HashiCorp Terraform Associate Certification Course (003) - Pass the Exam!
Key Takeaways
This video course prepares students for the HashiCorp Terraform Associate Certification, covering topics such as infrastructure as code, Terraform basics, and Terraform Cloud capabilities. The course focuses on practical knowledge and exam preparation, with a recommended study time of 30 hours for beginners.
Full Transcript
hey this is Andrew Brown over here on free cocam bringing you another free Cloud certification and this time it's the hashicorp terraform associate version three and the way we're going to achieve certification is through lecture content Hands-On labs and as always I provide you a free practice exam and so at the end of the day you're going to get that certification and you could put it on your resume on your LinkedIn to demonstrate that devops skills and try to go get that cloud or devops role you've been looking for or trying to upgrade to so if you like the materials here a great way to support more content like this is to look at the paid additional materials it will also help you increase the odds on your exam and it also really does help out and support the production of more of this kind of content and if you are not familiar with me I produce a lot of different kinds of cloud certification courses like AWS Azure kubernetes you name it I've taught it and so you're in really good hands and we'll see you in class soon ciao foreign [Music] everybody it's Andrew Brown and welcome to the start of our journey and we're asking the most important question first which is what is terraform and I just want to tell you that I'm on screen now but I'm going to vanish here shortly and stay out of the way so that you can see the full content but I just wanted to know you to know that I'm here with you the entire way okay so the terraform associate certification is a specialty certification in terraform terraform is a technology produced by hashicorp and it's specifically for infrastructures of code and it's a declarative infrastructure as a code and it's a cloud agnostic infrastructure as a code we will dive into all of this in great detail in the introduction section and just notice that I put an asterisk there on declarative because there is something special about terraform that we will discover if you are considering the terraform associate then you most likely are looking for a devops role you want to automate infrastructure or writing scripts you want to work with multiple Cloud providers or you know you enjoy designing iterating on end-to-end infrastructure life cycle so if this sounds like anything that you are interested in then you would probably want to take this certification I want to tell you that terraform is one of the most in-demand skills for devops rules today and it's becoming quickly the industry standard just because it is so flexible and works with all providers and goes beyond a lot of these other tools and the terraform associate exam itself isn't that difficult uh but I would say that the concept of learning terraform is a bit tricky because uh you know it's not something that you can just go do the lecture content uh and and do the lab content I had to do a mix of it uh so in this course you'll see me do lecture lab lecture lab because I'm trying to solidify the knowledge as soon as we do that this is not the format that I use for my other courses it's just because with terraform it requires patience it is a silical learning process to understand so just uh stick with it and by the end of it you will be really good with terraform uh you know and so that's that there so let's talk about our multi-cloud roadmap I'm going to get out of the way so we have a little bit more room um and so you know what I would recommend uh is that you start with an Associate certification so just getting my pen tool out here uh if I can get it here here we have the Google's Ace um the cloud engineer or maybe some level of AWS uh associate certification I personally think the sysops is the best pairing for terraform or the Azure administrator if you're going for Azure and quite possibly learning more than two would be very beneficial but of course whatever your primary provider you're using is where you're going to benefit with uh terraform and you really should learn this stuff before you do terraform it is super hard to learn both cloud and terraform at the same time you should have that Foundation before you tackle onto terraform and so there's a lot of different paths for multi-cloud and just to kind of give you an idea of all the different ways you can go you know you can go from associate to either Vault and to the Vault professional if you're looking at a security background but it's very common for people to get the terraform and then go for uh Vault afterwards but you know it's up to you to which path you want to take how long do you have to study to pass this exam well uh it's a spectrum based on where your background is so let's take a look at beginners first so a beginner to me would be someone that's never written IC uh they have not previously focused on automating infrastructure they might may not hold an associate level certification so you're adding those additional hours or trying to make up the difference you could be looking at 30 hours or more if you're already experienced with writing IAC but maybe just not terraform maybe you know Azure bicep or cloud formation you already work in devops you're already comfortable writing scripts and you hold associate level certification knowledge of you know a major cloud provider then you're looking at something like 12 hours but you know if you're looking for a general study guide somewhere in between I would recommend between one to two hours a day for 14 days and you'll be in a really good place by then you know what does it take to pass this exam well there is a lecture content and I have a lot of it um you know the thing is that the exam itself is very practical it's not like AWS aws's exams where it's very um uh Theory based at a conceptual level this one is very much how do we use this technology and so the lecture content is there to really support the lab content and you really really need to do the lab content uh because that's the nature of this exam um and to make this a lot easier I do recommend taking some practice exams we have a free practice exam and we also have uh many more practice exams if you take all these Pax exams and you've done the labs prior to that you're going to be in really good shape to pass in terms of the content outline um I can't remember how many domains we'll see how many there are but we have one so understand infrastructure as code so I see Concepts understand the purpose of terraform understand terraform Basics the use of terraform outside core workflows interact with terraform modules use the core terraform workflow Implement and maintain State regenerate and modify configuration and understand terraform Cloud capabilities so yeah nine domains uh something that's different about uh the hashicorp