (!=)
- Rejects a specific version while allowing others permitted by the remaining conditions.
- Dependency lock file
.terraform.lock.hcl, which records the exact provider versions and package checksums selected byterraform init.- terraform init -upgrade
- Re-selects the newest provider (and module) versions allowed by constraints and updates the lock file.
- Checksum (hash)
- A fingerprint of a provider package used to verify that the downloaded file is the expected one.
- .terraform directory
- Local working directory where init stores downloaded providers and modules; not committed.
- Provider schema
- The provider's definition of its resource types, data sources, arguments and attributes.
- Plugin cache
- An optional shared directory where init stores provider packages so they can be reused across working directories.
- Provider mirror
- A local or network copy of provider packages used instead of the public registry, for example on isolated networks.
- Computed attribute
- A value set by the provider or platform after creation, such as an ID, rather than by your configuration.
- Official provider
- Provider owned and maintained by HashiCorp, published under the
hashicorpnamespace. - Partner provider
- Provider written and maintained by a third-party company in HashiCorp's Technology Partner Program, published under the company's namespace.
- Community provider
- Provider published by individuals or groups in the community, with no HashiCorp or vendor support guarantee.
- Archived provider
- A provider that is no longer maintained, kept available so existing configurations still work.
- provider block
- Configuration for a provider, such as region, endpoint or authentication settings, normally placed in the root module.
- alias
- An argument that names an additional, non-default configuration of the same provider.
- provider meta-argument
- An argument on a resource or data block, like
provider = aws.west, that selects a specific provider configuration. - Meta-argument
- An argument handled by Terraform itself and usable on any resource type, such as
count,for_each,depends_on,providerandlifecycle. - Resource type prefix
- The part of a resource type before the first underscore, such as
dockerindocker_container, which selects the provider. - terraform providers
- Command that shows the providers required by the configuration and its modules.
- Dependency graph
- Terraform's internal map of which objects depend on which, used to order operations across all providers.
- Partial apply
- An apply that stops after some changes succeed; state records completed work so the next run can continue.
- State
- Terraform's record of the real objects it manages, their attributes and metadata, stored in
terraform.tfstateor a remote backend. - Resource address
- The identifier of a resource in configuration and state, such as
aws_instance.webormodule.net.aws_vpc.main. - Backend
- Where Terraform stores state, such as local disk, HCP Terraform or a cloud storage service.
- State locking
- A mechanism that prevents concurrent operations from writing the same state at once.
- terraform.tfstate
- The default local state file, a JSON document recording managed resources and their attributes.
- sensitive
- A flag on variables and outputs that redacts values in CLI output; the values are still stored in state.
- Ephemeral value
- A value that exists only during a Terraform run and is never persisted to state or plan files.
- Serial and lineage
- State metadata: the serial increments on each write, and the lineage identifies a single state's history.
Domain 3: Core Terraform workflow (19%)
Exam tips
- Know the order and purpose: Write (code), Plan (preview and review), Apply (provision). In teams the plan is reviewed alongside the code before anything is applied.
-migrate-statemoves state to the new backend;-reconfiguredoes not.-upgradechanges provider and module versions. None of init's options change real infrastructure.- Validate does not contact provider APIs or remote state, and does not need variable values, but it does need
terraform initfirst. Errors like a nonexistent image ID are caught only at plan or apply. - Memorize the symbols:
+create,-destroy,~update in place,-/+replace (destroy first),+/-replace (create first),<=read. Plan never changes infrastructure, though it does refresh from providers. -refresh=falseskips checking reality;-refresh-onlydoes only that check and updates state.terraform refreshis deprecated in favor ofapply -refresh-only.- Applying a saved plan file does not prompt for approval and does not accept new variables. Without a plan file, apply prompts unless
-auto-approveis used, and only the exact wordyesproceeds. terraform destroyequalsterraform apply -destroy.terraform plan -destroyonly previews. To remove one resource in normal work, delete its block and apply rather than using destroy with-target.- fmt only processes the current directory unless you add
-recursive, and-checknever writes files. fmt checks style, not correctness. - If a question asks for the recommended way to force recreation of a resource, choose
terraform apply -replace=ADDRESS, notterraform taint, which is deprecated. - Parallelism defaults to 10 and changes how many operations run at once, never the order. Order comes from the graph: implicit references plus
depends_on, reversed for destroy.
