Bird
Raised Fist0
Terraformcloud~5 mins

Environment variables (TF_VAR_) in Terraform - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
Sometimes you want to keep your settings secret or change them without editing files. Environment variables let you do this by storing values outside your code. Terraform uses special environment variables starting with TF_VAR_ to set input variables automatically.
When you want to keep sensitive data like passwords out of your Terraform files.
When you need to change variable values quickly without editing the Terraform configuration.
When running Terraform in automated scripts or pipelines where variables come from the environment.
When sharing Terraform code but want each user to provide their own settings.
When you want to avoid committing secrets to version control.
Config File - main.tf
main.tf
variable "region" {
  description = "The cloud region to deploy resources"
  type        = string
  default     = "us-east-1"
}

variable "instance_type" {
  description = "Type of the compute instance"
  type        = string
}

resource "aws_instance" "example" {
  ami           = "ami-0c55b159cbfafe1f0"
  instance_type = var.instance_type
  tags = {
    Name = "example-instance"
  }
}

This Terraform file defines two variables: region with a default value and instance_type which must be provided. It creates an AWS EC2 instance using the instance_type variable. By using environment variables starting with TF_VAR_, you can set instance_type without changing this file.

Commands
This command sets the environment variable TF_VAR_instance_type to t2.micro. Terraform will use this value for the instance_type variable when you run commands.
Terminal
export TF_VAR_instance_type=t2.micro
Expected OutputExpected
No output (command runs silently)
Initializes the Terraform working directory. It downloads necessary provider plugins and prepares the environment.
Terminal
terraform init
Expected OutputExpected
Initializing the backend... Initializing provider plugins... - Finding latest version of hashicorp/aws... - Installing hashicorp/aws v4.0.0... - Installed hashicorp/aws v4.0.0 (signed by HashiCorp) Terraform has been successfully initialized! You may now begin working with Terraform. Try running "terraform plan" to see any changes that are required for your infrastructure.
Shows what Terraform will do based on the current configuration and environment variables. It uses the instance_type value from the environment variable.
Terminal
terraform plan
Expected OutputExpected
Terraform used the selected providers to generate an execution plan. Plan: 1 to add, 0 to change, 0 to destroy. ───────────────────────────────────────────────────────────────────────────── Note: You didn't specify an "-out" parameter to save this plan, so Terraform can't guarantee that exactly these actions will be performed if "terraform apply" is subsequently run. ───────────────────────────────────────────────────────────────────────────── Note: The exact output may vary depending on your Terraform version and provider. # aws_instance.example will be created + resource "aws_instance" "example" { + ami = "ami-0c55b159cbfafe1f0" + arn = (known after apply) + instance_type = "t2.micro" + tags = { + "Name" = "example-instance" } }
Applies the planned changes to create the resources. The -auto-approve flag skips the confirmation prompt.
Terminal
terraform apply -auto-approve
Expected OutputExpected
aws_instance.example: Creating... aws_instance.example: Still creating... [10s elapsed] aws_instance.example: Creation complete after 20s [id=i-0123456789abcdef0] Apply complete! Resources: 1 added, 0 changed, 0 destroyed.
→
-auto-approve - Automatically approve the apply step without asking for confirmation
Key Concept

If you name environment variables with TF_VAR_ followed by your variable name, Terraform automatically uses those values for your input variables.

Common Mistakes
Setting environment variables without the TF_VAR_ prefix
Terraform ignores environment variables that do not start with TF_VAR_, so your variables remain unset.
Always prefix your environment variable names with TF_VAR_ followed by the exact variable name.
Not exporting the environment variable before running Terraform commands
If the variable is not exported, Terraform cannot see it in the environment and will not use it.
Use the export command to set the environment variable in the current shell session.
Using environment variables for variables that have default values and expecting them to override
Terraform uses environment variables to override defaults, but if the variable is not referenced properly or the environment variable is missing, the default remains.
Ensure the environment variable is set correctly and matches the variable name exactly to override defaults.
Summary
Set environment variables with the TF_VAR_ prefix to provide input variables to Terraform without editing files.
Run terraform init to prepare your working directory before planning or applying.
Use terraform plan to see what changes will happen using your environment variable values.
Use terraform apply to create or update resources based on your plan.

