# Providers and Version Constraints — Terraform

Source: https://www.skillbyai.com/en/terraform/i-providers

> Plugins that talk to APIs.

## required_providers and pinning

A **provider** is a plugin that knows how to manage resources for one platform. Declare providers in a `terraform { required_providers { ... } }` block with a source (`hashicorp/aws`) and a **version constraint** (`~> 5.0` allows 5.x but not 6.0). `required_version` constrains the Terraform CLI itself. The lock file records the exact versions selected; `terraform init -upgrade` moves to newer versions within the constraints. Configure provider settings (region, credentials via environment or roles, never hard-coded keys) in `provider` blocks.

## The provider block used in this course

Both providers manage local resources, so examples run without credentials.

```hcl
terraform {
  required_version = ">= 1.6"
  required_providers {
    local  = { source = "hashicorp/local", version = "~> 2.5" }
    random = { source = "hashicorp/random", version = "~> 3.6" }
  }
}
```

## Use pessimistic constraints

Constraints like ~> 5.0 accept fixes and features but stop at the next major version, which may break your code.

**Quiz:** What does the version constraint ~> 2.5 allow?

- [ ] Only versions below 2.5
- [ ] Exactly 2.5 only
- [ ] Any version
- [x] Versions 2.5 and above but below 3.0

*Answer:* Versions 2.5 and above but below 3.0. Pessimistic constraint operator.