Key terms
- Core workflow
- Terraform's Write, Plan and Apply cycle for changing infrastructure.
- Speculative plan
- A plan run for review only, such as on a pull request, that cannot be applied.
- Remote backend
- Shared state storage, such as HCP Terraform, that lets a team use one state safely with locking.
- Pull request
- A request to merge code changes that lets teammates review them, often with plan output attached.
- terraform init
- Command that initializes a working directory: configures the backend and installs modules and providers.
- -migrate-state
- Init option that copies existing state to a newly configured backend.
- -reconfigure
- Init option that configures the backend fresh, ignoring saved settings and not migrating state.
- Partial configuration
- Leaving backend settings out of code and supplying them with
-backend-configat init time. - terraform validate
- Command that checks configuration syntax and internal consistency without contacting remote services.
- Internal consistency
- Whether references, argument names, types and required arguments in the configuration agree with each other and with provider schemas.
- Provider schema
- The provider's list of resource types, arguments and types, needed by validate and obtained by
terraform init. - -json
- Option that outputs validation results in a machine-readable format.
- Execution plan
- Terraform's preview of the create, update, replace and destroy actions needed to match the configuration.
- -/+ (replace)
- Plan symbol meaning the existing object will be destroyed and a new one created.
- (known after apply)
- Plan annotation for values the provider will only determine when the change is carried out.
- Saved plan
- A plan written with
-out=FILEthat can be applied later exactly as reviewed. - -var / -var-file
- Options that set input variable values on the command line or from a file; highest precedence, last one wins.
- -target
- Limits planning to specific resources or modules and their dependencies; for exceptional use only.
- -refresh-only
- Plan or apply mode that updates state to match real infrastructure without changing that infrastructure.
- -replace
- Forces replacement of a specific resource instance in the plan.
- terraform apply
- Command that carries out a plan to create, update or destroy infrastructure and records the results in state.
- -auto-approve
- Skips the interactive
yesconfirmation; intended for automation with approval elsewhere. - Stale plan
- A saved plan whose state has changed since it was created; Terraform refuses to apply it.
- Tainted
- State marking for a resource that is known to be damaged, such as after a failed creation, so it will be replaced.
- terraform destroy
- Command that destroys all resources managed by the configuration; an alias for
terraform apply -destroy. - plan -destroy
- Creates a destroy plan to preview, and optionally save, without destroying anything.
- Reverse dependency order
- Destroy removes dependents before the objects they depend on.
- prevent_destroy
- Lifecycle setting that makes any plan that would destroy the resource fail.
- terraform fmt
- Command that rewrites configuration files into Terraform's canonical style without changing meaning.
- -check
- fmt option that reports unformatted files and exits nonzero without modifying them.
- -diff
- fmt option that displays the formatting differences.
- -recursive
- fmt option that also processes files in subdirectories.
- terraform taint
- Deprecated command that marked a resource in state for replacement on the next apply.
- terraform untaint
- Command that removes a tainted mark from a resource in state.
- Tainted resource
- A resource marked in state as damaged, usually after a failed create or provisioner, that will be replaced.
- Dependency graph
- Directed acyclic graph of configuration objects that Terraform uses to order operations.
- -parallelism
- Option setting the maximum number of concurrent operations during plan, apply or destroy; the default is 10.
- terraform graph
- Command that outputs the dependency graph in DOT format for visualization.
- Cycle
- A circular dependency between objects that makes the graph impossible to order; Terraform reports it as an error.
Domain 4: Terraform configuration (22%)
Exam tips
- Data sources are addressed with the
data.prefix and are never destroyed by Terraform. If an exam question asks how to use an existing object that Terraform should not manage, the answer is a data source. - Terraform orders operations using references, not file order. If a question asks how Terraform knows to create the network before the subnet, the answer is the implicit dependency from
aws_vpc.main.id. - Precedence from low to high: TF_VAR_ environment variables, terraform.tfvars, terraform.tfvars.json, *.auto.tfvars in lexical order, then -var and -var-file. Files not named with those patterns load only through -var-file.
