⚠️

Leave Active Challenge Lab?

Challenge in progress ({{ challengeProgressPct }}% completed)

If you exit this challenge now, your current Challenge Lab session will end and you will return to your Learning Path Tree.

🏆
Challenge Complete • 100%

{{ activeChallengeNode?.title || 'Challenge Mastered!' }}

You completed all 10 progressive Terraform questions in this challenge.

Completion
100%
Accuracy
{{ challengeCorrectCount * 10 }}%
Optional Study Drawer

🧠 Spaced Repetition & Path Details

Active Path: {{ activePathSummary.title }}
Current Node: {{ currentActiveNodeLabel }}
Path Completeness: {{ activePathCompletenessPct }}%
FSRS v4 Due Review Queue {{ (state.fsrs_due_queue || []).length }} Due
{{ card.concept }} {{ card.due_status }}
Stability: {{ card.stability_days }}d • Difficulty: {{ card.difficulty }}
External Tester Feedback

💬 Share Product & UX Feedback

✓ {{ feedbackStatusMessage }}
Internal CloudGraft Dev / QA & RBAC Simulator

🔐 Switch Active User Archetype (`DEVELOPER` / `ADMIN` / `USER`)

Select an account below to test CloudGraft's Database-Controlled RBAC Enforcement across both UI views and backend API endpoints (X-CloudGraft-User-ID):

Want to grant repos:import to a USER without taxonomy:write?
RBAC Gated Administration {{ activeUserType }}
{{ user.displayName }}
{{ activeUserType }}
{{ user.roleTitle }} • {{ effectiveLearnerXP }} XP
Release: {{ state.release_version || 'v1.21.0' }} Enterprise Edition

{{ oktaEmbeddedForm.step === 'mfa' ? 'Verify Your Identity' : (oktaEmbeddedForm.mode === 'signup' ? 'Create Your Account' : 'Welcome') }}

{{ authGate.errorMessage }}
{{ authGate.statusMessage }}
OR
⚡ Duolingo-Style Interactive Mastery for Enterprise Terraform & Google Cloud

Master Terraform Foundations, Fabric FAST & Your Own Cloud Repositories.

CloudGraft transforms static Infrastructure-as-Code documentation and complex Git repositories into interactive stepping-stone learning paths, AST code-pinpoint labs, global & country scoreboards, and FSRS v4 spaced-repetition mastery.

Finite 9-Level Curriculum

Terraform Foundations

Progress from core HCL blocks, provider version constraints, and `.tfvars` override precedence through `for_each` comprehensions, `dynamic` blocks, `try()`/`coalesce()`, and zero-downtime `moved {}` state refactoring.

Curated Cloud Blueprints

Google Cloud Fabric FAST

Train by Cloud Role Category (`Security & Identity`, `Networking`, `Compute & Serverless`, `Databases & Storage`) or drill into individual upstream modules (`kms`, `net-vpc`, `cloud-run-v2`, `cloudsql-instance`).

Enterprise Installations Only

Custom Enterprise Modules

🚧 Coming Soon • Enterprise Only

Connect your internal Terraform repositories (`main.tf`, `variables.tf`, `prod.tfvars`, `tfplan.json`) to auto-generate custom learning paths based purely on your own code. Coming Soon — Available only on Enterprise installations.

01 • AST CODE PINPOINT
Click Real HCL Tokens

Identify exact lines and expressions across `main.tf`, `variables.tf`, and `prod.tfvars` before answering.

02 • IMMEDIATE REMEDIATION
Socratic Hints & Re-Queue

Missed concepts are remediated on the spot with Socratic AI guidance before completing the node.

03 • FSRS v4 SPACED REPETITION
Long-Term Memory Retention

Calculates Stability (S) and Difficulty (D) per engineer to schedule reviews right before knowledge decay.

04 • DUAL LEADERBOARDS
Org & Role Rankings

Earn XP, maintain daily streaks, and benchmark mastery across your entire organization or engineering role.

Unified Visual Learning Platform

Built Around Three Visual Learning Paths

CloudGraft turns static Terraform codebases into interactive, bite-sized stepping stones. Choose a structured path, inspect real HCL in the browser IDE, and level up your cloud architecture skills.

{ }

Terraform Foundations

A 9-level zero-to-hero journey covering providers, `.tfvars` precedence, `for_each` loops, built-in functions, and zero-downtime `moved {}` state refactoring.

