Bird
Raised Fist0
Terraformcloud~10 mins

Output values after apply in Terraform - Step-by-Step Execution

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Process Flow - Output values after apply
Write Terraform config with outputs
↓
Run terraform init
↓
Run terraform apply
↓
Terraform creates resources
↓
Terraform shows output values
↓
User sees output values on screen
Terraform config defines outputs, then after apply, Terraform creates resources and shows output values to the user.
Execution Sample
Terraform
resource "aws_s3_bucket" "example" {
  bucket = "my-example-bucket"
}

output "bucket_name" {
  value = aws_s3_bucket.example.bucket
}
Creates an S3 bucket and outputs its name after apply.
Process Table
StepActionTerraform StateOutput Value Shown
1Write config with resource and outputNo resources createdNo output yet
2Run terraform initProviders initializedNo output yet
3Run terraform applyResource aws_s3_bucket.example createdNo output yet
4Terraform finishes applyState updated with bucket infobucket_name = "my-example-bucket"
5User sees output on screenState stablebucket_name = "my-example-bucket"
💡 Terraform apply completes and outputs are displayed to user.
Status Tracker
VariableStartAfter ApplyFinal
aws_s3_bucket.example.bucketundefined"my-example-bucket""my-example-bucket"
output.bucket_nameundefined"my-example-bucket""my-example-bucket"
Key Moments - 2 Insights
Why don't output values show before running 'terraform apply'?
Output values depend on resource attributes created during apply, so before apply, these values are undefined as shown in execution_table step 1 and 3.
Can output values change after apply without changing config?
Yes, if resource attributes change (like bucket name), output values update after next apply, reflecting new state as in execution_table step 4.
Visual Quiz - 3 Questions
Test your understanding
Look at the execution table, at which step does Terraform show the output value?
AStep 2
BStep 1
CStep 4
DStep 3
💡 Hint
Check the 'Output Value Shown' column in execution_table rows.
According to variable_tracker, what is the value of 'output.bucket_name' before apply?
Aundefined
B"my-example-bucket"
Cnull
Dempty string
💡 Hint
Look at the 'Start' column for 'output.bucket_name' in variable_tracker.
If the bucket name changes in config and you run apply again, what happens to the output value?
AOutput value stays the same
BOutput value updates to new bucket name
CTerraform errors out
DOutput value becomes undefined
💡 Hint
Refer to key_moments about output values changing after apply.
Concept Snapshot
Terraform outputs show resource info after apply.
Define outputs in config with 'output' blocks.
Run 'terraform apply' to create resources.
Outputs appear after apply completes.
Outputs reflect current resource state.
Full Transcript
This visual execution shows how Terraform outputs work. First, you write a config with resources and output blocks. Then you run 'terraform init' to prepare. Next, 'terraform apply' creates resources. After apply finishes, Terraform updates its state and shows output values on screen. Outputs depend on resource attributes created during apply, so they are undefined before apply. If resource attributes change, outputs update after next apply. This helps you see important info like resource names or IPs after deployment.

Practice

(1/5)
1. What is the main purpose of output values in a Terraform configuration?
easy
A. To create new cloud resources
B. To display important information after Terraform applies changes
C. To define variables used inside Terraform modules
D. To store Terraform state files remotely

Solution

  1. Step 1: Understand the role of output values

    Output values are used to show key information after Terraform finishes applying infrastructure changes.
  2. Step 2: Differentiate outputs from other Terraform features

    Variables define inputs, resources create infrastructure, and state files store deployment state. Outputs specifically display results.
  3. Final Answer:

    To display important information after Terraform applies changes -> Option B
  4. Quick Check:

    Outputs = display info after apply [OK]
Hint: Outputs show info after apply, not inputs or resources [OK]
Common Mistakes:
  • Confusing outputs with variables
  • Thinking outputs create resources
  • Mixing outputs with state storage
2. Which of the following is the correct syntax to define an output named instance_ip in Terraform?
easy
A. output "instance_ip" { value = aws_instance.example.private_ip }
B. output instance_ip = aws_instance.example.private_ip
C. output "instance_ip" = aws_instance.example.private_ip
D. output { instance_ip = aws_instance.example.private_ip }

