Bird
Raised Fist0
Terraformcloud~10 mins

Terraform's declarative approach - Step-by-Step Execution

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Process Flow - Terraform's declarative approach
Write desired state in config
↓
Run terraform plan
↓
Terraform compares current state
↓
Shows changes needed
↓
Run terraform apply
↓
Terraform makes changes to match desired state
↓
Infrastructure matches config
↓
End
Terraform lets you write what you want your cloud setup to look like. It then figures out what to change to make it so.
Execution Sample
Terraform
resource "aws_s3_bucket" "mybucket" {
  bucket = "my-unique-bucket-123"
  acl    = "private"
}
This code declares a private S3 bucket named 'my-unique-bucket-123'. Terraform will create or update the bucket to match this.
Process Table
StepActionTerraform StatePlanned ChangeResult
1Read config fileNo bucket existsCreate bucket 'my-unique-bucket-123'Plan shows bucket creation
2Run terraform applyNo bucket existsCreate bucket 'my-unique-bucket-123'Bucket created in cloud
3Run terraform plan againBucket exists as declaredNo changes neededPlan shows no changes
4Change acl to 'public-read' in configBucket acl is 'private'Update bucket acl to 'public-read'Plan shows acl update
5Run terraform applyBucket acl is 'private'Update bucket acl to 'public-read'Bucket acl updated
6Run terraform planBucket acl is 'public-read'No changes neededPlan shows no changes
💡 Terraform stops planning when the actual infrastructure matches the declared desired state.
Status Tracker
VariableStartAfter Step 2After Step 5Final
Bucket existenceFalseTrueTrueTrue
Bucket aclN/Aprivatepublic-readpublic-read
Key Moments - 3 Insights
Why does Terraform show changes even if I only wrote the desired state once?
Terraform compares the current real infrastructure with your desired state (see execution_table step 1). It plans changes to make them match.
What happens if I run 'terraform apply' without changing the config?
Terraform sees no difference between current and desired state (step 3), so it does nothing.
How does Terraform know what to change when I update the config?
It compares the old state with the new desired state and plans only the differences (step 4).
Visual Quiz - 3 Questions
Test your understanding
Look at the execution table, what is the planned change at step 4?
AUpdate bucket acl to 'public-read'
BCreate a new bucket
CDelete the bucket
DNo changes needed
💡 Hint
Check the 'Planned Change' column at step 4 in the execution_table.
At which step does Terraform first create the bucket?
AStep 1
BStep 3
CStep 2
DStep 4
💡 Hint
Look at the 'Result' column to see when the bucket is created.
If you run 'terraform plan' after step 6, what will it show?
APlan to delete the bucket
BNo changes needed
CPlan to create a new bucket
DPlan to update bucket acl to 'private'
💡 Hint
See the 'Planned Change' at step 6 in the execution_table.
Concept Snapshot
Terraform's declarative approach means you write what you want, not how to do it.
Terraform compares your desired state with the real state.
It plans only the changes needed to match.
Apply makes those changes.
Repeated plans show no changes if states match.
Full Transcript
Terraform uses a declarative approach where you write configuration files describing the desired cloud infrastructure. When you run 'terraform plan', it compares this desired state with the current real infrastructure state. It then shows what changes it will make to match your configuration. Running 'terraform apply' executes those changes. If you run 'terraform plan' again without changes, it shows no changes needed. If you update your config, Terraform plans only the differences and applies them. This way, you manage infrastructure by declaring the end state, and Terraform handles the steps to get there.

Practice

(1/5)
1. What does Terraform's declarative approach mean?
terraform apply will create resources based on what you specify, not how to create them.
easy
A. You describe the desired state of infrastructure, not the steps to create it.
B. You write scripts that run commands step-by-step to build infrastructure.
C. You manually create resources in the cloud console and Terraform tracks them.
D. You use Terraform only to delete resources, not create them.

Solution

  1. Step 1: Understand declarative vs imperative

    Declarative means describing the end state, while imperative means describing the steps to get there.
  2. Step 2: Apply to Terraform

    Terraform uses declarative approach by letting you write configuration files that describe what you want, not how to do it.
  3. Final Answer:

    You describe the desired state of infrastructure, not the steps to create it. -> Option A
  4. Quick Check:

    Declarative = Describe desired state [OK]
Hint: Declarative means say what, not how [OK]
Common Mistakes:
  • Confusing declarative with imperative scripting
  • Thinking Terraform runs commands step-by-step
  • Believing Terraform only deletes resources
2. Which Terraform configuration snippet correctly declares an AWS S3 bucket named "mybucket"?
easy
A. resource aws_s3_bucket mybucket { bucket_name = "mybucket" }
B. create aws_s3_bucket mybucket { name = "mybucket" }
C. aws_s3_bucket "mybucket" { bucket_name = "mybucket" }
D. resource "aws_s3_bucket" "mybucket" { bucket = "mybucket" }