Practice

(1/5)
1. What is the purpose of using environment variables with the TF_VAR_ prefix in Terraform?
easy
A. To set Terraform input variables without hardcoding them in configuration files
B. To define backend storage for Terraform state files
C. To specify the Terraform provider version
D. To enable debugging output during Terraform runs

Solution

  1. Step 1: Understand Terraform variable usage

    Terraform variables allow customization of configurations without changing code files.
  2. Step 2: Role of TF_VAR_ prefix

    Environment variables prefixed with TF_VAR_ automatically set Terraform input variables, keeping code clean and secure.
  3. Final Answer:

    To set Terraform input variables without hardcoding them in configuration files -> Option A
  4. Quick Check:

    Environment variables with TF_VAR_ prefix set variables [OK]
Hint: TF_VAR_ prefix sets Terraform variables via environment [OK]
Common Mistakes:
  • Confusing TF_VAR_ with backend configuration
  • Using TF_VAR_ to set provider versions
  • Expecting TF_VAR_ to enable debug logs
2. Which of the following is the correct way to set a Terraform variable named region using an environment variable?
easy
A. TF_VARregion=us-west-2
B. set TF_VAR-region=us-west-2
C. export TF_VAR_region=us-west-2
D. terraform var region=us-west-2

Solution

  1. Step 1: Identify correct environment variable syntax

    Terraform expects environment variables for variables to be prefixed with TF_VAR_ followed by the variable name.
  2. Step 2: Correct shell export command

    In Unix-like shells, export TF_VAR_region=us-west-2 correctly sets the variable.
  3. Final Answer:

    export TF_VAR_region=us-west-2 -> Option C
  4. Quick Check:

    Use export TF_VAR_variable=value [OK]
Hint: Use export TF_VAR_variable=value to set variables [OK]
Common Mistakes:
  • Using dash instead of underscore in TF_VAR_ prefix
  • Missing export keyword in Unix shell
  • Trying to set variables with terraform command directly
3. Given the Terraform variable declaration:
variable "instance_type" { default = "t2.micro" }

and the environment variable set as export TF_VAR_instance_type=t3.medium, what will be the value of var.instance_type during Terraform apply?
medium
A. "t2.micro" (default value)
B. "t3.medium" (from environment variable)
C. null (no value set)
D. Error: variable instance_type not set

Solution

  1. Step 1: Understand variable precedence

    Terraform uses environment variables with TF_VAR_ prefix to override default variable values.
  2. Step 2: Apply environment variable value

    Since TF_VAR_instance_type is set to "t3.medium", this value overrides the default "t2.micro".
  3. Final Answer:

    "t3.medium" (from environment variable) -> Option B
  4. Quick Check:

    Environment variable overrides default value [OK]
Hint: Environment variable overrides default Terraform variable [OK]
Common Mistakes:
  • Assuming default always applies ignoring environment variable
  • Expecting error if environment variable is set
  • Confusing null with default value
4. You set the environment variable TF_VAR_count=3 but Terraform still uses the default value count = 1 from the variable declaration. What is the most likely cause?
medium
A. The environment variable name is case-sensitive and should be TF_VAR_Count
B. The environment variable was set after running terraform init
C. The variable count is declared as a string, but environment variable is numeric
D. The shell session where Terraform runs does not have the environment variable exported

Solution

  1. Step 1: Check environment variable visibility

    Terraform reads environment variables from the shell session it runs in; if not exported, Terraform won't see it.
  2. Step 2: Confirm export of variable

    Setting TF_VAR_count=3 without export means it's not passed to child processes like Terraform.
  3. Final Answer:

    The shell session where Terraform runs does not have the environment variable exported -> Option D
  4. Quick Check:

    Environment variables must be exported to be visible [OK]
Hint: Always export environment variables before running Terraform [OK]
Common Mistakes:
  • Assuming variable names are case-insensitive
  • Thinking terraform init caches variable values
  • Confusing variable type mismatch as cause
5. You want to securely provide a sensitive variable db_password to Terraform without storing it in code or plain text files. Which approach using environment variables is best practice?
hard
A. Set export TF_VAR_db_password=your_password in your shell before running Terraform
B. Hardcode the password in terraform.tfvars file
C. Use terraform apply -var 'db_password=your_password' every time
D. Store the password in a public GitHub repository and reference it

Solution

  1. Step 1: Avoid storing sensitive data in code files

    Hardcoding passwords in files or public repos risks exposure.
  2. Step 2: Use environment variables for sensitive data

    Setting TF_VAR_db_password in the shell keeps secrets out of code and version control.
  3. Final Answer:

    Set export TF_VAR_db_password=your_password in your shell before running Terraform -> Option A
  4. Quick Check:

    Environment variables keep secrets out of code [OK]
Hint: Use TF_VAR_ environment variables to keep secrets out of code [OK]
Common Mistakes:
  • Storing secrets in terraform.tfvars files
  • Passing secrets on command line risking history leaks
  • Publishing secrets in public repositories