---
tags:
- devops
- l1
- flashcard-deck
- terraform-workflow
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Terraform Deep Dive](../../../../library/portal/topics.md) | **Domain:** DevOps & Tooling
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
terraform-workflow/00ef76ea2655	terraform-workflow	hard	terraform, apply	Why workspaces might not be the best solution for managing states for different environments? like staging and production	One reason is that all the workspaces are stored in one location (as in one backend) and usually you don't want to use the same access control and authentication for both staging and production for obvious reasons. Also working in workspaces is quite prone to human errors as you might accidentally think you are in one workspace, while you are working a completely different one.	projects/knowledge/interview/terraform/091-why-workspaces-might-not-be-the-best-solution-for-.txt
terraform-workflow/0b2ab0e3d5ba	terraform-workflow	hard	terraform, fmt, secrets, apply	How do you handle sensitive information like API keys or passwords in Terraform configurations?	Handling sensitive information in Terraform involves:\n* Variables: Use input variables and prompt for sensitive values during runtime.\n* Environment Variables: Leverage environment variables to store sensitive data.\n* Secret Management Tools: Integrate with tools like HashiCorp Vault or external secret management systems.\n* Terraform Vault Provider: Utilize the Vault provider for direct integration with HashiCorp Vault.\n* Secure File Storage: Store sensitive files separately and reference them securely.	projects/knowledge/interview/terraform/262-how-do-you-handle-sensitive-information-like-api-k.txt
terraform-workflow/16ecc63fb2f9	terraform-workflow	easy	terraform, plan	What is one reason why manual processes can be helpful?	For learning a platform when first starting out\n\nRemember: "init → plan → apply = the Terraform workflow." init downloads providers, plan previews, apply executes.	projects/knowledge/interview/terraform/006-what-is-one-reason-why-manual-processes-can-be-hel.txt
terraform-workflow/191eafad8370	terraform-workflow	hard	terraform, secrets, apply	What are the pros and cons of using environment variables for managing secrets in Terraform configurations?	Pros:\n\n- You avoid using secrets directly in configurations in plain text\n- free (no need to pay for secret management platforms/solutions)\n- Straightforward to use\n\nCons:\n\n- Configurations might not be usable without the environment variables which may make impact the user experience as the user has to know what environment variables he should pass for everything to work properly\n- Mostly managed outside of Terraform mechanisms which makes it hard to enforce, track, ... anything that is related to secrets when it depends on the user to pass environment variables	projects/knowledge/interview/terraform/163-what-are-the-pros-and-cons-of-using-environment-va.txt
terraform-workflow/1b25a25e9271	terraform-workflow	easy	terraform, fundamentals, iac	What is Terraform and what is infrastructure as code?	Terraform is an open-source Infrastructure as Code tool that lets you define cloud and on-prem infrastructure resources in declarative configuration files, then build and manage those resources safely and efficiently.\n\nRemember: "CI/CD for Terraform: PR triggers plan, merge triggers apply." Atlantis and Terraform Cloud automate this.	projects/knowledge/interview/terraform/273-what-is-terraform.txt
terraform-workflow/30571d9d9deb	terraform-workflow	hard	terraform, ci-cd, secrets	How does Terraform handle secret rotation for resources like database passwords?	Terraform doesn't handle secret rotation directly but can integrate with external tools. Strategies include:\n* External Tools: Use secret management tools like HashiCorp Vault or AWS Secrets Manager for rotation.\n* Variable Updates: Manually update secret variables in Terraform configurations.\n* CI/CD Pipelines: Integrate secret rotation into CI/CD pipelines for automated updates.\n* Custom Scripts: Employ custom scripts or Terraform provisioners for rotation.\n* Rolling Updates: Rotate secrets in a rolling fashion to minimize downtime.	projects/knowledge/interview/terraform/268-how-does-terraform-handle-secret-rotation-for-reso.txt
