Variable Management in Terraform Cloud
Any developer can tell you that when building an application, script, or any code-based object, variables are a critical component. The same is true with any Terraform configuration. From creating modularity and reusability to simply ensuring sensitive information isn’t stored in publicly-accessible repositories, variables are a simple way to make your code more flexible, secure, and readable. But those same developers can also tell you that managing variables in highly complex code can be a real chore!
» Managing Variables in Terraform Cloud
Terraform Cloud provides a robust system for managing your variables. Whether you want to manage them directly from a Terraform configuration or consume or control them via the UI, HashiCorp has you covered. And with our recent addition of variable descriptions in the UI and a facelift to the variable management page, we’d like to share some more about variables with you.
When working with Terraform Cloud, your runs are executed within a particular workspace. These workspaces are isolated from one another, each containing their own state file, access permissions, configurations, and yes, variables.
Because the workspace performs your runs in isolation, you can define two types of variables. Terraform variables are used by the configurations you apply and might normally be stored in a vars.tf
or terraform.tfvars
file in your repository, if you were using the Terraform CLI. Environment variables are those which you’d store in your system environment using export
or set
commands, depending on your operating system. Both types of variables set values that can be consumed by your configuration when a run happens.
» Workspace Variables in the UI
Managing variables in the Terraform Cloud UI is done by opening your workspace, then visiting the Variables pane. Here you can define both types of variables, as well as control how they are displayed and used throughout the workspace.
You may notice that some of these variables are marked with a Sensitive label. This means that the value is only visible when you first enter it on creation; after that, the value is marked as write-only. It can be changed, but not viewed by a UI user.
Another new label you’ll notice in the UI is HCL. This denotes a variable that contains not simple text, but rather HCL code that can be interpolated and processed as more than a string value. These variables now display in a fixed-width font for easy readability, and if you use the new pop-up variable actions menu to edit one you can see how it’s defined.
In this view, you can see how we have defined this simple map of AMI values as an HCL variable. We’ve also defined a description to make it clear to other users of the workspace what the intended purpose of this particular variable is, making it easier for your teammates to understand how a workspace is configured.
It’s also possible to manage your Terraform Cloud variables using the Terraform Enterprise Provider, which can be a simpler way to deal with large quantities of variables at once, or manage them programmatically. For more information on using the Terraform Enterprise Provider to manage variables, check out the documentation here.
» Getting Started
If you’d like to learn more about using variables within Terraform Cloud, you can sign up for a free account, head over to our documentation for more details, or visit the HashiCorp Learn platform and see Terraform in action today!
Sign up for the latest HashiCorp news
More blog posts like this one
Fannie Mae’s process for developing policy as code with Terraform Enterprise and Sentinel
Learn how to implement the policy as code development lifecycle used in the highly regulated cloud environments at Fannie Mae.
New Terraform integrations with Crowdstrike, Datadog, JFrog, Red Hat, and more
12 new Terraform integrations from 9 partners provide more options to automate and secure cloud infrastructure management.
Terraform delivers launch-day support for Amazon S3 Tables, EKS Hybrid Nodes, and more at re:Invent
The Terraform provider for AWS now enables users to manage a variety of new services just announced at re:Invent.