Bird
Raised Fist0
Terraformcloud~5 mins

Output declaration syntax in Terraform - Cheat Sheet & Quick Revision

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Recall & Review
beginner
What is the purpose of an output declaration in Terraform?
An output declaration in Terraform shows important information after applying the configuration, like IP addresses or resource IDs, so you can use or see them easily.
Click to reveal answer
beginner
Basic syntax of a Terraform output declaration?
Use the keyword output followed by a name without quotes, then a block with value = and the expression to output.
Example:
output "example" {
  value = aws_instance.myserver.id
}
Click to reveal answer
intermediate
Can Terraform outputs have descriptions? Why use them?
Yes, outputs can have a description field to explain what the output means. This helps others understand the purpose of the output when reading the Terraform plan or state.
Click to reveal answer
intermediate
How do you mark an output as sensitive in Terraform?
Add sensitive = true inside the output block to hide the output value from normal display, protecting secrets or private data.
Click to reveal answer
beginner
What happens if you omit the value in an output declaration?
Terraform requires the value field in an output block. Omitting it causes an error because Terraform doesn't know what to show as output.
Click to reveal answer
Which keyword starts an output declaration in Terraform?
Aresource
Boutput
Cvariable
Dprovider
How do you hide sensitive output values in Terraform?
ASet <code>private = true</code>
BUse <code>hidden = true</code>
CAdd <code>sensitive = true</code> inside the output block
DOutputs cannot be hidden
What must every Terraform output block include?
AA <code>value</code> field
BA <code>description</code> field
CA <code>type</code> field
DA <code>depends_on</code> field
What is the correct way to reference an AWS instance ID in an output?
Aaws_instance.myserver.id
Baws_instance.id.myserver
Cmyserver.aws_instance.id
Did.aws_instance.myserver
Why add a description to an output?
ATo change the output type
BTo make the output required
CTo hide the output
DTo explain what the output means
Write the syntax for a Terraform output that shows the public IP of a server and includes a description.
Start with output, give it a name, add value and description inside curly braces.
You got /5 concepts.
    Explain how to protect sensitive information in Terraform outputs and why it is important.
    Think about what happens if secret data is shown openly.
    You got /4 concepts.

      Practice

      (1/5)
      1. What is the purpose of an output block in a Terraform configuration?
      easy
      A. To display useful information after Terraform applies changes
      B. To define variables for input values
      C. To create resources in the cloud
      D. To delete resources automatically

      Solution

      1. Step 1: Understand Terraform output blocks

        Output blocks are used to show important information after Terraform finishes applying infrastructure changes.
      2. Step 2: Differentiate from other blocks

        Variables define inputs, resources create cloud items, and outputs only display results.
      3. Final Answer:

        To display useful information after Terraform applies changes -> Option A
      4. Quick Check:

        Output block = display info [OK]
      Hint: Outputs show info after apply, not inputs or resource creation [OK]
      Common Mistakes:
      • Confusing outputs with variables
      • Thinking outputs create resources
      • Assuming outputs delete resources
      2. Which of the following is the correct syntax to declare an output named instance_ip with value aws_instance.web.private_ip?
      easy
      A. output "instance_ip" { value = aws_instance.web.private_ip }
      B. output instance_ip = aws_instance.web.private_ip
      C. output "instance_ip" : aws_instance.web.private_ip
      D. output instance_ip { value: aws_instance.web.private_ip }

      Solution

      1. Step 1: Recall Terraform output block syntax

        The correct syntax uses the keyword output, a quoted name, and a block with value assignment using =.
      2. Step 2: Check each option

        output "instance_ip" { value = aws_instance.web.private_ip } matches the correct syntax exactly. Others use invalid assignment or missing quotes.
      3. Final Answer:

        output "instance_ip" { value = aws_instance.web.private_ip } -> Option A
      4. Quick Check:

        Output syntax = output "name" { value = ... } [OK]
      Hint: Output name must be quoted and value assigned with = inside braces [OK]
      Common Mistakes:
      • Omitting quotes around output name
      • Using = outside braces
      • Using colon instead of =
      3. Given this output block:
      output "db_password" {
        value     = var.db_password
        sensitive = true
      }

      What will Terraform do when you run terraform apply?
      medium
      A. Cause a syntax error because sensitive is not allowed
      B. Show the db_password value in the output after apply
      C. Hide the db_password value in the output to keep it secret
      D. Ignore the output block completely

      Solution

      1. Step 1: Understand the sensitive attribute

        Setting sensitive = true tells Terraform to hide the output value from the terminal to protect secrets.
      2. Step 2: Predict Terraform behavior on apply

        Terraform will not display the actual value but will note that a sensitive output exists.
      3. Final Answer:

        Hide the db_password value in the output to keep it secret -> Option C
      4. Quick Check:

        sensitive = true hides output value [OK]
      Hint: Sensitive outputs hide values after apply to protect secrets [OK]
      Common Mistakes:
      • Expecting sensitive outputs to show values
      • Thinking sensitive causes errors
      • Assuming outputs are ignored
      4. Identify the error in this output block:
      output "server_port" {
        value = 8080
        sensitive = "false"
      }
      medium
      A. The value 8080 must be a string, not a number
      B. The sensitive attribute should be a boolean, not a string
      C. Output names cannot be quoted
      D. Missing a comma after the value line

      Solution

      1. Step 1: Check attribute types in output block

        The sensitive attribute expects a boolean (true or false), not a string in quotes.
      2. Step 2: Validate other parts

        Value can be a number without quotes, output names must be quoted, and commas are not used between lines in HCL.
      3. Final Answer:

        The sensitive attribute should be a boolean, not a string -> Option B
      4. Quick Check:

        sensitive = true/false boolean, not "false" string [OK]
      Hint: Boolean attributes must not be quoted strings [OK]
      Common Mistakes:
      • Using quotes around boolean values
      • Thinking output names are unquoted
      • Adding commas between lines
      5. You want to output a list of public IPs from multiple AWS instances stored in aws_instance.web list. Which output block correctly returns their public IPs?
      hard
      A. output "public_ips" { value = for i in aws_instance.web { i.public_ip } }
      B. output "public_ips" { value = aws_instance.web.public_ip }
      C. output "public_ips" { value = aws_instance.web.public_ip[*] }
      D. output "public_ips" { value = [for i in aws_instance.web : i.public_ip] }

      Solution

      1. Step 1: Understand how to extract values from a list of resources

        Terraform uses for-expressions inside output value to map over lists and extract attributes.
      2. Step 2: Evaluate each option

        output "public_ips" { value = [for i in aws_instance.web : i.public_ip] } uses correct for-expression syntax. output "public_ips" { value = aws_instance.web.public_ip } tries direct attribute access on list (invalid). output "public_ips" { value = aws_instance.web.public_ip[*] } uses incorrect splat syntax. output "public_ips" { value = for i in aws_instance.web { i.public_ip } } has invalid block syntax.
      3. Final Answer:

        output "public_ips" { value = [for i in aws_instance.web : i.public_ip] } -> Option D
      4. Quick Check:

        Use for-expressions to map list attributes [OK]
      Hint: Use for-expressions with [for x in list : x.attr] to extract lists [OK]
      Common Mistakes:
      • Trying to access attribute directly on list
      • Using invalid syntax for list comprehension
      • Confusing for-expression with block syntax