⚠️

Leave Active Challenge Lab?

Challenge in progress ({{ challengeProgressPct }}% completed)

If you exit this challenge now, your current Challenge Lab session will end and you will return to your Learning Path Tree.

🏆
Challenge Complete • 100%

{{ activeChallengeNode?.title || 'Challenge Mastered!' }}

You completed all 10 progressive Terraform questions in this challenge.

Completion
100%
Accuracy
{{ challengeCorrectCount * 10 }}%
Optional Study Drawer

🧠 Spaced Repetition & Path Details

Active Path: {{ activePathSummary.title }}
Current Node: {{ currentActiveNodeLabel }}
Path Completeness: {{ activePathCompletenessPct }}%
FSRS v4 Due Review Queue {{ (state.fsrs_due_queue || []).length }} Due
{{ card.concept }} {{ card.due_status }}
Stability: {{ card.stability_days }}d • Difficulty: {{ card.difficulty }}
External Tester Feedback

💬 Share Product & UX Feedback

✓ {{ feedbackStatusMessage }}
Internal CloudGraft Dev / QA & RBAC Simulator

🔐 Switch Active User Archetype (`DEVELOPER` / `ADMIN` / `USER`)

Select an account below to test CloudGraft's Database-Controlled RBAC Enforcement across both UI views and backend API endpoints (X-CloudGraft-User-ID):

Want to grant repos:import to a USER without taxonomy:write?
RBAC Gated Administration {{ activeUserType }}
{{ user.displayName }}
{{ activeUserType }}
{{ user.roleTitle }} • {{ state.learner_profile?.total_xp || 1420 }} XP
Release: {{ state.release_version || 'v1.0.0-rc1' }} Cloud SQL 30d PITR
🔒 APPLICATION PORTAL LOCKED (AUTH REQUIRED)

Welcome to app.dev.cloudgraft.dev

The CloudGraft Split-Pane Terraform IDE, 9-Level Challenge Path, and Live Organization Leaderboards are protected behind cryptographic domain & email verification.

1.
Register Organization by Domain
Provide your corporate domain (e.g. acme.io) and matching @acme.io email. Confirm the email link to become ORG_ADMIN.
2.
Upfront Pre-Approved List or Admin Invite
Admins can upload a list of @domain emails upfront. Pre-approved users skip manual approval queues once they confirm their email link and set a password.
3.
Domain Self-Registration & Admin Approval
Users registering with an @domain email confirm their inbox first, then trigger an approval request to their Organization Admins.
🗄️ Cloud SQL (sql-cg-dev-pg) 30-Day PITR Enabled
⚡ Instant Evaluator Sign-In Verified Accounts

Click any pre-verified CloudGraft account below to sign in immediately and unlock the portal:

⚠️ {{ authGate.errorMessage }}
✓ {{ authGate.successMessage }}
📬 Transactional Verification Email Dispatched:
Token: {{ authGate.lastVerifyToken }}

Sign In to Your Organization

Enter your verified corporate email address and password to unlock CloudGraft.

Register New Organization by Domain

Your email domain must match the organization domain (alice@acme.io for acme.io). Consumer domains (gmail.com) are blocked.

Join Your Organization on CloudGraft

Active Organization Domain: @{{ state.org_config?.primary_domain || 'org-enterprise.io' }}. If your email was pre-approved upfront by your Admin, you will join immediately upon confirming your email!

Confirm Email Ownership & Set Password

Paste your single-use email verification token (verify_token) and choose your password to activate your account.

⚡ Duolingo-Style Interactive Mastery for Enterprise Terraform & Google Cloud

Master Terraform Foundations, Fabric FAST & Your Own Cloud Repositories.

CloudGraft transforms static Infrastructure-as-Code documentation and complex Git repositories into interactive stepping-stone learning paths, AST code-pinpoint labs, role-based leaderboards, and FSRS v4 spaced-repetition mastery.

Finite 9-Level Curriculum

Terraform Foundations

Progress from core HCL blocks, provider version constraints, and `.tfvars` override precedence through `for_each` comprehensions, `dynamic` blocks, `try()`/`coalesce()`, and zero-downtime `moved {}` state refactoring.

Curated Cloud Blueprints

Google Cloud Fabric FAST

Train by Cloud Role Category (`Security & Identity`, `Networking`, `Compute & Serverless`, `Databases & Storage`) or drill into individual upstream modules (`kms`, `net-vpc`, `cloud-run-v2`, `cloudsql-instance`).

Live Codebase Ingestion

Custom Organization Repos

Connect your internal Terraform repositories (`main.tf`, `variables.tf`, `prod.tfvars`, `tfplan.json`). CloudGraft parses the HCL Abstract Syntax Tree (AST) and auto-generates 2 to 9 custom levels tailored to your infrastructure.

