Terraform Interview Questions
22 questions
Terraform interview questions on provider versioning and the dependency lock file, workspaces versus separate state files, state management (drift, locking, splitting monoliths, sensitive data, backup/recovery), and module design — the kind of state-file and provider-behavior subtleties that only show up after running Terraform against real, shared infrastructure.
A corrupted or accidentally-overwritten Terraform state file threatens to make you lose track of an entire environment's real infrastructure — how would you design for recoverability?
AdvancedTerraform7 min
How would you design a CI/CD pipeline to automatically block a Terraform apply that would destroy a production database?
AdvancedTerraform8 min
How does Terraform's create_before_destroy interact with resources that have unique naming constraints, like a fixed identifier?
AdvancedTerraform7 min
What's the difference between state drift and a genuine configuration change in Terraform, and how does -refresh-only help distinguish them?
IntermediateTerraform6 min
A single Terraform state file managing an entire environment's infrastructure takes 10 minutes to plan and any change risks touching everything — how would you split it?
AdvancedTerraform8 min
Using terraform_remote_state to reference another team's outputs works, but creates a tight coupling that breaks when they change their state — what's the alternative?
AdvancedTerraform7 min
What's the difference between terraform state rm and just deleting a resource block from configuration — when would you use state rm specifically?
IntermediateTerraform6 min
A database password is passed as a resource argument in Terraform — does marking the variable sensitive actually protect it in the state file?
AdvancedTerraform7 min
terraform plan shows a production RDS instance will be destroyed and recreated after a change you thought was trivial. What would you investigate before running apply?
AdvancedTerraformAWS10 min