Bird
Raised Fist0
Terraformcloud~5 mins

Output values after apply in Terraform - Cheat Sheet & Quick Revision

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Recall & Review
beginner
What is the purpose of output values in Terraform?
Output values show important information about your infrastructure after Terraform finishes applying changes. They help you see results like IP addresses or resource IDs.
Click to reveal answer
beginner
How do you define an output value in Terraform?
Use the output block with a name and a value. For example:
output "instance_ip" {
  value = aws_instance.example.public_ip
}
Click to reveal answer
beginner
When can you see the output values in Terraform?
You see output values right after running terraform apply. You can also view them anytime with terraform output.
Click to reveal answer
intermediate
Can output values be used by other Terraform configurations?
Yes! Output values can be shared and used as inputs in other Terraform configurations using remote state or modules.
Click to reveal answer
intermediate
Why should you avoid putting sensitive data in output values?
Output values are visible in the terminal and state files. Sensitive data here can be exposed unintentionally. Use sensitive = true to hide them.
Click to reveal answer
What command shows output values after infrastructure is created?
Aterraform output
Bterraform init
Cterraform plan
Dterraform destroy
How do you mark an output value as sensitive in Terraform?
AAdd <code>sensitive = true</code> inside the output block
BPrefix the output name with 'secret_'
CUse <code>private = true</code>
DNo special setting is needed
Which of these is a valid output block in Terraform?
Aoutput { name = "db_password"; value = aws_db.password }
Boutput db_password = aws_db.password
Coutput "db_password" { value = aws_db.password }
Doutput "db_password" => aws_db.password
When are output values available?
AAfter terraform init
BOnly after terraform destroy
CBefore terraform plan
DOnly after running terraform apply
Can output values be used as inputs in other Terraform modules?
AOnly if you use terraform import
BYes, by referencing outputs in module inputs
COnly if you export them as environment variables
DNo, outputs are only for display
Explain what output values are in Terraform and why they are useful.
Think about what you want to see after creating resources.
You got /3 concepts.
    Describe how to define a sensitive output value and why sensitivity matters.
    Consider protecting secrets like passwords.
    You got /3 concepts.

      Practice

      (1/5)
      1. What is the main purpose of output values in a Terraform configuration?
      easy
      A. To create new cloud resources
      B. To display important information after Terraform applies changes
      C. To define variables used inside Terraform modules
      D. To store Terraform state files remotely

      Solution

      1. Step 1: Understand the role of output values

        Output values are used to show key information after Terraform finishes applying infrastructure changes.
      2. Step 2: Differentiate outputs from other Terraform features

        Variables define inputs, resources create infrastructure, and state files store deployment state. Outputs specifically display results.
      3. Final Answer:

        To display important information after Terraform applies changes -> Option B
      4. Quick Check:

        Outputs = display info after apply [OK]
      Hint: Outputs show info after apply, not inputs or resources [OK]
      Common Mistakes:
      • Confusing outputs with variables
      • Thinking outputs create resources
      • Mixing outputs with state storage
      2. Which of the following is the correct syntax to define an output named instance_ip in Terraform?
      easy
      A. output "instance_ip" { value = aws_instance.example.private_ip }
      B. output instance_ip = aws_instance.example.private_ip
      C. output "instance_ip" = aws_instance.example.private_ip
      D. output { instance_ip = aws_instance.example.private_ip }

      Solution

      1. Step 1: Recall Terraform output block syntax

        Outputs use the block syntax: output "name" { value = ... }.
      2. Step 2: Match syntax to options

        output "instance_ip" { value = aws_instance.example.private_ip } matches the correct block syntax with quotes and value assignment.
      3. Final Answer:

        output "instance_ip" { value = aws_instance.example.private_ip } -> Option A
      4. Quick Check:

        Output block = output "name" { value = ... } [OK]
      Hint: Outputs need block syntax with quotes and value key [OK]
      Common Mistakes:
      • Missing quotes around output name
      • Using equals sign outside block
      • Incorrect block structure
      3. Given this Terraform output block:
      output "bucket_name" {
        value = aws_s3_bucket.my_bucket.id
      }

      What will Terraform display after terraform apply if the bucket ID is my-bucket-123?
      medium
      A. "aws_s3_bucket.my_bucket.id"
      B. "my-bucket-123"
      C. bucket_name = "my-bucket-123"
      D. No output will be shown

      Solution

      1. Step 1: Understand output display format

        Terraform outputs show the output name followed by an equals sign and the value.
      2. Step 2: Apply the known value

        The value aws_s3_bucket.my_bucket.id is "my-bucket-123", so output shows: bucket_name = "my-bucket-123".
      3. Final Answer:

        bucket_name = "my-bucket-123" -> Option C
      4. Quick Check:

        Output format = name = value [OK]
      Hint: Outputs show name = value after apply [OK]
      Common Mistakes:
      • Expecting only the value without name
      • Confusing resource attribute with output text
      • Thinking outputs are hidden by default
      4. You wrote this output block:
      output "db_password" {
        value = var.db_password
        sensitive = true
      }

      After terraform apply, you still see the password printed in the console. What is the likely cause?
      medium
      A. You ran terraform output -raw db_password after apply
      B. You must set sensitive = false to hide output
      C. Terraform does not support sensitive outputs
      D. The output block syntax is invalid

      Solution

      1. Step 1: Understand sensitive output behavior

        Sensitive outputs hide values in the terraform apply console and standard terraform output. However, terraform output -raw <name> bypasses this and shows the value.
      2. Step 2: Identify cause of exposure

        The likely cause is running terraform output -raw db_password, which reveals sensitive values.
      3. Final Answer:

        You ran terraform output -raw db_password after apply -> Option A
      4. Quick Check:

        Sensitive hides output unless -raw [OK]
      Hint: Sensitive hides output unless -raw used [OK]
      Common Mistakes:
      • Thinking sensitive = false hides output
      • Believing Terraform can't mark outputs sensitive
      • Assuming syntax error causes exposure
      5. You want to output a list of instance IPs from multiple AWS instances created with a count. Which output block correctly returns all private IPs after apply?
      resource "aws_instance" "web" {
        count = 3
        private_ip = "10.0.0.${count.index + 1}"
      }
      
      output "instance_ips" {
        value = ???
      }
      hard
      A. aws_instance.web[0].private_ip
      B. aws_instance.web.*
      C. aws_instance.web.private_ip
      D. [for i in aws_instance.web : i.private_ip]

      Solution

      1. Step 1: Understand how to access multiple instances' attributes

        When using count, aws_instance.web is a list of resources. To get all private_ip values, use a for expression to extract each.
      2. Step 2: Evaluate options for correct syntax

        [for i in aws_instance.web : i.private_ip] uses a for expression to collect private_ip from each instance, which is valid and recommended.
      3. Final Answer:

        [for i in aws_instance.web : i.private_ip] -> Option D
      4. Quick Check:

        Use for expression to list attributes from count resources [OK]
      Hint: Use for expressions to output lists from multiple resources [OK]
      Common Mistakes:
      • Using wildcard (*) syntax without the attribute
      • Accessing single instance only
      • Trying to output resource without indexing