HashiCorp Terraform Associate Certification - Free Full Course Companion (19 Chapters with Timestamps, Mapped to the 004 Exam Objectives, What Changed from 003, Study Plan)


This is the companion page to my free Terraform Associate full course - five hours and twenty-five minutes of hands-on Terraform in nineteen chapters. The video walks through every lab; this page gives you the timestamps, the detailed blog post for each chapter (most chapters are a condensed version of a post on this site, so when you want more depth or the exact code, the link is here), and - the part that matters if you are taking the exam - the mapping to the current exam objectives.

That last part changed since I recorded the course. The video says 003; HashiCorp has since released Terraform Associate 004, which tests on Terraform version 1.12 and adds four topics (exam review). Everything in the course is still on the exam; section 3 covers what is new so that you do not walk in with a gap.

Table of Content

  1. About the exam - Terraform Associate 004
  2. The 19 chapters with timestamps and the detailed post for each
  3. What changed from 003 to 004 - the four new topics explained
  4. The eight exam objectives mapped to the chapters
  5. What the course does not cover - HCP Terraform
  6. A two-week study plan
  7. Exam-day tips and the questions people get wrong
  8. Conclusion



1. About the exam - Terraform Associate 004

From the HashiCorp certification pages and the 004 review -

  • Name - HashiCorp Certified: Terraform Associate (004). The entry-level of three Terraform certifications (the others are the Infrastructure Engineer Professional and the lab-based Authoring and Operations Advanced).
  • Tests on Terraform 1.12 - so the import block, moved and removed blocks, terraform test, provider-defined functions, ephemeral values and write-only arguments are all in scope.
  • Format - about an hour, multiple choice and multiple select, online proctored; the certificate is valid for two years. Price and registration are on the certification page (it has been in the $70 range).
  • No hands-on labs in the exam - but the questions are written so that only people who have done the labs answer them quickly. That is why this course is five hours of typing, not five hours of slides.
  • Eight objectives - listed in section 4.

Terraform Associate course map - the 19 chapters mapped to the 8 objectives of exam 004, with what changed from 003


2. The 19 chapters with timestamps and the detailed post for each

#ChapterStartsWhat you buildDetailed post
1What is Terraform04:21install, provider, first main.tf, init / plan / apply / destroy on a GCP VM and an AWS EC2 instanceinstall Terraform · VM on Google Cloud · EC2 on AWS
2Variables56:15string, number, bool, list, map, object; -var, TF_VAR_Terraform variables explained
3tfvars1:14:16variables.tf vs terraform.tfvars, -var-file, precedencevariables.tf vs terraform.tfvars
4Locals1:36:38computed values, local.how to use Terraform locals
5Output values1:46:42output, terraform output -raw, module outputsTerraform output values
6for loops, for_each1:59:09count, for_each + toset, for expressionscount, for_each and for expressions
7State files2:13:15local state, S3 remote backend, DynamoDB locking, terraform statemanaging Terraform state · state locking
8Provisioners2:31:15file, local-exec, remote-exec, connection, SSH into EC2Terraform provisioners · SSH into EC2
9Modules2:52:24two modules, each installing Apache with its own page; inputs and outputshow Terraform modules work
10Dynamic blocks3:10:17dynamic "ingress" over a list of rulesTerraform dynamic blocks
11null resource3:21:10null_resource with triggers and a provisioner - and today's terraform_datanull_resource and terraform_data
12Data sources3:40:00data "aws_ami", reading existing infrastructureTerraform data sources
13Workspaces3:53:18terraform workspace new dev, terraform.workspaceTerraform workspaces
14user_data4:16:21cloud-init script on EC2what is user_data in Terraform
15depends_on4:28:10explicit dependenciesterraform depends_on
16Template4:36:35templatefile() and .tftplTerraform template guide
17Debugging and validation4:56:39terraform validate, fmt, TF_LOG=DEBUG, TF_LOG_PATHtesting infrastructure as code
18Import5:03:59terraform import of an existing resource - and the import blockimport existing resources
19Upgrade5:09:18tfenv to install and switch Terraform versionsinstall Terraform

Two things to note while watching. First, the course was recorded on Terraform 1.5 and AWS provider 5; every linked post has since been re-verified against Terraform 1.16 and AWS provider 6, so where the video output differs slightly, the post is current. Second, several of the 2021-era posts used to show access keys inside the provider block - that was wrong then and is wrong now; the posts have been fixed and the right ways are in Terraform and AWS credentials handling.



