Bird
Raised Fist0
Terraformcloud~5 mins

Input variable precedence order in Terraform - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
Terraform uses variables to customize infrastructure. Sometimes, the same variable can be set in different places. Knowing which setting Terraform uses helps avoid confusion and errors.
When you want to override a default variable value without changing the code.
When you run Terraform on different machines and want different settings on each.
When you want to test changes by temporarily changing a variable value.
When you use automation tools that pass variables to Terraform.
When you want to keep sensitive values out of your main configuration files.
Config File - variables.tf
variables.tf
variable "region" {
  description = "The cloud region to deploy resources"
  type        = string
  default     = "us-east-1"
}

variable "instance_type" {
  description = "Type of instance to use"
  type        = string
  default     = "t2.micro"
}

This file defines two variables: region and instance_type. Each has a default value. These defaults are used if no other value is provided.

Commands

This command runs Terraform to create resources. It sets the region and instance_type variables directly on the command line, which overrides defaults and other settings.

Terminal
terraform apply -var='region=us-west-2' -var='instance_type=t3.small' -auto-approve
Expected OutputExpected
Acquiring state lock. This may take a few moments... Terraform used the selected providers to generate the following execution plan. Resource actions are indicated with the following symbols: + create Plan: 1 to add, 0 to change, 0 to destroy. Changes to Outputs: + instance_type = "t3.small" + region = "us-west-2" Do you want to perform these actions? Terraform will perform the actions described above. Apply complete! Resources: 1 added, 0 changed, 0 destroyed.
→
-var - Set variable values directly on the command line
→
-auto-approve - Skip interactive approval prompt

This command runs Terraform using a variable file named custom.tfvars. Values in this file override defaults but are overridden by command line variables.

Terminal
terraform apply -var-file=custom.tfvars -auto-approve
Expected OutputExpected
Acquiring state lock. This may take a few moments... Terraform used the selected providers to generate the following execution plan. Resource actions are indicated with the following symbols: + create Plan: 1 to add, 0 to change, 0 to destroy. Changes to Outputs: + instance_type = "t2.medium" + region = "us-east-2" Do you want to perform these actions? Terraform will perform the actions described above. Apply complete! Resources: 1 added, 0 changed, 0 destroyed.
→
-var-file - Load variables from a file
→
-auto-approve - Skip interactive approval prompt

This command runs Terraform without extra variable settings. It uses default values from the variable definitions.

Terminal
terraform apply -auto-approve
Expected OutputExpected
Acquiring state lock. This may take a few moments... Terraform used the selected providers to generate the following execution plan. Resource actions are indicated with the following symbols: + create Plan: 1 to add, 0 to change, 0 to destroy. Changes to Outputs: + instance_type = "t2.micro" + region = "us-east-1" Do you want to perform these actions? Terraform will perform the actions described above. Apply complete! Resources: 1 added, 0 changed, 0 destroyed.
→
-auto-approve - Skip interactive approval prompt
Key Concept

If you remember nothing else from this pattern, remember: command line variables override variable files, which override default values in the code.

Common Mistakes
Setting a variable in a .tfvars file but also setting it on the command line and expecting the file value to be used.
Terraform uses the command line variable value first, ignoring the .tfvars file for that variable.
Use only one method to set a variable or understand that command line variables have higher priority.
Not providing a value for a variable without a default and expecting Terraform to use a default.
Terraform will fail because it requires a value for variables without defaults.
Always provide a value via command line, variable file, or default for required variables.
Summary
Terraform variables can be set in multiple places with a clear priority order.
Command line variables have the highest priority and override variable files and defaults.
Variable files override default values defined in the Terraform code.

Practice

(1/5)
1. In Terraform, which source has the highest priority when setting the value of an input variable?
easy
A. Terraform variable definition files (.tfvars)
B. Environment variables
C. Command-line flags (CLI flags)
D. Default values in the variable block

Solution

  1. Step 1: Understand Terraform variable precedence

    Terraform uses a specific order to decide variable values: CLI flags first, then environment variables, then .tfvars files, and lastly default values.
  2. Step 2: Identify the highest priority source

    Since CLI flags are checked first, they override all other sources.
  3. Final Answer:

    Command-line flags (CLI flags) -> Option C
  4. Quick Check:

    CLI flags > env vars > tfvars > defaults [OK]
Hint: Remember: CLI flags always override others [OK]
Common Mistakes:
  • Thinking environment variables override CLI flags
  • Assuming .tfvars files have highest priority
  • Confusing default values as highest priority
2. Which of the following is the correct way to pass a variable value via CLI flag when running Terraform?
easy
A. terraform apply -var-file=region=us-west-1
B. terraform apply --set region=us-west-1
C. terraform apply -env region=us-west-1
D. terraform apply -var 'region=us-west-1'