terraform-workflow/3ae8eb4e4f42	terraform-workflow	medium	terraform, fmt, secrets, apply	How do you handle secrets and sensitive information in Terraform configurations?	Managing secrets in Terraform involves avoiding hardcoding sensitive information directly in configuration files. Best practices include:\n* Use Variables: Define variables for sensitive information and set them externally.\n* Environment Variables: Utilize environment variables to pass sensitive data securely.\n* Secret Management Tools: Integrate with secret management tools like HashiCorp Vault or AWS Secrets Manager.\n* Avoid Hardcoding: Refrain from hardcoding passwords, API keys, or other sensitive data in plain text.\nProper handling of secrets is crucial for security and compliance.	projects/knowledge/interview/terraform/229-how-do-you-handle-secrets-and-sensitive-informatio.txt
terraform-workflow/3dc5622bd21d	terraform-workflow	easy	terraform, apply	How to identify which workspace are you using?	`terraform workspace show` displays the name of the currently active workspace. Workspaces let you manage multiple environments (dev, staging, prod) from the same configuration. Each workspace has its own state file. List all with `terraform workspace list`. \nGotcha: save plans with `terraform plan -out=plan.tfplan` — plans expire if state changes between plan and apply.	projects/knowledge/interview/terraform/097-how-to-identify-which-workspace-are-you-using.txt
terraform-workflow/3eb09e902e38	terraform-workflow	hard	terraform, apply, plan	What's the difference between Terraform and technologies such as Ansible, Puppet, Chef, etc.	Terraform is considered to be an IaC technology. It's used for provisioning resources, for managing infrastructure on different platforms.\n\nAnsible, Puppet and Chef are Configuration Management technologies. They are used once there is an instance running and you would like to apply some configuration on it like installing an application, applying security policy, etc.\n\nRemember: "Workspaces separate state, not code." Same config, different state files.	projects/knowledge/interview/terraform/011-whats-the-difference-between-terraform-and-technol.txt
terraform-workflow/43a4186085e3	terraform-workflow	easy	terraform, ci-cd, plan, apply	What are the advantages in using Terraform or IaC in general?	- Full automation: In the past, resource creation, modification and removal were handled manually or by using a set of tooling. With Terraform or other IaC technologies, you manage the full lifecycle in an automated fashion. \n- Modular and Reusable: Code that you write for certain purposes can be used and assembled in different ways. You can write code to create resources on a public cloud and it can be shared with other teams who can also use it in their account on the same (or different) cloud> \n- Improved testing: Concepts like CI can be easily applied on IaC based projects and code snippets. This allow you to test and verify operations beforehand\n-	projects/knowledge/interview/terraform/005-what-are-the-advantages-in-using-terraform-or-iac-.txt
terraform-workflow/47849a66aba6	terraform-workflow	medium	terraform, apply	How to manage multiple AWS accounts?	One way is to define multiple different provider blocks, each with its own "assume_role"\n\n```\nprovider "aws" {\n  region = "us-west-1"\n  alias = "some-region"\n\n  assume_role {\n    role_arn = "arn:aws:iam::<SOME_ACCOUNT_ID>:role/<SOME_ROLE_NAME>"\n  }\n}\n```\n\nGotcha: Atlantis auto-plans on every PR update. Merge = apply. Make sure PR reviewers understand the plan output.	projects/knowledge/interview/terraform/158-how-to-manage-multiple-aws-accounts.txt
terraform-workflow/5ddc9f5acbdd	terraform-workflow	medium	terraform, apply, ci-cd, review	Explain how to use Terraform with version control systems like Git.	Using Terraform with version control involves:\n* Repository Setup: Create a Git repository to store Terraform configurations.\n* Commit and Push: Regularly commit and push changes to the repository.\n* Branching: Utilize branches for different environments or features.\n* Pull Requests: Use pull requests for code review and collaboration.\n* Tags: Tag releases for versioning and reproducibility.\n* CI/CD Integration: Integrate with CI/CD pipelines for automated testing and deployment.	projects/knowledge/interview/terraform/231-explain-how-to-use-terraform-with-version-control-.txt
terraform-workflow/69d9a74ba3b3	terraform-workflow	medium	terraform, apply, plan	Why is it advisable to avoid using manual processes when creating infrastructure at scale?	- Declarative: Terraform uses the declarative approach (rather than the procedural one) in order to define end-status of the resources\n- No agents: as opposed to other technologies (e.g. Puppet) where you use a model of agent and server, with Terraform you use the different APIs (of clouds, services, etc.) to perform the operations\n- Community: Terraform has strong community who constantly publishes modules and fixes when needed. This ensures there is good modules maintenance and users can get support quite quickly at any point\n-	projects/knowledge/interview/terraform/007-why-is-it-advisable-to-avoid-using-manual-processe.txt