3. What changed from 003 to 004 - the four new topics explained

HashiCorp lists four new topics in 004. None of them is big, all of them are fair game -

4f - depends_on and the create_before_destroy lifecycle rule. depends_on is chapter 15. create_before_destroy is the lifecycle argument that makes Terraform build the replacement before destroying the old resource - the difference between a few seconds of downtime and none when an instance or certificate must be replaced -

1resource "aws_instance" "web" {
2  # ...
3  lifecycle {
4    create_before_destroy = true
5    prevent_destroy       = false
6    ignore_changes        = [tags["LastDeployed"]]
7  }
8}

Expect questions on all three lifecycle arguments and on replace_triggered_by.

4g - Validate configuration using custom conditions. Three places: a validation block in a variable, and precondition / postcondition blocks in resources, data sources and outputs -

 1variable "environment" {
 2  type = string
 3  validation {
 4    condition     = contains(["dev", "staging", "prod"], var.environment)
 5    error_message = "environment must be dev, staging or prod."
 6  }
 7}
 8
 9resource "aws_instance" "web" {
10  ami = data.aws_ami.ubuntu.id
11  # ...
12  lifecycle {
13    precondition {
14      condition     = data.aws_ami.ubuntu.architecture == "x86_64"
15      error_message = "The AMI must be x86_64 for this instance type."
16    }
17  }
18}

Validation runs at plan time; the variables post has more.

4h - Ephemeral values and write-only arguments. Terraform 1.10 added ephemeral = true on variables and outputs - values that are never written to state or plan files - and ephemeral resources (a Vault token, a short-lived credential). Terraform 1.11 added write-only arguments on resources (password_wo on a database, for example) that are sent to the provider but never stored. Know what each is for: sensitive hides values in output but still stores them; ephemeral never stores them.

8c - HCP Terraform workspaces and projects. In HCP Terraform (the renamed Terraform Cloud) a workspace holds one state and one configuration; a project groups workspaces (by team or application) for permissions and variable sets. That is section 5.


4. The eight exam objectives mapped to the chapters

ObjectiveSub-itemsWhere in the course
1. IaC with Terraformwhat IaC is, its advantages, multi-cloud and provider-agnostic workflowsCh 1 (and the comparison with CloudFormation in EC2 on AWS)
2. Terraform fundamentalsinstall and version providers, how providers work, multiple providers, how state is managedCh 1, Ch 7, Ch 19; required_providers and provider aliases in AWS multi-account
3. Core workflowinit, validate, plan, apply, destroy, fmt, styleCh 1, Ch 17
4. Configurationresource and data blocks, references, variables and outputs, complex types, expressions and functions, dependencies (4f), custom conditions (4g), sensitive data incl. Vault and ephemeral values (4h)Ch 2-6, 10, 12, 14-16; securing sensitive data, Vault with Terraform
5. Modulessourcing (registry, Git, local), variable scope, using modules, versionsCh 9; module outputs
6. State managementlocal backend, locking, remote state with backend, drift and state operations (moved, removed, state mv/rm)Ch 7, Ch 13; remove from state, why not in Git
7. Maintain infrastructureimport existing infrastructure, inspect state, verbose loggingCh 17, Ch 18
8. HCP Terraformcreate infrastructure, collaboration and governance, workspaces and projects (8c), configure the integrationnot in the video - section 5


5. What the course does not cover - HCP Terraform

Objective 8 is the one gap in the video, because the course is about Terraform the CLI. HCP Terraform (formerly Terraform Cloud) is HashiCorp's hosted service that runs Terraform for you. What you need to know -