certifications is they do not provide distribution of domains what do I mean by that well they're not weighted right so it's not like uh we know that uh like eight is I'm going to have a particular weighting that's higher but we can look at the exam guide outline to see generally how many questions we probably would so we could kind of infer our own waiting but they do not provide it so I would just say it's not known but we'll take our best guess when we look at the full exam guide outline where do you take this exam well you can take it in an in-person test center or online from the convenience of your own home I do believe that the test center that hashicorp is using is PSI or PSI online and understand that this is a proctored exam so someone is supervising you watching you monitoring you as you take the exam so that you uh that there's no funny business happening there's no cheating and to ensure that uh you know that you gain gain that knowledge in a reputable way so just understand that in terms of the grading you need to get about 70 percent to pass or round that it uses scaled scoring uh is it possible for you to fail if you've got exactly 70 percent it might be so always aim to get higher than 70 percent um and so I always say aim for a target of you know 10 to 15 above what the score is if you're getting that on your prax exams then you're going to be in good shape in terms of the response types they don't tell you exactly how many questions there are but I've always observed there's 57 questions and so you know based on that calculation I feel that you have 70 17 questions you can get wrong there are no penalties for wrong questions so always answer your questions do not leave any blank the format of the questions is multiple choice and multiple answer and then sometimes you get a fill in the blank so type a one word answer most likely it's going to be a command right so or a flag for a command so you definitely have to know the technical components of terraform okay the duration of the exam is one hour so that means you get about a minute to answer per questions the questions are very short format so it's not like you have to read a ton of text to figure out what's going on the exam time is 60 Minutes the seat time is actually 90 minutes so when we say C time referring to the amount of time you should allocate for the exam so that means that would include things like time to review the instructions show uh show the online proctored your workspace to make sure there's nothing going funny on with your environment read and accept the NDA complete the exam provide feedback at the end and I'm going to tell you you really do want to get for your exam much sooner than you think because it is a very stressful process and things tend to always go wrong when when you uh when you don't show up early enough okay so just make sure you do that if you do pass this exam it's going to be valid for 24 months so that's two years before recertification and the last thing I just want to talk about is um well maybe not the last thing I got two more slides here for you but this course is going to be designed around the 1.1.6.0 specification of terraform and even when I'm making this course as of today 1.60 is an alpha this will be in the future so 1.60 will be out but I like to try to give you more knowledge in the future even if it's not an exam just so that you are prepared and this course does not go stale sooner terraform is always incrementing inversion so you know when you study you always want to go back three minor versions since I'm showing 1.60 it doesn't make a whole lot of sense but if you're let's say you're on 1.54 you'd want to do one you want to make sure you know terraform for a range of versions going a few versions back and so so you know I will be showing you things that may be deprecated but are still uh but might still be in use based on the version that people are using so just understand that um and again you know these these certifications are or the terraform certification is heavily dependent on your practical knowledge so if you are taking the time to apply the knowledge uh this version difference differencing is not going to make a big difference okay um so just make sure you know you put the time in with the labs um now this is the third version of the certification and so I just kind of want to tell you that not a whole lot has changed between version zero zero two and zero zero three uh the one of the big differences is they change the badge design why I don't know uh is it better who cares um but uh it is a different looking badge um one thing is that there were superficial name changes to the outlines of the domain so basically all the domains are the same they just kind of did some tweaks there they did kind of cut some content out in the uh the like first uh first first two domains because those ones were just more General concept of knowledge and so they slim those down I'm leaving that content in this course because I think it's very valuable to know more rounded knowledge there so you're going to be over prepared for those first two domains there used to be this thing called provisioners it's still in terraform but the thing is that it's just no longer needed to know in the exam so this is about doing remote execution annoying all the provisioners and so I mean local execute and remote execute are things you need to learn and definitely something that you will use on the job but knowing how to provision and use a lot of Provisions is no longer a focus there there's this thing called null resource that we learn about and now they have a new thing called terraform data so that is a evolution of terraform data so we'll still learn about null resource but we'll also learn terraform data where it makes more sense to use uh you know terraform Tate had taint has been replaced with uh just a flag uh called hyphen hyphen uh uh replace uh on the terraform plan and we have a few more others like that so refresh has a flag um and uh the thing was is that when I made this exam the first time they were already talking about doing this so This exam is already um my previous one is up to date with the current version of zero zero three if that if that's surprising here uh terraform workspace is no longer part of the exam um I would still cover terraform workspace uh you know if we come across it because I still think again it's practical knowledge that you should know um connecting to terraform Cloud now uses its own cloud block instead of remote block um I believe that we can still use remote block here and I will definitely test that in the in the um in the uh the labs in this course so you know it's good to know both of them but the focus will be using uh Cloud block um we have the lock file so the lock.hcl files are new um I mean they weren't new when I made the previous exam so they were already in there so again I already had this content here um but I'm just pointing out that that's something that they're focusing on uh within the certification here um you need to know