In this article, we will dive into the wonderful world of Regular expressions (Regex or Regexp), first explaining what they are and why you might need to use them. We will show some examples of how to use these expressions with the regex and regexall functions in your Terraform code, and we will also take a look at the replace function.
What we will cover:
- What are regular expressions?
- What regex does Terraform use?
- What is the regex function in Terraform?
- Example: Using the Terraform regex function
- What is the regexall function in Terraform?
- Example: Using the Terraform regexall function
- What is the replace string function in Terraform?
- Example: Using the Terraform replace function
TL;DR
Terraform handles regular expressions with three functions, all using Google’s RE2 engine (the same syntax as Go). RE2 does not support backreferences or lookahead/lookbehind assertions.
regex(pattern, string)returns the first match. Its return type depends on your capture groups: a string with no groups, a list with unnamed groups, or a map with named groups. If nothing matches, it raises an error, so wrap it incan()ortry()when a match isn’t guaranteed.regexall(pattern, string)returns all matches as a list, and returns an empty list when nothing matches.replace(string, old, new)substitutes a literal substring by default, but treatsoldas a regular expression when you wrap it in forward slashes (for example,/pattern/), with$1or$namebackreferences in the replacement.
What are regular expressions?
Regex expressions are special text patterns used to match specific patterns within text. They are a powerful tool for searching, extracting, and manipulating text data in various applications, such as text editors, search tools, and programming languages.
Regular expressions are supported in many programming languages, often through built-in libraries or modules. The concept of regular expressions dates back to the 1950s when mathematician Stephen Cole Kleene formalized the idea of regular languages.
The common use cases for regex include:
- Text search and manipulation – Finding specific words or phrases within a large document
- Data extraction – Extracting specific data points from text, such as phone numbers or email addresses, from a log file
- Input validation – Ensuring user input conforms to a specific format, like a valid email address or password
- Code search and refactoring – Finding specific code patterns within large codebases
What regex does Terraform use?
Terraform uses Google’s RE2 regular expression engine, which is known for its high efficiency and comprehensive feature set. However, although Terraform offers a wide array of regex functionalities, it does not encompass the full spectrum of capabilities available in the RE2 engine.
One notable limitation is that RE2 does not support backreferences or lookaround assertions (lookahead and lookbehind). This is a deliberate design choice: RE2 guarantees linear-time matching, which those features would break. Terraform’s regex functions support:
- Character matching (literal characters and special characters)
- Repetition (specifying how many times a pattern can occur)
- Alternatives (matching one of several options)
- Grouping and capturing subpatterns, including named capture groups
You can find documentation on RE2 on GitHub. As Regex expressions can quickly become complex, you can use an online test tool that includes the RE2 engine to validate your Regex expression.
Regex patterns
We’ll break down these regex patterns into the key concepts you need to understand to use regular expressions effectively. You can use the reference below to help you form your own regex expressions.
Common patterns quick reference
[a-z]: Matches any lowercase letter\d+: Matches one or more digits^abc$: Matches the exact string “abc” (beginning and end of line).*: Matches any sequence of characters (zero or more)
Literals
Literal characters match themselves. For example, the regex abc matches the string “abc”.
Metacharacters
Metacharacters are the special characters with specific meanings in regex. Common metacharacters include:
.: Matches any single character except newline^: Matches the start of a string$: Matches the end of a string*: Matches 0 or more occurrences of the preceding element+: Matches 1 or more occurrences of the preceding element?: Matches 0 or 1 occurrence of the preceding element[]: Matches any single character within the brackets (character class)|: Acts as a logical OR operator(): Groups patterns and captures the matched text
Character classes
[abc]: Matches any one of the characters a, b, or c[a-z]: Matches any lowercase letter from a to z[0-9]: Matches any digit from 0 to 9[^abc]: Matches any character except a, b, or c
Quantifiers
*: Matches 0 or more occurrences+: Matches 1 or more occurrences?: Matches 0 or 1 occurrence{n}: Matches exactly n occurrences{n,}: Matches n or more occurrences{n,m}: Matches between n and m occurrences
Anchors
^: Matches the start of a string$: Matches the end of a string\b: Matches a word boundary\B: Matches a non-word boundary
Escape sequences
\d: Matches any digit (equivalent to [0-9])\D: Matches any non-digit\w: Matches any word character (alphanumeric plus underscore)\W: Matches any non-word character\s: Matches any whitespace character\S: Matches any non-whitespace character
What is the regex function in Terraform?
