Terraform Resource Identity · Terraform systems note

Terraform for_each Keys Are Resource Identity, Not Loop Variables

The keys in for_each become part of resource addresses. Renaming a key can look like deleting one object and creating another even when the human thinks only a label changed.

for_each looks like iteration, but Terraform uses its keys as durable instance identity.

aws_iam_user.user["alice"]
aws_iam_user.user["bob"]

Key changes are address changes

If alice becomes a.smith, Terraform sees one old instance removed and one new instance introduced unless a moved mapping says they are the same remote object.

Choose semantic stable keys

Good keys survive cosmetic edits: canonical service names, immutable account IDs, fixed environment names. Display labels and list positions are often poor long-lived identity.

Keys must be known before apply

Terraform needs the graph before remote operations, so for_each cannot depend on keys that are only known after another resource is created.

Sensitive keys are prohibited

Keys appear in resource addresses and normal UI output, so Terraform will not accept sensitive values as instance keys.

Design for_each keys like database primary keys. Once they exist in state, renaming them is a migration.

Sources and further reading