Auto-approve flag and its danger in Terraform - Time & Space Complexity
Start learning this pattern below
Jump into concepts and practice - no test required
We want to understand how using the auto-approve flag affects the number of operations Terraform performs.
Specifically, how does it change the approval step when applying changes?
Analyze the time complexity of running Terraform apply with and without the auto-approve flag.
terraform apply -auto-approve
terraform apply
This sequence shows applying infrastructure changes automatically versus requiring manual approval.
Look at what happens repeatedly during apply commands.
- Primary operation: Terraform plans and applies changes to resources.
- How many times: Each apply command triggers one plan and one apply operation.
- Approval step: Without auto-approve, a manual confirmation is required before applying.
As the number of resources grows, the plan and apply steps take longer.
| Input Size (n) | Approx. API Calls/Operations |
|---|---|
| 10 | ~10 resource operations + 1 approval step |
| 100 | ~100 resource operations + 1 approval step |
| 1000 | ~1000 resource operations + 1 approval step |
Pattern observation: The approval step is constant and does not grow with input size.
Time Complexity: O(n)
This means the main work grows linearly with the number of resources, while approval is a fixed step.
[X] Wrong: "Using auto-approve makes Terraform run faster because it skips steps."
[OK] Correct: Auto-approve only skips manual confirmation; it does not reduce the number of resource operations, which dominate execution time.
Understanding how flags like auto-approve affect operation flow helps you explain automation trade-offs clearly and confidently.
"What if we added a pre-check script before apply? How would that affect the time complexity?"
Practice
-auto-approve flag do when running terraform apply?Solution
Step 1: Understand the purpose of the
This flag is designed to skip the manual confirmation step during-auto-approveflagterraform apply.Step 2: Identify the effect on the apply process
By skipping confirmation, Terraform applies changes immediately without waiting for user input.Final Answer:
It skips the confirmation prompt and applies changes immediately. -> Option CQuick Check:
-auto-approveskips confirmation [OK]
- Thinking it shows the plan before applying
- Assuming it cancels the apply
- Confusing it with validation only
Solution
Step 1: Recall the exact flag name for skipping confirmation
The correct flag is-auto-approve, which tells Terraform to apply changes without asking.Step 2: Check the options for correct syntax
Only terraform apply -auto-approve uses the correct flag-auto-approvewith proper syntax.Final Answer:
terraform apply -auto-approve -> Option DQuick Check:
Correct flag syntax is-auto-approve[OK]
- Using --skip-confirm which does not exist
- Confusing with --no-approve or --force-apply
- Adding extra dashes or misspelling the flag
terraform apply -auto-approve, what is the main risk involved?Solution
Step 1: Understand what
This flag skips the manual confirmation step, so Terraform applies changes immediately.-auto-approvedoesStep 2: Identify the risk of skipping confirmation
Without reviewing the plan, unintended or harmful changes might be applied automatically.Final Answer:
Changes will be applied without reviewing the plan first. -> Option AQuick Check:
Auto-approve skips review, causing risk [OK]
- Thinking no changes will apply
- Assuming double confirmation happens
- Believing it only validates without applying
terraform apply -auto-approve and accidentally deleted a critical resource. What is the best way to prevent this in the future?Solution
Step 1: Identify the cause of accidental deletion
Using-auto-approvewithout reviewing the plan can cause unintended changes.Step 2: Find the best practice to avoid mistakes
Always review the plan output withterraform planbefore applying changes automatically.Final Answer:
Use-auto-approveonly after reviewing the plan withterraform plan. -> Option BQuick Check:
Review plan before auto-approve prevents mistakes [OK]
- Thinking running apply without flags always prevents errors
- Disabling state locking which is unrelated
- Running auto-approve twice does not add confirmation
terraform apply -auto-approve. Which practice reduces the danger of unintended changes?Solution
Step 1: Understand the risk of auto-approve in automation
Auto-approve skips manual review, so unintended changes can happen if the plan is not checked.Step 2: Identify a safe automation practice
Runningterraform planfirst and saving its output allows verification before applying changes automatically.Step 3: Confirm the best option
Runterraform planand save the plan output, then apply only if the plan matches expectations. describes this safe practice, reducing risk in CI/CD pipelines.Final Answer:
Runterraform planand save the plan output, then apply only if the plan matches expectations. -> Option AQuick Check:
Plan then apply ensures safe automation [OK]
- Skipping plan to save time
- Using auto-approve with destroy carelessly
- Running apply manually defeats automation purpose