9 Levels • 45 Stars Core HCL Mastery
VPC KMS RUN SQL

Google Cloud Fabric FAST

Train on Google Cloud’s production `FAST` architectures by role category (`Networking`, `Security`, `Serverless`) or pick any single module (`net-vpc`, `kms`, `cloud-run-v2`).

Role & Module Tracks Production GCP
AST::REPO

Organization Repositories

Import your own internal `.tf` and `.tfvars` repositories. CloudGraft parses the HCL Abstract Syntax Tree and builds custom levels directly from your codebase.

Auto-Sized 2–9 Levels Live Repo AST
Interactive Path Mechanics

Stepping-Stone Stars From the Live Application

Each section of a path features 5 tactile 3D stepping-stone medallions that track your live progress:

✓
Completed Node

Turns emerald with a checkmark (`✓`) once mastered. Replay anytime to sharpen retention.

★
Current Active Star

Bounces gently (`★`) on the path track to show your exact next 10-question IDE lab.

★
Upcoming Challenge Star

Waiting ahead on the winding track—unlocks automatically as you complete the active star.

Core Capabilities

Built for Engineering Fluency

🧠

Personal Learning

Interactive 10-question IDE labs where you pinpoint live `.tf` lines and tokens, backed by FSRS v4 spaced repetition.

⚡

XP & Mastery

Earn XP for every challenge (`+200 XP` per completed star), build daily streaks, and use optional Socratic AI hints when stuck.

🏆

Leaderboards

Benchmark your progress on both the Organization-Wide Top 10 and Role-Specific cohorts (`Cloud Architect`, `Platform Engineer`).

🛠️

Path & Skill Customization

Tailor tracks by role category, individual Fabric FAST modules, and custom Git repos governed by fine-grained Database RBAC.

Frequently Asked Questions

CloudGraft F.A.Q

Click any question below to expand its architectural and pedagogical answer.

{{ item.answer }}
Learner & Platform Guide

How CloudGraft Interactive Code Challenges Work

Every challenge pairs a live multi-file Terraform IDE (main.tf, module.tf, variables.tf, prod.tfvars, and tfplan.json) directly with the exact code under inspection.

📖 Describe What Is Happening

Analyze highlighted blocks inside main.tf and module.tf to explain how modules, loops, and lifecycle rules behave.

🏗️ Identify Provisioned Resources

Multi-select the exact cloud resources (google_compute_network, google_kms_crypto_key) created across root and child module files.

🎯 Interactive Code Walk

Step through the IDE and click the exact line or HCL token (prevent_destroy, cidrsubnet) that implements an architectural requirement.

Direct Admin Team Dispatch

Contact the CloudGraft Team

Have questions about enterprise onboarding, custom repository ingestion, or external beta testing? Send a message directly to admin@cloudgraft.dev.

✓ Email Dispatched to CloudGraft Admin Team!
To: {{ contactEmailReceipt.to }} • Receipt: {{ contactEmailReceipt.receipt_id }}
Subject: {{ contactEmailReceipt.subject }} ({{ contactEmailReceipt.status }})
Overall Learner Level {{ overallLearnerLevel }} {{ user.displayName }} • {{ user.roleTitle }}

Welcome to Your CloudGraft Learning Zone

Select a Learning Path or specific Google Cloud Fabric FAST Module Skill below to open its interactive Path Tree.

Total XP
⚡ {{ effectiveLearnerXP }}
Overall Completeness
{{ overallPlatformCompletenessPct }}%
{ }
Terraform Foundations {{ foundationsCompletenessPct }}%

Master core HCL blocks, providers, .tfvars precedence, locals, for_each loops, custom modules, and moved refactoring.

Active Foundations Stage
{{ activeFoundationsStageTitle }}
{{ foundationsCompletenessPct }}%
VPC KMS RUN SQL
Google Cloud Fabric FAST {{ fabricFastCompletenessPct }}%

Master production Google Cloud Foundation Fabric (FAST) modules grouped by Cloud Domain Category or studied module-by-module.

Role Categories
Individual FAST Modules
🚧 Coming Soon • Enterprise Only
AST::REPO
Enterprise Custom Modules Coming Soon 35%

AST-digested learning tracks synthesized purely from your own organization’s internal Terraform code repositories. Available only on Enterprise installations.

