Bird
Raised Fist0
Terraformcloud~10 mins

Auto-approve flag and its danger in Terraform - Step-by-Step Execution

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Process Flow - Auto-approve flag and its danger
Start terraform apply
↓
Check auto-approve flag
↓
Skip prompt
↓
Apply changes
↓
Finish
↓
Finish
Terraform apply checks if auto-approve is set. If yes, it skips confirmation and applies changes immediately. If no, it asks for user confirmation before applying.
Execution Sample
Terraform
terraform apply -auto-approve

# Applies changes without asking for confirmation
This command runs terraform apply and skips the confirmation prompt, applying changes immediately.
Process Table
StepAuto-approve FlagUser PromptAction TakenResult
1YesSkippedApply changes immediatelyInfrastructure updated without confirmation
2NoShownWait for user inputUser confirms or cancels
3NoUser confirmsApply changesInfrastructure updated after confirmation
4NoUser cancelsAbort applyNo changes made
💡 Execution stops after changes are applied or user cancels.
Status Tracker
VariableStartAfter Step 1After Step 2After Step 3Final
auto_approveunsettruefalsefalsefalse
user_promptunsetskippedshownshownshown
apply_actionnoneappliedwaitingappliedaborted
infrastructure_stateunchangedupdatedunchangedupdatedunchanged
Key Moments - 2 Insights
Why is skipping the confirmation prompt dangerous?
Because changes are applied immediately without user review, mistakes or unintended changes can happen, as shown in step 1 of the execution_table.
What happens if the user cancels when auto-approve is not set?
The apply is aborted and no changes are made, as shown in step 4 of the execution_table.
Visual Quiz - 3 Questions
Test your understanding
Look at the execution_table, what is the action taken when auto-approve is set to Yes?
AAbort apply
BWait for user confirmation
CApply changes immediately
DShow error
💡 Hint
Refer to step 1 in the execution_table where auto-approve is Yes.
At which step does the user have a chance to cancel the apply?
AStep 1
BStep 4
CStep 2
DStep 3
💡 Hint
Look at the execution_table rows where user cancels the apply.
If auto-approve is false, what variable tracks whether the user prompt is shown?
Auser_prompt
Bapply_action
Cauto_approve
Dinfrastructure_state
💡 Hint
Check variable_tracker for user_prompt values when auto_approve is false.
Concept Snapshot
terraform apply -auto-approve skips confirmation prompt
Danger: changes apply immediately without review
Without auto-approve, user must confirm before apply
Use auto-approve carefully to avoid unintended changes
Best practice: avoid auto-approve in production
Full Transcript
When you run terraform apply, it usually asks you to confirm before making changes. If you add the -auto-approve flag, it skips this confirmation and applies changes right away. This can be dangerous because you might apply changes you did not intend. Without auto-approve, Terraform waits for your confirmation, and you can cancel if needed. The key variables are auto_approve which controls skipping prompt, user_prompt which tracks if confirmation is shown, apply_action which shows if changes are applied or aborted, and infrastructure_state which shows if infrastructure is updated. Always be careful using auto-approve to avoid mistakes.

Practice

(1/5)
1. What does the -auto-approve flag do when running terraform apply?
easy
A. It cancels the apply process automatically.
B. It shows a detailed plan before applying changes.
C. It skips the confirmation prompt and applies changes immediately.
D. It only validates the configuration without applying changes.

Solution

  1. Step 1: Understand the purpose of the -auto-approve flag

    This flag is designed to skip the manual confirmation step during terraform apply.
  2. Step 2: Identify the effect on the apply process

    By skipping confirmation, Terraform applies changes immediately without waiting for user input.
  3. Final Answer:

    It skips the confirmation prompt and applies changes immediately. -> Option C
  4. Quick Check:

