Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To plan Terraform changes, run terraform plan from your Terraform working directory, inspect each proposed action and value, and apply only a plan that still matches your intent. Planning previews changes; it does not by itself modify remote infrastructure. For a review handoff or automation, save the plan with -out, inspect it with terraform show, and apply that saved plan.

Generate a plan before making changes

  1. Open a terminal in the directory containing the Terraform configuration. If the working environment has not been initialized, run terraform init first. Initialization prepares the directory for Terraform operations. See HashiCorp’s Create a Terraform plan tutorial.

  2. Run terraform plan. In normal mode, Terraform refreshes its view of remote objects, compares configuration with prior state, and proposes actions to make managed objects match the configuration. The command does not carry out those actions.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  3. Review the proposed actions and values, including resource addresses, replacements, deletions, and output changes. Do not rely on the summary totals alone.

Terraform’s plan command reference calls a plan without an output file speculative: it is useful for review, but remote infrastructure can change before a later apply. Re-check the final plan immediately before approving it.

Read the proposed actions

The symbols in Terraform’s plan output indicate what it proposes for each resource:

Symbol Meaning What to review
+ Create a resource Confirm the resource should exist and its planned settings are correct.
- Destroy a resource Verify that removal is intended and identify any dependent effects.
~ Update a resource in place Check which values change and whether the update has the intended effect.
-/+ Replace a resource by destroying and recreating it Treat this as high impact: check the reason for replacement, potential interruption, and whether the replacement is acceptable.

Inspect the full resource address and planned values for each important change. In particular, a replacement or deletion can have a substantially different effect from an in-place update, even if the overall count of planned actions looks small. The action symbols and examples are documented in the Terraform plan reference.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose a review and apply workflow

Interactive CLI review

For a local, interactive workflow, run terraform apply. Terraform creates a fresh plan and asks for approval by default. Review that final plan before approving; do not treat an earlier speculative plan as approval for a potentially different set of changes. See the terraform apply command reference.

Rank #3

Saved plan for a handoff or automation

When one stage or person reviews a plan and another applies it, save the reviewed plan and pass that same file to apply:

  1. Create the plan: terraform plan -out=tfplan.

  2. Inspect the saved plan: terraform show tfplan.

  3. Apply the reviewed plan: terraform apply tfplan.

Applying a saved plan uses its recorded planned operations and does not prompt for confirmation. Treat the file as sensitive: HashiCorp says it contains the full configuration, planned values, plan options, and input variables. It is an opaque Terraform format, not a general-purpose interchange file. In automation, -input=false prevents interactive prompts for missing input; configure required inputs through the automation environment. HashiCorp documents this workflow in its Running Terraform in automation guidance and apply reference.

Use the planning mode that matches the intended outcome

Mode or option Use it when Effect to understand
Normal mode: terraform plan You want to review changes that bring managed remote objects toward the configuration. Terraform refreshes its view of remote objects, compares them with configuration and prior state, and proposes infrastructure actions.
Refresh-only: terraform plan -refresh-only You intentionally changed remote infrastructure outside Terraform and want to review how recorded state and root module outputs should be updated. It proposes state reconciliation; it does not undo the external changes in the remote system.
Destroy: terraform plan -destroy You intend to remove all managed remote objects. It previews a plan to destroy those objects. Inspect every proposed deletion before applying.
Targeted replacement: terraform plan -replace=ADDRESS You intend to replace a specific resource instance. It instructs Terraform to plan replacement of the specified address. Review the resulting plan, including dependent changes.

Refresh-only plans and unexpected drift

Use refresh-only mode to reconcile Terraform’s recorded view with intentional changes made outside Terraform, not to reverse those changes. Review the proposed state and output changes before applying them. An unexpected disappearance can be a configuration problem rather than a deleted object: HashiCorp’s refresh-only mode tutorial describes how a provider pointed at the wrong region may fail to find a real resource and infer that it was deleted. If a plan reports unexpected removals, check credentials, provider configuration, and region before accepting the state change.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The older terraform refresh command is deprecated. It automatically applies a state refresh, so HashiCorp recommends reviewing changes with terraform plan -refresh-only and, if appropriate, applying with terraform apply -refresh-only. See the terraform refresh command reference.

Destroy plans

terraform plan -destroy previews the removal of all managed remote objects. Use it only when that removal is the intended outcome, and check the complete deletion list before applying. terraform destroy is a convenience command that runs apply in destroy mode; it is not a substitute for reviewing what will be removed. See the terraform destroy command reference.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Options that change what a plan tells you

Skip refresh only when you understand the trade-off

-refresh=false skips Terraform’s normal state refresh. It may make planning faster, but can ignore external changes and produce an incomplete or incorrect plan. It cannot be combined with refresh-only mode. For most reviews where current remote state matters, use the default refresh behavior.

Save a plan when you need to apply that reviewed proposal

-out=FILENAME saves a plan in Terraform’s opaque format for later inspection and application. A saved plan carries the planned operations, so protect it as sensitive data and make sure the file being applied is the one that was reviewed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Request a specific resource replacement

-replace=ADDRESS asks Terraform to plan replacement of the specified resource instance. The option does not make replacement safe by itself: inspect the full plan for the targeted resource and any related changes before applying.

Final checks before approval

  • Confirm the working directory, provider configuration, credentials, and region are the ones intended for this change.
  • Check every resource address and the actual planned values, not only the action totals.
  • Investigate unexpected replacements or deletions before approval.
  • For an interactive apply, review the fresh plan Terraform presents. For automation or a staged handoff, inspect and apply the same saved plan file.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.