Master state locks recovery, drift management, resource graph logic, variables/secrets loading, reusable module designs, and dynamic blocks.
AR
Written by Ashmit N. Rai • Co-Founder & DevOps Platform EngineerDevOps specialist and platform automation architect. Infrastructure-as-Code expert.
Interactive Flashcards
# 1
Unreviewed
How does Terraform determine resource creation order? Does it provision them in parallel or sequentially?
Answer Guide
Terraform builds a Dependency Graph of all resources defined in the configuration. Resources that do not depend on each other are created in parallel (up to the default limit of 10 concurrent operations). If a resource depends on another (indicated by implicit references or the "depends_on" meta-argument), Terraform sequences those creation steps.
Key Concepts Checklist
Evaluate difficulty:
# 2
Unreviewed
How do you create 10 resources one by one if there are no native implicit dependencies?
Answer Guide
To force sequential creation of resources, you can use the "depends_on" meta-argument to chain the resources together sequentially. For example, Resource B depends_on [Resource A], Resource C depends_on [Resource B], and so on.
Key Concepts Checklist
Evaluate difficulty:
# 3
Unreviewed
How do you secure the Terraform state file (terraform.tfstate)?
Answer Guide
Store the state file in a remote backend (such as Amazon S3) with bucket encryption (AES-256) enabled, versioning turned on, and access restricted via IAM policies. Additionally, configure state locking using a database (like DynamoDB) to prevent concurrent runs from corrupting the state file.
Key Concepts Checklist
Evaluate difficulty:
# 4
Unreviewed
Explain the Terraform lifecycle, terraform refresh, and terraform import.
Answer Guide
The Terraform lifecycle determines how resources are created, updated, and destroyed. "terraform refresh" queries the real-world infrastructure provider APIs to update the state file with any external changes. "terraform import" brings existing real-world resources (created manually or via CLI) under Terraform control by writing their configuration details into the state file.
Key Concepts Checklist
Evaluate difficulty:
# 5
Unreviewed
What is Terraform drift, and how do you resolve it?
Answer Guide
Terraform drift occurs when the actual state of real-world infrastructure diverges from the state described in the Terraform configuration (e.g., manual edits via the AWS Console). To resolve, run "terraform plan" to view differences, and then either modify your code to match the infrastructure or run "terraform apply" to overwrite manual changes.
Key Concepts Checklist
Evaluate difficulty:
# 6
Unreviewed
If two people are working on the same Terraform module, how does it work?
Answer Guide
They must use a shared remote backend (like S3, Terraform Cloud, or Consul) that supports state locking. When Person A runs "terraform apply", a lock is acquired, preventing Person B from running plan/apply until Person A finishes, preventing race conditions and state corruption.
Key Concepts Checklist
Evaluate difficulty:
# 7
Unreviewed
How do you remove a Terraform lock file so the next person can apply?
Answer Guide
If a lock is stuck (often due to a crashed CI/CD process), you can release it by running "terraform force-unlock <lock-id>" using the Lock ID shown in the error message. Ensure first that no other team member is actively running Terraform.
Key Concepts Checklist
Evaluate difficulty:
# 8
Unreviewed
When you change a Terraform module (e.g., S3), what happens during the terraform plan?
Answer Guide
Terraform compares the updated module configuration in code with the existing resources in the state file. It generates an execution plan showing what will happen: green plus (+) for additions, yellow tilde (~) for in-place modifications, and red minus (-) for destructions/recreations due to changes in immutable arguments.
Key Concepts Checklist
Evaluate difficulty:
# 9
Unreviewed
How do you create 50 identical instances using Terraform efficiently?
Answer Guide
Use the "count" meta-argument or the "for_each" meta-argument in the resource block. "count" is simple for index-based replication (e.g., count = 50), while "for_each" is preferred when resources are defined by distinct keys or maps, preventing mass recreation if an item is removed from the middle.
Key Concepts Checklist
Evaluate difficulty:
# 10
Unreviewed
What is the "dynamic" block in Terraform and where is it used?
Answer Guide
A "dynamic" block allows you to programmatically generate nested configuration blocks (like multiple security group "ingress" rules or subnets) inside a resource based on a list or map variable, avoiding repetitive code.
Key Concepts Checklist
Evaluate difficulty:
# 11
Unreviewed
How do you securely store DB usernames and passwords in Terraform?
Answer Guide
Do not hardcode secrets in .tf files. Pass them as environment variables prefixed with "TF_VAR_" (e.g., TF_VAR_db_password), store them in a secure backend like AWS Secrets Manager and reference them using data sources, or integrate HashiCorp Vault. Mark variables as "sensitive = true" to mask them in console output.
Key Concepts Checklist
Evaluate difficulty:
# 12
Unreviewed
What is the difference between terraform destroy and terraform taint?
Answer Guide
"terraform destroy" permanently deletes all infrastructure managed by the current configuration. "terraform taint" marks a single resource as degraded or out of sync, forcing Terraform to delete and recreate that specific resource during the next "terraform apply".
Key Concepts Checklist
Evaluate difficulty:
Scenario Challenges
Select a scenario below to test your troubleshooting workflow.
Topic: State Lock Recovery
A Jenkins pipeline step crashed during a terraform apply, leaving the S3 remote state locked. Release the lock safely.
Locate the Lock ID from the failed pipeline execution console output logs.Click to select
Confirm with the team that no one is currently running a local plan or apply.Click to select
Execute terraform force-unlock <lock-id> to remove the lock from the DynamoDB table.Click to select
Selected Sequence
No steps selected yet. Click options above in sequence.
Topic: Syncing Console Drift
A developer manually added port 443 to a Security Group via the AWS Console. Bring this change into your Terraform code.
Run terraform plan to identify the specific attributes that have drifted from your code.Click to select
Add the port 443 ingress rule block inside the security group definition in your .tf files.Click to select
Run terraform plan again and verify that it reports "No changes" and configuration matches state.Click to select
Selected Sequence
No steps selected yet. Click options above in sequence.
Topic: Importing AWS S3 Bucket
An S3 bucket named "app-assets-prod" was created via the CLI. Bring it under Terraform control without recreating it.
Write a blank aws_s3_bucket resource block in your main.tf file.Click to select
Run terraform import aws_s3_bucket.assets app-assets-prod to load the bucket details into state.Click to select
Execute terraform plan and fill in the missing attributes until the plan reports no changes.Click to select
Selected Sequence
No steps selected yet. Click options above in sequence.
Topic: Multi-Environment Modules
Structure a modular VPC layout that can be reused across development, staging, and production environments.
Create a reusable module in a modules/vpc directory with variables.tf and outputs.tf.Click to select
Create environment directories (e.g., envs/dev) and instantiate the module with specific cidr parameters.Click to select
Initialize and run terraform apply inside each environment folder to generate independent state files.Click to select
Selected Sequence
No steps selected yet. Click options above in sequence.
Topic: Dynamic Ingress Config
Configure a Security Group that needs to allow traffic on 10 different ports using a dynamic block instead of repeating code.
Declare a local variable list containing the 10 target ports.Click to select
Implement a dynamic "ingress" block utilizing for_each to iterate over the local port list.Click to select
Run terraform plan to confirm the provider successfully generates the 10 separate rules.Click to select
Selected Sequence
No steps selected yet. Click options above in sequence.
We value your privacy
We use cookies to analyze site traffic, personalize content, and support our free educational platforms. By clicking "Accept All", you consent to our use of cookies.