terraform-workflow/6cba2c46d64f	terraform-workflow	medium	terraform, ci-cd, plan	What is Infrastructure as Code (IaC)?	Infrastructure as Code (IaC) is a key DevOps practice that involves managing and provisioning infrastructure using code rather than manual processes. In the context of Terraform, IaC means representing infrastructure configurations as code in declarative language syntax. This code defines the desired state of the infrastructure, allowing for version control, collaboration, and automation of the entire infrastructure lifecycle.	projects/knowledge/interview/terraform/193-what-is-infrastructure-as-code-iac.txt
terraform-workflow/6fb4dbd727b3	terraform-workflow	medium	terraform, apply	How to create multiple AWS instances but each with a different name?	```\nresource "aws_instance" "server" {\n  count = 6\n\n  tags = {\n    Name = "instance-${count.index}"\n  }\n}\n```\n\nThe above configuration will create 6 instances, each with a different name.\n\nRemember: "Pre-commit hooks catch issues before CI." terraform fmt, terraform validate, tflint in pre-commit.	projects/knowledge/interview/terraform/104-how-to-create-multiple-aws-instances-but-each-with.txt
terraform-workflow/72af4a3079e1	terraform-workflow	medium	terraform, plan, init, validate	How do you test and lint modules during development?	```bash\nterraform -chdir=examples/vpc init\nterraform -chdir=examples/vpc validate\nterraform -chdir=examples/vpc plan\ntflint --module\n```\n\n- `terraform validate` catches syntax errors and missing providers. \n- Running `plan` against an example stack surfaces integration issues before promotion. \n- `tflint --module` adds provider-specific linting; tools like Terratest can provision ephemeral infra for assertions. \n- Include these commands in CI so every module change is exercised automatically.	projects/knowledge/interview/terraform/138-how-do-you-test-and-lint-modules-during-developmen.txt
terraform-workflow/787dee8d33be	terraform-workflow	medium	terraform, apply, plan	What structure layout do you use for your projects?	There is no right or wrong answer, just what you personally adopted or your team, and being able to explain why.\n\nOne common approach is to have a separate directory for each environment.\n\n```\nterraform_project/\n  staging/\n  production/\n```\n\nEach environment has its own backend (as you don't want to use the same authentication and access controls for all environments)\n\nGoing further, under each environment you'll separate between components, applications and services\n\n```\nterraform_project/\n  staging/\n    applications/\n      some-app-service-1/\n      some-app-service-2/\n    databases/\n      mongo/\n      postgres/\n    networking/\n```	projects/knowledge/interview/terraform/166-what-structure-layout-do-you-use-for-your-projects.txt
terraform-workflow/79f7ef9c29fc	terraform-workflow	medium	terraform, plan, apply	One of the engineers in your team complains the inline shell scripts are quite big and maintaining them in Terraform files seems like a bad idea. What would you do?	A good solution for not including shell scripts inline (as in inside terraform configuration files) is to keep them in a separate file and then use the terraform `templatefile` function to render and get them as a string	projects/knowledge/interview/terraform/170-one-of-the-engineers-in-your-team-complains-the-in.txt
terraform-workflow/860be4527f07	terraform-workflow	medium	terraform, plan, apply, ci-cd	When working with nested layout of many directories, it can make it cumbresome to run terraform commands in many different folders. How to deal with it?	There are multiple ways to deal with it:\n\n1. Write scripts that perform some commands recursively with different conditions\n2. Use tools like Terragrunt where you commands like "run-all" that can run in parallel on multiple different paths\n\nRemember: "Blue-green deploys with Terraform: create new, switch traffic, destroy old." Terraform isn't ideal for this — it's declarative, not orchestrative.	projects/knowledge/interview/terraform/169-when-working-with-nested-layout-of-many-directorie.txt
terraform-workflow/8670c280a5c8	terraform-workflow	medium	terraform, best-practices, safety	How do you avoid accidentally applying changes in Terraform?	By running terraform plan first to review changes, and using version control for .tf files. Also, you can use a manual approval workflow or the -destroy and -refresh-only plan options to be explicit. Terraform Cloud/Enterprise can enforce manual confirms and policies (Sentinel).\n\nRemember: "Terraform PR workflow: branch → plan → review → merge → apply." Never apply from a feature branch.	projects/knowledge/interview/terraform/278-avoid-accidental-apply.txt