Solution

  1. Step 1: Recall CLI flag syntax for variables

    The correct syntax to pass a variable via CLI is using -var followed by 'key=value'.
  2. Step 2: Match the correct option

    terraform apply -var 'region=us-west-1' uses -var 'region=us-west-1', which is the correct syntax.
  3. Final Answer:

    terraform apply -var 'region=us-west-1' -> Option D
  4. Quick Check:

    Use -var 'key=value' for CLI variable input [OK]
Hint: Use -var 'key=value' to pass variables via CLI [OK]
Common Mistakes:
  • Using --set instead of -var
  • Confusing environment variable syntax with CLI flags
  • Using -var-file incorrectly for single variables
3. Given the following Terraform variable declaration and usage:
<pre>variable "env" { default = "dev" } # Command run: # terraform apply -var 'env=prod' # Environment variable: # TF_VAR_env=staging # tfvars file content: # env = "qa" What value will Terraform use for the variable env during this apply?
medium
A. "prod" (from CLI flag)
B. "dev" (default value)
C. "staging" (from environment variable)
D. "qa" (from tfvars file)

Solution

  1. Step 1: List variable sources and their precedence

    Terraform checks CLI flags first, then environment variables, then tfvars files, then defaults.
  2. Step 2: Identify the highest priority value provided

    CLI flag sets env=prod, which overrides environment variable (staging), tfvars (qa), and default (dev).
  3. Final Answer:

    "prod" (from CLI flag) -> Option A
  4. Quick Check:

    CLI flag value "prod" is used [OK]
Hint: CLI flags beat env vars and tfvars files [OK]
Common Mistakes:
  • Choosing environment variable over CLI flag
  • Picking tfvars value over environment variable
  • Assuming default value is used when others exist
4. You run Terraform with the environment variable TF_VAR_region=us-east-1 set, but your configuration uses a region variable with a default value of us-west-2. You also have a terraform.tfvars file setting region = "eu-central-1". However, Terraform still uses us-west-2. What is the most likely cause?
medium
A. You passed a CLI flag overriding all other values
B. The environment variable name is incorrect; it should be TF_REGION
C. The variable is marked as sensitive and ignores external values
D. The terraform.tfvars file is not loaded automatically

Solution

  1. Step 1: Check environment variable naming

    TF_VAR_region is correct naming for environment variable to set variable 'region'.
  2. Step 2: Recall precedence order

    CLI flags > env vars > tfvars > defaults. Env var us-east-1 should override tfvars and default.
  3. Step 3: Identify cause of default value

    To override the env var and use default us-west-2, a CLI flag like -var 'region=us-west-2' must have been passed.
  4. Final Answer:

    You passed a CLI flag overriding all other values -> Option A
  5. Quick Check:

    CLI flags > env vars > tfvars > defaults [OK]
Hint: CLI flags override env vars and tfvars [OK]
Common Mistakes:
  • Assuming environment variable name is wrong
  • Thinking sensitive variables block external values
  • Ignoring possibility of CLI flag override
5. You want to ensure a Terraform variable instance_type always uses the value from a .tfvars file, ignoring any CLI flags or environment variables. Which approach correctly enforces this behavior?
hard
A. Remove default value and only set instance_type in the .tfvars file; avoid passing CLI flags or env vars
B. Terraform cannot enforce this; CLI flags always override .tfvars files
C. Use a local variable to override instance_type with the .tfvars value inside the configuration
D. Use a validation rule in the variable block to reject values not matching the .tfvars file

Solution

  1. Step 1: Understand variable precedence limits

    Terraform's precedence is fixed: CLI flags > env vars > .tfvars > defaults. Cannot natively prioritize .tfvars over CLI/env.
  2. Step 2: Confirm no enforcement mechanism

    There is no way to access or prioritize the .tfvars value separately from the resolved input variable.
  3. Step 3: Why other options fail

    A relies on user discipline; B validation cannot reference .tfvars; C locals use the already-resolved var value from highest precedence.
  4. Final Answer:

    Terraform cannot enforce this; CLI flags always override .tfvars files -> Option B
  5. Quick Check:

    Precedence fixed, cannot override CLI/env with tfvars [OK]
Hint: Terraform precedence cannot be changed natively [OK]
Common Mistakes:
  • Assuming Terraform can block CLI flag precedence natively
  • Relying on validation rules to enforce external values
  • Thinking removing defaults affects precedence order