Terraform Resource Identity · Terraform systems note
Terraform for_each Keys Are Resource Identity, Not Loop Variables
The keys in for_each become part of resource addresses. Renaming a key can look like deleting one object and creating another even when the human thinks only a label changed.
for_each looks like iteration, but Terraform uses its keys as durable instance identity.
aws_iam_user.user["alice"]
aws_iam_user.user["bob"]Key changes are address changes
If alice becomes a.smith, Terraform sees one old instance removed and one new instance introduced unless a moved mapping says they are the same remote object.
Choose semantic stable keys
Good keys survive cosmetic edits: canonical service names, immutable account IDs, fixed environment names. Display labels and list positions are often poor long-lived identity.
Keys must be known before apply
Terraform needs the graph before remote operations, so for_each cannot depend on keys that are only known after another resource is created.
Sensitive keys are prohibited
Keys appear in resource addresses and normal UI output, so Terraform will not accept sensitive values as instance keys.
Design for_each keys like database primary keys. Once they exist in state, renaming them is a migration.