terraform-workflow/a413570d7408	terraform-workflow	medium	terraform, ci-cd, review, secrets	How can you manage secrets/credentials in CI/CD?	That very much depends on the CI/CD system/platform you are using.\n\n- GitHub Actions: Use Open ID Connect (OIDC) to establish connection with your provider. You then can specify in your GitHub Actions workflow the following:\n\n```\n- uses: aws-actions/configure-aws-credentials@v1\nwith:\n role-to-assume: arn:aws:iam::someIamRole\n aws-region: ...\n```\n\n- Jenkins: If Jenkins runs on the provider, you can use the provider access entities (like roles, policies, ...) to grant the instance, on which Jenkins is running, access control\n- CircleCI: you can use `CircleCI Context` and then specify it in your CircleCI config file\n\n```\ncontext:\n- some-context\n```	projects/knowledge/interview/terraform/162-how-can-you-manage-secretscredentials-in-cicd.txt
terraform-workflow/b92107b3a518	terraform-workflow	hard	terraform, apply, plan	Explain the difference between Terraform and other configuration management tools.	While traditional configuration management tools like Ansible, Chef, and Puppet focus on automating the configuration of software on existing servers, Terraform is specifically designed for provisioning and managing infrastructure. Terraform is an Infrastructure as Code tool that allows you to define, deploy, and update infrastructure across various cloud providers and on-premises environments. Unlike configuration management tools, Terraform is not tied to a specific technology stack and is cloud-agnostic, providing a unified approach to managing diverse infrastructure resources.	projects/knowledge/interview/terraform/192-explain-the-difference-between-terraform-and-other.txt
terraform-workflow/bc8d5ad327a9	terraform-workflow	easy	terraform, apply, plan	What are some use cases for using Terraform?	- Infra provisioning and management: You need to automated or code your infra so you are able to test it easily, apply it and make any changes necessary.\n- Multi-cloud environment: You manage infrastructure on different clouds, but looking for a consistent way to do it across the clouds\n- Consistent environments: You manage environments such as test, production, staging, ... and looking for a way to have them consistent so any modification in one of them, applies to other environments as well	projects/knowledge/interview/terraform/010-what-are-some-use-cases-for-using-terraform.txt
terraform-workflow/c148d4277130	terraform-workflow	easy	terraform, apply	How to create a new workspace?	`terraform workspace new <WORKSPACE_NAME>` creates a new workspace and switches to it immediately. Each workspace gets its own state file, allowing parallel environments from the same codebase. \nExample: `terraform workspace new staging`. Use `terraform.workspace` in your config to vary resources per workspace (e.g., smaller instances in dev). List workspaces with `terraform workspace list`.	projects/knowledge/interview/terraform/096-how-to-create-a-new-workspace.txt
terraform-workflow/c1d2f2ecc2bb	terraform-workflow	medium	terraform, plan	What files do you have in your Terraform projects?	Again, no right or wrong answer. Just your personal experience.\n\nmain.tf\nproviders.tf\noutputs.tf\nvariables.tf\ndependencies.tf\n\nEach one of these files can be divided to smaller parts if needed (no reason to maintain VERY long files)\n\nRemember: "terraform apply -auto-approve skips confirmation." Only use in CI after a reviewed plan.	projects/knowledge/interview/terraform/167-what-files-do-you-have-you-have-in-your-terraform-.txt
terraform-workflow/c2435e3dbd64	terraform-workflow	medium	terraform, plan, apply, init	What's a typical Terraform workflow?	1. Write Terraform definitions: `.tf` files written in HCL that described the desired infrastructure state (and run `terraform init` at the very beginning)\n2. Review: With command such as `terraform plan` you can get a glance at what Terraform will perform with the written definitions\n3. Apply definitions: With the command `terraform apply` Terraform will apply the given definitions, by adding, modifying or removing the resources\n\nThis is a manual process. Most of the time this is automated so user submits a PR/MR to propose terraform changes, there is a process to test these changes and once merged they are applied (`terraform apply`).\n\nRemember: "Terraform Cloud runs: plan, cost estimation, sentinel policy check, apply." Each step is a gate.	projects/knowledge/interview/terraform/009-whats-a-typical-terraform-workflow.txt
