Recommended Free Tools
A tofu plan shows what OpenTofu proposes to do; it does not make those changes. Read the summary and each proposed resource action, then decide whether they match your intent. For scripts, -detailed-exitcode distinguishes an empty plan, an error, and a plan with changes. Saved plans and JSON output need careful handling because they can expose sensitive values.
What a plan tells you—and what it does not
OpenTofu uses a plan to compare your configuration with prior state and refreshed information about existing remote objects, then presents proposed actions. The official plan command documentation describes it as a way to preview proposed infrastructure changes. Running tofu plan alone does not carry out those changes.
A plan is a point-in-time proposal, not proof that remote infrastructure has changed. Conditions in the target system can change after planning, so review a fresh final plan before applying it. A plan created without -out is speculative; it is not a saved artifact for later application.
How to read the plan summary
Start with the final summary. For example, Plan: 1 to add, 0 to change, 0 to destroy means OpenTofu proposes adding one resource and proposes no changes or destructions. It describes planned actions, not completed work.
#1 Best Overall
Then inspect the resource-level details. Check which resources are affected and whether each proposed action fits the change you intended. In particular, treat proposed destruction or replacement as a reason to understand the specific resource diff before proceeding. The summary is an overview; the resource details explain what is behind it.
What detailed exit codes mean
When you pass -detailed-exitcode to tofu plan, OpenTofu uses three exit codes:
Rank #2
| Exit code | Meaning | How to interpret it |
|---|---|---|
| 0 | Success with an empty diff | No changes are planned. |
| 1 | Error | The plan command did not complete successfully. |
| 2 | Success with a non-empty diff | Changes are present; this is not an ordinary command failure. |
In automation, branch explicitly on all three values. A shell or CI system may treat any nonzero code as failure by default, so a job must account for code 2 as “changes present” rather than report it as a plan error. These meanings apply when -detailed-exitcode is enabled; do not assume the same interpretation for a command run without that option. See OpenTofu’s plan command reference.
Choose the right way to inspect a plan
| Need | Command or option | What to expect |
|---|---|---|
| Review a saved plan in a terminal | tofu show PLANFILE |
Human-readable plan output. |
| Parse a saved plan in a program | tofu show -json PLANFILE |
Machine-readable JSON describing plan data. |
| Save a plan for later inspection or application | tofu plan -out=FILE |
A saved plan file, rather than only a speculative terminal proposal. |
Replace PLANFILE and FILE with the path you intend to use. The commands and their behavior are documented in OpenTofu’s show reference and plan reference.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #3
Protect saved plans and JSON output
A saved plan is a sensitive artifact. It may retain configuration, variable values, and sensitive values even when the terminal display masked them. JSON output can also show sensitive state values in plain text. Restrict access to the plan file and any JSON or logs derived from it; do not casually attach them to tickets or publish them in CI output. OpenTofu calls out these risks in its plan and show documentation.
Understand the JSON before automating against it
OpenTofu’s plan JSON contains more than a human-readable summary. Its documented structure represents plan information alongside configuration, values and prior state, resource changes, and checks. A consumer should interpret the JSON format rather than assume that one field alone describes the full result. See the JSON Output Format reference.
Rank #4
The format includes a format_version. OpenTofu’s compatibility guidance says consumers should tolerate compatible minor additions by ignoring unknown properties, and reject an unsupported major version rather than assume it can be parsed safely. Build parsers to account for the documented version policy instead of failing on every unfamiliar property or silently accepting an unsupported major version.
Troubleshoot display and result mismatches
tofu show cannot interpret the plan cleanly
Displaying provider-specific plan structures depends on provider schema information. If the provider versions currently installed differ from those used to create the artifact, schema upgrades may be needed. OpenTofu also documents constraints around viewing plans created with refresh disabled. Check the plan’s provenance and provider versions before concluding that the artifact itself is corrupt. The relevant details are in the show command reference and init command reference.
JSON has resource changes, but the CLI says “No changes”
Do not treat every entry in JSON’s resource_changes as proof that OpenTofu considers a plan non-empty. OpenTofu documents an ephemeral-resource edge case: an open action can appear in resource_changes while the CLI reports “No changes” and -detailed-exitcode returns 0, because that action is ignored by the emptiness test. A downstream consumer that classifies any resource-change entry as a non-empty plan can therefore disagree with OpenTofu. See the provider documentation.
The command behaves differently than expected
First confirm the installed OpenTofu version and the effective command-line arguments. CLI examples can vary by version, and environment variables may add flags: TF_CLI_ARGS can affect commands generally, while TF_CLI_ARGS_plan adds plan-specific arguments. Inspect these alongside the command you typed before attributing a surprising result to the plan file. OpenTofu documents these behaviors in its basic CLI features and environment variables references.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

