HCL & Resources
The language itself — resources, data sources, locals, expressions, and the meta-arguments controlling how many instances exist and how they change. This is where day-to-day Terraform writing happens, so interviewers probe it for depth rather than syntax recall.
part ofTerraformoverview, primer and where to startread it →on this pageshowhide
explore
- Expressions and Functions6 questions
- count vs for_each5 questions
- Dynamic Blocks5 questions
- Lifecycle Meta-Arguments6 questions
- Dependencies and the Resource Graph5 questions
- Data Sources5 questions
- Provisioners6 questions
questions
page 2 of 2What does the `terraform graph` command produce, and how do you actually make use of its output?
basics
~20 sterraform graph prints Terraform's internal dependency graph to stdout in Graphviz DOT format. You pipe it into the dot tool to render a picture, typically to confirm why an unexpected edge exists or, with -draw-cycles, to see a loop.
Inside a Terraform resource that sets for_each = toset(var.names) over a list of strings, what do each.key and each.value hold, and how does that change when for_each is given a map instead?
basics
~20 sWith a set of strings, each.key and each.value are both the element itself. With a map, each.key is the map key and each.value is the corresponding value, which can be an object carrying per-instance settings.
What does cidrsubnet("10.0.0.0/16", 8, 3) return in Terraform, and what do the two numeric arguments mean?
basics
~20 sIt returns "10.0.3.0/24". The second argument is newbits - how many bits to add to the given prefix length, so /16 plus 8 becomes /24. The third is netnum - the index of which of those equally sized subnets to return, counting from zero.
What does the Terraform lifecycle argument `replace_triggered_by` do, and why is it often paired with a `terraform_data` resource?
basics
~20 sreplace_triggered_by lists other resources or their attributes, and replaces this resource whenever one of them changes. It accepts only resource references, so a plain value such as a variable has to be wrapped in a terraform_data resource first.
In Terraform, what is terraform_data for, and why did it supersede null_resource as the place to hang a provisioner?
basics
~20 sterraform_data is a built-in resource, added in Terraform 1.4, that does nothing itself but can hold provisioners or store values. It replaces null_resource because it needs no third-party provider, and its triggers_replace argument forces replacement when a value changes.
When would you use Terraform's `external` or `http` data sources, and what are the risks of shipping one in a production configuration?
basics
~20 sThey are escape hatches for facts no provider exposes: external runs a program and reads a JSON object of strings from its stdout, http performs a request and exposes the response. Both run on every plan, on every machine that plans, and their results land in state.
A Terraform config generates CloudFront ordered_cache_behavior blocks with a dynamic block whose for_each is a map. Why is that risky, and what would you use instead?
basics
~20 sA map iterates in lexical key order, so the precedence of order-sensitive blocks follows key names rather than intent, and adding or renaming a key silently reshuffles them. Drive order-sensitive nested blocks from a list, where configuration order is preserved.
What is a destroy-time provisioner in Terraform, and what restrictions apply to what it can reference?
basics
~20 sA provisioner with when = destroy runs before Terraform destroys the resource, typically to deregister or drain it. It may only reference self, count.index and each.key — not variables, locals or other resources — and it must still be in the configuration when the destroy happens.
showing 31–38 of 38