Jump into concepts and practice - no test required
or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Terraform Resource Dependencies (Implicit)
📖 Scenario: You are setting up a simple cloud infrastructure using Terraform. You want to create a virtual network and then create a virtual machine inside that network. The virtual machine must be created only after the network is ready.
🎯 Goal: Build a Terraform configuration that creates a virtual network and a virtual machine. Use implicit resource dependencies so Terraform knows to create the network before the virtual machine.
📋 What You'll Learn
Create a resource called azurerm_virtual_network named main_network with address space 10.0.0.0/16.
Create a resource called azurerm_subnet named main_subnet inside main_network with address prefix 10.0.1.0/24.
Create a resource called azurerm_network_interface named main_nic attached to main_subnet.
Create a resource called azurerm_linux_virtual_machine named main_vm that uses main_nic.
Use implicit dependencies by referencing resource attributes to ensure correct creation order.
💡 Why This Matters
🌍 Real World
Cloud engineers often create networks and virtual machines that depend on each other. Using implicit dependencies in Terraform helps automate the correct creation order without extra configuration.
💼 Career
Understanding resource dependencies is essential for infrastructure as code roles, ensuring reliable and maintainable cloud deployments.
Progress0 / 4 steps
1
Create the virtual network resource
Create a resource block for azurerm_virtual_network named main_network with the address space set to ["10.0.0.0/16"].
Terraform
Hint
Use resource "azurerm_virtual_network" "main_network" { ... } and set address_space to ["10.0.0.0/16"].
2
Add a subnet resource inside the virtual network
Create a resource block for azurerm_subnet named main_subnet with the address prefix "10.0.1.0/24". Reference the virtual network ID from azurerm_virtual_network.main_network.id to attach the subnet to the network.
Terraform
Hint
Reference the virtual network name using azurerm_virtual_network.main_network.name inside the subnet resource.
3
Create a network interface attached to the subnet
Create a resource block for azurerm_network_interface named main_nic. Set the subnet_id to azurerm_subnet.main_subnet.id to attach it to the subnet.
Terraform
Hint
Inside ip_configuration, set subnet_id to azurerm_subnet.main_subnet.id.
4
Create a Linux virtual machine using the network interface
Create a resource block for azurerm_linux_virtual_machine named main_vm. Set the network_interface_ids to a list containing azurerm_network_interface.main_nic.id. Use name as "main-vm", resource_group_name as "myResourceGroup", and location as "eastus". Set size to "Standard_DS1_v2". Use admin_username as "adminuser" and admin_password as "Password1234!". Set os_disk with caching as "ReadWrite" and storage_account_type as "Standard_LRS". Use source_image_reference for Ubuntu 20.04 LTS with publisher "Canonical", offer "UbuntuServer", sku "20_04-lts", and version "latest". This will implicitly depend on the network interface.
Terraform
Hint
Reference the network interface ID in network_interface_ids to create an implicit dependency.
Practice
(1/5)
1. What does Terraform use to determine the order of resource creation when no explicit depends_on is set?
easy
A. The alphabetical order of resource names
B. The order resources are written in the file
C. References between resources inside the configuration
A. aws_vpc.main -> aws_subnet.subnet1 -> aws_instance.web
B. aws_instance.web -> aws_subnet.subnet1 -> aws_vpc.main
C. aws_subnet.subnet1 -> aws_vpc.main -> aws_instance.web
D. aws_vpc.main -> aws_instance.web -> aws_subnet.subnet1
Solution
Step 1: Identify dependencies from references
aws_subnet.subnet1 depends on aws_vpc.main via vpc_id. aws_instance.web depends on aws_subnet.subnet1 via subnet_id.
Step 2: Determine creation order
Terraform creates resources in order of dependencies: first aws_vpc.main, then aws_subnet.subnet1, then aws_instance.web.
Final Answer:
aws_vpc.main -> aws_subnet.subnet1 -> aws_instance.web -> Option A
Quick Check:
Dependency chain order = B [OK]
Hint: Follow references to find creation order [OK]
Common Mistakes:
Ignoring dependency direction
Assuming alphabetical or file order
Mixing up resource references
4. You have two resources: aws_security_group.sg and aws_instance.web. The instance should be created after the security group. The code is:
resource "aws_security_group" "sg" {
name = "web-sg"
}
resource "aws_instance" "web" {
ami = "ami-123456"
instance_type = "t2.micro"
}
Why might Terraform create the instance before the security group, and how to fix it?
medium
A. Because no reference exists; add vpc_security_group_ids = [aws_security_group.sg.id] to instance
B. Because depends_on is missing; add depends_on = [aws_security_group.sg] to instance
C. Because resource names are unordered; rename aws_security_group.sg to sg1
D. Because Terraform always creates instances first; no fix possible
Solution
Step 1: Identify missing implicit dependency
The instance resource does not reference the security group, so Terraform sees no dependency and may create in any order.
Step 2: Fix by adding reference
Adding vpc_security_group_ids = [aws_security_group.sg.id] creates an implicit dependency, ensuring the security group is created first.
Final Answer:
Add vpc_security_group_ids referencing security group to instance -> Option A
Quick Check:
Reference creates implicit dependency [OK]
Hint: Add resource attribute reference to create implicit dependency [OK]
Common Mistakes:
Relying only on depends_on when reference is better
Changing resource names expecting order change
Assuming Terraform creates instances first always
5. You have a Terraform configuration with three resources: aws_lb.lb, aws_lb_target_group.tg, and aws_lb_listener.listener. The listener must be created after the load balancer and target group. The target group references the load balancer's ARN. The listener references the target group's ARN. However, you want to ensure the listener is created only after both are fully ready. Which is the best way to enforce this implicit dependency correctly?
hard
A. Use explicit depends_on everywhere and avoid references
B. Reference aws_lb.lb.arn in aws_lb_target_group.tg and aws_lb_target_group.tg.arn in aws_lb_listener.listener without using depends_on
C. Create the listener first, then the target group and load balancer
D. Add depends_on = [aws_lb.lb, aws_lb_target_group.tg] in aws_lb_listener.listener and no references
Solution
Step 1: Understand implicit dependency chaining
Referencing aws_lb.lb.arn in the target group creates an implicit dependency on the load balancer. Referencing aws_lb_target_group.tg.arn in the listener creates an implicit dependency on the target group.
Step 2: Avoid unnecessary explicit depends_on
Using references allows Terraform to build the dependency graph automatically and safely without manual depends_on, which should be reserved for special cases.
Final Answer:
Use references to create implicit dependencies without depends_on -> Option B
Quick Check:
Implicit references chain dependencies best [OK]
Hint: Chain resource references to build implicit dependencies [OK]
Common Mistakes:
Overusing depends_on instead of references
Creating resources in wrong order manually
Avoiding references and relying only on depends_on