HashiCorp Terraform Associate Certification - Free Full Course Companion (19 Chapters with Timestamps, Mapped to the 004 Exam Objectives, What Changed from 003, Study Plan)
This is the companion page to my free Terraform Associate full course - five hours and twenty-five minutes of hands-on Terraform in nineteen chapters. The video walks through every lab; this page gives you the timestamps, the detailed blog post for each chapter (most chapters are a condensed version of a post on this site, so when you want more depth or the exact code, the link is here), and - the part that matters if you are taking the exam - the mapping to the current exam objectives.
That last part changed since I recorded the course. The video says 003; HashiCorp has since released Terraform Associate 004, which tests on Terraform version 1.12 and adds four topics (exam review). Everything in the course is still on the exam; section 3 covers what is new so that you do not walk in with a gap.
Table of Content
- About the exam - Terraform Associate 004
- The 19 chapters with timestamps and the detailed post for each
- What changed from 003 to 004 - the four new topics explained
- The eight exam objectives mapped to the chapters
- What the course does not cover - HCP Terraform
- A two-week study plan
- Exam-day tips and the questions people get wrong
- Conclusion
1. About the exam - Terraform Associate 004
From the HashiCorp certification pages and the 004 review -
- Name - HashiCorp Certified: Terraform Associate (004). The entry-level of three Terraform certifications (the others are the Infrastructure Engineer Professional and the lab-based Authoring and Operations Advanced).
- Tests on Terraform 1.12 - so the
importblock,movedandremovedblocks,terraform test, provider-defined functions, ephemeral values and write-only arguments are all in scope. - Format - about an hour, multiple choice and multiple select, online proctored; the certificate is valid for two years. Price and registration are on the certification page (it has been in the $70 range).
- No hands-on labs in the exam - but the questions are written so that only people who have done the labs answer them quickly. That is why this course is five hours of typing, not five hours of slides.
- Eight objectives - listed in section 4.
2. The 19 chapters with timestamps and the detailed post for each
| # | Chapter | Starts | What you build | Detailed post |
|---|---|---|---|---|
| 1 | What is Terraform | 04:21 | install, provider, first main.tf, init / plan / apply / destroy on a GCP VM and an AWS EC2 instance | install Terraform · VM on Google Cloud · EC2 on AWS |
| 2 | Variables | 56:15 | string, number, bool, list, map, object; -var, TF_VAR_ | Terraform variables explained |
| 3 | tfvars | 1:14:16 | variables.tf vs terraform.tfvars, -var-file, precedence | variables.tf vs terraform.tfvars |
| 4 | Locals | 1:36:38 | computed values, local. | how to use Terraform locals |
| 5 | Output values | 1:46:42 | output, terraform output -raw, module outputs | Terraform output values |
| 6 | for loops, for_each | 1:59:09 | count, for_each + toset, for expressions | count, for_each and for expressions |
| 7 | State files | 2:13:15 | local state, S3 remote backend, DynamoDB locking, terraform state | managing Terraform state · state locking |
| 8 | Provisioners | 2:31:15 | file, local-exec, remote-exec, connection, SSH into EC2 | Terraform provisioners · SSH into EC2 |
| 9 | Modules | 2:52:24 | two modules, each installing Apache with its own page; inputs and outputs | how Terraform modules work |
| 10 | Dynamic blocks | 3:10:17 | dynamic "ingress" over a list of rules | Terraform dynamic blocks |
| 11 | null resource | 3:21:10 | null_resource with triggers and a provisioner - and today's terraform_data | null_resource and terraform_data |
| 12 | Data sources | 3:40:00 | data "aws_ami", reading existing infrastructure | Terraform data sources |
| 13 | Workspaces | 3:53:18 | terraform workspace new dev, terraform.workspace | Terraform workspaces |
| 14 | user_data | 4:16:21 | cloud-init script on EC2 | what is user_data in Terraform |
| 15 | depends_on | 4:28:10 | explicit dependencies | terraform depends_on |
| 16 | Template | 4:36:35 | templatefile() and .tftpl | Terraform template guide |
| 17 | Debugging and validation | 4:56:39 | terraform validate, fmt, TF_LOG=DEBUG, TF_LOG_PATH | testing infrastructure as code |
| 18 | Import | 5:03:59 | terraform import of an existing resource - and the import block | import existing resources |
| 19 | Upgrade | 5:09:18 | tfenv to install and switch Terraform versions | install Terraform |
Two things to note while watching. First, the course was recorded on Terraform 1.5 and AWS provider 5; every linked post has since been re-verified against Terraform 1.16 and AWS provider 6, so where the video output differs slightly, the post is current. Second, several of the 2021-era posts used to show access keys inside the provider block - that was wrong then and is wrong now; the posts have been fixed and the right ways are in Terraform and AWS credentials handling.