- The block is
localsbut the reference islocal.name. Child module values are reachable only through outputs, asmodule.NAME.OUTPUT_NAME. - Lists are ordered and indexed; sets are unordered and unique; maps have string keys. Objects and tuples are the structural versions allowing mixed types.
for_eachneeds a map or set, so convert lists withtoset(). - Know which brackets produce what:
[for ...]gives a list or tuple,{for ... : k => v}gives a map or object. Splat works on lists, not maps, anddynamicgenerates nested blocks, not resources. - Terraform does not support user-defined functions in HCL. To test function behavior, use
terraform console, which evaluates expressions without modifying infrastructure. for_eachaccepts maps and sets of strings, not lists, and gives stable keys.countindexes shift when items are removed from the middle. You cannot use both on one block.- Use
depends_ononly for hidden dependencies. Remember thatprevent_destroydoes not stop destruction if the whole resource block is removed, and that lifecycle values must be literals, not variables. - Remember severity: validation, precondition and postcondition failures are errors that stop the run, while a failed check block assertion is only a warning.
- The exam's favorite trap: sensitive only hides values from CLI output. It does not encrypt them or keep them out of the state file.
- Secrets read from Vault through a normal data source end up in Terraform state. Vault does not change that; protect the state and prefer short-lived or ephemeral secrets.
Key terms
- Resource block
- Declares an infrastructure object that Terraform creates, updates and destroys.
- Data block (data source)
- Declares a read-only lookup of existing information that Terraform reads but does not manage.
- Resource address
- The reference form
TYPE.NAMEfor resources anddata.TYPE.NAMEfor data sources, extended with module paths and instance keys. - Local name
- The second label of a resource or data block, chosen by you and unique per type within a module.
- Reference
- An expression that uses a value from another object, such as
aws_vpc.main.idorvar.region. - Implicit dependency
- An ordering relationship Terraform infers automatically from a reference between objects.
- Computed attribute
- An attribute set by the provider after creation, such as an ID, often shown as known after apply.
- moved block
- A block that tells Terraform a resource's address changed so it updates state instead of replacing the object.
- Input variable
- A module parameter declared with a
variableblock and referenced asvar.NAME. - TF_VAR_ environment variable
- An environment variable named
TF_VAR_<name>that sets a root module variable; lowest precedence. - terraform.tfvars
- Variable definitions file that Terraform loads automatically from the root module directory.
- nullable
- Variable setting (default true) controlling whether
nullis accepted; when false, null is replaced by the default. - sensitive
- Variable setting that redacts the value in CLI output but does not keep it out of state.
- Output value
- A named value a module exports, printed for the root module and accessed as
module.NAME.OUTPUTfor child modules. - Local value
- A named expression defined in a
localsblock and referenced aslocal.NAME, usable only inside its module. - terraform output
- Command that reads root module output values from state, with
-rawand-jsonoptions. - terraform_remote_state
- Data source that reads the root module outputs of another configuration's state.
- Collection type
- list, map or set: many values that all share the same element type.
- Structural type
- object or tuple: a fixed shape whose attributes or positions may have different types.
- set
- An unordered collection of unique values with no index.
- optional()
- Modifier in an object type that makes an attribute omittable, optionally with a default.
- Type conversion
- Automatic or function-based changing of a value to a compatible type, such as
toset()on a list. - Conditional expression
condition ? a : b, which chooses one of two values based on a boolean.- for expression
- An expression that builds a list or map by transforming, and optionally filtering, another collection.
- Splat expression
[*]shorthand that extracts one attribute from every element of a list, such asaws_instance.web[*].id.- String template
- A string with
${...}interpolation or%{...}directives. - dynamic block
- A construct that generates repeated nested blocks from a collection using
for_eachandcontent. - Built-in function
- A function supplied by Terraform, such as
joinorcidrsubnet, callable in expressions; user-defined functions are not supported. - terraform console
- Interactive command for evaluating expressions against the current configuration and state without making changes.