    -auto-approve skips confirmation [OK]
Hint: Remember: auto-approve means no manual confirmation [OK]
Common Mistakes:
  • Thinking it shows the plan before applying
  • Assuming it cancels the apply
  • Confusing it with validation only
2. Which is the correct syntax to apply Terraform changes without confirmation?
easy
A. terraform apply --force-apply
B. terraform apply --skip-confirm
C. terraform apply --no-approve
D. terraform apply -auto-approve

Solution

  1. Step 1: Recall the exact flag name for skipping confirmation

    The correct flag is -auto-approve, which tells Terraform to apply changes without asking.
  2. Step 2: Check the options for correct syntax

    Only terraform apply -auto-approve uses the correct flag -auto-approve with proper syntax.
  3. Final Answer:

    terraform apply -auto-approve -> Option D
  4. Quick Check:

    Correct flag syntax is -auto-approve [OK]
Hint: Flag always spelled exactly as -auto-approve [OK]
Common Mistakes:
  • Using --skip-confirm which does not exist
  • Confusing with --no-approve or --force-apply
  • Adding extra dashes or misspelling the flag
3. Given this command: terraform apply -auto-approve, what is the main risk involved?
medium
A. Changes will be applied without reviewing the plan first.
B. Terraform will only validate the configuration.
C. Terraform will prompt twice for confirmation.
D. Terraform will not apply any changes.

Solution

  1. Step 1: Understand what -auto-approve does

    This flag skips the manual confirmation step, so Terraform applies changes immediately.
  2. Step 2: Identify the risk of skipping confirmation

    Without reviewing the plan, unintended or harmful changes might be applied automatically.
  3. Final Answer:

    Changes will be applied without reviewing the plan first. -> Option A
  4. Quick Check:

    Auto-approve skips review, causing risk [OK]
Hint: Auto-approve skips review, so risk is blind apply [OK]
Common Mistakes:
  • Thinking no changes will apply
  • Assuming double confirmation happens
  • Believing it only validates without applying
4. You ran terraform apply -auto-approve and accidentally deleted a critical resource. What is the best way to prevent this in the future?
medium
A. Always run terraform apply without any flags.
B. Use -auto-approve only after reviewing the plan with terraform plan.
C. Disable Terraform state locking.
D. Run terraform apply -auto-approve twice to confirm.

Solution

  1. Step 1: Identify the cause of accidental deletion

    Using -auto-approve without reviewing the plan can cause unintended changes.
  2. Step 2: Find the best practice to avoid mistakes

    Always review the plan output with terraform plan before applying changes automatically.
  3. Final Answer:

    Use -auto-approve only after reviewing the plan with terraform plan. -> Option B
  4. Quick Check:

    Review plan before auto-approve prevents mistakes [OK]
Hint: Review plan first, then auto-approve safely [OK]
Common Mistakes:
  • Thinking running apply without flags always prevents errors
  • Disabling state locking which is unrelated
  • Running auto-approve twice does not add confirmation
5. In an automated CI/CD pipeline, you want to safely use terraform apply -auto-approve. Which practice reduces the danger of unintended changes?
hard
A. Run terraform plan and save the plan output, then apply only if the plan matches expectations.
B. Use -auto-approve with terraform destroy to clean up resources automatically.
C. Skip the plan step and apply directly to save time.
D. Run terraform apply manually after the pipeline finishes.

Solution

  1. Step 1: Understand the risk of auto-approve in automation

    Auto-approve skips manual review, so unintended changes can happen if the plan is not checked.
  2. Step 2: Identify a safe automation practice

    Running terraform plan first and saving its output allows verification before applying changes automatically.
  3. Step 3: Confirm the best option

    Run terraform plan and save the plan output, then apply only if the plan matches expectations. describes this safe practice, reducing risk in CI/CD pipelines.
  4. Final Answer:

    Run terraform plan and save the plan output, then apply only if the plan matches expectations. -> Option A
  5. Quick Check:

    Plan then apply ensures safe automation [OK]
Hint: Always plan and verify before auto-approve in pipelines [OK]
Common Mistakes:
  • Skipping plan to save time
  • Using auto-approve with destroy carelessly
  • Running apply manually defeats automation purpose