Input variable precedence order in Terraform - Time & Space Complexity
Start learning this pattern below
Jump into concepts and practice - no test required
We want to understand how Terraform decides which input variable value to use when multiple sources provide values.
How does the number of input sources affect the time it takes to determine the final value?
Analyze the time complexity of resolving input variable values from multiple sources.
variable "example" {
type = string
default = "default_value"
}
# Possible input sources:
# 1. CLI -var option
# 2. Environment variable TF_VAR_example
# 3. terraform.tfvars file
# 4. Default value in variable block
# Terraform picks the value based on precedence order.
This shows the variable declaration and the possible input sources Terraform checks in order.
Terraform checks each input source one by one until it finds a value.
- Primary operation: Checking each input source for the variable value.
- How many times: Once per input source, in a fixed order.
As the number of input sources increases, Terraform checks each source in order until it finds a value.
| Input Sources (n) | Approx. Checks |
|---|---|
| 2 | Up to 2 checks |
| 4 | Up to 4 checks |
| 10 | Up to 10 checks |
Pattern observation: The number of checks grows linearly with the number of input sources.
Time Complexity: O(n)
This means the time to find the variable value grows directly with the number of input sources checked.
[X] Wrong: "Terraform checks all input sources every time and merges values."
[OK] Correct: Terraform stops checking as soon as it finds a value, so it does not always check all sources.
Understanding how input variable precedence works helps you explain how Terraform handles configuration inputs efficiently and predictably.
"What if Terraform allowed parallel checking of input sources? How would that affect the time complexity?"
Practice
Solution
Step 1: Understand Terraform variable precedence
Terraform uses a specific order to decide variable values: CLI flags first, then environment variables, then .tfvars files, and lastly default values.Step 2: Identify the highest priority source
Since CLI flags are checked first, they override all other sources.Final Answer:
Command-line flags (CLI flags) -> Option CQuick Check:
CLI flags > env vars > tfvars > defaults [OK]
- Thinking environment variables override CLI flags
- Assuming .tfvars files have highest priority
- Confusing default values as highest priority
Solution
Step 1: Recall CLI flag syntax for variables
The correct syntax to pass a variable via CLI is using -var followed by 'key=value'.Step 2: Match the correct option
terraform apply -var 'region=us-west-1' uses -var 'region=us-west-1', which is the correct syntax.Final Answer:
terraform apply -var 'region=us-west-1' -> Option DQuick Check:
Use -var 'key=value' for CLI variable input [OK]
- Using --set instead of -var
- Confusing environment variable syntax with CLI flags
- Using -var-file incorrectly for single variables
<pre>variable "env" { default = "dev" } # Command run: # terraform apply -var 'env=prod' # Environment variable: # TF_VAR_env=staging # tfvars file content: # env = "qa" What value will Terraform use for the variable
env during this apply?Solution
Step 1: List variable sources and their precedence
Terraform checks CLI flags first, then environment variables, then tfvars files, then defaults.Step 2: Identify the highest priority value provided
CLI flag sets env=prod, which overrides environment variable (staging), tfvars (qa), and default (dev).Final Answer:
"prod" (from CLI flag) -> Option AQuick Check:
CLI flag value "prod" is used [OK]
- Choosing environment variable over CLI flag
- Picking tfvars value over environment variable
- Assuming default value is used when others exist
TF_VAR_region=us-east-1 set, but your configuration uses a region variable with a default value of us-west-2. You also have a terraform.tfvars file setting region = "eu-central-1". However, Terraform still uses us-west-2. What is the most likely cause?Solution
Step 1: Check environment variable naming
TF_VAR_region is correct naming for environment variable to set variable 'region'.Step 2: Recall precedence order
CLI flags > env vars > tfvars > defaults. Env var us-east-1 should override tfvars and default.Step 3: Identify cause of default value
To override the env var and use default us-west-2, a CLI flag like -var 'region=us-west-2' must have been passed.Final Answer:
You passed a CLI flag overriding all other values -> Option AQuick Check:
CLI flags > env vars > tfvars > defaults [OK]
- Assuming environment variable name is wrong
- Thinking sensitive variables block external values
- Ignoring possibility of CLI flag override
instance_type always uses the value from a .tfvars file, ignoring any CLI flags or environment variables. Which approach correctly enforces this behavior?Solution
Step 1: Understand variable precedence limits
Terraform's precedence is fixed: CLI flags > env vars > .tfvars > defaults. Cannot natively prioritize .tfvars over CLI/env.Step 2: Confirm no enforcement mechanism
There is no way to access or prioritize the .tfvars value separately from the resolved input variable.Step 3: Why other options fail
A relies on user discipline; B validation cannot reference .tfvars; C locals use the already-resolved var value from highest precedence.Final Answer:
Terraform cannot enforce this; CLI flags always override .tfvars files -> Option BQuick Check:
Precedence fixed, cannot override CLI/env with tfvars [OK]
- Assuming Terraform can block CLI flag precedence natively
- Relying on validation rules to enforce external values
- Thinking removing defaults affects precedence order