3. What changed from 003 to 004 - the four new topics explained
HashiCorp lists four new topics in 004. None of them is big, all of them are fair game -
4f - depends_on and the create_before_destroy lifecycle rule. depends_on is chapter 15. create_before_destroy is the lifecycle argument that makes Terraform build the replacement before destroying the old resource - the difference between a few seconds of downtime and none when an instance or certificate must be replaced -
1resource "aws_instance" "web" {
2 # ...
3 lifecycle {
4 create_before_destroy = true
5 prevent_destroy = false
6 ignore_changes = [tags["LastDeployed"]]
7 }
8}
Expect questions on all three lifecycle arguments and on replace_triggered_by.
4g - Validate configuration using custom conditions. Three places: a validation block in a variable, and precondition / postcondition blocks in resources, data sources and outputs -
1variable "environment" {
2 type = string
3 validation {
4 condition = contains(["dev", "staging", "prod"], var.environment)
5 error_message = "environment must be dev, staging or prod."
6 }
7}
8
9resource "aws_instance" "web" {
10 ami = data.aws_ami.ubuntu.id
11 # ...
12 lifecycle {
13 precondition {
14 condition = data.aws_ami.ubuntu.architecture == "x86_64"
15 error_message = "The AMI must be x86_64 for this instance type."
16 }
17 }
18}
Validation runs at plan time; the variables post has more.
4h - Ephemeral values and write-only arguments. Terraform 1.10 added ephemeral = true on variables and outputs - values that are never written to state or plan files - and ephemeral resources (a Vault token, a short-lived credential). Terraform 1.11 added write-only arguments on resources (password_wo on a database, for example) that are sent to the provider but never stored. Know what each is for: sensitive hides values in output but still stores them; ephemeral never stores them.
8c - HCP Terraform workspaces and projects. In HCP Terraform (the renamed Terraform Cloud) a workspace holds one state and one configuration; a project groups workspaces (by team or application) for permissions and variable sets. That is section 5.
4. The eight exam objectives mapped to the chapters
| Objective | Sub-items | Where in the course |
|---|---|---|
| 1. IaC with Terraform | what IaC is, its advantages, multi-cloud and provider-agnostic workflows | Ch 1 (and the comparison with CloudFormation in EC2 on AWS) |
| 2. Terraform fundamentals | install and version providers, how providers work, multiple providers, how state is managed | Ch 1, Ch 7, Ch 19; required_providers and provider aliases in AWS multi-account |
| 3. Core workflow | init, validate, plan, apply, destroy, fmt, style | Ch 1, Ch 17 |
| 4. Configuration | resource and data blocks, references, variables and outputs, complex types, expressions and functions, dependencies (4f), custom conditions (4g), sensitive data incl. Vault and ephemeral values (4h) | Ch 2-6, 10, 12, 14-16; securing sensitive data, Vault with Terraform |
| 5. Modules | sourcing (registry, Git, local), variable scope, using modules, versions | Ch 9; module outputs |
| 6. State management | local backend, locking, remote state with backend, drift and state operations (moved, removed, state mv/rm) | Ch 7, Ch 13; remove from state, why not in Git |
| 7. Maintain infrastructure | import existing infrastructure, inspect state, verbose logging | Ch 17, Ch 18 |
| 8. HCP Terraform | create infrastructure, collaboration and governance, workspaces and projects (8c), configure the integration | not in the video - section 5 |
5. What the course does not cover - HCP Terraform
Objective 8 is the one gap in the video, because the course is about Terraform the CLI. HCP Terraform (formerly Terraform Cloud) is HashiCorp's hosted service that runs Terraform for you. What you need to know -
- Remote runs -
terraform planandapplyexecute on HCP Terraform's workers (or your own agents), with state stored there, encrypted, versioned and locked automatically - it replaces the S3 + DynamoDB backend from chapter 7. - Workflows - CLI-driven (you run
terraformlocally, it executes remotely), VCS-driven (a push to GitHub triggers a plan, a merge triggers an apply) and API-driven. - Workspaces and projects - a workspace = one state + one configuration + variables; a project = a group of workspaces with shared permissions and variable sets (one AWS credential set for twenty workspaces).