- lookup
- Function that returns a map value by key, or a default when the key is missing.
- cidrsubnet
- Function that calculates a subnet address range within a larger CIDR block.
- count
- Meta-argument that creates a number of instances addressed by integer index.
- count.index
- The zero-based index of the current instance in a
countblock. - for_each
- Meta-argument that creates one instance per element of a map or set, addressed by key.
- each.key / each.value
- In a
for_eachblock, the current element's key and value; identical for sets. - depends_on
- Meta-argument declaring an explicit dependency that no attribute reference expresses.
- create_before_destroy
- Lifecycle setting that creates the replacement object before destroying the old one.
- prevent_destroy
- Lifecycle setting that makes any plan destroying the resource fail with an error.
- ignore_changes
- Lifecycle setting listing attributes whose drift Terraform should not try to correct.
- replace_triggered_by
- Lifecycle setting that replaces the resource when referenced resources or attributes change.
- validation block
- A rule inside a variable block with a condition and error_message that rejects bad input values before planning.
- precondition
- A lifecycle (or output) condition evaluated before an object is created or changed; failure is an error that halts the run.
- postcondition
- A lifecycle condition evaluated after an object is created, updated or read; it can use self to inspect the result.
- check block
- A top-level block of assert conditions, optionally with a scoped data source, whose failures produce warnings instead of errors.
- sensitive = true
- Marks a variable or output so its value is redacted in CLI output; the value is still stored in state.
- Ephemeral variable
- A variable declared with ephemeral = true whose value is available during a run but never written to plan or state.
- Ephemeral resource
- An ephemeral block that obtains a temporary value (such as a secret or token) each run without persisting it.
- Write-only argument
- A resource argument that accepts a value and passes it to the provider but never stores it in plan or state, usually paired with a version argument.
- HashiCorp Vault
- A secrets management tool that stores, controls access to, audits and dynamically generates secrets.
- Dynamic secret
- A credential Vault generates on demand with a lease and revokes automatically when the lease expires.
- Vault provider
- The Terraform provider used to configure Vault and to read secrets from it through data sources or ephemeral resources.
- Lease
- The time period a Vault secret is valid for before it must be renewed or is revoked.
Domain 5: Terraform modules (11%)
Exam tips
- If a question asks what makes a directory a module, the answer is simply that it contains Terraform configuration files; the root module is whichever one you run commands from.
- Know the address shapes: ./ or ../ means local, three slash-separated parts mean public registry, a hostname plus three parts means private registry, and git:: or ?ref= means a Git source.
- Arguments in a module block (other than the meta-arguments) map one-to-one to the child's variable blocks; a missing required variable or an undeclared argument are both errors.
- Values move down only through module block arguments and up only through outputs; a child can never read the parent's var. values directly.
- Default provider configurations are inherited automatically; aliased ones never are and must be passed with the providers map on the module block.
- version is for registry modules only; Git modules pin with ?ref=. Also remember that the lock file does not pin module versions.
- Adding or changing a module source or version requires init (or get); changing only module input values does not. Never commit the .terraform directory.
- Prefer for_each over count when instances are distinct and may be removed individually; count indexes shift when an item in the middle is removed.
- File names are a convention, not a requirement: Terraform merges all .tf files in a directory, but the standard structure (main, variables, outputs, README) is what the registry and reviewers expect.
Key terms
- Module
- Any directory containing Terraform configuration files; Terraform treats all .tf files in it as one unit.
- Root module
- The module in the working directory where Terraform commands are run; the top of the module tree.
- Child module
- A module called by another module through a module block.
- Module address
- The path to a resource through the module tree, such as module.network.aws_subnet.private.
- source argument
- The required module block argument that tells Terraform where to find the module code.
- Registry source
- A module address in the form NAMESPACE/NAME/PROVIDER, prefixed with a hostname for private registries.
- Local path source
- A module path beginning with ./ or ../ that Terraform reads directly from disk without downloading.
- Double-slash subdirectory
- The // syntax in a source address that selects a subdirectory within a downloaded repository or archive.