Solution

  1. Step 1: Recall Terraform output block syntax

    Outputs use the block syntax: output "name" { value = ... }.
  2. Step 2: Match syntax to options

    output "instance_ip" { value = aws_instance.example.private_ip } matches the correct block syntax with quotes and value assignment.
  3. Final Answer:

    output "instance_ip" { value = aws_instance.example.private_ip } -> Option A
  4. Quick Check:

    Output block = output "name" { value = ... } [OK]
Hint: Outputs need block syntax with quotes and value key [OK]
Common Mistakes:
  • Missing quotes around output name
  • Using equals sign outside block
  • Incorrect block structure
3. Given this Terraform output block:
output "bucket_name" {
  value = aws_s3_bucket.my_bucket.id
}

What will Terraform display after terraform apply if the bucket ID is my-bucket-123?
medium
A. "aws_s3_bucket.my_bucket.id"
B. "my-bucket-123"
C. bucket_name = "my-bucket-123"
D. No output will be shown

Solution

  1. Step 1: Understand output display format

    Terraform outputs show the output name followed by an equals sign and the value.
  2. Step 2: Apply the known value

    The value aws_s3_bucket.my_bucket.id is "my-bucket-123", so output shows: bucket_name = "my-bucket-123".
  3. Final Answer:

    bucket_name = "my-bucket-123" -> Option C
  4. Quick Check:

    Output format = name = value [OK]
Hint: Outputs show name = value after apply [OK]
Common Mistakes:
  • Expecting only the value without name
  • Confusing resource attribute with output text
  • Thinking outputs are hidden by default
4. You wrote this output block:
output "db_password" {
  value = var.db_password
  sensitive = true
}

After terraform apply, you still see the password printed in the console. What is the likely cause?
medium
A. You ran terraform output -raw db_password after apply
B. You must set sensitive = false to hide output
C. Terraform does not support sensitive outputs
D. The output block syntax is invalid

Solution

  1. Step 1: Understand sensitive output behavior

    Sensitive outputs hide values in the terraform apply console and standard terraform output. However, terraform output -raw <name> bypasses this and shows the value.
  2. Step 2: Identify cause of exposure

    The likely cause is running terraform output -raw db_password, which reveals sensitive values.
  3. Final Answer:

    You ran terraform output -raw db_password after apply -> Option A
  4. Quick Check:

    Sensitive hides output unless -raw [OK]
Hint: Sensitive hides output unless -raw used [OK]
Common Mistakes:
  • Thinking sensitive = false hides output
  • Believing Terraform can't mark outputs sensitive
  • Assuming syntax error causes exposure
5. You want to output a list of instance IPs from multiple AWS instances created with a count. Which output block correctly returns all private IPs after apply?
resource "aws_instance" "web" {
  count = 3
  private_ip = "10.0.0.${count.index + 1}"
}

output "instance_ips" {
  value = ???
}
hard
A. aws_instance.web[0].private_ip
B. aws_instance.web.*
C. aws_instance.web.private_ip
D. [for i in aws_instance.web : i.private_ip]

Solution

  1. Step 1: Understand how to access multiple instances' attributes

    When using count, aws_instance.web is a list of resources. To get all private_ip values, use a for expression to extract each.
  2. Step 2: Evaluate options for correct syntax

    [for i in aws_instance.web : i.private_ip] uses a for expression to collect private_ip from each instance, which is valid and recommended.
  3. Final Answer:

    [for i in aws_instance.web : i.private_ip] -> Option D
  4. Quick Check:

    Use for expression to list attributes from count resources [OK]
Hint: Use for expressions to output lists from multiple resources [OK]
Common Mistakes:
  • Using wildcard (*) syntax without the attribute
  • Accessing single instance only
  • Trying to output resource without indexing