how to Mark data as being sensitive again that's something I had in the older exam but one major thing is terraform cloud has a new UI and it looks like there's a lot more functionality so in terms of the old exam or a course that I produce and this one I'm definitely going to have to reshoot all of terraform cloud and go deeper into it there's obviously a few different functionalities that have been added like the terraform Cloud block the terraform data block um but you know for the most part there's not a whole lot that has changed so the majority of this will be very similar to the last one but I'm just touching up and improving lab content where we can and hopefully adding a lot more additional content to expand the terraform knowledge that I wasn't able to do the first time around so hopefully that gives you a good idea of what you're getting yourself into uh but yeah we will proceed forward to looking at the exam guide foreign Brown and welcome back as we are taking a look at the exam guide uh for the hashicorp terraform associate certification I want to tell you uh throughout this course I'm going to show you where I get things so I will be going to Google I will be typing in where things are it's not because I don't know where things are I'm doing that for your benefits so that you build up the skill to know how to find things just the way that I would go find things and I'll be very transparent about that so for this one all I did was go into Google and type in terraform exam guide and so I found it here this is also the place where you can register for the exam so if you click this it should load up certain metrics I'll make a pop-up you have to authenticate it I'm not showing that here right now but when you are ready to register for the exam you can go ahead and do that you'll notice they also have this button here called prepare for the exam they have their own study guide here it's very text based heavy I do believe that somewhere in here there is a way to launch tutorials and this will launch sandbox environments I think through instruct at least the last time I checked those are great if you don't have an environment set up what I want to do with you is I want I want you to set everything up in your own environment because I want you to have those Real World skills so you can use this stuff adjacent to this course I've gone through all this material here I'm trying to cover things that aren't in here and try to make sure that we are doing things without guard rails without the bowling bumpers because I want you get that Real World Experience okay but I do want to point out that this is here and you can use it um and it's okay so let's scroll down and take a look at our exam guide here and so here they say we have some prerequisites so they say basic terminal skills that makes sense we're going to be doing a lot of stuff uh in terminal basic understanding of on-premise and Cloud architecture uh I think what they really mean is do you know how to use AWS you know how to use Azure gcp what is your major uh cloud provider or or stuff like that um now I keep talking or focusing on AWS Azure gcp but understand that terraform can be used for anything as long as there is a provider for it it can provision on almost anything okay and that's why they're being very generic in their description this says the product version tested is terraform 1.00 and higher so it shows you that this is still even though it's the zero zero three it's still really the zero zero two exam with some minor tweaks but just understand in this course we're going to go well beyond this because I'm just future proofing you and making sure you have Real World skills let's scroll on down here and let's just it's about renewing your certification so if you hold an unexpired terraform associate 002 certification uh you can take the new one starting 18 months after your previous exam if you hold an unexpired one you can take the new exam starting 18 months after your previous exam uh if you hold an expired one you're eligible to recertify at any time I really like this because what happens for me with certifications not a problem for you but problem for me is that I will sit a certification and then nine months later the new one comes out and I can't sit the new one and tell you about it so it looks like we've gotten a bit of flexibility there and again I'm on video here I will get out of the way um it's just that we're in the uh these earlier videos and I want to just hang out here with you okay going down below we can confirm it's the one hour duration this is seventy dollars it might vary based on your location and other stuff you I just don't want to tell you that 70 I want you to go through the process and find out yourself but that's probably what it's going to cost you um there is no free retake included um some certifications like CompTIA you are basically or uh the kubernetes ones from looks Foundation you basically get a retake so you're basically paying a love for two and they call it a free retake which it really isn't free but uh I think this is okay um I think it's fine there's no retake it's in English expires in two years we covered that before let's take a look at the exam objectives so the first one is understand infrastructure as a code and Concepts they used to have a bunch of junk in here um and honestly I didn't even know what they were talking about when they said that I remember I had to comb through uh the study guide and try to watch uh articles and stuff like that but I think they realized that it was junk uh that they were trying to uh impart too much conceptual stuff and they cut back this one here same thing with two it doesn't show us the comparison of the old one at some point on this website they showed the comparative between zero zero two and zero zero three but all I'm saying is that they cut back here I have a bit more content on this in the course it's not going to hurt you to watch it it's just going to help you understand it but you're not going to be tested 100 on this stuff the other thing I want to note is that for each point that is here each subdomain or or Point whatever you want to call it they're going to ask you a question on this is very different uh way of Designing uh an exam uh other exams like AWS they will they will list a bunch of stuff but they say it might not be on the exam or it might have stuff that are that's outside of it so you just have to broadly study and uh you'll over over study for the content because you just don't know what you're going to get uh get on the exam for hashicorp exams they're very fair if you know each of these points you can expect to see them generally on the exam and that's how you're going to know that you are ready if you if you know all these things in this course we're going to go beyond that because again I want you to have those Real World skills but just feel confidence in knowing every single point Point here going down here understand terraform Basics install and version terraform providers so that is what we will be doing