Resource dependencies (implicit) in Terraform - Time & Space Complexity
Start learning this pattern below
Jump into concepts and practice - no test required
When Terraform creates resources, some depend on others. Understanding how these dependencies affect the time it takes to build infrastructure is important.
We want to know how the number of resources and their connections change the total work Terraform does.
Analyze the time complexity of creating resources with implicit dependencies.
resource "aws_vpc" "main" {
cidr_block = "10.0.0.0/16"
}
resource "aws_subnet" "subnet" {
vpc_id = aws_vpc.main.id
cidr_block = "10.0.1.0/24"
}
resource "aws_instance" "web" {
subnet_id = aws_subnet.subnet.id
ami = "ami-123456"
instance_type = "t2.micro"
}
This sequence creates a VPC, then a subnet inside it, then an instance inside the subnet. Each resource depends on the previous one implicitly.
Look at what Terraform does repeatedly when creating these resources.
- Primary operation: API calls to create each resource (VPC, subnet, instance).
- How many times: Once per resource, but each depends on the previous one finishing first.
As you add more resources with dependencies, Terraform must wait for each to finish before starting the next.
| Input Size (n) | Approx. API Calls/Operations |
|---|---|
| 10 | 10 calls, done one after another |
| 100 | 100 calls, each waiting for the previous |
| 1000 | 1000 calls, sequentially dependent |
Pattern observation: The total time grows roughly in direct proportion to the number of resources because each waits for the last.
Time Complexity: O(n)
This means the time to create all resources grows linearly with the number of dependent resources.
[X] Wrong: "Terraform creates all resources at the same time, so adding more resources doesn't increase time much."
[OK] Correct: When resources depend on each other, Terraform waits for one to finish before starting the next, so time adds up.
Understanding how dependencies affect deployment time helps you design infrastructure that builds efficiently and predict how long changes will take.
"What if some resources had no dependencies and could be created at the same time? How would that change the time complexity?"
Practice
depends_on is set?Solution
Step 1: Understand Terraform's dependency mechanism
Terraform automatically detects dependencies by checking if one resource references another inside its configuration.Step 2: Compare with other options
The order in the file, alphabetical order, or manual input do not affect resource creation order unless explicitly coded.Final Answer:
References between resources inside the configuration -> Option CQuick Check:
Implicit dependencies = references [OK]
- Thinking order in file matters
- Assuming alphabetical order controls creation
- Believing manual input sets dependencies
aws_vpc.main?Solution
Step 1: Identify implicit dependency via reference
resource "aws_subnet" "subnet1" { vpc_id = aws_vpc.main.id, cidr_block = "10.0.1.0/24" } referencesaws_vpc.main.idinsidevpc_id, creating an implicit dependency.Step 2: Check other options
resource "aws_subnet" "subnet1" { cidr_block = "10.0.1.0/24" } lacks any reference, so no implicit dependency. resource "aws_subnet" "subnet1" { depends_on = [aws_vpc.main], cidr_block = "10.0.1.0/24" } uses explicitdepends_on, not implicit. resource "aws_subnet" "subnet1" { vpc_id = "vpc-123456", cidr_block = "10.0.1.0/24" } uses a hardcoded string, no reference.Final Answer:
resource "aws_subnet" "subnet1" { vpc_id = aws_vpc.main.id, cidr_block = "10.0.1.0/24" } -> Option DQuick Check:
Reference attribute = implicit dependency [OK]
- Confusing explicit depends_on with implicit
- Using hardcoded IDs instead of references
- Missing the reference attribute in resource
resource "aws_vpc" "main" {
cidr_block = "10.0.0.0/16"
}
resource "aws_subnet" "subnet1" {
vpc_id = aws_vpc.main.id
cidr_block = "10.0.1.0/24"
}
resource "aws_instance" "web" {
subnet_id = aws_subnet.subnet1.id
ami = "ami-123456"
instance_type = "t2.micro"
}Solution
Step 1: Identify dependencies from references
aws_subnet.subnet1depends onaws_vpc.mainviavpc_id.aws_instance.webdepends onaws_subnet.subnet1viasubnet_id.Step 2: Determine creation order
Terraform creates resources in order of dependencies: firstaws_vpc.main, thenaws_subnet.subnet1, thenaws_instance.web.Final Answer:
aws_vpc.main -> aws_subnet.subnet1 -> aws_instance.web -> Option AQuick Check:
Dependency chain order = B [OK]
- Ignoring dependency direction
- Assuming alphabetical or file order
- Mixing up resource references
aws_security_group.sg and aws_instance.web. The instance should be created after the security group. The code is:
resource "aws_security_group" "sg" {
name = "web-sg"
}
resource "aws_instance" "web" {
ami = "ami-123456"
instance_type = "t2.micro"
}
Why might Terraform create the instance before the security group, and how to fix it?Solution
Step 1: Identify missing implicit dependency
The instance resource does not reference the security group, so Terraform sees no dependency and may create in any order.Step 2: Fix by adding reference
Addingvpc_security_group_ids = [aws_security_group.sg.id]creates an implicit dependency, ensuring the security group is created first.Final Answer:
Add vpc_security_group_ids referencing security group to instance -> Option AQuick Check:
Reference creates implicit dependency [OK]
- Relying only on depends_on when reference is better
- Changing resource names expecting order change
- Assuming Terraform creates instances first always
aws_lb.lb, aws_lb_target_group.tg, and aws_lb_listener.listener. The listener must be created after the load balancer and target group. The target group references the load balancer's ARN. The listener references the target group's ARN. However, you want to ensure the listener is created only after both are fully ready. Which is the best way to enforce this implicit dependency correctly?Solution
Step 1: Understand implicit dependency chaining
Referencingaws_lb.lb.arnin the target group creates an implicit dependency on the load balancer. Referencingaws_lb_target_group.tg.arnin the listener creates an implicit dependency on the target group.Step 2: Avoid unnecessary explicit depends_on
Using references allows Terraform to build the dependency graph automatically and safely without manualdepends_on, which should be reserved for special cases.Final Answer:
Use references to create implicit dependencies without depends_on -> Option BQuick Check:
Implicit references chain dependencies best [OK]
- Overusing depends_on instead of references
- Creating resources in wrong order manually
- Avoiding references and relying only on depends_on
