Input variable precedence order in Terraform - Commands & Configuration
Start learning this pattern below
Jump into concepts and practice - no test required
variable "region" { description = "The cloud region to deploy resources" type = string default = "us-east-1" } variable "instance_type" { description = "Type of instance to use" type = string default = "t2.micro" }
This file defines two variables: region and instance_type. Each has a default value. These defaults are used if no other value is provided.
This command runs Terraform to create resources. It sets the region and instance_type variables directly on the command line, which overrides defaults and other settings.
terraform apply -var='region=us-west-2' -var='instance_type=t3.small' -auto-approve
-var - Set variable values directly on the command line-auto-approve - Skip interactive approval promptThis command runs Terraform using a variable file named custom.tfvars. Values in this file override defaults but are overridden by command line variables.
terraform apply -var-file=custom.tfvars -auto-approve
-var-file - Load variables from a file-auto-approve - Skip interactive approval promptThis command runs Terraform without extra variable settings. It uses default values from the variable definitions.
terraform apply -auto-approve
-auto-approve - Skip interactive approval promptIf you remember nothing else from this pattern, remember: command line variables override variable files, which override default values in the code.
Practice
Solution
Step 1: Understand Terraform variable precedence
Terraform uses a specific order to decide variable values: CLI flags first, then environment variables, then .tfvars files, and lastly default values.Step 2: Identify the highest priority source
Since CLI flags are checked first, they override all other sources.Final Answer:
Command-line flags (CLI flags) -> Option CQuick Check:
CLI flags > env vars > tfvars > defaults [OK]
- Thinking environment variables override CLI flags
- Assuming .tfvars files have highest priority
- Confusing default values as highest priority
Solution
Step 1: Recall CLI flag syntax for variables
The correct syntax to pass a variable via CLI is using -var followed by 'key=value'.Step 2: Match the correct option
terraform apply -var 'region=us-west-1' uses -var 'region=us-west-1', which is the correct syntax.Final Answer:
terraform apply -var 'region=us-west-1' -> Option DQuick Check:
Use -var 'key=value' for CLI variable input [OK]
- Using --set instead of -var
- Confusing environment variable syntax with CLI flags
- Using -var-file incorrectly for single variables
<pre>variable "env" { default = "dev" } # Command run: # terraform apply -var 'env=prod' # Environment variable: # TF_VAR_env=staging # tfvars file content: # env = "qa" What value will Terraform use for the variable
env during this apply?Solution
Step 1: List variable sources and their precedence
Terraform checks CLI flags first, then environment variables, then tfvars files, then defaults.Step 2: Identify the highest priority value provided
CLI flag sets env=prod, which overrides environment variable (staging), tfvars (qa), and default (dev).Final Answer:
"prod" (from CLI flag) -> Option AQuick Check:
CLI flag value "prod" is used [OK]
- Choosing environment variable over CLI flag
- Picking tfvars value over environment variable
- Assuming default value is used when others exist
TF_VAR_region=us-east-1 set, but your configuration uses a region variable with a default value of us-west-2. You also have a terraform.tfvars file setting region = "eu-central-1". However, Terraform still uses us-west-2. What is the most likely cause?Solution
Step 1: Check environment variable naming
TF_VAR_region is correct naming for environment variable to set variable 'region'.Step 2: Recall precedence order
CLI flags > env vars > tfvars > defaults. Env var us-east-1 should override tfvars and default.Step 3: Identify cause of default value
To override the env var and use default us-west-2, a CLI flag like -var 'region=us-west-2' must have been passed.Final Answer:
You passed a CLI flag overriding all other values -> Option AQuick Check:
CLI flags > env vars > tfvars > defaults [OK]
- Assuming environment variable name is wrong
- Thinking sensitive variables block external values
- Ignoring possibility of CLI flag override
instance_type always uses the value from a .tfvars file, ignoring any CLI flags or environment variables. Which approach correctly enforces this behavior?Solution
Step 1: Understand variable precedence limits
Terraform's precedence is fixed: CLI flags > env vars > .tfvars > defaults. Cannot natively prioritize .tfvars over CLI/env.Step 2: Confirm no enforcement mechanism
There is no way to access or prioritize the .tfvars value separately from the resolved input variable.Step 3: Why other options fail
A relies on user discipline; B validation cannot reference .tfvars; C locals use the already-resolved var value from highest precedence.Final Answer:
Terraform cannot enforce this; CLI flags always override .tfvars files -> Option BQuick Check:
Precedence fixed, cannot override CLI/env with tfvars [OK]
- Assuming Terraform can block CLI flag precedence natively
- Relying on validation rules to enforce external values
- Thinking removing defaults affects precedence order