- Governance - Sentinel and OPA policies that block an apply ("no public S3 buckets"), run tasks (security scanners), cost estimation, team-based RBAC, and the private registry for your modules.
- Configuration - the
cloudblock in theterraformblock -
1terraform {
2 cloud {
3 organization = "jhooq"
4 workspaces {
5 name = "prod-network"
6 }
7 }
8}
then terraform login and terraform init. The free tier covers up to 500 managed resources - enough to practise every item of objective 8 in an evening with the HCP Terraform tutorials. Do that evening; it is 10-15% of the exam.
6. A two-week study plan
| Days | Watch | Do |
|---|---|---|
| 1-2 | Ch 1-3 | install Terraform, create and destroy an EC2 instance, parameterise it with variables and a tfvars file |
| 3-4 | Ch 4-6 | locals, outputs, rebuild the IAM users example with count, then for_each - watch the plan difference when you remove one |
| 5-6 | Ch 7, 13 | move state to S3 with locking; create dev and prod workspaces; practise terraform state list/show/mv/rm, write a moved block |
| 7 | Ch 8, 11, 14 | provisioners vs user_data vs terraform_data; know when the exam expects "provisioners are a last resort" |
| 8-9 | Ch 9, 10 | write a module, call it twice, use a registry module with a version constraint; a dynamic block for security group rules |
| 10 | Ch 12, 15, 16 | data sources, depends_on, templatefile; add validation, precondition and lifecycle blocks (the 004 additions) |
| 11 | Ch 17, 18, 19 | validate, fmt -check, TF_LOG; import a resource with both the command and the import block; tfenv |
| 12 | - | HCP Terraform evening - free account, CLI-driven workspace, a variable set, a Sentinel policy from the examples |
| 13 | - | read the review guide top to bottom and the study guide; take HashiCorp's sample questions |
| 14 | - | exam |
7. Exam-day tips and the questions people get wrong
terraform initdoes not create resources and does not read variables - it downloads providers and modules and configures the backend.-upgraderefreshes provider versions within constraints.terraform plan -refresh-onlyshows drift;terraform apply -refresh-onlyaccepts it into state;terraform refreshis the deprecated spelling.terraform taintis deprecated - useterraform apply -replace=aws_instance.web.- Provisioners run only at creation (or destruction with
when = destroy) and are a last resort;user_dataand configuration tools are preferred. - State contains sensitive data in plain text -
sensitive = trueonly masks CLI output; protect the backend.ephemeralvalues are never stored. - Modules - a child module's variables and outputs are its only interface; the root module cannot see a child's resources without an output. Version constraints work only for registry modules, not Git sources (use
?ref=). - Workspaces (CLI) are separate state files of the same configuration; HCP Terraform workspaces are a broader concept.
terraform import(and theimportblock) only writes to state - you must write the matching configuration, andterraform planthen shows the gaps.- Backend changes need
terraform init -migrate-state;-reconfigureabandons the old state. terraform consoleevaluates expressions and functions interactively - the fastest way to settle "what doeslookup()return" during revision, and a frequent question topic.- Know the meta-arguments by name -
count,for_each,provider,depends_on,lifecycle- and thatcountandfor_eachcannot be used together. terraform fmtchanges formatting only;terraform validatechecks syntax and internal consistency and does not need credentials (it does needinit).
8. Conclusion
The course gives you the hands-on Terraform the exam assumes - variables and tfvars, loops, state, provisioners, modules, dynamic blocks, data sources, workspaces, import and debugging - and this page keeps it current: the exam is now Terraform Associate 004 on Terraform 1.12, with lifecycle rules, custom conditions, ephemeral values and write-only arguments and HCP Terraform workspaces and projects added. Watch the chapters, do the labs from the linked posts, spend one evening in HCP Terraform, read HashiCorp's review guide, and the exam is a formality. Everything Terraform on this site is indexed on the Terraform table of content, and the authoritative source for the exam is the HashiCorp certification page with the 004 study guide.