- module block
- A block that calls a child module, giving it a local name, a source and values for its input variables.
- Input variable
- A variable declared in the child module that callers set as an argument in the module block.
- Required input
- A module variable without a default; callers must supply it or Terraform reports an error.
- Meta-arguments
- Arguments Terraform itself handles on a module block: source, version, count, for_each, providers and depends_on.
- Module scope
- The rule that each module has its own namespace and sees only its own variables, locals and resources.
- Output value
- A value a module exports with an output block, readable by its caller as module.NAME.OUTPUT.
- Re-exporting
- Declaring a root module output whose value is a child module output, so it appears in terraform output.
- TF_VAR_ environment variable
- An environment variable that sets a root module input variable; it does not reach child modules directly.
- Provider alias
- An extra, named configuration of a provider created with the alias meta-argument and referenced as PROVIDER.ALIAS.
- providers argument
- A map on a module block that assigns the caller's provider configurations to the provider names the child module uses.
- Implicit provider inheritance
- The default behavior where child modules automatically use the parent's default, unaliased provider configurations.
- configuration_aliases
- A required_providers setting in a child module that declares additional provider configuration names the caller must pass in.
- version argument
- A module block argument that sets a version constraint; valid only for registry module sources.
- ref parameter
- A query parameter in a Git source address that selects a tag, branch or commit to check out.
- Pessimistic constraint (~>)
- A version operator that allows only the rightmost specified component to increase, such as ~> 1.4 allowing 1.x from 1.4 up.
- Dependency lock file
- .terraform.lock.hcl, which records provider versions and hashes but not module versions.
- .terraform/modules
- The hidden directory in the working directory where Terraform stores downloaded module code and the modules.json manifest.
- terraform get
- A command that downloads and updates modules only, without initializing backends or providers.
- terraform init -upgrade
- Re-evaluates version constraints and installs the newest allowed module and provider versions.
- modules.json
- A manifest in .terraform/modules that records each module call's source, version and install directory.
- count on a module
- Creates a number of module instances addressed by index, such as module.web[0].
- for_each on a module
- Creates one module instance per map key or set element, addressed by key, such as module.web["blue"].
- each.key / each.value
- Values available inside a for_each block that identify the current element.
- Legacy module
- A module containing its own provider blocks; it cannot be used with count, for_each or depends_on.
- main.tf
- The conventional primary file of a module, holding its main resources and module calls.
- variables.tf
- The conventional file holding a module's input variable declarations, forming its input interface.
- outputs.tf
- The conventional file holding a module's output declarations, forming its output interface.
- terraform-PROVIDER-NAME
- The repository naming convention required for modules published to the public Terraform Registry.
Domain 6: Terraform state management (11%)
Exam tips
- No backend block means the local backend, which writes terraform.tfstate plus a single-step terraform.tfstate.backup in the working directory.
- Locking is automatic on supporting backends. force-unlock needs the lock ID and is a last resort; -lock-timeout waits for a lock instead of failing immediately.
- The backend block goes inside terraform {}, only in the root module, and any change to it requires running terraform init again.
- If a question shows var. inside a backend block, the answer is that it is not allowed; use -backend-config files or key/value pairs at init instead.
- To keep your resources tracked when changing backends, use -migrate-state; -reconfigure starts fresh with the new backend and copies nothing.
- The cloud block and a backend block are mutually exclusive; the cloud block selects workspaces by name (one) or tags (many) and can be overridden with TF_CLOUD_ORGANIZATION and TF_WORKSPACE.
- sensitive = true is not encryption. Protect state with an encrypted, access-controlled remote backend and keep it out of version control.
- apply -refresh-only updates state only and never changes infrastructure; to keep a manual change permanently you must also update the configuration.
- CLI workspaces separate state only, not credentials or backends; they are not recommended as the isolation boundary for production environments.
Key terms
- State
- Terraform's record mapping resources in configuration to real objects, with their attributes and metadata.
- Local backend
- The default backend, which stores state in a file on the local disk.
- terraform.tfstate
- The JSON state file the local backend writes in the working directory.
