All certifications / Terraform Associate / Lessons
Terraform Associate Terraform Associate (004) lessons
Study Terraform Associate for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Terraform Associate study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Infrastructure as Code (IaC) with Terraform
- What IaC is: infrastructure defined in version-controlled, machine-readable files instead of manual console changes
- Advantages of IaC: repeatability, consistency, code review, audit history, automation, fewer configuration errors
- Declarative (describe the end state) vs imperative (list the steps) approaches
- Idempotence: applying the same configuration twice makes no further changes
- Terraform's plugin model: one workflow and language (HCL) for many providers
- Multi-cloud and hybrid-cloud deployments from a single configuration
- Service-agnostic workflows: managing SaaS, DNS, Git, Kubernetes and monitoring tools with providers
- Terraform vs configuration management tools: provisioning infrastructure vs configuring software inside servers
- Immutable infrastructure: replace rather than patch in place
Domain 2: Terraform fundamentals
- Installing Terraform and pinning its version with `required_version`
- The `required_providers` block: `source` addresses (hostname/namespace/type) and `version` constraints
- Version constraint operators: `=`, `!=`, `>=`, `<=`, and the pessimistic `~>`
- The dependency lock file `.terraform.lock.hcl`: what it records and why it is committed
- How providers work: plugins that call APIs, downloaded by `terraform init` from the Terraform Registry
- Provider tiers in the registry: official, partner and community
- Provider configuration blocks, multiple configurations with `alias`, and the `provider` meta-argument
- Using several different providers in one configuration
- What state is for: mapping configuration to real objects, tracking metadata and dependencies, speeding up plans
- State contents: resource attributes, including sensitive values, in plain JSON
Domain 3: Core Terraform workflow
- The Write → Plan → Apply workflow for individuals and teams
- `terraform init`: backend setup, provider and module download, `-upgrade`, `-migrate-state`, `-reconfigure`, `-backend-config`
- `terraform validate`: syntax and internal consistency checks without contacting provider APIs
- `terraform plan`: refresh, diff and symbols (`+`, `-`, `~`, `-/+`), saved plans with `-out`
- Planning options: `-var`, `-var-file`, `-target`, `-refresh=false`, `-refresh-only`, `-replace`
- `terraform apply`: interactive approval, `-auto-approve`, applying a saved plan file
- `terraform destroy` and `terraform plan -destroy`
- `terraform fmt`: canonical style, `-check`, `-diff` and `-recursive`
- Resource replacement with `-replace` instead of the deprecated `terraform taint`
- Parallelism and the dependency graph during apply
Domain 4: Terraform configuration
- Resource blocks vs data blocks, and addressing them (`TYPE.NAME`, `data.TYPE.NAME`)
- Cross-resource references and implicit dependencies
- Input variables: `type`, `default`, `description`, `sensitive`, `nullable`, and value precedence (TF_VAR_, tfvars, auto.tfvars, -var)
- Output values and local values
- Complex types: list, map, set, object, tuple; type conversion
- Expressions: conditionals, `for` expressions, splat `[*]`, string templates, `dynamic` blocks
- Built-in functions and testing them in `terraform console`
- `count` vs `for_each`, `count.index`, `each.key` and `each.value`
- Explicit dependencies with `depends_on`; `lifecycle` rules: `create_before_destroy`, `prevent_destroy`, `ignore_changes`, `replace_triggered_by`
- Custom conditions: variable `validation`, `precondition` and `postcondition`, and `check` blocks
- Sensitive data: `sensitive` values, ephemeral variables and resources, write-only arguments, secrets in state
- Secrets management with HashiCorp Vault and the Vault provider
Domain 5: Terraform modules
- Root module vs child modules; a module is any directory of .tf files
- Module sources: local paths (`./` or `../`), the public Terraform Registry, private registries, Git and HTTP URLs
- Calling a module with a `module` block and passing input variables
- Variable scope: child modules only see values passed in; outputs are read as `module.NAME.OUTPUT`
- Passing provider configurations to modules with the `providers` argument
- The `version` argument (registry sources only) and `ref` for Git sources
- `terraform init` or `terraform get` to install modules into `.terraform/modules`
- Using `count` and `for_each` on module blocks
- Standard module structure: main.tf, variables.tf, outputs.tf, README
Domain 6: Terraform state management
- The default local backend and the `terraform.tfstate` file, `terraform.tfstate.backup`
- State locking: why it prevents corruption, which backends support it, `-lock-timeout` and `terraform force-unlock`
- The `backend` block inside `terraform {}`: remote backends such as S3, azurerm, gcs, consul and pg
- Backend blocks cannot use variables; partial configuration with `-backend-config`
- Migrating state between backends with `terraform init -migrate-state`
- The `cloud` block for HCP Terraform
- Sensitive data in state and protecting remote state (encryption, access control)
- Resource drift: detecting it with `plan` and `apply -refresh-only`, reconciling configuration
- CLI workspaces: `terraform workspace new/select/list`, `terraform.workspace`
Domain 7: Maintain infrastructure with Terraform
- Importing existing infrastructure with `import` blocks and generating configuration with `terraform plan -generate-config-out`
- The older `terraform import` CLI command
- Inspecting state: `terraform state list`, `terraform state show`, `terraform show`, `terraform output`
- Refactoring: `moved` blocks and `terraform state mv`
- Removing resources from state without destroying them: `removed` blocks and `terraform state rm`
- Verbose logging with `TF_LOG` (TRACE, DEBUG, INFO, WARN, ERROR, JSON), `TF_LOG_PATH`, `TF_LOG_CORE` and `TF_LOG_PROVIDER`
- When to use logs: provider errors, crashes and bug reports
- Reviewing outputs and dependencies with `terraform output -json` and `terraform graph`
Domain 8: HCP Terraform
- HCP Terraform (formerly Terraform Cloud): remote state, remote runs, a free tier and paid tiers
- Connecting the CLI: `terraform login` and the `cloud` block (organization, workspaces by name or tags)
- Workflows: VCS-driven, CLI-driven and API-driven runs
- Workspaces: each holds its own state, variables, run history and permissions
- Projects: grouping workspaces and assigning team access at the project level
- Variables and variable sets; Terraform vs environment variables; sensitive variables
- Collaboration and governance: teams and permissions, run approvals, policy as code (Sentinel and OPA), private registry
- Health assessments: drift detection and continuous validation
- Integrations: VCS providers, run triggers, run tasks, notifications, dynamic provider credentials