Setting Up Approval Workflows in Terraform Cloud with Permissions
A company uses Terraform with multiple cloud providers and wants to integrate with their existing CI/CD pipeline. They need to enforce that all infrastructure changes go through code review and automated testing before being applied to production. Which approach best meets these requirements?
⚠ Common exam trap
HashiCorp often tests the misconception that simply using a remote backend or running terraform apply in a pipeline is sufficient for governance, but the key requirement here is enforced code review and automated testing, which only Terraform Cloud's policy checks and run triggers provide natively.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Terraform Cloud with run triggers and policy checks
Terraform Cloud's run triggers and policy checks (e.g., Sentinel) enforce that all infrastructure changes must pass code review and automated testing before being applied. This integrates directly with the CI/CD pipeline by requiring a pull request to trigger a plan, which is then reviewed and approved via Terraform Cloud's governance controls, ensuring no change reaches production without validation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store state in a remote backend and use terraform apply in the pipeline
Why it's wrong here
Storing state in a remote backend centralizes state management, preventing concurrent modification issues and providing a single source of truth. However, simply using `terraform apply` within a CI/CD pipeline, even with remote state, does not inherently enforce code review or policy checks before execution. The pipeline would execute changes automatically based on the merged code, lacking a mandatory human or automated policy gate for review.
- ✓
Configure Terraform Cloud with run triggers and policy checks
Why this is correct
Terraform Cloud provides a robust platform for managing Terraform workflows, offering features like run triggers that automate infrastructure changes upon code commits. Its integrated policy checks, powered by Sentinel, enforce compliance and security standards by evaluating plans before application. This setup ensures mandatory code review and automated policy enforcement, creating a secure and auditable change management process.
- ✗
Use the Terraform CLI in the CI/CD pipeline with remote state
Why it's wrong here
Utilizing the Terraform CLI in a CI/CD pipeline with remote state allows for automated execution and shared state, improving consistency over local runs. However, this approach, by itself, does not natively incorporate mechanisms for policy enforcement or mandatory code review within the Terraform workflow. While a CI/CD pipeline can be configured with custom steps for review, the CLI itself doesn't provide the integrated policy-as-code capabilities or structured approval gates found in dedicated platforms.
- ✗
Run terraform apply locally after manual approval
Why it's wrong here
Running `terraform apply` locally, even after a manual approval, introduces significant risks and lacks proper governance. This method bypasses centralized control, audit trails, and consistent execution environments, making it prone to configuration drift and human error. Furthermore, 'manual approval' in this context typically doesn't equate to a structured code review process with automated policy validation, failing to enforce critical security and compliance checks.
Go deeper
Related to this question
About these practice questions
One of 434 original TF-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on TF-004
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. You are a platform engineer at a large enterprise that uses Terraform Cloud with a VCS-backed workflow for all infrastructure. Your team manages a configuration that provisions AWS EC2 instances for a critical application. Recently, a junior team member accidentally committed a change that removed a required tag from the EC2 instance resource. The change passed the plan stage but was blocked by a Sentinel policy during the apply, preventing the infrastructure from being updated. The team needs to fix the configuration and apply the change. However, the repository is configured to automatically trigger runs on every push to the main branch. The team wants to avoid triggering an unwanted run while they work on the fix. What should the team do?
hard- A.Temporarily disable the VCS connection in Terraform Cloud to prevent runs
- B.Run terraform apply locally with the fixed configuration to bypass Terraform Cloud
- ✓ C.Create a feature branch, fix the configuration, and merge via pull request
- D.Amend the commit on main and force push to overwrite history
Why C: Using a feature branch and pull request allows the team to fix the configuration without triggering a run on the main branch, since Terraform Cloud’s VCS integration only auto-triggers runs on pushes to the configured branch (typically main). Once the fix is merged via pull request, the change will be applied through the normal VCS-backed workflow, maintaining audit trails and policy enforcement. This approach avoids disrupting the VCS connection or bypassing Terraform Cloud’s governance.
Variation 2. An organization uses Terraform Cloud for team collaboration. They have a workspace that manages production infrastructure. Due to a security policy, they must ensure that all changes go through a peer review process before they are applied. How can they enforce this requirement?
medium- ✓ A.Enable 'apply on merge' and set the workspace to require approval before applying.
- B.Require all changes to be submitted via a VCS pull request.
- C.Use run triggers to automatically apply after a successful plan in another workspace.
- D.Lock the workspace and only unlock it for approved changes.
Why A: Enabling 'apply on merge' combined with requiring approval before applying enforces a peer review process: changes must be merged via a VCS pull request (triggering the plan), and then a separate approval step is needed before Terraform Cloud applies the changes. This ensures that no change is applied without explicit human approval after the plan is reviewed.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This TF-004 practice question is part of Courseiva's free HashiCorp certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the TF-004 exam.