- terraform.tfstate.backup
- A copy of the previous state that the local backend writes before replacing terraform.tfstate.
- State locking
- A backend feature that allows only one state-writing Terraform operation at a time to prevent corruption.
- -lock-timeout
- A flag that makes Terraform retry acquiring a held lock for a given duration before failing.
- terraform force-unlock
- Manually removes a stale lock using its lock ID; for use only when no operation is running.
- Lock ID
- The identifier shown in a lock error that force-unlock needs to release that specific lock.
- Backend
- The component that determines where Terraform state is stored and whether it can be locked.
- backend block
- A block inside terraform {} that selects a backend type and sets its arguments; only one per root module.
- Remote backend
- A backend that stores state in a shared service such as S3, Azure Storage, GCS, Consul or PostgreSQL.
- key (s3/azurerm)
- The path or blob name under which the state file is stored in the bucket or container.
- Partial configuration
- Leaving some backend arguments out of the backend block and supplying them at terraform init time.
- -backend-config
- An init flag that supplies backend settings, either as KEY=VALUE pairs or as a path to a configuration file.
- Backend configuration file
- An HCL file of backend arguments passed with -backend-config, often named with a .tfbackend suffix.
- Early evaluation
- The reason backends cannot use variables: backends are initialized before variables and locals are evaluated.
- terraform init -migrate-state
- Re-initializes with a changed backend and copies existing state from the old backend to the new one.
- terraform init -reconfigure
- Re-initializes with a changed backend while ignoring the previous backend settings and without migrating state.
- -force-copy
- An init flag that automatically answers yes to state migration prompts.
- terraform state pull
- Outputs the current state from the configured backend, useful for taking a backup before migration.
- cloud block
- A block inside terraform {} that connects a configuration to HCP Terraform or Terraform Enterprise for state and runs.
- organization
- The cloud block argument naming the HCP Terraform organization that owns the workspaces.
- workspaces { name / tags }
- The nested block that maps the configuration to one workspace by name or to several by tags.
- Execution mode
- A workspace setting that decides whether runs execute remotely in HCP Terraform, locally, or on agents.
- Secrets in state
- The fact that Terraform stores resource attributes, including passwords and keys, in state in plain text.
- Encryption at rest
- Protection of stored state by the backend's storage service, such as S3 server-side encryption.
- Access control
- IAM or platform permissions that restrict who can read or write the state storage.
- terraform_remote_state
- A data source that reads root outputs from another configuration's state, requiring access to that state.
- Drift
- A difference between real infrastructure and the state Terraform last recorded, usually from changes made outside Terraform.
- Refresh
- The step where Terraform reads the current state of managed objects from providers before planning.
- -refresh-only
- A plan or apply mode that only updates state to match real infrastructure, without changing any resources.
- ignore_changes
- A lifecycle setting that tells Terraform to ignore changes to specific attributes when planning.
- CLI workspace
- A named, separate state for the same configuration and backend, managed with terraform workspace commands.
- default workspace
- The workspace every configuration starts in; it cannot be deleted.
- terraform.workspace
- An expression that returns the name of the current workspace for use in configuration.
- terraform.tfstate.d
- The directory where the local backend stores state for non-default workspaces.
Domain 7: Maintain infrastructure with Terraform (8%)
Exam tips
- import blocks are reviewed in plan and applied like other changes; -generate-config-out writes starter HCL into a file that must not already exist.
- terraform import needs the resource block to exist first, imports one object at a time and does not generate configuration; import blocks remove those limits.
- state list gives addresses, state show gives one resource's attributes, show gives everything (or a plan file), and output gives root outputs only.
- Renaming a resource without moved or state mv makes Terraform plan a destroy and create; moved is the reviewable, declarative choice.
- Deleting a resource block alone means destroy. To stop managing without deleting, use a removed block with destroy = false or terraform state rm.
- TRACE is the most verbose level, JSON outputs TRACE-level logs as JSON, and TF_LOG_PATH does nothing unless a log level is set.
- Use logs for provider errors and crashes; include terraform version output, a minimal configuration and a redacted TRACE log in bug reports.