  1. Remote runs - terraform plan and apply execute on HCP Terraform's workers (or your own agents), with state stored there, encrypted, versioned and locked automatically - it replaces the S3 + DynamoDB backend from chapter 7.
  2. Workflows - CLI-driven (you run terraform locally, it executes remotely), VCS-driven (a push to GitHub triggers a plan, a merge triggers an apply) and API-driven.
  3. Workspaces and projects - a workspace = one state + one configuration + variables; a project = a group of workspaces with shared permissions and variable sets (one AWS credential set for twenty workspaces).
  4. Governance - Sentinel and OPA policies that block an apply ("no public S3 buckets"), run tasks (security scanners), cost estimation, team-based RBAC, and the private registry for your modules.
  5. Configuration - the cloud block in the terraform block -
1terraform {
2  cloud {
3    organization = "jhooq"
4    workspaces {
5      name = "prod-network"
6    }
7  }
8}

then terraform login and terraform init. The free tier covers up to 500 managed resources - enough to practise every item of objective 8 in an evening with the HCP Terraform tutorials. Do that evening; it is 10-15% of the exam.


6. A two-week study plan

DaysWatchDo
1-2Ch 1-3install Terraform, create and destroy an EC2 instance, parameterise it with variables and a tfvars file
3-4Ch 4-6locals, outputs, rebuild the IAM users example with count, then for_each - watch the plan difference when you remove one
5-6Ch 7, 13move state to S3 with locking; create dev and prod workspaces; practise terraform state list/show/mv/rm, write a moved block
7Ch 8, 11, 14provisioners vs user_data vs terraform_data; know when the exam expects "provisioners are a last resort"
8-9Ch 9, 10write a module, call it twice, use a registry module with a version constraint; a dynamic block for security group rules
10Ch 12, 15, 16data sources, depends_on, templatefile; add validation, precondition and lifecycle blocks (the 004 additions)
11Ch 17, 18, 19validate, fmt -check, TF_LOG; import a resource with both the command and the import block; tfenv
12-HCP Terraform evening - free account, CLI-driven workspace, a variable set, a Sentinel policy from the examples
13-read the review guide top to bottom and the study guide; take HashiCorp's sample questions
14-exam

7. Exam-day tips and the questions people get wrong

  1. terraform init does not create resources and does not read variables - it downloads providers and modules and configures the backend. -upgrade refreshes provider versions within constraints.
  2. terraform plan -refresh-only shows drift; terraform apply -refresh-only accepts it into state; terraform refresh is the deprecated spelling.
  3. terraform taint is deprecated - use terraform apply -replace=aws_instance.web.
  4. Provisioners run only at creation (or destruction with when = destroy) and are a last resort; user_data and configuration tools are preferred.
  5. State contains sensitive data in plain text - sensitive = true only masks CLI output; protect the backend. ephemeral values are never stored.
  6. Modules - a child module's variables and outputs are its only interface; the root module cannot see a child's resources without an output. Version constraints work only for registry modules, not Git sources (use ?ref=).
  7. Workspaces (CLI) are separate state files of the same configuration; HCP Terraform workspaces are a broader concept.
  8. terraform import (and the import block) only writes to state - you must write the matching configuration, and terraform plan then shows the gaps.
  9. Backend changes need terraform init -migrate-state; -reconfigure abandons the old state.
  10. terraform console evaluates expressions and functions interactively - the fastest way to settle "what does lookup() return" during revision, and a frequent question topic.
  11. Know the meta-arguments by name - count, for_each, provider, depends_on, lifecycle - and that count and for_each cannot be used together.
  12. terraform fmt changes formatting only; terraform validate checks syntax and internal consistency and does not need credentials (it does need init).


8. Conclusion

The course gives you the hands-on Terraform the exam assumes - variables and tfvars, loops, state, provisioners, modules, dynamic blocks, data sources, workspaces, import and debugging - and this page keeps it current: the exam is now Terraform Associate 004 on Terraform 1.12, with lifecycle rules, custom conditions, ephemeral values and write-only arguments and HCP Terraform workspaces and projects added. Watch the chapters, do the labs from the linked posts, spend one evening in HCP Terraform, read HashiCorp's review guide, and the exam is a formality. Everything Terraform on this site is indexed on the Terraform table of content, and the authoritative source for the exam is the HashiCorp certification page with the 004 study guide.


Read More - Terragrunt -

  1. How to use Terragrunt?

Posts in this series