certslothcertsloth
004/Topic 02

HashiCorp / Associate

Providers and Resource Identity

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Provider talks; state remembers.

Must remember

  • A provider is a plugin implementing resource and data-source operations for an API. Terraform Core handles language evaluation and the dependency graph; it delegates API behavior to providers.
  • required_providers declares source addresses and allowed versions. A provider block supplies a configuration such as region or endpoint. required_version constrains Terraform itself, not a provider.
  • terraform init installs providers. Commit .terraform.lock.hcl so colleagues reuse selected provider versions and verified checksums. The lock file does not lock remote module versions.
  • ~> 6.2 permits later 6.x releases; ~> 6.2.0 permits later 6.2.x patches. init -upgrade reselects versions within constraints, so review the lock-file diff.
  • Multiple configurations of one provider use alias; select one with provider = aws.secondary. Child modules receive aliases through an explicit providers mapping and declare expected aliases.
  • A Terraform resource address identifies a configured instance, such as module.web.aws_instance.node["blue"]. State connects that address to the remote object identifier. Renaming an address without a move declaration can look like delete-and-create.

Choose under exam pressure

Requirement Choice and reason
Same API, two regions Two provider configurations, one aliased, with explicit resource/module selection.
Reproducible plugin selection Compatible constraints plus the committed dependency lock file.

Traps

  • A provider alias is not a separate state file.
  • An omitted default provider configuration can produce an empty default configuration, which may lack required settings.

Active recall

1. What downloads a provider?

terraform init resolves the declared source and installs a compatible plugin.

2. Does required_version pin AWS?

No. It constrains the Terraform CLI; required_providers constrains the AWS provider.

3. What does the lock file record?

Selected provider versions and package checksums, not module source versions.

4. Why use an alias?

To select another configuration of the same provider, such as another region or account.

5. What identifies an object to Terraform?

The resource-instance address is bound in state to the provider’s remote object ID.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.