Terraform and OpenTofu Interview Questions and Answers (with AWS Examples)

· 5 min read · Terraform & OpenTofu Tutorials

Terraform interview questions, grouped by topic #

Short answers to the questions that appear most in DevOps, SRE and cloud engineer interviews. Each answer links to a longer guide. Everything also applies to OpenTofu.

Basics #

What is Terraform and what problem does it solve? An Infrastructure as Code tool that describes infrastructure in declarative HCL files, compares them with reality and creates, changes or destroys resources through provider APIs. It gives repeatable, reviewable and versioned infrastructure.

What is the difference between declarative and imperative? In a declarative tool (Terraform) you describe the desired end state and the tool works out the steps. In an imperative one (a Bash script with the AWS CLI) you write the steps.

What are the main commands? init, validate, plan, apply and destroy. See the cheat sheet.

What does terraform init do? Downloads providers and modules, configures the backend and creates .terraform.lock.hcl.

What is the difference between Terraform and OpenTofu? OpenTofu is the open-source (MPL 2.0) fork under the Linux Foundation. Same language and providers, plus features such as state encryption. See Terraform vs OpenTofu.

State #

What is the state file and why does it matter? It maps your code to the real resources and stores their attributes. Without it Terraform cannot know what it manages. See Terraform state.

Where should you store it in a team? In a remote backend with locking, versioning and encryption, such as S3 with use_lockfile (Terraform 1.10 and later, and OpenTofu), or DynamoDB for older versions. See backends.

What is state locking? It prevents two runs from changing the state at the same time. A stuck lock is released with terraform force-unlock <ID>, after checking that no run is active.

How do you protect secrets in the state? Encrypted private backend, restricted access, state encryption in OpenTofu, and AWS-managed secrets so the value never enters the state. See secrets management.

What is drift and how do you handle it? Differences between code and reality caused by manual changes. Detect it with a scheduled plan, then update the code or re-apply. See drift.

How do you bring existing infrastructure under Terraform? import blocks (or terraform import), then run plan until it is clean. See import, moved and removed.

Language #

What is the difference between count and for_each? count indexes by number and recreates items when the list changes. for_each indexes by key. See for_each vs count.

What is a data source? A read-only lookup of existing information. See data sources.

What are variables, locals and outputs? Inputs, named expressions and returned values. See variables, outputs and locals.

What is a dynamic block? It generates repeated nested blocks from a collection. See dynamic blocks.

How do implicit and explicit dependencies work? A reference to another resource creates an implicit dependency. depends_on creates an explicit one. See dependencies.

What does the lifecycle block do? prevent_destroy, create_before_destroy, ignore_changes, replace_triggered_by and conditions. See lifecycle.

How do you write a conditional resource? count = var.enabled ? 1 : 0. See conditionals and for expressions.

What are provisioners and why avoid them? They run scripts on a resource after creation. They are a last resort because they are not declarative and are not tracked in the plan. See provisioners and user data.

Modules and structure #

What is a module and how do you version it? A reusable directory of resources with inputs and outputs. Pin the version of external modules with Git tags or registry versions. See modules and popular AWS modules.

How do you manage several environments? Separate state per environment: directories, tfvars with a backend per environment, or workspaces. See workspaces vs directories.

How do you organize a large project? Split state by layer and lifecycle. See project structure.

How do you use several AWS regions or accounts? Provider aliases. See multi-region and multi-account providers.

AWS and operations #

How does Terraform authenticate to AWS? Environment variables, shared profiles, instance roles or SSO. In CI/CD, short-lived credentials with OIDC. See the AWS provider.

How would you design a CI/CD pipeline for Terraform? Format, validate, lint and scan on pull requests, save the plan, require review, and apply the same plan from the main branch with approval. See CI/CD.

How do you test Terraform code? validate, linters, security scanners, terraform test and Terratest. See testing and security scanning.

How do you rename a resource without destroying it? A moved block.

What do you do when apply fails halfway? The state records what was created. Fix the cause and run apply again. See common errors.

How do you force a resource to be recreated? terraform apply -replace=<address>. See replace, taint and target.

How do you control cost? Estimate in pull requests with Infracost and follow FinOps practices.

Scenario questions #

Someone changed a security group by hand. What do you do? Run plan to see the drift, decide which side is right, update the code or apply, and restrict console write access.

A teammate's apply crashed and the lock remains. Confirm nothing is running, then force-unlock.

The plan takes 20 minutes. Split the state, reduce data sources, increase -parallelism, and avoid -refresh on huge states only as a last resort.

You need to move a resource from one state to another. removed block with destroy = false in the source and import in the target, or terraform state mv with -state-out.

For certification study, see the Terraform Associate guide.

#Terraform #OpenTofu #AWS