Converge scoped workspace access and dependency transport
A hands-on TERRAFORM-004 lab. You produce the real artefact and 9 automated checks verify it behaves the way the exam expects.
Try this labAll TERRAFORM-004 practice
- Certification
- TERRAFORM-004
- Format
- Structured configuration
- Difficulty
- hard
- Estimated time
- 35 min
- Automated checks
- 9
The brief
Edit collaboration.policy.json. Keep workspaceProjects unchanged. Grant both operators run apply and state read-outputs access in api and worker, with variables none and no capabilities in network/security. Permissions are additive across all actor teams and scopes. Use a custom payments project grant or equivalent api/worker workspace grants. Share network output only with api and worker; bind each subnet_id to {workspace: network, output: subnet_id} so both changing probes work. Create exactly network-to-api and network-to-worker trigger records. Both consumers must use agent execution with a supplied pool reaching private-api. Supported permissions are runs none/read/plan/apply, state none/read-outputs/read/write, variables none/read/write. The normalized manifest supports only declared names and project/workspace scopes plus the broad organization Manage all workspaces grant. Run tests, inspect independent failures and repair without Reset.
What the checks verify
Your work is graded on 9 independent properties, not on matching one reference answer.
- Use the declared normalized collaboration manifest fields and typed supported permissions.
- Preserve each declared workspace project assignment and independently supplied state context.
- Both release operators can apply runs in api and worker through their effective team memberships.
- Neither operator receives any capability in network or security from any of their teams.
- Operators can read outputs in api and worker but cannot download/write full state or read/write variables.
- Only api and worker are approved consumers of network outputs.
- Both consumers explicitly read network subnet_id and follow subnet-v2 and subnet-v3 probes.
- Network successful apply schedules exactly api and worker, without reverse or additional run edges.
- Both consumer runs use a declared agent pool that can reach the supplied private-api endpoint.
Where this sits in the TERRAFORM-004 blueprint
- Domain
- HCP Terraform
- Objective
- Governance and Organization
- Skill
- Projects, Workspaces and Shared Controls
Part of TERRAFORM-004 preparation
Labs are written by ExamNova to teach the decisions the exam tests. They are not reproductions of vendor lab content.