Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To set up Terraform with AWS, install Terraform and AWS CLI, sign in using a short-term credential method, select the intended AWS profile and region, configure Terraform’s AWS provider, then run terraform init and inspect terraform plan before making changes. This sequence helps verify that Terraform can use your AWS credentials without storing secrets in your configuration.

Install Terraform and AWS CLI

Install both tools using their official instructions for your operating system; the installation commands differ by platform and can change over time.

  1. Install Terraform: Follow HashiCorp’s Terraform installation guide. Open a new terminal and run terraform -help. The help output confirms that the executable is available.
  2. Install AWS CLI: Follow AWS’s AWS CLI setup guide, then run aws --version to verify the installation. The browser-based aws login method described below requires AWS CLI version 2.32.0 or later.

Choose an AWS sign-in method

Prefer temporary or federated credentials for local development. The right method depends on how your organization manages AWS access and whether you can use browser-based sign-in.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Method When it fits Important detail
aws login with console credentials You can sign in to AWS with console credentials and your identity is permitted to use this flow. AWS says the CLI automatically refreshes the temporary credentials for up to 12 hours. Requires AWS CLI 2.32.0 or later. See AWS’s local sign-in guide.
IAM Identity Center Your organization provides workforce access through IAM Identity Center. Use AWS’s aws configure sso and aws sso login process, following the AWS CLI authentication guide.
Long-term IAM user access keys Only when a constrained legacy workflow requires them and your organization permits their use. AWS marks long-term IAM user credentials as not recommended for development. Do not create a root access key. Keep any required keys out of Terraform files and version control. See AWS’s IAM user authentication guidance.

For aws login, run the command in the terminal and follow its browser sign-in flow. For IAM Identity Center, configure the SSO session and then complete aws sso login as described by AWS. Do not proceed until the sign-in method you chose has completed successfully.

Select a profile and region deliberately

AWS CLI profiles let you keep settings and credentials for different accounts or environments separate. If you do not select a profile, the CLI uses the default profile. On Linux and macOS, AWS CLI shared files are under ~/.aws/: credentials are normally in credentials, while general settings such as region are in config. On Windows, they are under your user profile’s .aws directory. AWS documents the file locations and settings in its configuration and credential file guide.

When you have multiple profiles, select the intended one explicitly for CLI commands, for example:

aws sts get-caller-identity --profile my-profile

This command displays the identity associated with the selected credentials; it does not create or change resources. Replace my-profile with the profile you configured. For commands that support it, --profile makes the intended choice visible. AWS CLI precedence rules mean command-line options can override environment variables, which can in turn override stored settings. If a command uses the wrong identity or region, check the selected profile, AWS_PROFILE, region options and environment variables, and the shared configuration files. See AWS’s authentication and credential documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure the Terraform AWS provider

In your project directory, create or edit a Terraform configuration file such as main.tf. Declare the AWS provider source and a version constraint in the terraform block, then set the region in the provider block. The following is an illustrative structure, not a recommendation to use a particular provider release or region:

terraform {
  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 5.0" # Illustrative only; check current provider documentation.
    }
  }
}

provider "aws" {
  region = "us-west-2"
}

Choose a region that matches your intended deployment and a version constraint compatible with your project. Check the current HashiCorp provider configuration guide before choosing a provider version. Terraform downloads provider plugins during initialization. For local development, use the AWS CLI credential flow and profile rather than putting keys in the provider block. HashiCorp warns against setting provider credentials in configuration because shared configuration may expose them.

Initialize the project and inspect the plan

  1. From the directory containing your Terraform configuration, run terraform init. Terraform initializes the working directory and downloads the required providers and modules.
  2. Before planning, confirm that your credentials resolve to the intended AWS account and that the provider is configured for the intended region. If your configuration or workflow selects a profile explicitly, verify that selection too.
  3. Run terraform plan and read the full output. Check which resources Terraform proposes to create, change, or destroy, and confirm the workspace, backend/state, and input variables are the ones you intend to use.
  4. Do not run terraform apply until you understand and approve the proposed changes.

A plan is an inspection of the configuration against the state and information available at planning time; it does not guarantee that a later apply will produce identical actions if configuration or remote state changes. HashiCorp’s provider tutorial uses planning to verify provider access and display proposed changes.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Troubleshoot common setup problems

  • Terraform or AWS commands are not found: Recheck the relevant installation instructions for your operating system, open a fresh terminal, and run terraform -help or aws --version again.
  • Credentials are missing or expired: Complete the selected sign-in flow again, such as aws login or aws sso login, and confirm Terraform is using the expected credential source and profile.
  • The wrong account or region appears: Check the CLI profile, command-line flags, environment variables, shared AWS files, and the Terraform provider’s region. Higher-priority CLI settings can override stored values.
  • AWS returns AccessDenied: The required permissions depend on the resources and operations in your configuration. There is no universal minimum policy for every Terraform project; ask your AWS administrator for permissions appropriate to the specific work rather than assuming broad administrator access is necessary.
  • Credentials appear in a repository: Remove secrets from Terraform configuration and keep local credential files out of version control. Rotate exposed credentials through your organization’s AWS process.
  • The plan includes unexpected changes: Stop before applying. Review the entire plan, then verify the workspace, account, region, backend/state, and variables.

For teams that later need hosted collaboration, HashiCorp documents an HCP Terraform workflow for AWS, including configuring AWS credentials in a workspace: Collaborate using HCP Terraform.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.