a lot of in this because we're going to at least touch more than one provider in this course I'm not going to go in great detail on uh the cloud infrastructure part of it because you're already supposed to know it um and I'm going to leave that for other things doing future projects for specific uh for for specific Cloud providers we're focused here on terraform in this course not the underlying providers but we do use multiple ones here describe plug-in based architecture write terraform configuration using multiple providers describe how terraform finds and fetches providers so you can see there is a a lot of stuff about providers not to be confused with provisioners I said earlier that provisioners is no longer covered in this certification course but again the materials here so you can learn it for real world practice use terraform outside of core of core workflows I think this used to be like you use terraform CLI outside of core workflows so they made a small tweak there so it says destroy describe when to use terraform import to import existing infrastructure into your terraform State terraform import is super super powerful going over to other providers uh you know for a long time AWS did not have an import option and so the idea is that by having this import we can bring an infrastructure that was not necessarily there before we have terraform state to view our terraform State something that you're going to find unique to terraform is State Management it's something that's super important and it's probably the hardest Concept in terraform because when you use something like cloud formation or Azure bicep the state is managed by services on those providers there isn't a managed service managed service on those providers and so you have to decide where you want to put your State uh and one example would be terraform cloud and that's one that we do use in this in this course here describe one to enable verbose logging and what the outcome is so you have to know how to debug things here which is great interact with terraform module so contrast and use different module Source options including public terraform module registry interact with modules inputs and outputs describe variable scope and module child modules set module versions modules is a way of creating reusable code uh we are going to use uh public libraries as well as uh make our own modules making modules is not as hard as you would imagine but they can get very complex uh so you know we're not going to go super Advanced into modules but we are going to make sure we can write our own and and use public ones use the terraform uh use the terraform workflow so this is something we're going to have to know a lot about which is just the general life cycle workflow of working with infrastructure as code so we have a knit validate plan apply destroy format plan it apply are the ones we're going to be using a lot of there is a lot of trickery with the init so that's something else that we'll do there as well Implement and maintain state so maintaining State working with State super super important so we'll look at how it works with local state state locking handling back-end Cloud Integrations authentication methods uh you know they're talking about managed providers like terraform Cloud the different between remote State back-end options manage resource drift and terraform State terraform is super good at drift and fixing drift it's so good at remediation compared to other IEC tools and that's why it is such a popular tool to use describe back-end block and Cloud integration configuration understand secret management and state files then we have regenerate modify configuration so demonstrate the use of variable variables and outputs describe secure secret injection best practices understand the use of collection and structural types create and differentiate resource and data configuration use resource addressing and resource parameters to connect resources together use HCL and terraform functions to write configuration describe built-in dependency management and the last one here is understand terraform Cloud capabilities so explain how terraform clouds helps to manage infrastructure describe how terraform Cloud enables collaboration government governance I'm going to tell you right now we're going to probably do more terraform Cloud than we we need to it's just because when I made this course the first time I I just lightly did terraform Cloud just enough to pass the exam I have the time to do a little bit more there I would like to do that for your own benefit and so we will expand on that a bit more but you can see this is mostly about terraform the technology not necessarily terraform Cloud the uh the service if you're confused about terraform and terraform Cloud uh again we'll explain that in this course and make sure it's very clear what the difference is one other thing I wanted to notice that you do have some sample questions here so you can go through here and you can just see that the questions are very straightforward and they're just like this they're very simple uh but you know you do have to know you do have to know what you're looking at and see like here they're showing code so you can see you have to choose code and you might get a code block so it is very focused on the Practical component of it it's less about the conceptual okay but yeah hopefully that gives you an idea of what we're getting into and we'll see in the next one okay ciao foreign hey this is Andrew Brown from exam Pro and what I want to do is walk you through a few of our practices and questions just to give you an idea of what it will be like on the real exam and where we might have had to make some adjustments to help your study so what you'd have to do to access this prax exam is you'd have to be signed up and logged in to the exam Pro platform make a way over to the hashicorp terraform course except the free tier or pay for full access but once you go there you'll scroll all the way down to the bottom and you should see three or four products exams at the time of writing this we're still writing the questions so that's why they're not shown in the video here but what I want you to do is to go to the first practice exam and notice that there are 57 questions you get an hour on on the exam here and we have a breakdown based on domain now the percentage is not something that uh terraform or hashicorp provides so we just had to break it down based on the coverage of questions that we saw in the exam guide outline and so that should be accurate enough and that's kind of what it felt like on the exam so I don't think that's going to be a problem if we click into here we're just going to look at some of the questions I'll talk around them so the first one here is we have how do you create a workspace and it's showing us a bunch of CLI commands and so on the exam you do need to know um uh you know CLI commands and the difference of them and the questions can be as simple as this where you're just choosing the option and some are obvious distractors like