Enterprise Edition Feature
🏢 Private Git & Custom HCL Module Ingestion
ENTERPRISE

{{ activePathSummary.title }}

{{ level.shortChip || level.unitLabel }} ● ACTIVE SECTION ✓ LEVEL MASTERED

{{ level.title }}

▸

Tested Module Source & Supporting Google Cloud Docs
Section Mastery {{ level.completionPct }}%
💡 Click the bouncing yellow star (★) or completed green ticks (✓) on the continuous path to launch the IDE lab.
🔒
Code Editor Locked

This question tests core Terraform concepts and does not require code inspection.

{{ activeRepo?.breadcrumb_prefix || activeRepo?.name || 'cloud-foundation-fabric / modules / kms' }} / {{ activeCodeFile }}
{{ challengeProgressPct }}%
{{ activeChallengeNode?.title || 'Terraform Challenge' }} {{ currentQuestion?.type_badge || currentQuestion?.modality }}
📄 Active File: {{ currentQuestion.target_file || activeCodeFile }} ☑️ Select All Provisioned Resources ({{ selectedMultiIndices.length }} selected) 🎯 Code Walk: Click Line {{ currentQuestion.target_line }} in IDE

Active IDE Selection: {{ selectedToken ? (selectedToken + ' (' + activeCodeFile + ':' + selectedLineNumber + ')') : selectedLineNumber ? (activeCodeFile + ' • Line ' + selectedLineNumber) : 'None selected — click a line or token in ' + activeCodeFile }}
💡 Hint

{{ lastSubmissionFeedback.correct ? '✓ Correct!' : '✕ Review Explanation Below' }}

User Profile, Communications & Workspace Preferences

Manage your Okta-authenticated profile, SendGrid email communication preferences, visual theme, and IDE layout.

Profile & Engineering Bio

🔐 Okta OIDC + MFA Verified

Theme & Code IDE Preferences

📬 Communications — Send Me Emails About

Delivered via Verified SendGrid Domain (noreply@dev.cloudgraft.dev). All categories are enabled by default; untick any category you wish to mute.

✉️ SendGrid v3 Active
{{ commPrefsStatusMsg }}

Leaderboards & Standing

Public Edition Scoreboards • Country: {{ currentUserCountryLabel }}

Enterprise Organization: {{ currentOrganizationName }} • Job Role Cohort: {{ user.roleTitle }}

{{ userInitials }}
{{ user.displayName }}
@{{ currentUsername }} • {{ currentUserCountryAlpha3 }}
Total XP {{ effectiveLearnerXP.toLocaleString() }} XP
🌐 GLOBAL SCOREBOARD
Worldwide Public Standings
#{{ currentGlobalRankInfo.rank }} of {{ currentGlobalRankInfo.total }} players
Global XP Ranking across all countries
🏳️ COUNTRY SCOREBOARD
{{ selectedLeaderboardCountryLabel }}
#{{ currentCountryRankInfo.rank }} of {{ currentCountryRankInfo.total }} in {{ selectedLeaderboardCountryCode }}
National Cohort Standing
{{ userInitials }}
{{ user.displayName }}
{{ user.roleTitle }}
Total XP {{ effectiveLearnerXP.toLocaleString() }} XP
🎖️ ENTERPRISE JOB ROLE RANK
{{ user.roleTitle }}
#{{ currentRoleRankInfo.rank }} of {{ currentRoleRankInfo.total }} peers
Enterprise Edition breaks down exclusively by Job Role.

{{ unifiedLeaderboardTitle }}

{{ unifiedLeaderboardSubtitle }}

Filter by Country:
Filter by Enterprise Job Role:
No players found in this cohort yet. Complete a challenge or sign in via Okta to claim #1!
Active Session: {{ activeUserType }} • {{ user.displayName }}

Google Cloud Foundation Fabric FAST Modules Catalog ({{ (state.fabric_modules || []).length }} Modules)

Upstream: {{ fabricSyncStatus.version }}

Pulls module schemas from GoogleCloudPlatform/cloud-foundation-fabric/modules and updates course criteria while preserving 100% of learner XP, streaks, and progress.

