Bird
Raised Fist0
Terraformcloud~20 mins

Environment variables (TF_VAR_) in Terraform - Practice Problems & Coding Challenges

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Challenge - 5 Problems
🎖️
TF_VAR Environment Master
Get all challenges correct to earn this badge!
Test your skills under time pressure!
🧠 Conceptual
intermediate
2:00remaining
How does Terraform use environment variables prefixed with TF_VAR_?

Terraform allows setting input variables using environment variables prefixed with TF_VAR_. What happens when you set TF_VAR_region=us-west-2 before running terraform apply?

ATerraform automatically assigns the value 'us-west-2' to the input variable named 'region'.
BTerraform ignores environment variables and requires variables to be set only in .tf files.
CTerraform treats 'TF_VAR_region' as a resource name and creates a resource called 'region'.
DTerraform throws an error because environment variables cannot be used for variables.
Attempts:
2 left
💡 Hint

Think about how environment variables can provide values to Terraform variables without editing files.

❓ Configuration
intermediate
2:00remaining
What is the value of the variable 'instance_type' after applying this configuration with environment variable set?

Given the Terraform variable declaration and environment variable below, what value will instance_type have during terraform apply?

variable "instance_type" {
  type    = string
  default = "t2.micro"
}

Environment variable set before running Terraform:

export TF_VAR_instance_type="m5.large"
A"m5.large"
Bnull
C"t2.micro"
DTerraform throws an error due to conflicting values
Attempts:
2 left
💡 Hint

Environment variables override default values in Terraform variables.

❓ Architecture
advanced
2:30remaining
How to securely manage sensitive variables using TF_VAR_ environment variables?

You want to pass a sensitive variable like a database password to Terraform without storing it in code or state files. Which approach using TF_VAR_ environment variables is best practice?

AStore the sensitive value in a public GitHub repository as a <code>TF_VAR_</code> environment variable.
BHardcode the sensitive value in the Terraform variable default to avoid environment variables.
CSet the sensitive variable as a <code>TF_VAR_</code> environment variable only in your local shell before running Terraform, and mark the variable as sensitive in Terraform.
DPass the sensitive variable as a plain text command line argument to <code>terraform apply</code>.
Attempts:
2 left
💡 Hint

Think about avoiding storing secrets in code or version control.

❓ service_behavior
advanced
2:00remaining
What happens if a required variable is not set and no TF_VAR_ environment variable exists?

Consider a Terraform variable declared as:

variable "region" {
  type = string
}

No default is set. You do not set TF_VAR_region or provide the variable in any other way. What will happen when you run terraform apply?

ATerraform applies with a null value for 'region' without error.
BTerraform uses an empty string as the value for 'region'.
CTerraform fails immediately with a syntax error.
DTerraform prompts you to enter a value interactively before applying.
Attempts:
2 left
💡 Hint

Think about how Terraform handles required variables without defaults or environment variables.

❓ security
expert
3:00remaining
Why is relying solely on TF_VAR_ environment variables for secrets risky in CI/CD pipelines?

In a CI/CD pipeline, you set sensitive secrets as TF_VAR_ environment variables to pass to Terraform. What is a key security risk of this approach?

ATerraform encrypts all environment variables automatically, so there is no risk.
BEnvironment variables can be exposed in logs or process listings, risking secret leakage.
CCI/CD pipelines do not support environment variables, so secrets are lost.
DUsing TF_VAR_ variables disables Terraform state encryption.
Attempts:
2 left
💡 Hint

Consider how environment variables might be exposed during pipeline execution.

Practice

(1/5)
1. What is the purpose of using environment variables with the TF_VAR_ prefix in Terraform?
easy
A. To set Terraform input variables without hardcoding them in configuration files
B. To define backend storage for Terraform state files
C. To specify the Terraform provider version
D. To enable debugging output during Terraform runs

Solution

  1. Step 1: Understand Terraform variable usage

    Terraform variables allow customization of configurations without changing code files.
  2. Step 2: Role of TF_VAR_ prefix

    Environment variables prefixed with TF_VAR_ automatically set Terraform input variables, keeping code clean and secure.
  3. Final Answer:

    To set Terraform input variables without hardcoding them in configuration files -> Option A
  4. Quick Check:

