Converge scoped workspace access and dependency transport

A hands-on TERRAFORM-004 lab. You produce the real artefact and 9 automated checks verify it behaves the way the exam expects.

Try this labAll TERRAFORM-004 practice

Certification
TERRAFORM-004
Format
Structured configuration
Difficulty
hard
Estimated time
35 min
Automated checks
9

The brief

Edit collaboration.policy.json. Keep workspaceProjects unchanged. Grant both operators run apply and state read-outputs access in api and worker, with variables none and no capabilities in network/security. Permissions are additive across all actor teams and scopes. Use a custom payments project grant or equivalent api/worker workspace grants. Share network output only with api and worker; bind each subnet_id to {workspace: network, output: subnet_id} so both changing probes work. Create exactly network-to-api and network-to-worker trigger records. Both consumers must use agent execution with a supplied pool reaching private-api. Supported permissions are runs none/read/plan/apply, state none/read-outputs/read/write, variables none/read/write. The normalized manifest supports only declared names and project/workspace scopes plus the broad organization Manage all workspaces grant. Run tests, inspect independent failures and repair without Reset.

What the checks verify

Your work is graded on 9 independent properties, not on matching one reference answer.

  • Use the declared normalized collaboration manifest fields and typed supported permissions.
  • Preserve each declared workspace project assignment and independently supplied state context.
  • Both release operators can apply runs in api and worker through their effective team memberships.
  • Neither operator receives any capability in network or security from any of their teams.
  • Operators can read outputs in api and worker but cannot download/write full state or read/write variables.
  • Only api and worker are approved consumers of network outputs.
  • Both consumers explicitly read network subnet_id and follow subnet-v2 and subnet-v3 probes.
  • Network successful apply schedules exactly api and worker, without reverse or additional run edges.
  • Both consumer runs use a declared agent pool that can reach the supplied private-api endpoint.

Where this sits in the TERRAFORM-004 blueprint

Domain
HCP Terraform
Objective
Governance and Organization
Skill
Projects, Workspaces and Shared Controls

Part of TERRAFORM-004 preparation

Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.