Bird
Raised Fist0
Terraformcloud~10 mins

Variable validation rules in Terraform - Step-by-Step Execution

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Process Flow - Variable validation rules
Define variable with validation
↓
Input value provided
↓
Check validation rule
↓
Accept value
↓
Use variable
Terraform checks the variable's input against validation rules. If valid, it proceeds; if invalid, it stops with an error.
Execution Sample
Terraform
variable "env" {
  type = string
  validation {
    condition     = contains(["dev", "prod"], var.env)
    error_message = "env must be 'dev' or 'prod'"
  }
}
Defines a variable 'env' that only accepts 'dev' or 'prod' values.
Process Table
StepInput ValueValidation ConditionResultAction
1"dev"contains(["dev", "prod"], "dev")TrueAccept value, continue deployment
2"test"contains(["dev", "prod"], "test")FalseShow error: env must be 'dev' or 'prod', stop deployment
💡 Execution stops if validation condition is False, preventing invalid variable usage.
Status Tracker
VariableStartAfter Step 1After Step 2
var.envundefined"dev"Error - invalid value, deployment halted
Key Moments - 2 Insights
Why does Terraform stop deployment when the variable value is invalid?
Terraform enforces validation rules strictly. As shown in execution_table step 2, when the condition is false, it shows the error message and stops to prevent misconfiguration.
Can the validation condition use complex expressions?
Yes, the condition can use any expression that returns true or false. It runs at plan/apply time to check the input value, as seen in the condition field in execution_table.
Visual Quiz - 3 Questions
Test your understanding
Look at the execution table, what happens when the input value is "dev"?
ATerraform stops deployment with an error
BTerraform ignores the validation
CTerraform accepts the value and continues
DTerraform changes the value automatically
💡 Hint
Refer to execution_table row 1 where the condition is true and action is to accept value.
At which step does the validation condition become false?
AStep 2
BStep 1
CNever
DBoth steps
💡 Hint
Check execution_table row 2 where input "test" fails the condition.
If we add "stage" to the allowed list in the condition, how would step 2 change?
AStep 2 would pass validation if input is "stage"
BStep 2 would still fail validation
CStep 2 would cause a syntax error
DStep 2 would be skipped
💡 Hint
Step 2 input is "test". Adding "stage" to ["dev", "prod"] results in ["dev", "prod", "stage"], which still does not contain "test", so it fails.
Concept Snapshot
Terraform variable validation rules:
- Define validation block inside variable
- Use condition expression returning true/false
- Provide error_message for invalid input
- Deployment stops if validation fails
- Helps catch config errors early
Full Transcript
Terraform variable validation rules let you check if a variable's input value meets certain conditions before deployment proceeds. You define a validation block inside the variable with a condition expression that returns true or false. If the input value passes the condition, Terraform accepts it and continues deployment. If it fails, Terraform shows the error message and stops deployment to prevent misconfiguration. This ensures only valid values are used, catching errors early. The validation condition can be any expression, such as checking if the value is in a list of allowed strings.

Practice

(1/5)
1. What is the main purpose of variable validation rules in Terraform?
easy
A. To speed up the Terraform apply process
B. To automatically fix errors in the Terraform code
C. To create new variables dynamically during runtime
D. To check if input values meet specific conditions before applying configuration

Solution

  1. Step 1: Understand variable validation role

    Variable validation rules ensure inputs are correct before Terraform uses them.
  2. Step 2: Identify the purpose

    They check conditions and show errors if inputs are invalid, preventing mistakes.
  3. Final Answer:

    To check if input values meet specific conditions before applying configuration -> Option D
  4. Quick Check:

    Validation checks inputs = C [OK]
Hint: Validation rules check inputs before use to avoid errors [OK]
Common Mistakes:
  • Thinking validation fixes errors automatically
  • Confusing validation with variable creation
  • Assuming validation speeds up apply
2. Which of the following is the correct syntax to add a validation rule for a variable in Terraform?
easy
A. variable "name" { validation { condition = length(var.name) > 3 error_message = "Name too short" } }
B. variable "name" { validate { condition = length(var.name) > 3 message = "Name too short" } }
C. variable "name" { validation_rule { check = length(var.name) > 3 error = "Name too short" } }
D. variable "name" { validate_rule { condition = length(var.name) > 3 error_message = "Name too short" } }

