Terraform Modules — Challenge
Turn a working configuration into a network module and a compute module, called twice with different inputs.
- Time
- 50 min
- Level
- Intermediate
- Objectives
- 5 objectives
- Cost
- Low cost
Where this fits in the platform
Already built
This lab adds
- A reusable module with inputs and outputs
Before you start
You will need
- Terraform >= 1.6
- AWS CLI v2, configured
You will be able to
- Extract a module with a deliberate input/output contract
- Call one module from another and let the graph order the work
- Know when a module is not worth writing
Cost — Low cost
— a VPC, subnets and one `t3.micro`. No NAT Gateway in this lab, deliberately: it is the one resource here that would bill hourly.
The goal#
Achieve the same outcome as Terraform Modules, from an empty starting point, without the steps.
The configuration from the previous lab works, and now a second environment needs the same shape with different addresses. Copying the directory is the obvious move and the wrong one — two copies drift, and the drift is discovered during an incident.
A module is how the same definition serves both.
Hands-on environment
Run this lab in a real terminal, free and in your browser. The environment is temporary and yours alone — break it as much as you like.
Start the challengeOpens in Killercoda, in a new tab — keep this page open for the steps.
This is the guided lab's environment — the same machine, with its walkthrough on the left. Work from the task above and leave those steps alone until you are done, or you are reading the answers.
Run it on AWS
This lab builds real cloud infrastructure, so it needs your own AWS account. Follow the cost and cleanup notes above — the resources are yours, and so is the bill.
Anything you tick here is your own record. EgyKode cannot see inside that terminal, so the success criteria stay self-assessed even when the environment checks your work for you.
What must be true when you are done
Step 1 of 3
What must be true when you are done#
- A
modules/networkmodule creates a VPC and subnets from inputs, exposing subnet ids as outputs. - A
modules/computemodule places an instance into a subnet it did not create. - The root module wires them together with no hardcoded ids anywhere.
- Calling the network module twice with different CIDRs produces two independent networks.
- You can explain why the compute module never references
aws_vpcdirectly.
Rules#
- Do not open the guided lab until you are finished, or until the same problem has held you up for 20 minutes.
- Documentation is allowed. In the job it is the first thing you open.
- Verify every criterion with a command whose output you can read.
If you get stuck#
- What did you expect, exactly?
- What happened instead — the error text, not a paraphrase?
- Which layer is that error from?
- What is the smallest command that proves the layer below is fine?
You are done when
0 of 5
The concept behind it
Next up
Lab 21 of 59 on the project path