01 • AST CODE PINPOINT
Click Real HCL Tokens

Identify exact lines and expressions across `main.tf`, `variables.tf`, and `prod.tfvars` before answering.

02 • IMMEDIATE REMEDIATION
Socratic Hints & Re-Queue

Missed concepts are remediated on the spot with Socratic AI guidance before completing the node.

03 • FSRS v4 SPACED REPETITION
Long-Term Memory Retention

Calculates Stability (S) and Difficulty (D) per engineer to schedule reviews right before knowledge decay.

04 • DUAL LEADERBOARDS
Org & Role Rankings

Earn XP, maintain daily streaks, and benchmark mastery across your entire organization or engineering role.

Unified Visual Learning Platform

Built Around Three Visual Learning Paths

CloudGraft turns static Terraform codebases into interactive, bite-sized stepping stones. Choose a structured path, inspect real HCL in the browser IDE, and level up your cloud architecture skills.

{ }

Terraform Foundations

A 9-level zero-to-hero journey covering providers, `.tfvars` precedence, `for_each` loops, built-in functions, and zero-downtime `moved {}` state refactoring.

9 Levels • 45 Stars Core HCL Mastery
VPC KMS RUN SQL

Google Cloud Fabric FAST

Train on Google Cloud’s production `FAST` architectures by role category (`Networking`, `Security`, `Serverless`) or pick any single module (`net-vpc`, `kms`, `cloud-run-v2`).

Role & Module Tracks Production GCP
AST::REPO

Organization Repositories

Import your own internal `.tf` and `.tfvars` repositories. CloudGraft parses the HCL Abstract Syntax Tree and builds custom levels directly from your codebase.

Auto-Sized 2–9 Levels Live Repo AST
Interactive Path Mechanics

Stepping-Stone Stars From the Live Application

Each section of a path features 5 tactile 3D stepping-stone medallions that track your live progress:

✓
Completed Node

Turns emerald with a checkmark (`✓`) once mastered. Replay anytime to sharpen retention.

★
Current Active Star

Bounces gently (`★`) on the path track to show your exact next 10-question IDE lab.

★
Upcoming Challenge Star

Waiting ahead on the winding track—unlocks automatically as you complete the active star.

Core Capabilities

Built for Engineering Fluency

🧠

Personal Learning

Interactive 10-question IDE labs where you pinpoint live `.tf` lines and tokens, backed by FSRS v4 spaced repetition.

⚡

XP & Mastery

Earn XP for every challenge (`+200 XP` per completed star), build daily streaks, and use optional Socratic AI hints when stuck.

🏆

Leaderboards

Benchmark your progress on both the Organization-Wide Top 10 and Role-Specific cohorts (`Cloud Architect`, `Platform Engineer`).

🛠️

Path & Skill Customization

Tailor tracks by role category, individual Fabric FAST modules, and custom Git repos governed by fine-grained Database RBAC.

Frequently Asked Questions

CloudGraft F.A.Q

Click any question below to expand its architectural and pedagogical answer.

{{ item.answer }}
Learner & Platform Guide

How CloudGraft Interactive Code Challenges Work

Every challenge pairs a live multi-file Terraform IDE (main.tf, module.tf, variables.tf, prod.tfvars, and tfplan.json) directly with the exact code under inspection.

📖 Describe What Is Happening

Analyze highlighted blocks inside main.tf and module.tf to explain how modules, loops, and lifecycle rules behave.

🏗️ Identify Provisioned Resources

Multi-select the exact cloud resources (google_compute_network, google_kms_crypto_key) created across root and child module files.

🎯 Interactive Code Walk

Step through the IDE and click the exact line or HCL token (prevent_destroy, cidrsubnet) that implements an architectural requirement.

Direct Admin Team Dispatch

Contact the CloudGraft Team

Have questions about enterprise onboarding, custom repository ingestion, or external beta testing? Send a message directly to admin@cloudgraft.dev.

✓ Email Dispatched to CloudGraft Admin Team!
To: {{ contactEmailReceipt.to }} • Receipt: {{ contactEmailReceipt.receipt_id }}
Subject: {{ contactEmailReceipt.subject }} ({{ contactEmailReceipt.status }})
Overall Learner Level {{ overallLearnerLevel }} {{ user.displayName }} • {{ user.roleTitle }}

Welcome to Your CloudGraft Learning Zone

Select a Learning Path or specific Google Cloud Fabric FAST Module Skill below to open its interactive Path Tree.