- terraform output -json shows sensitive values in plain text; terraform graph outputs DOT, which you render with Graphviz.
Key terms
- import block
- A declarative block with to and id that tells Terraform to bring an existing object under a resource address during plan and apply.
- Import ID
- The provider-specific identifier of an existing object, such as an instance ID or bucket name.
- -generate-config-out
- A terraform plan flag that writes generated HCL for import targets that lack resource blocks into a new file.
- Adopting infrastructure
- Bringing manually created resources under Terraform management without recreating them.
- terraform import
- A CLI command that immediately writes an existing object into state at a given resource address.
- ADDRESS
- The resource address in configuration that the imported object will be bound to.
- Prerequisite resource block
- The resource block that must already exist in configuration before terraform import can succeed.
- Post-import plan
- Running terraform plan after import and adjusting configuration until no changes are shown.
- terraform state list
- Lists the addresses of all resources in state, optionally filtered by an address prefix.
- terraform state show
- Shows all recorded attributes of one resource instance in state.
- terraform show
- Shows the whole state, or a saved plan file, in human-readable or JSON form.
- terraform output
- Prints root module output values from state, with -json and -raw options for scripting.
- moved block
- A configuration block with from and to that records a change of address so Terraform updates state instead of replacing the object.
- terraform state mv
- A CLI command that immediately changes the address of an object in state.
- Refactoring
- Restructuring configuration (renaming, moving into modules) without changing the real infrastructure.
- Resource address
- The identifier Terraform uses to track an object, such as module.app.aws_instance.web[0].
- removed block
- A configuration block that tells Terraform to stop managing an address, destroying it or not according to lifecycle destroy.
- destroy = false
- The removed block lifecycle setting that removes the object from state while leaving the real infrastructure in place.
- terraform state rm
- A CLI command that immediately deletes a resource entry from state without affecting the real object.
- Unmanaged resource
- A real object that exists but is not tracked in any Terraform state.
- TF_LOG
- Environment variable that enables Terraform logging at TRACE, DEBUG, INFO, WARN, ERROR or JSON level.
- TF_LOG_PATH
- Environment variable that writes (appends) log output to a file instead of standard error.
- TF_LOG_CORE
- Environment variable that sets the log level for Terraform core only.
- TF_LOG_PROVIDER
- Environment variable that sets the log level for provider plugins only.
- Provider error
- A failure in a provider plugin or the remote API it calls, often diagnosed with provider logs.
- Crash (panic)
- An unexpected termination of Terraform or a plugin that prints a stack trace and should be reported with logs.
- terraform version
- Command that shows the Terraform version and installed provider versions, needed for bug reports.
- Minimal reproduction
- The smallest configuration that still shows the problem, included in a bug report.
- terraform output -json
- Prints root outputs as JSON with value, type and sensitive fields, revealing sensitive values.
- terraform graph
- Prints the dependency graph of the configuration or plan in DOT format.
- DOT / Graphviz
- A graph description language and the toolset (including the dot command) that renders it as an image.
- Implicit dependency
- A dependency Terraform infers from an expression referencing another resource's attributes.
Domain 8: HCP Terraform (10%)
Exam tips
- Terraform Cloud was renamed HCP Terraform; Terraform Enterprise is the self-hosted version. Avoid memorizing prices; know which features are core versus governance.
- terraform login stores a token in credentials.tfrc.json; in CI use TF_TOKEN_<host> instead. In the cloud block, workspaces use name (one) or tags (many), never both.
- Pull requests trigger speculative (plan-only) runs in the VCS workflow; merges to the tracked branch trigger real runs. VCS-connected workspaces do not accept CLI applies.
- HCP Terraform workspaces are full, separately permissioned environments (state, variables, runs, access); CLI workspaces only separate state.
- Hierarchy: organization contains projects, projects contain workspaces; each workspace is in exactly one project, and project-level access covers all its workspaces.
- Provider credentials go in environment variables, not Terraform variables. Sensitive variables are write-only; priority variable sets override workspace values.