there isn't there is no one called terraform workspace Branch okay so just understand that you not just need to know the conceptual ideas behind terraform but also it in practice okay another one here would be the terraform registry can search based on the following Search terms we have an option to choose multiple questions and so this is something that you will see on the exam where you're choosing multiples of something I didn't get a lot on my exam but I cannot say for certain like how many questions would show up like this um but you know they're not really that hard to figure out okay and this question is about um a tool or sorry uh the public terraform registry website and that is just a uh a public-facing website if we go to registry.terraform.io here it's this website here so it's not just the tooling of terraform itself but it's the ecosystem around it so terraform Cloud the terraform registry things like that another type of question you will see and I think it's over here is what they will do is they'll ask you to fill in the blank now we don't have that support in our platform just as of yet but the idea is they'll say like okay uh we'll ask you a question or we'll even give you um maybe they'll have like underscores they'll say fill in this thing and you'll literally have to type type the answer in but the answer is going to be like a one word answer so on the exam I literally had a question which was like where is the API stored and it was actually terraformed at TF state but I did not know I could not recall the name of it which is kind of embarrassing but uh you know that is the level of fill-ins that you'll have to do and you're very likely to see some code on the on the exam two so if I just click through here really quickly you may see a code block okay and you might have to decipher it so that's the difficulty exam I would not say this is a heart exam but you just have to understand the scope of those kind of questions and make sure that you have well-rounded study in both practical and conceptual concepts of terraform so hopefully that helps you out okay [Music] everybody there it's Andrew Brown and I just wanted to tell you about the content that you're going through because honestly between the zero zero two and zero zero three there was not much to update um and so you know the key differences is the versions of terraform and the versions of the providers that you are using um and for the most part everything worked out perfectly fine I thought that I'd have to reshoot all of the lab content but it turns out nope barely nothing has changed what has changed and I want to point this out early on is that when you are specifying a version for the provider just go use at least version five zero you can use an older version if you want to follow along but uh you know I think it's better to be more um up to date if you can the version that we were using prior in the follow alongs was version three again there are no major changes that will break anything um so at least there shouldn't be but I ran through these Labs my cloud support engineer ran through these Labs so we're pretty confident you're going to be in good shape otherwise if they weren't I would go re-record them but I just wanted to point out those two things uh there so hopefully you know that makes sense and you're going to be in good shape okay now I did say that we're scoping things around terraform 1.6.0 and again there's not much to call out for that the biggest thing that I think that 1.6.0 might bring would be testing and even if I looked into it and it just wasn't where I thought it was going to be so I did not include it at least at this time in uh this uh this this course and again this is me going uh above and beyond because I'm trying to just future proof the contents of this course and future proof uh stuff that I believe that is coming to terraform form but yeah you should be in good shape and you know if there are any changes on exam Pro we're very proactive of having those differences there so if you do run into anything that's giving you any kind of issue they're going to be on the the main learning platform there okay if if for whatever reason there's minor updates or things that are found out but yeah you'll be in good shape and have fun on your journey learning terraform ciao [Music] hey this is Andrew Brown from exam Pro and we are looking at what is infrastructure as code and before we talk about that we need to talk about the problem with manual configuration so manually configuring your Cloud infrastructure allows you to easily start using new cloud service offerings to quickly prototype architectures however it comes with a few downsides so it's easy to misconfigure a service through human error it's hard to manage the expected state of the configuration for compliance it's hard to transfer configuration knowledge to other team members and so this is why infrastructure code is going to really help us out so infrastructure is code commonly abbreviated to IAC and you'll see that a lot in this course allows you to write a configuration script to automate creating updating or destroying Cloud infrastructure notice I gave great emphasis on automate or automation because that is really key to infrastructure as code IEC could also be thought of as a blueprint of your infrastructure IEC allows you to easily share version or inventory your Cloud infrastructure and just to kind of get your visualization imagine you write a script and that's going to provision and launch a bunch of cloud services that are all interconnected okay [Music] all right so we're taking a look at popular IAC tools and so of course this course is about terraform but by understanding um all the options out there if you understand why we're using terraform uh and one thing that is very important to understand is the difference between declarative and imperative IAC tools those are the broad categories that we see for IAC so let's start with declarative so the idea here is what you see is what you get everything's explicit it's more verbose but there's zero chance of misconfiguration and this all relies on the fact that they use a scripting language such as Json yaml XML in the case of terraform they have their own language called HCL but the way these languages are structured is that they're very verbose and there's not a lot of programming logic involved so for Azure we have arm templates and Azure blueprints for AWS we have cloud formation for Google we have Cloud deployment manager and there there is of course terraform which has many cloud service providers such as AWS Azure gcp kubernetes and a lot more but these are all in the declarative category on the right hand side we have imperative so you say what you want and the rest is filled in everything here is implicit it's less verbose but you could end up with misconfiguration and when I say that it's that like if you were to find um let's say a virtual machine you might not have to provide every single uh option that you would normally do and it would fill in the rest but