Solution

  1. Step 1: Recall Terraform variable validation syntax

    Terraform uses validation block inside variable with condition and error_message.
  2. Step 2: Match syntax with options

    variable "name" { validation { condition = length(var.name) > 3 error_message = "Name too short" } } matches correct keywords and structure exactly.
  3. Final Answer:

    variable "name" { validation { condition = length(var.name) > 3 error_message = "Name too short" } } -> Option A
  4. Quick Check:

    Correct keywords: validation, condition, error_message = A [OK]
Hint: Look for 'validation' block with 'condition' and 'error_message' keys [OK]
Common Mistakes:
  • Using 'validate' instead of 'validation'
  • Using wrong keys like 'message' or 'error'
  • Incorrect block names like 'validation_rule'
3. Given this variable definition, what happens if the input is "ab"?
variable "username" {
  type = string
  validation {
    condition = length(var.username) >= 3
    error_message = "Username must be at least 3 characters"
  }
}
medium
A. Terraform apply ignores the validation and warns only
B. Terraform apply succeeds and uses "ab" as username
C. Terraform apply fails with error: Username must be at least 3 characters
D. Terraform apply replaces "ab" with default username

Solution

  1. Step 1: Check validation condition

    The condition requires username length >= 3.
  2. Step 2: Evaluate input "ab" length

    "ab" length is 2, which is less than 3, so condition fails.
  3. Final Answer:

    Terraform apply fails with error: Username must be at least 3 characters -> Option C
  4. Quick Check:

    Input length < 3 triggers error = A [OK]
Hint: Check if input meets condition; if not, apply fails with error [OK]
Common Mistakes:
  • Assuming apply succeeds despite validation failure
  • Thinking validation only warns, not errors
  • Believing default values replace invalid input
4. Identify the error in this variable validation block:
variable "port" {
  type = number
  validation {
    condition = var.port > 0 && var.port < 65536
    error_message = "Port must be between 1 and 65535"
  }
}
medium
A. Using 'number' type instead of 'number' is invalid
B. Validation condition uses 'var.port' instead of 'self'
C. Error message is missing a period at the end
D. Validation block must be outside the variable block

Solution

  1. Step 1: Understand validation condition context

    Inside validation, use self to refer to the variable value, not var.port.
  2. Step 2: Identify incorrect usage

    The condition incorrectly uses var.port, which is not best practice.
  3. Final Answer:

    Validation condition uses 'var.port' instead of 'self' -> Option B
  4. Quick Check:

    Use 'self' in validation condition = B [OK]
Hint: Use 'self' to refer to variable value inside validation [OK]
Common Mistakes:
  • Using 'var.variable_name' inside validation condition
  • Placing validation block outside variable block
  • Ignoring syntax errors in condition
5. You want to validate a list variable so it only accepts lists with exactly 3 strings, each at least 2 characters long. Which validation condition is correct?
hard
A. condition = length(self) == 3 && all([for s in self : length(s) >= 2])
B. condition = length(self) == 3 && all([for s in self : s > 2])
C. condition = length(self) == 3 && alltrue([for s in self : s >= 2])
D. condition = length(self) == 3 && alltrue([for s in self : length(s) >= 2])

Solution

  1. Step 1: Check list length condition

    We want exactly 3 items, so length(self) == 3 is correct.
  2. Step 2: Validate each string length

    Use all() to ensure all elements satisfy length(s) >= 2.
  3. Step 3: Identify correct function and condition

    all() is the modern function; alltrue() is legacy.
  4. Final Answer:

    condition = length(self) == 3 && all([for s in self : length(s) >= 2]) -> Option A
  5. Quick Check:

    Use 'all' with length checks and list length = D [OK]
Hint: Use 'all' function and 'self' for list validation [OK]
Common Mistakes:
  • Using 'alltrue' instead of 'all'
  • Comparing strings directly to numbers
  • Using 's > 2' instead of 'length(s) >= 2'