Preserve shared ownership and enforce lifecycle guarantees

A hands-on TERRAFORM-004 lab. You produce the real artefact and 10 automated checks verify it behaves the way the exam expects.

Try this labAll TERRAFORM-004 practice

Certification
TERRAFORM-004
Format
Structured configuration
Difficulty
hard
Estimated time
35 min
Automated checks
10

The brief

Edit lifecycle.tf.json. Preserve the resource input links architecture = ${var.architecture}, owner = ${var.owner}, external_note = scanner-declared and triggers_replace = ${var.revision}. Admit x86_64 and arm64, and reject sparc with a lifecycle precondition. Add a postcondition that compares produced self.output.owner with the requested var.owner; both payments and platform requests must pass, while an injected intruder result must fail. A revision v1 to v2 must replace the service in create-then-delete order without prevent_destroy blocking it. For in-place changes, retain scanner-observed external_note while updating architecture and owner. The proven narrow JSON ignore path is input.external_note. Whole input, all attributes and triggers_replace suppression violate required changes. Keep terraform_data.audit input security-log and exactly the service/audit declarations. Supported lifecycle flags are literal Booleans, ignore_changes is a list of dotted input field paths, input, triggers_replace or the literal all keyword, and guards are ${...} expressions with var.<configured-name> references; postconditions also allow self.output.<configured-field>. Conditions support literals, lists, comparisons, Boolean operators and contains, length, trimspace, floor. Unknown references, arbitrary functions, bracket ignore paths and other resources are rejected. Add nonempty literal error_message text for each guard. Read validProbes, replacementProbe and injectedResultProbe after Run tests. Repair through normal edits without Reset.

What the checks verify

Your work is graded on 10 independent properties, not on matching one reference answer.

  • Use supported Terraform JSON resource and lifecycle syntax.
  • Keep architecture and owner linked to their declared variables and the declared external note literal.
  • Changing revision v1 to v2 requests a replacement without prevent_destroy blocking it.
  • The revision replacement creates the new marker before deleting the old marker.
  • The precondition admits both valid x86_64 and arm64 input probes.
  • The precondition rejects the supplied sparc input before the operation.
  • The postcondition admits valid produced results for both requested owners.
  • The postcondition rejects the injected intruder owner result.
  • In-place updates retain scanner-observed external_note while applying architecture and owner changes.
  • Keep exactly service and audit resources and the audit security-log input unchanged.

Where this sits in the TERRAFORM-004 blueprint

Domain
Terraform configuration
Objective
Dependency and Conditions
Skill
Ordering, Lifecycle and Custom Conditions

Part of TERRAFORM-004 preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.