The regex function in Terraform applies a regular expression pattern to a string and returns the matched substrings. What it returns depends on your capture groups: a single string if the pattern has no capture groups, a list if it has unnamed capture groups, or a map if it has named capture groups. If the pattern finds no match, regex raises an error rather than returning an empty value, so wrap it in can() or try() when a match isn’t guaranteed:
can(regex("[0-9]+", var.input)) # true / false
try(regex("[0-9]+", var.input), "no match") # fallback valueThe syntax is as follows:
regex(pattern, string)Where
pattern– The regular expression pattern that defines what you want to match within the string.string– The text string you want to search against.
Examples: Using the Terraform regex function
Let’s see some examples using the Terraform regex function.
Example 1: Matching a domain name
In this example, we define a variable website_url that might hold a URL like “https://www.example.com”.
variable "website_url" {
type = string
default = "https://www.example.com"
}
locals {
# Match the host, ignoring the scheme and an optional "www."
domain = regex("https?://(?:www\\.)?([^/]+)", var.website_url)
}
output "extracted_domain" {
value = element(local.domain, 0) # first captured group → "example.com"
}- The
regexfunction extracts “example.com” by matching the optional scheme (https?://) and an optionalwww., then capturing everything up to the next slash ([^/]+). - The
elementfunction is used to access the first element (index 0) of the returned list, which contains the captured domain name.
Example 2: Validating input variables
You can also use the regex function to validate input variables. For instance, to ensure that a variable follows a specific format:
variable "email" {
type = string
default = "example@example.com"
}
locals {
email_valid = can(regex("^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\\.[a-zA-Z]{2,}$", var.email))
}
output "is_valid_email" {
value = local.email_valid
}In this example, local.email_valid will be true if var.email is a valid email address according to the regex pattern.
Suppose you want to determine whether a string starts with the letter ‘p’ followed by one or more digits:
name = can(regex("p[1-9]+", my_input)) ? "production" : "testing"- If
my_inputis “pab1”, it evaluates to “testing”. - If
my_inputis “p123”, it evaluates to “production”.
What is the regexall function in Terraform?
The regexall function in Terraform is a variant of the regex function specifically designed to find all potential matches of a regular expression pattern within a string. The function returns a list, even if there’s only one match or no matches at all, in which case it returns an empty list.
The syntax for this function is as follows:
regexall(pattern,string)
Where:
pattern: The regular expression pattern defining what you want to match.string: The text string you want to search against.
What is the difference between regex and regexall in Terraform?
Both regex and regexall functions in Terraform work with capture groups in regular expressions. However, regexall returns a list of captured elements for each match, whereas regex might return a single list or map depending on the capture group structure.
If the pattern matches multiple times within the string, regexall captures all occurrences and returns them as a list. regexall is specifically intended to find all matching substrings, whereas regex typically returns only the first match (or the entire matched string if no capture groups are used).
Use regexall when you need to find all occurrences of a pattern within a string, and use the regex function when you’re only interested in the first match or want to perform specific actions based on the existence of a single match (e.g., validating a format).
Examples: Using the Terraform regexall function
Now, let’s go explore some examples using the regexall function.
Example 1: Finding all email addresses
In this example, we are searching for all email addresses within a text block stored in text_data.
text_data = var.content
emails = regexall("[\\w!#$%&'*+/=?^`{|}~-]+(?:\\.[\\w!#$%&'*+/=?^`{|}~-]+)*@[\\w-]+(?:\\.[\\w-]+)*", text_data)
output "extracted_emails" {
value = emails
}The regexall function here returns a list containing all email addresses found in the text.
Example 2: Extracting tags with named capture groups
In the next example, we parse a log line to extract all key-value pairs representing tags.
variable "log_message" {
type = string
default = "tag:env=prod tag:team=platform"
}
locals {
tags = regexall("tag:(?P<key>[^ ]+)=(?P<value>[^ ]*)", var.log_message)
}
output "extracted_tags" {
value = local.tags
}The pattern uses named capture groups, (?P<key>[^ ]+) for the tag key and (?P<value>[^ ]*) for the value, so regexall returns a list of maps, where each map represents a single tag with its key and value.
What is the replace string function in Terraform?
