Keep object identity through a module refactor

A hands-on TERRAFORM-004 lab. You produce the real artefact and 8 automated checks verify it behaves the way the exam expects.

Try this labAll TERRAFORM-004 practice

Certification
TERRAFORM-004
Format
Structured configuration
Difficulty
hard
Estimated time
25 min
Automated checks
8

The brief

Repair migration.tf.json, a Terraform JSON configuration file. Keep module.services sourced from ./modules/service and pass exactly api = public-api, worker = async-worker and cron = nightly-job in its services map. The read-only child declares variable services as map(string) and resource terraform_data.node with for_each = var.services and input = each.value. Preserve the original object IDs and inputs while relocating count instances to their matching keyed module addresses. Current bindings are terraform_data.service[0] = original-api/public-api, [1] = original-worker/async-worker and [2] = original-cron/nightly-job. The separate terraform_data.audit = original-audit/security-log must remain at its current address. Add moved blocks as JSON objects in the moved array, with from and to containing static Terraform addresses. You can move each instance directly or move the whole resource first and then map its instance indexes to stable keys. A successful refactor must have no create, update or destroy actions for the supplied objects. Run tests and inspect plannedActions when an incomplete mapping leaves old objects unmatched. The artifact supports the supplied module call and static moved resource addresses; the state snapshot, child module and audit declaration are read-only facts.

What the checks verify

Your work is graded on 8 independent properties, not on matching one reference answer.

  • The artifact uses the bounded Terraform JSON module and moved-block structure.
  • The child module receives the original three stable service keys and input values.
  • The move graph is acyclic, unambiguous and has unique destination ownership.
  • The API service keeps its original ID and input at the intended keyed module address.
  • The worker keeps its original ID and input at the intended keyed module address.
  • The scheduled job keeps its original ID and input at the intended keyed module address.
  • The separately owned audit object retains its original address, ID and input.
  • The resulting plan contains no creates, updates or destroys for the supplied objects.

Where this sits in the TERRAFORM-004 blueprint

Domain
Terraform state management
Objective
Change Reconciliation
Skill
Drift, Refresh and Address Refactoring

Part of TERRAFORM-004 preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.