Total XP
⚡ {{ state.learner_profile?.total_xp || 1420 }}
Overall Completeness
{{ overallPlatformCompletenessPct }}%
{ }
Terraform Foundations {{ foundationsCompletenessPct }}%

Master core HCL blocks, providers, .tfvars precedence, locals, for_each loops, custom modules, and moved refactoring.

Active Foundations Stage
Level 2: Input Variables & Precedence
{{ foundationsCompletenessPct }}%
VPC KMS RUN SQL
Google Cloud Fabric FAST 40%

Master production Google Cloud Foundation Fabric (FAST) modules grouped by Cloud Domain Category or studied module-by-module.

Role Categories
Individual FAST Modules
AST::REPO
Organization Repositories 35%

AST-digested learning tracks synthesized directly from your organization’s internal Terraform repositories.

{{ activePathSummary.title }}

{{ level.shortChip || level.unitLabel }} ● ACTIVE SECTION ✓ LEVEL MASTERED

{{ level.title }}

▸

Tested Module Source & Supporting Google Cloud Docs
Section Mastery {{ level.completionPct }}%
💡 Click the bouncing yellow star (★) or completed green ticks (✓) on the continuous path to launch the IDE lab.
🔒
Code Editor Locked

This question tests core Terraform concepts and does not require code inspection.

{{ activeRepo?.breadcrumb_prefix || activeRepo?.name || 'cloud-foundation-fabric / modules / kms' }} / {{ activeCodeFile }}
{{ challengeProgressPct }}%
{{ activeChallengeNode?.title || 'Terraform Challenge' }} {{ currentQuestion?.type_badge || currentQuestion?.modality }}
📄 Active File: {{ currentQuestion.target_file || activeCodeFile }} ☑️ Select All Provisioned Resources ({{ selectedMultiIndices.length }} selected) 🎯 Code Walk: Click Line {{ currentQuestion.target_line }} in IDE

Active IDE Selection: {{ selectedToken ? (selectedToken + ' (' + activeCodeFile + ':' + selectedLineNumber + ')') : selectedLineNumber ? (activeCodeFile + ' • Line ' + selectedLineNumber) : 'None selected — click a line or token in ' + activeCodeFile }}
💡 Hint

{{ lastSubmissionFeedback.correct ? '✓ Correct!' : '✕ Review Explanation Below' }}

User Settings & Workspace Preferences

Customize your personal profile, bio, visual theme, and IDE layout preferences.

Profile & Engineering Bio

Theme & Code IDE Preferences

Leaderboards & Standing

Organization: {{ currentOrganizationName }} • Role Cohort: {{ user.roleTitle }}

{{ userInitials }}
{{ user.displayName }}
{{ user.roleTitle }}
Total XP {{ effectiveLearnerXP.toLocaleString() }} XP
🏆 ORGANIZATION RANK
{{ currentOrganizationName }}
#{{ currentOrgRankInfo.rank }} of {{ currentOrgRankInfo.total }} engineers
{{ currentOrgRankInfo.rank > 10 ? ('Outside Top 10 (' + currentOrgRankInfo.xpToTop10 + ' XP to reach #10)') : 'In Organization Top 10 Elite!' }}
🎖️ ROLE-BASED RANK
{{ user.roleTitle }}
#{{ currentRoleRankInfo.rank }} of {{ currentRoleRankInfo.total }} peers
{{ currentRoleRankInfo.rank > 10 ? ('Outside Role Top 10 (' + currentRoleRankInfo.xpToTop10 + ' XP to #10)') : ('Top ' + Math.max(5, Math.round((currentRoleRankInfo.rank / currentRoleRankInfo.total) * 100)) + '% in role') }}
🗺️ LEARNING PATH RANK
{{ selectedLeaderboardPath }}
#{{ currentPathRankInfo.rank }} of {{ currentPathRankInfo.total }} learners
{{ currentPathRankInfo.xp.toLocaleString() }} Path XP earned

{{ unifiedLeaderboardTitle }}

{{ unifiedLeaderboardSubtitle }}

Filter by Engineering Role:
Filter by Learning Path:
Active Session: {{ activeUserType }} • {{ user.displayName }}

Google Cloud Foundation Fabric FAST Modules Catalog ({{ (state.fabric_modules || []).length }} Modules)

Upstream: {{ fabricSyncStatus.version }}

Pulls module schemas from GoogleCloudPlatform/cloud-foundation-fabric/modules and updates course criteria while preserving 100% of learner XP, streaks, and progress.