Read More - Terragrunt -
Posts in this series
- HashiCorp Terraform Associate Certification - Free Full Course Companion (19 Chapters with Timestamps, Mapped to the 004 Exam Objectives, What Changed from 003, Study Plan)
- Deploying a Next.js SaaS on Google Cloud Run with Terraform: Cloud SQL, Secret Manager, Cloud Build and a deployer service account (ReplyDial case study)
- Securing Sensitive Data in Terraform
- Boost Your AWS Security with Terraform : A Step-by-Step Guide
- How to Load Input Data from a File in Terraform?
- Can Terraform be used to provision on-premises infrastructure?
- Fixing the Terraform Error creating IAM Role. MalformedPolicyDocument Has prohibited field Resource
- In terraform how to handle null value with default value?
- Terraform use module output variables as inputs for another module?
- How to Reference a Resource Created by a Terraform Module?
- Understanding Terraform Escape Sequences
- How to fix private-dns-enabled cannot be set because there is already a conflicting DNS domain?
- Terraform AWS IAM - How to Create IAM Users, Roles and Policies (with aws_iam_policy_document examples)
- How to split Your Terraform main.tf File into Multiple Files
- How to use Terraform variable within variable
- Mastering the Terraform Lookup Function for Dynamic Keys
- Copy files to EC2 and S3 bucket using Terraform
- Troubleshooting Error creating EC2 Subnet InvalidSubnet Range The CIDR is Invalid
- Troubleshooting InvalidParameter Security group and subnet belong to different networks
- Managing strings in Terraform: A comprehensive guide
- How to use terraform depends_on meta argument?
- What is user_data in Terraform?
- Why you should not store terraform state file(.tfstate) inside Git Repository?
- How to import existing resource using terraform import comand?
- Terraform - A detailed guide on setting up ALB(Application Load Balancer) and SSL?
- Testing Infrastructure as Code with Terraform?
- How to remove a resource from Terraform state?
- Terraform null_resource Explained - Triggers, local-exec and remote-exec Examples, and When to Use terraform_data Instead
- In terraform how to skip creation of resource if the resource already exist?
- How to setup Virtual machine on Google Cloud Platform
- How to use Terraform locals?
- Terraform Guide - Docker Containers & AWS ECR(elastic container registry)?
- How to generate SSH key in Terraform using tls_private_key?
- How to fix-Terraform Error acquiring the state lock ConditionalCheckFiledException?
- Terraform Template (templatefile and .tftpl) - A Complete Guide with Examples
- How to use Terragrunt?
- Terraform and AWS Multi account Setup?
- Terraform and AWS credentials handling?
- How to fix-error configuring S3 Backend no valid credential sources for S3 Backend found?
- Terraform state locking using DynamoDB (aws_dynamodb_table)?
- Terraform State File Explained: terraform.tfstate, Remote State on S3, Locking, Pull and Push
- Securing AWS secrets using HashiCorp Vault with Terraform?
- How to use Workspaces in Terraform?
- How to run specific terraform resource, module, target?
- How Terraform modules works?
- Secure AWS EC2s & GCP VMs with Terraform SSH Keys!
- What is terraform provisioner?
- Is terraform destroy needed before terraform apply?
- How to fix terraform error Your query returned no results. Please change your search criteria and try again?
- How to use Terraform Data sources?
- How to use Terraform resource meta arguments?
- How to use Terraform Dynamic blocks?
- Terraform - How to nuke AWS resources and save additional AWS infrastructure cost?
- Terraform count, for_each and for Expressions Explained - Loop Over Lists, Sets and Maps (with the count vs for_each trap)
- How to use Terraform output values?
- How to fix error configuring Terraform AWS Provider error validating provider credentials error calling sts GetCallerIdentity SignatureDoesNotMatch?
- How to fix Invalid function argument on line in provider credentials file google Invalid value for path parameter no file exists
- How to fix error value for undeclared variable a variable named was assigned on the command line?
- What is variable.tf and terraform.tfvars?
- Terraform Variables Explained - Input Variables (string, number, bool, list, map, object), Validation, Sensitive, Locals, Outputs and tfvars
- Terraform Create EC2 Instance on AWS - Step by Step (Provider v6, aws_ami Data Source, Key Pair, Security Group, user_data and Provisioners)
- How to fix Error creating service account googleapi Error 403 Identity and Access Management (IAM) API has not been used in project before or it is disabled
- Install terraform on Ubuntu 20.04, CentOS 8, MacOS, Windows 10, Fedora 33, Red hat 8 and Solaris 11