Concept and mechanism
resource declares a managed object; data queries information through a provider. Attribute references help Terraform infer dependencies. depends_on serves behavioral relationships not expressed through references, but excessive use can make planning conservative. Types such as list, map, and object structure inputs; expressions and functions transform values while outputs expose results. Variable validation and preconditions can block invalid conditions. A failed assertion in a check produces a warning, so it should not be confused with a blocking gate.
Guided application
In configuration containing credentials, sensitive redacts display in appropriate contexts but does not automatically remove persisted values. Ephemeral and supported write-only arguments can avoid particular persistence, with context and version restrictions. Confirm provider support and protect state, plans, and logs. When using create_before_destroy, assess naming, quotas, and coexistence: creating first neither migrates data nor guarantees continuity. Record those limits in review so support knows what automation actually does.
A password is hidden in terminal output but the plan is shared without access control. The team reviews artifact permissions and secret-handling mechanisms.
Common pitfalls
Using depends_on everywhere; confusing sensitive with encryption or checks with blocking gates.
Related topics: Modules and usage contracts · State, locking, and drift
Configuration should express intent, dependencies, and validation limits.
Reference: Validate infrastructure configuration · 004