    Environment variables with TF_VAR_ prefix set variables [OK]
Hint: TF_VAR_ prefix sets Terraform variables via environment [OK]
Common Mistakes:
  • Confusing TF_VAR_ with backend configuration
  • Using TF_VAR_ to set provider versions
  • Expecting TF_VAR_ to enable debug logs
2. Which of the following is the correct way to set a Terraform variable named region using an environment variable?
easy
A. TF_VARregion=us-west-2
B. set TF_VAR-region=us-west-2
C. export TF_VAR_region=us-west-2
D. terraform var region=us-west-2

Solution

  1. Step 1: Identify correct environment variable syntax

    Terraform expects environment variables for variables to be prefixed with TF_VAR_ followed by the variable name.
  2. Step 2: Correct shell export command

    In Unix-like shells, export TF_VAR_region=us-west-2 correctly sets the variable.
  3. Final Answer:

    export TF_VAR_region=us-west-2 -> Option C
  4. Quick Check:

    Use export TF_VAR_variable=value [OK]
Hint: Use export TF_VAR_variable=value to set variables [OK]
Common Mistakes:
  • Using dash instead of underscore in TF_VAR_ prefix
  • Missing export keyword in Unix shell
  • Trying to set variables with terraform command directly
3. Given the Terraform variable declaration:
variable "instance_type" { default = "t2.micro" }

and the environment variable set as export TF_VAR_instance_type=t3.medium, what will be the value of var.instance_type during Terraform apply?
medium
A. "t2.micro" (default value)
B. "t3.medium" (from environment variable)
C. null (no value set)
D. Error: variable instance_type not set

Solution

  1. Step 1: Understand variable precedence

    Terraform uses environment variables with TF_VAR_ prefix to override default variable values.
  2. Step 2: Apply environment variable value

    Since TF_VAR_instance_type is set to "t3.medium", this value overrides the default "t2.micro".
  3. Final Answer:

    "t3.medium" (from environment variable) -> Option B
  4. Quick Check:

    Environment variable overrides default value [OK]
Hint: Environment variable overrides default Terraform variable [OK]
Common Mistakes:
  • Assuming default always applies ignoring environment variable
  • Expecting error if environment variable is set
  • Confusing null with default value
4. You set the environment variable TF_VAR_count=3 but Terraform still uses the default value count = 1 from the variable declaration. What is the most likely cause?
medium
A. The environment variable name is case-sensitive and should be TF_VAR_Count
B. The environment variable was set after running terraform init
C. The variable count is declared as a string, but environment variable is numeric
D. The shell session where Terraform runs does not have the environment variable exported

Solution

  1. Step 1: Check environment variable visibility

    Terraform reads environment variables from the shell session it runs in; if not exported, Terraform won't see it.
  2. Step 2: Confirm export of variable

    Setting TF_VAR_count=3 without export means it's not passed to child processes like Terraform.
  3. Final Answer:

    The shell session where Terraform runs does not have the environment variable exported -> Option D
  4. Quick Check:

    Environment variables must be exported to be visible [OK]
Hint: Always export environment variables before running Terraform [OK]
Common Mistakes:
  • Assuming variable names are case-insensitive
  • Thinking terraform init caches variable values
  • Confusing variable type mismatch as cause
5. You want to securely provide a sensitive variable db_password to Terraform without storing it in code or plain text files. Which approach using environment variables is best practice?
hard
A. Set export TF_VAR_db_password=your_password in your shell before running Terraform
B. Hardcode the password in terraform.tfvars file
C. Use terraform apply -var 'db_password=your_password' every time
D. Store the password in a public GitHub repository and reference it

Solution

  1. Step 1: Avoid storing sensitive data in code files

    Hardcoding passwords in files or public repos risks exposure.
  2. Step 2: Use environment variables for sensitive data

    Setting TF_VAR_db_password in the shell keeps secrets out of code and version control.
  3. Final Answer:

    Set export TF_VAR_db_password=your_password in your shell before running Terraform -> Option A
  4. Quick Check:

    Environment variables keep secrets out of code [OK]
Hint: Use TF_VAR_ environment variables to keep secrets out of code [OK]
Common Mistakes:
  • Storing secrets in terraform.tfvars files
  • Passing secrets on command line risking history leaks
  • Publishing secrets in public repositories