Bird
Raised Fist0
Terraformcloud~5 mins

Outputs for module communication in Terraform - Cheat Sheet & Quick Revision

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Recall & Review
beginner
What is the purpose of output blocks in Terraform modules?
Output blocks allow a module to expose values to the parent module or root configuration. They help share information like resource IDs or IP addresses between modules.
Click to reveal answer
beginner
How do you reference an output from a child module in the root module?
Use module.<module_name>.<output_name>. For example, module.webserver.ip_address accesses the ip_address output from the webserver module.
Click to reveal answer
intermediate
Can outputs be used to pass sensitive information between modules?
Yes, outputs can be marked as sensitive = true to hide their values in Terraform's output and logs, helping protect secrets during module communication.
Click to reveal answer
intermediate
What happens if a module output is not defined but you try to access it?
Terraform will return an error during plan or apply, indicating the output does not exist. Outputs must be explicitly declared in the module to be accessible.
Click to reveal answer
advanced
Why is it a best practice to use outputs for module communication instead of directly accessing resources?
Outputs create a clear interface for modules, improving modularity and encapsulation. This avoids tight coupling and makes modules reusable and easier to maintain.
Click to reveal answer
How do you define an output in a Terraform module?
AUsing an <code>output</code> block with a <code>value</code> attribute
BUsing a <code>variable</code> block
CUsing a <code>resource</code> block
DUsing a <code>provider</code> block
How do you access an output named db_endpoint from a module called database?
A<code>output.database.db_endpoint</code>
B<code>module.database.db_endpoint</code>
C<code>var.database.db_endpoint</code>
D<code>resource.database.db_endpoint</code>
What does setting sensitive = true on an output do?
AMakes the output read-only
BEncrypts the output value in the state file
CPrevents the output from being shown in Terraform plan and apply output
DAutomatically deletes the output after apply
If a module does not define an output, can you still access its resource attributes directly from the root module?
AOnly if you use data sources
BYes, always
COnly if the resource is public
DNo, you must define outputs to expose values
Why is using outputs for module communication considered a best practice?
AIt creates a clear interface and improves module reusability
BIt makes Terraform run faster
CIt reduces the number of resources created
DIt automatically documents the module
Explain how outputs enable communication between Terraform modules and why they are important.
Think about how one module shares information with another.
You got /4 concepts.
    Describe how to mark an output as sensitive and why you might want to do that.
    Consider security when sharing secrets.
    You got /3 concepts.

      Practice

      (1/5)
      1. What is the main purpose of output blocks in Terraform modules?
      easy
      A. To share values from one module to another or to the user
      B. To create new resources in the cloud
      C. To define variables for user input
      D. To delete resources after deployment

      Solution

      1. Step 1: Understand the role of output blocks

        Output blocks are used to expose values from a module so other modules or users can access them.
      2. Step 2: Differentiate outputs from other blocks

        Unlike resource or variable blocks, outputs do not create or accept input but share information.
      3. Final Answer:

        To share values from one module to another or to the user -> Option A
      4. Quick Check:

        Outputs share values = D [OK]
      Hint: Outputs share info between modules or users [OK]
      Common Mistakes:
      • Confusing outputs with resource creation
      • Thinking outputs accept user input
      • Assuming outputs delete resources
      2. Which of the following is the correct syntax to define an output named instance_ip with value aws_instance.web.private_ip?
      easy
      A. output instance_ip = aws_instance.web.private_ip
      B. output "instance_ip" { value = aws_instance.web.private_ip }
      C. output "instance_ip" = aws_instance.web.private_ip
      D. output { instance_ip = aws_instance.web.private_ip }

      Solution

      1. Step 1: Recall Terraform output block syntax

        Outputs use the syntax: output "name" { value = expression }
      2. Step 2: Match syntax with options

        output "instance_ip" { value = aws_instance.web.private_ip } matches the correct syntax with quotes and value assignment inside braces.
      3. Final Answer:

        output "instance_ip" { value = aws_instance.web.private_ip } -> Option B
      4. Quick Check:

        Correct output block syntax = B [OK]
      Hint: Output blocks need quotes and value inside braces [OK]
      Common Mistakes:
      • Missing quotes around output name
      • Using equals sign outside braces
      • Placing value outside output block
      3. Given this module output block:
      output "db_endpoint" {
        value = aws_db_instance.main.endpoint
      }

      And this root module code:
      module "database" {
        source = "./modules/db"
      }
      
      output "database_url" {
        value = module.database.db_endpoint
      }

      What will terraform output database_url show after deployment?
      medium
      A. The endpoint address of the AWS database instance
      B. The string 'module.database.db_endpoint'
      C. An error because outputs cannot be nested
      D. The IP address of the AWS database instance

      Solution

      1. Step 1: Understand module output forwarding

        The module outputs 'db_endpoint' which is accessed in root as 'module.database.db_endpoint'.
      2. Step 2: Check root output value

        The root output 'database_url' uses the module output value, so it will show the actual endpoint string.
      3. Final Answer:

        The endpoint address of the AWS database instance -> Option A
      4. Quick Check:

        Module output forwarded = A [OK]
      Hint: Root output uses module output value directly [OK]
      Common Mistakes:
      • Thinking output shows variable name as string
      • Assuming outputs cannot be nested
      • Confusing endpoint with IP address
      4. You wrote this output block inside a module:
      output "server_ip" {
        value = aws_instance.app.private_ip
      }

      But when you run terraform apply, you get an error: Reference to undeclared resource. What is the likely cause?
      medium
      A. The output block is missing a description
      B. Output blocks cannot reference resource attributes
      C. Output names cannot contain underscores
      D. The resource aws_instance.app is not defined in the module

      Solution

      1. Step 1: Analyze the error message

        'Reference to undeclared resource' means Terraform cannot find 'aws_instance.app' in the module.
      2. Step 2: Check output references

        Outputs must reference existing resources; if resource is missing, error occurs.
      3. Final Answer:

        The resource aws_instance.app is not defined in the module -> Option D
      4. Quick Check:

        Missing resource causes reference error = A [OK]
      Hint: Check resource exists before referencing in output [OK]
      Common Mistakes:
      • Assuming outputs can't reference resources
      • Thinking underscores are invalid in output names
      • Believing description is mandatory
      5. You have a module that creates multiple AWS instances and outputs a list of their private IPs:
      output "instance_ips" {
        value = [for i in aws_instance.app : i.private_ip]
      }

      How can you use this output in the root module to create a security group rule allowing SSH from all these IPs?
      hard
      A. Use count = length(module.app.instance_ips) but no for_each
      B. Directly assign cidr_blocks = module.app.instance_ips without conversion
      C. Use for_each = toset(module.app.instance_ips) in the security group rule resource
      D. Outputs cannot be used to create security group rules

      Solution

      1. Step 1: Understand output is a list of IPs

        The output returns a list of private IP addresses from multiple instances.
      2. Step 2: Use for_each with a set for unique IPs

        Security group rules can be created per IP using for_each with toset() to avoid duplicates.
      3. Final Answer:

        Use for_each = toset(module.app.instance_ips) in the security group rule resource -> Option C
      4. Quick Check:

        Use for_each with toset for multiple IP rules = C [OK]
      Hint: Use for_each with toset() for list outputs in resources [OK]
      Common Mistakes:
      • Assigning list directly to cidr_blocks without for_each
      • Using count without mapping IPs
      • Thinking outputs can't be used in resource blocks