Hands-on lab repository for the HashiCorp Certified: Terraform Associate (004) — Terraform 1.12, Google Cloud provider.
Every directory is an independent root module built while working through the official learning path. Nothing here is copied: each exercise is run for real against a GCP project, broken on purpose, then repaired. The goal is not to pass a quiz but to know what Terraform does before it does it.
| Directory | Exam objectives | What is exercised |
|---|---|---|
00-get-started/ |
1, 2, 3 | Provider, terraform block, init/plan/apply/destroy, variables, outputs — the official Get Started – Google Cloud collection |
01-state/ |
6, 7 | GCS remote backend with locking, state list/show/mv/rm, import (command and block), -refresh-only, -replace, drift detection, lock file breakage and recovery |
02-modules/ |
4, 5 | Local versioned module, for_each vs count, dynamic, variable validation, lifecycle (create_before_destroy, ignore_changes, replace_triggered_by, prevent_destroy), pre/postconditions, check, moved / removed, ephemeral & write-only values |
03-hcp/ |
8 | Migration GCS → HCP Terraform, CLI-driven then VCS-driven workflow, projects, variable sets, run triggers, policy |
- One root module per directory, no shared state between them.
.terraform.lock.hclis committed (reproducible provider versions). State files and*.tfvarsnever are.- Provider pinned with a
~>constraint; Terraform version pinned withrequired_version. - Every directory has a
NOTES.md: what was tried, what broke, what the fix was, and the exam-relevant takeaway. terraform fmt -checkandterraform validatepass before any commit.
export GOOGLE_PROJECT=<project-id>
export GOOGLE_REGION=europe-west1
gcloud auth application-default login
cd 00-get-started/<tutorial>
terraform init
terraform plan -out=tfplan
terraform apply tfplan
terraform destroyNothing in this repo is meant to stay up. destroy is part of every exercise.