Route an ephemeral credential through a write-only consumer

A hands-on TERRAFORM-004 lab. You produce the real artefact and 9 automated checks verify it behaves the way the exam expects.

Try this labAll TERRAFORM-004 practice

Certification
TERRAFORM-004
Format
Structured configuration
Difficulty
hard
Estimated time
30 min
Automated checks
9

The brief

Edit secret.tf.json. Keep required string password and numeric epoch inputs with no defaults. Mark password sensitive and ephemeral. Route the supplied password to password_wo, directly or through ./secret-bridge (input password, ephemeral/sensitive output secret). Remove ordinary password. Keep epoch non-ephemeral and bind password_wo_version to it so probes 2 and 3 both work. Publish only rotation_version with that changing normal counter. Preserve the supplied resource settings and Owner. The editor supports primitive variable declarations, static literals, direct var references, the declared module output and the counter resource attribute; it rejects other expressions. Run tests, inspect each independent failing concern and repair without Reset.

What the checks verify

Your work is graded on 9 independent properties, not on matching one reference answer.

  • Use supported Terraform JSON primitive variables, direct references and the supplied child bridge.
  • Keep the required string password and numeric epoch inputs without embedded defaults.
  • Mark the root credential sensitive and preserve sensitive flow into its consumer.
  • Omit the supplied root credential from saved-plan variables and every persistable secret path.
  • Send the supplied password through a direct reference or the declared ephemeral bridge.
  • Consume the credential only through password_wo and keep ephemeral values out of normal persisted arguments and root outputs.
  • Persist a non-ephemeral numeric epoch and bind password_wo_version to both epoch probes 2 and 3.
  • Expose only the non-ephemeral rotation_version that follows both requested epochs.
  • Keep the supplied resource identity, database settings and Owner metadata.

Where this sits in the TERRAFORM-004 blueprint

Domain
Terraform configuration
Objective
Sensitive Data
Skill
Sensitive, Ephemeral and Write-Only Values

Part of TERRAFORM-004 preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.