OnCallReady

Chapter 14 Terraform in Real Life & the Associate Exam

Environments, a cluster platform module (AKS), linting and security scanning, plans as pipeline artifacts, secrets through Key Vault, upgrades - and the Terraform Associate (004) exam.

In plain words

Learning to cook at home is one thing; running a restaurant kitchen is another. In a restaurant the same dish must come out the same in every branch, a head chef checks each plate before it leaves, the fridge with the expensive ingredients is locked, suppliers change their products and you test the new ones before the menu changes, and a health inspector checks the kitchen against a rulebook.

This chapter is the restaurant version of Terraform. Environments are the branches (envs/dev, envs/prod), the platform module (a cluster with its network, identity and vault) is the signature dish, fmt, validate, tflint and checkov are the inspectors, the pipeline with a saved plan and a manual approval is the head chef's check, Key Vault is the locked fridge, and pinning plus deliberate upgrades is how you change suppliers safely. The Associate exam at the end checks you know the rulebook.

Why it matters on call

This is what Terraform looks like in a real platform team, and most of it is the job itself: reviewing the plan artifact at an approval gate, explaining why the pipeline refuses a stale plan, getting a checkov failure on a storage account and fixing it instead of skipping it, moving a secret out of tfvars into Key Vault with a managed identity, and running the azurerm 3-to-4 upgrade across three environments without a single replacement.

It also produces something concrete for your portfolio: a platform module, built around an Azure-managed cluster, called from dev and prod with different sizing, remote state and a gated pipeline, which is exactly the Block 2 build and a strong interview talking point. And it closes Terraform with the Associate (004) exam, so the chapter ends with the objective list, the recall facts and timed mocks.

Lessons

  1. Environments: directory per environment vs workspaces
  2. The platform module: network, identity, cluster (AKS), Key Vault
  3. Code quality: fmt, validate, tflint
  4. Security scanning: checkov on code and on plans
  5. The pipeline: plan as an artifact, gates, approval, apply
  6. Secrets: Key Vault references, not tfvars
  7. Pinning and upgrading Terraform, providers and modules
  8. HCP Terraform: the exam's objective 8
  9. The Terraform Associate (004) exam

23 hands-on labs (missions, incidents and drills) run in the terminal: Open this chapter in the terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.

Questions people ask

Directory per environment or workspaces: which does this chapter recommend?

Directory per environment for real environments. Each envs/<env> is a thin root with its own backend key (ideally its own storage account and identity) and tfvars, so the environment is visible in the path, isolation is real and promotion is a diff. CLI workspaces share one backend and set of credentials, which HashiCorp itself says is unsuitable for environments needing separate access control. They are fine for short-lived copies like feature previews.

Why run fmt, validate, tflint and checkov if the plan catches everything anyway?

The plan does not catch everything, and it is slow and needs cloud credentials. fmt, validate, tflint and checkov run in seconds offline and catch style, language errors, values Azure would reject ten minutes into apply, and insecure settings. That leaves plan reviewers free to think about what the change does, instead of indentation and open SSH rules.

Is sensitive = true enough for secrets in pipelines?

No. It only redacts CLI output. Secrets still land in state and saved plan files, and in git if they are in tfvars. The chapter's approach: generate secrets with random_password straight into Key Vault, have apps read them at runtime through Key Vault references with a managed identity, use identities instead of passwords where possible, and, on 1.10+, ephemeral values.

Do I need HCP Terraform for my job?

Not necessarily. Many Azure shops run Terraform from their own pipelines (GitHub Actions, Azure DevOps) with an azurerm backend and checkov. But exam objective 8 is entirely HCP Terraform, and knowing its model (organisations, projects, workspaces, remote runs, variable sets, Sentinel) lets you map it onto whatever your team uses.

How long does the Terraform Associate exam take, and what version does it test?

Version 004 is one hour of multiple-choice questions, online proctored, and tests Terraform 1.12, including features the lab's 1.9 does not have, like ephemeral values and write-only arguments. The chapter maps each objective to the lessons, and the question bank and mocks follow the exam's style: exact commands and flags, "what happens when", and select-two questions.