- Policy checks run after plan and before apply. Know Sentinel's three levels: advisory warns, soft-mandatory can be overridden, hard-mandatory cannot.
- Health assessments only detect and report; they never change infrastructure or state. Drift detection equals a scheduled refresh-only plan.
- Match the feature: run triggers chain workspaces, run tasks call external checks, notifications send alerts, and dynamic provider credentials replace static cloud keys with per-run OIDC credentials.
Key terms
- HCP Terraform
- HashiCorp's hosted service (formerly Terraform Cloud) for remote state, remote runs and team collaboration with Terraform.
- Terraform Enterprise
- The self-hosted distribution of HCP Terraform for organizations that run it on their own infrastructure.
- Remote run
- A Terraform plan or apply executed on HCP Terraform workers, with output shown in the UI and CLI.
- State version history
- The record of every state saved in a workspace, which can be viewed and used for recovery.
- terraform login
- A command that obtains an HCP Terraform API token through the browser and stores it locally for the CLI.
- credentials.tfrc.json
- The local file where terraform login stores API tokens in plain text.
- TF_TOKEN_hostname
- An environment variable that supplies an API token for a given host, such as TF_TOKEN_app_terraform_io.
- Workspace tags mapping
- Using tags in the cloud block so one configuration maps to multiple HCP Terraform workspaces.
- VCS-driven workflow
- A workspace connected to a repository branch, where commits trigger runs and pull requests trigger speculative plans.
- CLI-driven workflow
- Runs started from the local terraform CLI that upload configuration and execute remotely in HCP Terraform.
- API-driven workflow
- Runs started by external tools that upload configuration versions and create runs through the HCP Terraform API.
- Speculative plan
- A plan-only run that shows proposed changes but can never be applied, used for pull request checks.
- HCP Terraform workspace
- A container for one infrastructure collection with its own state, variables, run history, settings and permissions.
- Run history
- The recorded list of a workspace's plans and applies with logs, triggers and resulting state versions.
- Auto-apply
- A workspace setting that applies successful plans automatically instead of waiting for manual confirmation.
- Remote state sharing
- A workspace setting that controls which other workspaces may read its outputs.
- Project
- An HCP Terraform container that groups related workspaces for organization and access control.
- Default project
- The project new workspaces are placed in when no other project is specified.
- Project-level team access
- Permissions granted to a team on a project that apply to all its current and future workspaces.
- Organization
- The top-level HCP Terraform container that holds projects, workspaces, teams and settings.
- Terraform variable (category)
- A workspace variable that sets a Terraform input variable declared in the configuration.
- Environment variable (category)
- A workspace variable exported into the run's shell, used for provider credentials and Terraform settings.
- Sensitive variable
- A write-only variable whose value cannot be viewed after saving but is available to runs.
- Variable set
- A reusable group of variables applied to selected workspaces, projects or the whole organization.
- Owners team
- The built-in team with full administrative control of an HCP Terraform organization.
- Sentinel
- HashiCorp's policy-as-code framework with advisory, soft-mandatory and hard-mandatory enforcement levels.
- OPA (Open Policy Agent)
- An open-source policy engine using the Rego language, supported in HCP Terraform with advisory and mandatory levels.
- Private registry
- An organization-only registry for sharing approved modules and providers with versioning.
- Health assessment
- An automatic, scheduled HCP Terraform check of a workspace for drift and failing conditions.
- Drift detection
- The part of health assessments that uses refresh-only plans to find changes made outside Terraform.
- Continuous validation
- The part of health assessments that re-evaluates check blocks and pre/postconditions between runs.
- Drifted workspace
- A workspace whose real infrastructure no longer matches its stored state.
- Run trigger
- A link that automatically queues a run in a workspace after a source workspace applies successfully.
- Run task
- An integration that sends run data to an external service at a set stage and can block the run on failure.
- Notification configuration
- A workspace setting that sends run and health events to email, chat tools or webhooks.
- Dynamic provider credentials
- Short-lived cloud credentials obtained per run by exchanging an HCP Terraform OIDC workload identity token.
Study Terraform Associate for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Terraform Associate study planLessons, quizzes, exam simulations and hands-on labs.