Solution

  1. Step 1: Identify correct Terraform resource syntax

    Terraform resource blocks start with 'resource', then resource type in quotes, then resource name in quotes, followed by braces with arguments.
  2. Step 2: Match correct attribute names

    The attribute to name an S3 bucket is 'bucket', not 'bucket_name'. resource "aws_s3_bucket" "mybucket" { bucket = "mybucket" } matches correct syntax and attribute.
  3. Final Answer:

    resource "aws_s3_bucket" "mybucket" { bucket = "mybucket" } -> Option D
  4. Quick Check:

    Correct resource block syntax = resource "aws_s3_bucket" "mybucket" { bucket = "mybucket" } [OK]
Hint: Terraform resource blocks start with resource "type" "name" [OK]
Common Mistakes:
  • Using incorrect keywords like 'create' instead of 'resource'
  • Missing quotes around resource type or name
  • Using wrong attribute names like 'bucket_name'
3. Given this Terraform configuration:
resource "aws_instance" "example" {
  ami           = "ami-123456"
  instance_type = "t2.micro"
}

What will Terraform do when you run terraform apply for the first time?
medium
A. It will delete any existing EC2 instances named example.
B. It will only plan the changes but not create any resources.
C. It will create an AWS EC2 instance with the specified AMI and instance type.
D. It will throw a syntax error due to missing provider block.

Solution

  1. Step 1: Understand resource declaration effect

    The resource block declares an EC2 instance with given AMI and type. Terraform will create it on apply.
  2. Step 2: Consider first apply behavior

    On first apply, Terraform creates resources to match the declared state. Missing provider block is not a syntax error but requires provider configuration elsewhere.
  3. Final Answer:

    It will create an AWS EC2 instance with the specified AMI and instance type. -> Option C
  4. Quick Check:

    First apply creates declared resources [OK]
Hint: terraform apply creates resources declared first time [OK]
Common Mistakes:
  • Confusing plan with apply behavior
  • Expecting deletion instead of creation
  • Assuming missing provider block causes syntax error
4. You wrote this Terraform code:
resource "aws_s3_bucket" "bucket" {
  bucket = "mybucket"
  acl    = "public-read"
}

But Terraform apply fails with an error about bucket name already existing. What is the best fix?
medium
A. Change the bucket name to a unique one because S3 bucket names must be globally unique.
B. Remove the acl attribute to fix the error.
C. Rename the resource block from "bucket" to "mybucket".
D. Run terraform destroy before apply to clear existing buckets.

Solution

  1. Step 1: Understand S3 bucket naming rules

    S3 bucket names must be globally unique across all AWS accounts.
  2. Step 2: Analyze error cause

    The error means the bucket name "mybucket" is already taken by someone else, so Terraform cannot create it.
  3. Step 3: Choose fix

    Changing the bucket name to a unique one solves the problem. Other options do not address uniqueness.
  4. Final Answer:

    Change the bucket name to a unique one because S3 bucket names must be globally unique. -> Option A
  5. Quick Check:

    S3 bucket names must be unique globally [OK]
Hint: S3 bucket names must be unique globally [OK]
Common Mistakes:
  • Thinking acl attribute causes name conflict
  • Renaming resource block does not change bucket name
  • Destroying resources unnecessarily
5. You want to manage a set of AWS EC2 instances with Terraform declaratively. You have a list of instance names and want to create one instance per name. Which Terraform feature best fits this declarative approach?
hard
A. Manually create each instance resource block with a unique name.
B. Use a for_each meta-argument on the resource block with the list of names.
C. Write a shell script to loop and run terraform apply multiple times.
D. Use a count meta-argument with a fixed number and hardcoded names.

Solution

  1. Step 1: Understand declarative resource creation for multiple items

    Terraform's for_each lets you declare multiple instances based on a collection, matching the declarative style.
  2. Step 2: Evaluate options

    Shell scripts and manual blocks are imperative or repetitive, not declarative. Using count with hardcoded names is less flexible than for_each.
  3. Final Answer:

    Use a for_each meta-argument on the resource block with the list of names. -> Option B
  4. Quick Check:

    for_each creates resources declaratively from collections [OK]
Hint: for_each creates multiple resources declaratively [OK]
Common Mistakes:
  • Using imperative loops outside Terraform
  • Hardcoding multiple resource blocks manually
  • Using count without dynamic naming