if you weren't aware of what it was doing that's where you could end up with misconfiguration uh though I would say that imperative tools generally try to always uh have their defaults as best practices so you're not usually in a bad position uh but you know you might end up with something you don't expect imperative can do more than declarative so there's just some very hard limitations with declarative languages so there's just cases where you want to do imperative and the idea here is imperative languages use programming language you know like python Ruby JavaScript golang you know whatever it is uh there's likely an SDK for it and so it's just a lot more programmer friendly a lot of developers like imperative tools so AWS has their own called Cloud development kit cdk and it technically only supports AWS I say technically because hashicorp has a very cool library that allows you to generate out terraform HCL files which allows you to work with anything but when we're just talking about cdk on its own it's just for AWS then you have plumy it supports AWS Azure gcp and kubernetes so it can do a lot so why would you choose with your team to use declarative over imperative well it just really depends on your your team right so like if they're all used to if they're all administrators and they're used to using Json yaml and they're not good with programming languages that is one reason why you might want to use declarative over imperative the other thing is just you know you prefer to know exactly every single thing that was defined right you don't want anything left up to a chance and so that is another reason why you might want to use declarative but both are great options it's just really depends depends on your team's knowledge and what your goals are okay [Music] so we just looked at imperative and declarative but I just want to clarify that terraform even though it's a declarative language it has imperative-like features so I've coined the phrase declarative plus and so terraform kind of gives you the best of both worlds so you have declarative and imperative and then the three types so our yaml Json XML we have terraform language which actually utilizes HCL underneath and then you have programming languages on the right hand side like Ruby python JavaScript what it have you right so when we're looking at yaml or Json these are very limited languages or scripting languages where uh you know you don't really have any kind of complex data types you probably don't have a whole lot of robust functions but in some cases you can extend That Base Behavior so in the case of cloud formation which uses yaml or Json files they have a concept called macros so you can extend it a bit but again it's very inflexible and so a lot of people are led to go and use cdk so terraform is great because it kind of has a lot of stuff you'd see in programming languages like for Loops Dynamic blocks locals it also has complex data structures and a lot of functions around using those data structures and so it allows you to stay in that declarative world but having the stuff that you generally need when you're in the parative world when you're in the imperative side the idea is that the language is what you're utilizing so you can do anything that the program language allows you to do but I just wanted to kind of show you that terraform sits in the middle okay [Music] hey it's Andrew Brown from exam Pro and we are looking at infrastructure life cycle so what is infrastructure lifecycle it's the idea of having clearly defined and distinct work phases which are used by devops Engineers to plan design build test deliver maintain and retire Cloud infrastructure where we're talking about like sdlc so software development life cycle there's usually a really great visual that I can show for you but for infrastructure lifecycle especially Cloud infrastructure lifecycle there isn't something that is well defined which is weird by the definition but I think that there's just nobody's agreed up on one yet or nobody's made the graphic yet so I just don't have anything to show you for that but I just want you to get familiar with the term infrastructure life cycle because you're likely to hear it again but one particular infrastructure life cycle that is pretty common is ones that talk about day zero day one and day two so the idea here is this is a simplified way to describe phases of infrastructure life cycle so when we say we are on day Zero we are planning and designing our infrastructure on day one we are developing and iterating it so we might be uh you know deploying or provisioning it and actually testing it uh in the cloud and then day two is actually when we go live with real production users and maintain it and the idea of mentioning day zero one and two is to say Well when does IAC start and the idea is it starts on Day Zero okay the days do not literally mean a 24 hour day it's just a broad way of defining where in the infrastructure project we would be okay [Music] so after defining what infrastructure life cycle is what advantage or what an advancement are we going to have when we add IAC to our infrastructure lifecycle well the first thing we're going to get is reliability so IC makes changes impotent consistent repeatable and predictable I'm going to give extra attention here to impotent because it is a very strange English word but no matter how many times you run your IC you will always end up with the same state that is expected that is a very important concept of IEC whereas if you use configuration management there's no guarantee of that that's why you use terraform over something like ansible okay you have manageability so enable mutation via code revise with minimal changes and then you have sensibility so avoid financial and reputational losses to even loss of life when considering government and Military dependencies on infrastructure so there you go [Music] okay so it impotent is a very important concept to infrastructure as code and so we're going to give it a little bit more attention I wouldn't stress out about the pronunciation uh there's more than one way to pronounce it in English and I've probably even said it wrong uh in the previous slide so uh just be uh forgiving on that part okay but the idea is that let's stage a scenario between a non-itipotent example and an independent example so when I deploy my IAC config file it will provision and launch two virtual machines that is what I'm expecting okay and that is what I get but what happens when I go and I update this infrastructure code file saying maybe I want to increase the size of the VMS or some of the configuration I deploy that again when it's non-edepotent what will end up happening is I will end up with two additional virtual machines with the new configuration and the old ones will be there and so this is something you might not want because you just want to have a file that says exactly the state that you expect okay so when we have something that is Idi potent the idea is we will go and we will Define our two virtual machines and we