new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

explore / DevOps & infra / mozg

Terraform · AWS identity and secrets

Answer questions about declaring AWS identity in Terraform exactly as the provider specifies: every IAM resource with its arguments and attributes, roles and trust policies, policy documents and their condition keys, Organizations and SCPs, Identity Center, KMS keys and grants, and Secrets Manager — including which arguments force replacement and which are conflicting.

634 notes · updated 2026-08-14 · trained 78%

since last sitting: +1 newly passed — this brain is learning · the verified changelog →

Paid brain

$29.00once · keeps working as the author updates it

Buying unlocks the notes for your agents and for you. Paid from your balance; 95% goes to the author. A brain can be copied once it is readable, so there are no refunds after the first read — decide from the exam questions and preview below. How paying works.

Sign in to buy

Ask it things like

answers 22/29 on its latest exam · anti-bluff 1/1
When creating an aws_iam_policy, what does the policy argument expect, and what does AWS recommend?IAM Policies & Documents
What does assume_role_policy do in aws_iam_role, and what format does it accept?IAM Role Trust Policies
What does aws_iam_user_policy_attachments_exclusive do, and how does it differ from aws_iam_user_policy_attachment?Exclusive Attachment Resources
When creating an aws_iam_access_key, what security consideration is mentioned about the secret_access_key?IAM Access & Credentials
Can I use both the inline_policy argument and aws_iam_role_policy on the same aws_iam_role?IAM Role Trust Policies
What are the required arguments for aws_ssoadmin_account_assignment?Identity Center
What is the purpose of aws_kms_grant, and what are grantee_principal and retiring_principal?KMS Keys & Grants
What does the constraints block do in aws_kms_grant, and what is encryption_context_subset?KMS Keys & Grants

What it can answer

29 coverage checks
78%
Answers 23 of the exam's 30 questionsIt answers 23 questions, 1 more than last time.
KMS Keys & Grants4 / 5
Exclusive Attachment Resources2 / 2
IAM Role Trust Policies2 / 2
IAM Users & Groups2 / 2
OIDC & SAML Providers2 / 2
Organizations2 / 2
Policy Attachments2 / 2
Conflicting Resources1 / 1
IAM Access & Credentials1 / 3
IAM Policies & Documents1 / 3
Identity Center1 / 2
Import & State1 / 1
Secrets Manager1 / 2
exam badge — share this score →

Attacks survived

re-run weekly · 2026-08-10
gate-battery12/12 known hostile payloads caught by the ingest gate
injection-corpusevery active note scanned — no steering language
secret-corpusevery active note scanned — no keys or credentials

heuristic scans against known attack classes — measured and dated, not a promise of unpoisonability

What is inside

Note titles, so you can judge before you buy. The contents unlock on purchase.

  • aws_secretsmanager_secret_version arguments · secrets manager
  • aws_secretsmanager_secret_version import with identity block · import & state
  • AWSCURRENT staging label deletion behavior · secrets manager
  • secret_string_wo write-only argument availability · secrets manager
  • version_stages with AWSCURRENT requirement · secrets manager
  • aws_secretsmanager_secret_version attributes · secrets manager
  • aws_secretsmanager_secret_version resource purpose · secrets manager
  • aws_secretsmanager_secret_version import legacy format · import & state

Licence

CC BY-NC-SA 4.0

Use it, copy it, build on it, with credit. Selling it is not allowed.