The replace function substitutes part of a string with another string. By default it matches a literal substring, but it also supports regular expressions: if you wrap the old argument in forward slashes, Terraform treats it as an RE2 pattern (the same syntax as regex), and the replacement string can reference capture groups with $1, $2, or $name.
Syntax:
replace(string, old, new)Where:
string: The text string where you want to perform the replacement.old: The substring you want to replace.new: The replacement string that will take the place ofold.
Examples: Using the Terraform replace function
Example 1
In this first example, we conditionally define a new server name based on the environment.
We want the replace function to swap the dev prefix for prod when the environment is production, and leave the name unchanged otherwise.
environment = "production"
old_name = "dev-server"
# Swap the "dev" prefix for "prod" when running in production
replaced_name = environment == "production" ? replace(old_name, "dev", "prod") : old_name
output "server_name" {
value = replaced_name
}Example 2
Here, replace(var.input_string, "Hello", "Hi") replaces the substring “Hello” with “Hi” in var.input_string, so local.replaced_string contains “Hi, World!”.
variable "input_string" {
type = string
default = "Hello, World!"
}
locals {
replaced_string = replace(var.input_string, "Hello", "Hi")
}
output "result" {
value = local.replaced_string
}Why use Spacelift to manage Terraform?
Terraform provisions infrastructure well on its own, but a secure GitOps workflow needs a platform that can run your Terraform for you.
Spacelift is the infrastructure orchestration platform built for the AI-accelerated software era. It manages the full lifecycle for both traditional infrastructure as code (IaC) and AI-provisioned infrastructure, giving you access to a powerful CI/CD workflow and unlocking features such as:
- Policies (based on Open Policy Agent) – You can control how many approvals you need for runs, what kind of resources you can create, and what kind of parameters these resources can have, and you can also control the behavior when a pull request is open or merged.
- Multi-IaC workflows – Combine Terraform with Kubernetes, Ansible, and other IaC tools such as OpenTofu, Pulumi, and CloudFormation, create dependencies among them, and share outputs.
- Build self-service infrastructure – You can use Templates and Blueprints to build self-service infrastructure; simply complete a form to provision infrastructure based on Terraform and other supported tools.
- AI-powered provisioning and diagnostics – Spacelift Intelligence adds an AI-powered layer for natural language provisioning, diagnostics, and operational insight across your infrastructure workflows.
- Integrations with any third-party tools – You can integrate with your favorite third-party tools and even build policies for them. For example, see how to integrate security tools in your workflows using Custom Inputs.
Spacelift enables you to create private workers inside your infrastructure, which helps you execute Spacelift-related workflows on your end. Read the documentation for more information on configuring private workers.
You can check it for free by creating a trial account or booking a demo with one of our engineers.
Key points
Regular expressions can be used within your terraform code anywhere pattern matching is required.
- Use
regexallwhen you need to find all occurrences of a pattern within a string. - Use
regexwhen you’re only interested in the first match or want to perform specific actions based on the existence of a single match (e.g., validating a format). - Use
replacefor simple string replacements without the need for regular expressions.
Note: Terraform moved to the BUSL license starting with version 1.6, so version 1.5.x and earlier remain open source under MPL 2.0. OpenTofu is an open-source fork of Terraform, created from version 1.5.6, that expands on Terraform’s existing concepts. It is a viable alternative to HashiCorp’s Terraform.
Orchestrate Terraform deployments with Spacelift
Orchestrate your Terraform workflows and build governed pipelines using policy as code, programmatic configuration, context sharing, drift detection, resource visualization, and many more.
Frequently asked questions
Does Terraform regex support backreferences and lookahead?
No. Terraform uses Google’s RE2 engine, which does not support backreferences, and it also excludes lookaround assertions (lookahead and lookbehind). This keeps matching linear-time, so patterns relying on those features need to be restructured or handled outside regex.
What happens when the Terraform regex function finds no match?
It raises an error rather than returning an empty result. This is the key difference from regexall, which returns an empty list when nothing matches while regex fails outright. Wrap the call in can() for a true/false check or try() to supply a fallback value when a match isn’t guaranteed.
Can the Terraform replace function use regular expressions?
Yes. By default replace matches a literal substring, but wrapping the pattern in forward slashes makes Terraform treat it as an RE2 regular expression, using the same syntax as regex. The replacement string can then reference capture groups with $1, $2, or $name.