will get our two virtual machines but we go and we update that file and we deploy again and what happens this time is it just ends up modifying the original virtual machines or if it really can't and it has to it might delete them and recreate them but the idea is that we end up in a state of exactly what we want so in the first case we expect it to but we ended up with four but with the independent uh case we expected to and we always end up with two so hopefully that makes that very clear okay [Music] hey this is Andrew Brown from exam Pro and what I want to do here is concretely Define the difference between provisioning deployment and orchestration now in practice sometimes these have overlapping responsibility so you might say provisioning when you really mean deployment or vice versa it's not a big deal uh we all get kind of mixed up about it but I did want to just take the time to make sure that we understand what these things are supposed to mean okay so the First on our list here is provisioning so to prepare a server with systems data and software and then make it ready for Network operation if you're using a configuration management tool you are most likely provisioning because that's what these tools do so puppet ansible Chef bash scripts Powershell or cloudnit so you can provision a server when you launch a cloud service and configure it you are provisioning it okay then you have deployments the deployment is the act of delivering a version of your application to run a provision server deployment could be performed via AWS code pipeline harness which is a third-party deployment tool Jenkins GitHub action Circle CI there's a lot more other providers out there then you have orchestration so orchestration is the active coordinating multiple systems or Services orchestration is a common term when working with microservices containers and kubernetes so orchestration could be done with kubernetes salt or fabric so if you're working with containers generally like you use the word orchestration especially with kubernetes because you're working with thousands of microservices okay so you know hopefully that helps you know the difference between the three again it's not a big deal if you don't perfectly know them but there you go [Music] hey this is Andrew Brown from exam Pro and we are taking a look at configuration drift so this is when provision infrastructure has an unexpected configuration change due to team members manually adjusting configuration options malicious actors so maybe they're trying to cause downtime or breach data or side effects from apis sdks or CLI so you've written some code that uses a CLI and a bash script and it does something you did not expect to happen so here an example could be imagine you have a server like a database and a junior developer turns off delete on termination for your production database this could be a problem where let's say there's an accidental deletion of the database this feature would protect the database from deletion but if it's turned off you don't have that right so configuration drift going unnoticed could be a loss or breach of cloud services and residing data will result in Interruption of services or unexpected downtime so there's a lot of downsides to to neglecting or not noticing configuration drift so what can we do about this so how to detect so there's three things detect um we can fix it and then prevent it okay so to detect configuration drift if you have a compliance Tool uh it can detect misconfiguration so it was config can do that as your policies can do that gcp security health analytics can do that some of these are constrained to security things not just configuration in general but there are tools there for all the cloud service providers there is built-in support for drift detection for it was cloud formation it's called cloud formation drift detection other providers don't necessarily have that if you're using terraform which is this which is all this course is about you have the terraform State files which says what the state of things should be so that's how you could detect configuration drift how to correct configuration drift well compliance tools can remediate so again it is config you can create a custom Lambda to say hey when this happens then do this so set the configuration back into place with terraform you can use the refresh and plan command which we'll look at in detail in this course or you can manually correct it so if the option was changed you could do that not recommended to do that another thing would be tearing down and setting up the infrastructure again because that would bring it back into its original state that could be a risky thing to do depending on how you have things set up or could be it could be fine right then there's prevention so um this is a the important thing and kind of why we're talking about configuration drift which is all about immutable infrastructure so always create and just destroy never reuse so that might be blue green deployment strategies servers are never modified they are all they're just always deployed with a new version the way you would do that would be baking Ami images or containers via AWS image Builder or hashicor Packer or a build server like gcp Cloud run or code build like AWS but the idea is that you're not modifying after they're deployed you'd have that image already ready to go another thing you could use is git Ops so you would Version Control your IAC like within GitHub or something like that and you would peer review every single uh change the a pull request to the infrastructure so hopefully that gives you an idea of things we can do to tackle configuration drift okay [Music] we were just talking about immutable infrastructure but I just want to give it a bit more attention here so the idea is um we are going to first develop our infrastructure as a code file terraform cloudformation what have you and then we're going to go ahead and deploy that so we'll end up with our own virtual machine and that virtual machine needs to be configured so you need to install packages and things like that that's where Cloud init would come into play ansible puppet Chef salt whatever configuration management tool you want to use the problem here is that there's no guarantee that that configuration is going to stay in place so that's where immutable infrastructure comes into play so we develop our infrastructure as a code file terraform cloud formation and then we're going to go ahead and do our configuration by building a virtual machine or building a container so we can use something like Packer and then the idea is once we are happy with our configuration what we're going to do is bake that image and put it in an image repository and then that image is going to be referenced when we do our deploy and so that's going to make sure that our infrastructure is always immutable okay [Music] hey this is Andrew Brown from exam Pro and we are taking a look at the concept or methodology of git Ops so this is when you take infrastructure as code and you use a git repository to introduce a formal process to review and accept changes to infrastructure code and once that code is accepted it automatically triggers a deploy and changes that infrastructure so here's my illustration through it so the idea is you would have a terraform file and you would place that in something like GitHub you would apply your commits and when you're ready you'd make a pull request you would merge that pull request into the main branch or whichever branch is set up for production and that could trigge