ZERO XP / PROGRESS LOSS {{ fabricSyncStatus.lastSyncMessage }}
Synced at {{ fabricSyncStatus.syncedAt }}
Filter by Category:
{{ mod.category }} {{ mod.levels_count }} Lvls × {{ mod.challenges_per_level }}
⚡ {{ mod.name }}
{{ mod.source_path }}

{{ mod.description }}

{{ mod.enabled ? '● Enabled' : '○ Disabled' }}

{{ editingRepoId ? '✏️ Edit Custom Organization Repository' : '➕ Add Custom Organization Repo (Auto-Sizes Path Levels)' }}

Upload .zip Archive or .tf / .tfvars Files
CloudGraft digests the AST and determines how many Levels (× 5 Challenges) are required.

Custom Organization Repositories ({{ state.repositories?.length || 0 }})

{{ repo.name }} {{ repo.calculated_levels || 2 }} Levels × {{ repo.challenges_per_level || 5 }} Challenges
{{ repo.complexity_tier }}

{{ repo.context_note }}

AST Complexity Digest & 5-Archetype Question Preview

{{ sandboxASTSummary.complexity_tier }}

Auto-Sized: {{ sandboxASTSummary.calculated_levels }} Levels × {{ sandboxASTSummary.challenges_per_level }} Challenges
{{ pq.question_type_badge || pq.modality }} Target: {{ pq.target_file || 'main.tf' }} (Line {{ pq.target_line || 1 }})

{{ editingEnvId ? '✏️ Edit Cloud Environment' : '➕ Add Cloud Provider & Environment' }}

{{ env.name }}
{{ env.provider || 'Google Cloud (GCP)' }} • {{ env.org_id }} • {{ env.domain }}
{{ env.folder_path }}

{{ env.context_note }}

{{ editingTaxId ? '✏️ Edit Role / Discipline' : '➕ Add Role or Discipline Tag' }}

{{ t.name }} {{ t.kind }}

{{ t.description }}

Enterprise Organization & RBAC Administration Okta OIDC + PKCE + Multi-Factor Authentication (MFA) & SendGrid v3

Organization Setup (`ORG_ADMIN` / `ADMIN`), Okta Domain Approvals, Teams & Fine-Grained Database RBAC

The initial customer administrator (ORG_ADMIN) configures the Organization Name, GCP Organization ID, Primary Email Domain, and Engineering Teams. All authentication (Passkeys, Socials, and Authenticator MFA) is 100% offloaded to Okta with zero passwords stored in CloudGraft.

✓ {{ rbacStatusBanner }}

🌱 Multi-Tenant PoC: Register New Customer Organization (`POST /api/v1/orgs/register`)

Onboard a brand-new tenant organization and automatically provision the initial founding `ORG_ADMIN` user via Okta SSO.

TENANT ONBOARDING

✉️ Admin Direct User Invitation (`POST /api/v1/orgs/users/invite`)

Invite a user in {{ currentOrganizationName }} via SendGrid to sign in with Okta SSO + MFA (`INVITED_OKTA_SSO`).

users:manage_rbac

🏢 1. Initial Customer Organization Configuration

Configure the Organization Name (displayed across Leaderboards) and GCP Organization ID.

org:manage_config

👥 2. Organization Engineering Teams

Create or remove teams within {{ currentOrganizationName }} and assign engineers below.

{{ availableOrgTeams.length }} Teams
{{ teamName }}

🔐 3. Organization User Directory & Okta SSO Status

Approve pending domain users to activate their Okta OIDC + MFA access and dispatch a SendGrid welcome notification.

100% Zero Local Passwords
{{ u.name }} {{ u.account_status || 'ACTIVE' }}
{{ u.email }} • {{ u.team || 'Platform Engineering' }} • {{ u.role_title }}
✓ Okta OIDC + MFA Verified

🛡️ 5. User Team/Role Assignment & Database-Controlled RBAC Matrix

Assign users to Teams, Roles, and Personas (`ORG_ADMIN`, `ADMIN`, `USER`) or toggle individual database permissions.

Users: {{ (state.rbac_users || []).length }}
{{ u.user_type }} {{ u.name }} ACTIVE SESSION
{{ u.email }} • Team: {{ u.team || 'Platform Engineering' }} • {{ u.role_title }}
Path 1 • Zero-to-Hero Core Terraform Reference

📖 Terraform Core Constructs & Built-In Functions (Levels 1–9)

Level {{ cat.level }} of 9 {{ cat.badge }}

{{ cat.title }}

{{ cat.summary }}

{{ fn }}
{{ cat.snippet }}