terraform-workflow/d0adf066548a	terraform-workflow	hard	terraform, apply	Discuss the considerations for managing security groups and firewall rules in Terraform.	Managing security groups and firewall rules in Terraform involves:\n* Variable Configuration: Using variables for flexible security group configurations.\n* Security Group Rules: Defining rules based on protocols, ports, and sources.\n* Dynamic Block Usage: Employing dynamic blocks for dynamic rule creation.\n* Provider-Specific Rules: Adapting configurations to the specificities of each cloud provider.\n* Network Policies: Implementing network policies for fine-grained control.	projects/knowledge/interview/terraform/257-discuss-the-considerations-for-managing-security-g.txt
terraform-workflow/d5dffc2a3da9	terraform-workflow	easy	terraform, plan, apply	Every time there is a change in tags standards (for example your team decided to change one of the tags' name) you find yourself changing tags in multiple files and you find the process quite tedious. What can be done about it?	Use `default_tags` in the provider configuration to apply tags automatically to all resources. Example in AWS provider: `default_tags { tags = { Environment = var.env, Team = "platform" } }`. This eliminates repetitive tag blocks across resources and ensures consistency. Individual resource tags merge with and can override default_tags. Changes propagate automatically on the next apply.	projects/knowledge/interview/terraform/173-every-time-there-is-a-change-in-tags-standards-for.txt
terraform-workflow/db58a476a387	terraform-workflow	medium	terraform, fmt, secrets, apply	How does Terraform manage secrets and sensitive information?	Terraform provides several mechanisms for managing secrets and sensitive information. One common approach is to use input variables with sensitive data types (string, object, etc.) and mark them as sensitive. Additionally, Terraform supports the use of environment variables, external vaults, or third-party tools for managing secrets. It's crucial to avoid storing sensitive information directly in Terraform configurations to ensure security and compliance. Best practices include leveraging secure storage solutions and not committing sensitive data to version control.\n\nRemember: "terraform refresh is now terraform apply -refresh-only." Explicit refresh is better than auto-refresh during plan.	projects/knowledge/interview/terraform/208-how-does-terraform-manage-secrets-and-sensitive-in.txt
terraform-workflow/db5e6f8157c9	terraform-workflow	medium	terraform, plan, apply	How does Terraform support the concept of "immutable infrastructure"?	Immutable infrastructure is the practice of not modifying running infrastructure components but instead replacing them with new instances. Terraform supports this concept by facilitating the creation and management of infrastructure as code. When changes are needed, Terraform generates a new plan and applies it, resulting in the recreation of resources with the updated configuration. This approach ensures consistency, reproducibility, and easier rollbacks. Immutable infrastructure is aligned with Terraform's declarative nature, where the desired state is defined, and Terraform determines the actions required to achieve that state.	projects/knowledge/interview/terraform/225-how-does-terraform-support-the-concept-of-immutabl.txt
terraform-workflow/ec392af48a7d	terraform-workflow	medium	terraform, init, plan	How do you install Terraform?	To install Terraform, you can follow these general steps:\n* Download the appropriate Terraform binary for your operating system from the official website (https://www.terraform.io/downloads.html).\n* Extract the downloaded archive to a directory in your system's PATH.\n* Verify the installation by running terraform --version in the terminal. If installed correctly, it will display the installed Terraform version.	projects/knowledge/interview/terraform/194-how-do-you-install-terraform.txt
terraform-workflow/f1dfc274506b	terraform-workflow	hard	terraform, apply, plan	What is "Terraform Enterprise," and how does it cater to enterprise-scale infrastructure deployments?	Terraform Enterprise is a commercial offering by HashiCorp designed for enterprise-scale infrastructure management. Features include:\n* Collaboration: Enables collaboration and access control for large teams.\n* VCS Integration: Integrates with version control systems for automated workflows.\n* Registry Integration: Connects with Terraform Registry for module sharing.\n* Policy Enforcement: Enforces policies for compliance and security.\n* Workspaces: Supports multiple workspaces for environment isolation.\n* Remote Operations: Facilitates remote execution of Terraform runs.	projects/knowledge/interview/terraform/249-what-is-terraform-enterprise-and-how-does-it-cater.txt