Original Description
Prepare for the HashiCorp Terraform Associate Certification and pass! The Terraform Associate certification is for Cloud Engineers specializing in operations, IT, or development who know the basic concepts and skills associated with open source HashiCorp Terraform.
Get your Free Practice and Downloadable Cheatsheets: https://www.exampro.co/terraform
📢 View updates: https://www.exampro.co/terraform
✏️ Developed by Andrew Brown of ExamPro
🔗 https://twitter.com/andrewbrown
0:00:00 Course Intro
☁️ 0:15:03 Introduction
Exam Guide
Practice Exam Preview
Version 003 Considerations
☁️ 0:31:55 IaC Concepts
What is Infrastructure as Code
Popular Infrastructure as Code tools
Declarative
Infrastructure Lifecycle
Infrastructure Lifecycle Advantages
Non Idempontent vs Idempontent
Provisioning vs Deployment vs Orchestration
Configuration Drift
Mutable vs Immutable Infrastructure
What is GitOps
Immutable Infrastructure Guarantee
☁️ 0:52:26 Hashicorp Introduction
HashiCorp
What is Terraform
What is Terraform Cloud
☁️ 0:56:33 Terraform Basics
Terraform Lifecycle
Change Automation
Execution Plans
Visualizing Execution Plans
Resource Graph
Use Cases
Core and Plugins
Up and Running
Best Practices
Install
CLI and Configuration
Init
Plan and Apply
Apply Update
Inputs Variables
Local Values
Outputs
Modules
Divide Files
Destroy
Cloud
Cloud Updated
Cleanup
☁️ 1:07:37 Terraform Provisioners
Terraform Provisioners
Exec
File
Connection
Null Resources
Terraform Data
Cloud Init
Local Exec
Remote Exec
File
Null Resource
Terraform Data
Cleanup
☁️ 1:20:19 Terraform Providers
Providers
Registry
Providers Command
Providers Configuration
Modules
The Fine Line
Azure Provider
GCP Provider
☁️ 1:30:35 Terraform Language
Terraform Language
Alternate JSON Syntax
Terraform Settings
HashiCorp Configuration Language
☁️ 1:35:23 Variables and Data
Input Variables
Variable Definition Files
Variables vs Environment Variables
Loading Input Variables
Output Values
Local Values
Data Sources
References to
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from freeCodeCamp.org · freeCodeCamp.org · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
React: Production Server Setup Part 2 - Live Coding with Jesse
freeCodeCamp.org
cookies vs localStorage vs sessionStorage - Beau teaches JavaScript
freeCodeCamp.org
Browser history tutorial - Beau teaches JavaScript
freeCodeCamp.org
Graph Data Structure Intro (inc. adjacency list, adjacency matrix, incidence matrix)
freeCodeCamp.org
React: Parameterized Routing with Next.js - Live Coding with Jesse
freeCodeCamp.org
React: Dealing with jQuery Issues - Live Coding with Jesse
freeCodeCamp.org
setInterval and setTimeout: timing events - Beau teaches JavaScript
freeCodeCamp.org
Browser and Device Testing - Live Coding with Jesse
freeCodeCamp.org
Last Minute Updates - Live Coding with Jesse
freeCodeCamp.org
Post Launch Updates - Live Coding with Jesse
freeCodeCamp.org
React: Setting Up Google Analytics - Live Coding with Jesse
freeCodeCamp.org
React: Masonry Layout - Live Coding with Jesse
freeCodeCamp.org
Load Balancing Digital Ocean Droplets - Live Coding with Jesse
freeCodeCamp.org
try, catch, finally, throw - error handling in JavaScript
freeCodeCamp.org
Load Balancing: SSL Passthrough Setup - Live Coding with Jesse
freeCodeCamp.org
Graphs: breadth-first search - Beau teaches JavaScript
freeCodeCamp.org
React: Masonry Layout Part 2 - Live Coding with Jesse
freeCodeCamp.org
React: WordPress API Live Search - Live Coding with Jesse
freeCodeCamp.org
Creating WordPress Custom Post Types - Live Coding With Jesse
freeCodeCamp.org
Dates - Beau teaches JavaScript
freeCodeCamp.org
Miscellaneous Front End Updates - Live Coding with Jesse
freeCodeCamp.org
Merging a Pull Request from GitHub - Live Coding with Jesse
freeCodeCamp.org
React + Prettier + Standard JS - Live Coding with Jesse
freeCodeCamp.org
React: Sortable Responsive Table - Live Coding with Jesse
freeCodeCamp.org
Geolocation Sorting by Distance - Live Coding with Jesse
freeCodeCamp.org
Tradeoff Matrix - Agile Software Development
freeCodeCamp.org
The Definition of Ready - Agile Software Development
freeCodeCamp.org
Getting first React job without experience - Ask Preethi
freeCodeCamp.org
React: Google Analytics Click Tracking - Live Coding with Jesse
freeCodeCamp.org
Submitting a PR to an Open Source Project - Live Coding with Jesse
freeCodeCamp.org
Should I go back to school to get CS degree? - Ask Preethi
freeCodeCamp.org
Hero Section CSS Changes - Live Coding with Jesse
freeCodeCamp.org
Working Agreement - Agile Software Development
freeCodeCamp.org
A day at Pennybox with Co-Founder Reji Eapen
freeCodeCamp.org
React: Sorting and Filtering Data - Live Coding with Jesse
freeCodeCamp.org
React: Sorting and Filtering Data Part 2 - Live Coding with Jesse
freeCodeCamp.org
React: Building a New UI - Live Coding with Jesse
freeCodeCamp.org
Definition of Done - Agile Software Development
freeCodeCamp.org
Getting started with jQuery (tutorial) - Beau teaches JavaScript
freeCodeCamp.org
Making a React Blog with WordPress Content - Live Coding with Jesse
freeCodeCamp.org
React, NextJS, CSS - Live Coding with Jesse
freeCodeCamp.org
jQuery events - Beau teaches JavaScript
freeCodeCamp.org
React/NextJS Routing and WordPress API Custom Types - Live Coding with Jesse
freeCodeCamp.org
React: Working with API Data - Live Coding with Jesse
freeCodeCamp.org
React: Refactoring Components - Live Streaming with Jesse
freeCodeCamp.org
jQuery effects - Beau teaches JavaScript
freeCodeCamp.org
More React Refactoring - Live Coding with Jesse
freeCodeCamp.org
animate in jQuery - Beau teaches JavaScript
freeCodeCamp.org
"Finishing" My React Site - Live Coding with Jesse
freeCodeCamp.org
Starting a New React Project (P2D1) - Live Coding with Jesse
freeCodeCamp.org
React Project 2 Day 2: Learning Material UI - Live Coding with Jesse
freeCodeCamp.org
The Agile Manifesto - Agile Software Development
freeCodeCamp.org
jQuery: get and set with http, text, val, and attr - Beau teaches JavaScript
freeCodeCamp.org
React Project 2 Day 3 - Live Coding with Jesse
freeCodeCamp.org
The INVEST approach to product backlog items
freeCodeCamp.org
React Project 2 Day 4 - Live Coding with Jesse
freeCodeCamp.org
Chickens and Pigs - Agile Software Development
freeCodeCamp.org
React Project 2 Day 5 - Live Coding with Jesse
freeCodeCamp.org
jQuery: add and remove DOM elements - Beau teaches JavaScript
freeCodeCamp.org
React Project 2 Day 6 - Live Coding with Jesse
freeCodeCamp.org
More on: Tool Use & Function Calling
View skill →Related Reads
🎓
Tutor Explanation
DeepCamp AI