ZERO XP / PROGRESS LOSS {{ fabricSyncStatus.lastSyncMessage }}
Synced at {{ fabricSyncStatus.syncedAt }}
Filter by Category:
{{ mod.category }} {{ mod.levels_count }} Lvls × {{ mod.challenges_per_level }}
⚡ {{ mod.name }}
{{ mod.source_path }}

{{ mod.description }}

{{ mod.enabled ? '● Enabled' : '○ Disabled' }}

{{ editingRepoId ? '✏️ Edit Custom Organization Repository' : '➕ Add Custom Organization Repo (Auto-Sizes Path Levels)' }}

Upload .zip Archive or .tf / .tfvars Files
CloudGraft digests the AST and determines how many Levels (× 5 Challenges) are required.

Custom Organization Repositories ({{ state.repositories?.length || 0 }})

{{ repo.name }} {{ repo.calculated_levels || 2 }} Levels × {{ repo.challenges_per_level || 5 }} Challenges
{{ repo.complexity_tier }}

{{ repo.context_note }}

AST Complexity Digest & 5-Archetype Question Preview

{{ sandboxASTSummary.complexity_tier }}

Auto-Sized: {{ sandboxASTSummary.calculated_levels }} Levels × {{ sandboxASTSummary.challenges_per_level }} Challenges
{{ pq.question_type_badge || pq.modality }} Target: {{ pq.target_file || 'main.tf' }} (Line {{ pq.target_line || 1 }})

{{ editingEnvId ? '✏️ Edit Cloud Environment' : '➕ Add Cloud Provider & Environment' }}

{{ env.name }}
{{ env.provider || 'Google Cloud (GCP)' }} • {{ env.org_id }} • {{ env.domain }}
{{ env.folder_path }}

{{ env.context_note }}

{{ editingTaxId ? '✏️ Edit Role / Discipline' : '➕ Add Role or Discipline Tag' }}

{{ t.name }} {{ t.kind }}

{{ t.description }}

Enterprise Organization & RBAC Administration Google Cloud Identity Platform Multi-Tenancy + KMS Envelope Encryption

Organization Setup (`ORG_ADMIN` / `ADMIN`), Domain Approvals, Teams & Fine-Grained Database RBAC

The initial customer administrator (ORG_ADMIN) configures the Organization Name, GCP Organization ID, Primary Email Domain, and Engineering Teams. Self-registered domain users enter the approval queue, receive an encrypted temporary password upon admin approval, and complete a mandatory password change on first login.

✓ {{ rbacStatusBanner }}

🌱 Multi-Tenant PoC: Register New Customer Organization (`POST /api/v1/orgs/register`)

Onboard a brand-new tenant organization and automatically provision the initial founding `ORG_ADMIN` user with full permissions.

TENANT ONBOARDING

✉️ Admin Direct User Provisioning (`POST /api/v1/orgs/users/invite`)

Directly create/invite a user in {{ currentOrganizationName }} with a temporary password (`PROVISIONED_MUST_CHANGE_PASSWORD`).

users:manage_rbac

🏢 1. Initial Customer Organization Configuration

Configure the Organization Name (displayed across Leaderboards) and GCP Organization ID.

org:manage_config

👥 2. Organization Engineering Teams

Create or remove teams within {{ currentOrganizationName }} and assign engineers below.

{{ availableOrgTeams.length }} Teams
{{ teamName }}

📝 3. Domain User Self-Registration (`POST /api/v1/auth/register`)

New engineers register under your domain and enter `PENDING_APPROVAL` until approved by an `ORG_ADMIN` or `ADMIN`.

🔐 4. Domain Registration Approval & First-Login Password Change Queue

Approve pending registrations to dispatch a temporary password (`PROVISIONED_MUST_CHANGE_PASSWORD`), then complete first-login password rotation (`ACTIVE`).

Zero-Password Logging Redaction
{{ u.name }} {{ u.account_status || 'ACTIVE' }}
{{ u.email }} • {{ u.team || 'Platform Engineering' }} • {{ u.role_title }}
✓ Account Active & Verified

🛡️ 5. User Team/Role Assignment & Database-Controlled RBAC Matrix

Assign users to Teams, Roles, and Personas (`ORG_ADMIN`, `ADMIN`, `USER`) or toggle individual database permissions.

Users: {{ (state.rbac_users || []).length }}
{{ u.user_type }} {{ u.name }} ACTIVE SESSION
{{ u.email }} • Team: {{ u.team || 'Platform Engineering' }} • {{ u.role_title }}
Path 1 • Zero-to-Hero Core Terraform Reference

📖 Terraform Core Constructs & Built-In Functions (Levels 1–9)

Level {{ cat.level }} of 9 {{ cat.badge }}

{{ cat.title }}

{{ cat.summary }}

{{ fn }}
{{ cat.snippet }}