Dependencies · 11 min read · Reviewed 2026-08-29
Terraform Dependency Graph: How Resource References Work
Terraform does not create blocks from top to bottom. It builds a dependency graph from the values resources reference. When a subnet reads a VPC ID, Terraform knows the VPC must be created first—even if the blocks live in different files.
A direct dependency reference
The subnet needs the VPC ID. That reference is what lets Terraform infer that the VPC must be created first.
resource "aws_vpc" "main" {
cidr_block = "10.0.0.0/16"
}
resource "aws_subnet" "public" {
vpc_id = aws_vpc.main.id
cidr_block = "10.0.1.0/24"
}Implicit dependencies are the preferred default
aws_vpc.main.id communicates both the value the subnet needs and the order Terraform should use. This direct reference is an implicit dependency and normally gives the clearest description of the architecture.
References can use IDs, ARNs, names, locations, or other exported attributes. The cloud display name is not necessarily the Terraform local name, so match the declared type and local name exactly.
When depends_on is appropriate
Use depends_on for a genuine hidden ordering requirement, such as an IAM policy attachment that must exist before a service starts but is not otherwise passed as an input value.
Keep it small and explainable. If a direct attribute reference is available, it is usually better because it models both the data flow and the creation order.
Cycles need a design change
A cycle means Terraform cannot decide what to create first because resources require each other’s values. Read the cycle error as a path through the graph and identify the reference that closes the loop.
The answer is usually to separate creation from later configuration or use a value available earlier. File order and extra depends_on entries cannot break a true cycle.
Put it into practice
Paste the example into Build and follow the subnet arrow to the VPC. Rename main to an undeclared name, read the validation message, then correct it by copying the declared address.
- Read a reference as type.name.attribute.
- Confirm its resource type and local name were declared.
- Prefer direct references when a real value is needed.
- Use depends_on only for a prerequisite Terraform cannot infer.
Frequently asked questions
How does Terraform know which resource to create first?
Terraform reads references between resources and builds a dependency graph. When a subnet uses aws_vpc.main.id, Terraform sees that the VPC must exist before the subnet can receive that ID.
Do I need depends_on when one resource uses another resource ID?
Usually no. A direct ID, ARN, or similar attribute reference already creates an implicit dependency. Use depends_on only when there is a real ordering requirement that Terraform cannot infer from a value reference.
Can depends_on fix a Terraform circular dependency?
No. A real cycle means two resources require values that are not available until the other resource exists. The configuration needs a design change, such as separating creation from later configuration.
Continue with Terraform Architect
- Visualize a dependency graph
Paste the VPC and subnet example into Build to see the resource reference become an architecture connection.
- Learn Terraform foundations
Start with providers, resources, variables, and the workflow that makes dependency graphs easier to read.
- Practise fixing references
Use the debugging challenges to identify an incorrect Terraform resource address before revealing the solution.