terraform-workflow/f5be912f8af2	terraform-workflow	medium	terraform, apply, ci-cd, review	Explain the benefits of using Terraform with infrastructure orchestration tools.	Using Terraform with infrastructure orchestration tools like Jenkins, GitLab CI, or AWS CodePipeline offers several benefits:\n* Automation: Enables automated infrastructure provisioning and updates.\n* Integration: Integrates seamlessly with CI/CD pipelines.\n* Versioning: Facilitates version-controlled infrastructure as code.\n* Scalability: Scales infrastructure provisioning across environments.\n* Consistency: Ensures consistent deployments in various scenarios.\n* Auditing: Provides audit trails for changes made to infrastructure.\n* Collaboration: Supports collaborative development practices.	projects/knowledge/interview/terraform/236-explain-the-benefits-of-using-terraform-with-infra.txt
terraform-workflow/fa8b89bc3565	terraform-workflow	medium	terraform, apply	You noticed your Terraform code includes quite a lot of hardcoded values (like ports, subnets, ...) and they are duplicated in many locations. How'd you deal with it?	Using variables might not be a good solution because some things shouldn't be exposed and accidentally overridden. In such case you might want to use the concept of `locals`	projects/knowledge/interview/terraform/172-you-noticed-your-terraform-code-includes-quite-a-l.txt
terraform-workflow/fdefbe167ad9	terraform-workflow	medium	terraform, secrets, apply, plan	How does Terraform manage secrets, and what are the alternatives to storing them securely?	Terraform typically manages secrets through variables. However, storing secrets directly in configuration files poses security risks. Alternatives include:\n* Environment Variables: Load secrets from environment variables during runtime.\n* Secret Management Tools: Utilize external tools like HashiCorp Vault or AWS Secrets Manager.\n* Parameter Stores: Leverage cloud provider parameter stores for secure secret storage.\n* Encryption: Encrypt sensitive data using encryption tools or services.\n\nRemember: "State file backups: terraform.tfstate.backup is created on every apply." For real protection, use remote state with versioning.	projects/knowledge/interview/terraform/246-how-does-terraform-manage-secrets-and-what-are-the.txt
terraform-workflow/fe9ee3d0caef	terraform-workflow	medium	terraform, apply, plan	You noticed a lot of your Terraform code/configuration is duplicated, between repositories and also within the same repository between different directories. What one way you may adopt that will help handling with that?	Using Terraform modules can help greatly with duplicated code and so different environments for example (staging and production) can reuse the same code by using the same modules.\n\nRemember: "Terraform best practices: remote state, version pinning, small modules, CI/CD pipeline, code review for plans."	projects/knowledge/interview/terraform/171-you-noticed-a-lot-of-your-terraform-codeconfigurat.txt
terraform-workflow/feaa6601495d	terraform-workflow	easy	terraform, plan	An engineer in your team complains about having to copy-paste quite a lot of code between different folders and files of Terraform. What would you do?	Suggest using Terraform modules to encapsulate reusable infrastructure patterns. Modules group related resources into a single unit with defined inputs (variables) and outputs. \nExample: a 'vpc' module that creates VPC, subnets, route tables, and NAT gateways — called once per environment with different parameters. This follows DRY (Don't Repeat Yourself) principles and reduces copy-paste errors.	projects/knowledge/interview/terraform/168-an-engineer-in-your-team-complains-about-having-to.txt

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Runbook: Terraform Drift Detection Response](../../../../library/runbooks/cloud-terraform/drift-detection.md) (Runbook, L2) — Terraform Deep Dive
- [Terraform Deep Dive](../../../../library/topics/terraform-deep-dive/index.md) (Topic Pack, L2) — Terraform Deep Dive
- Terraform Modules Flashcards *(CLI)* (flashcard_deck, L1) — Terraform Deep Dive
- Terraform Providers Flashcards *(CLI)* (flashcard_deck, L1) — Terraform Deep Dive
- Terraform State Flashcards *(CLI)* (flashcard_deck, L1) — Terraform Deep Dive

<!-- wiki:related:end -->
