Bird
Raised Fist0
Terraformcloud~5 mins

Plan output reading in Terraform - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
When you make changes to your infrastructure code, you want to see what will happen before applying them. Terraform's plan command shows you the changes it will make without actually changing anything. This helps avoid surprises and mistakes.
When you want to check what resources will be created, changed, or deleted before applying changes.
When you want to review infrastructure updates with your team before making them live.
When you want to verify that your code changes will not accidentally remove important resources.
When you want to understand the impact of a configuration change on your cloud environment.
When you want to catch errors or unexpected changes early in your deployment process.
Config File - main.tf
main.tf
terraform {
  required_version = ">= 1.0"
  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 4.0"
    }
  }
}

provider "aws" {
  region = "us-east-1"
}

resource "aws_s3_bucket" "example_bucket" {
  bucket = "example-terraform-bucket-123456"
  acl    = "private"
}

This file configures Terraform to use AWS as the cloud provider in the us-east-1 region. It defines a simple S3 bucket resource named example_bucket with private access. This setup is used to demonstrate how Terraform plans changes before applying them.

Commands
This command initializes the Terraform working directory. It downloads the required provider plugins and prepares the environment for running Terraform commands.
Terminal
terraform init
Expected OutputExpected
Initializing the backend... Initializing provider plugins... - Finding hashicorp/aws versions matching "~> 4.0"... - Installing hashicorp/aws v4.0.0... - Installed hashicorp/aws v4.0.0 (signed by HashiCorp) Terraform has been successfully initialized! You may now begin working with Terraform. Try running "terraform plan" to see any changes that are required for your infrastructure.
This command shows what Terraform will do when you apply your changes. It lists resources to be added, changed, or destroyed without making any actual changes.
Terminal
terraform plan
Expected OutputExpected
Refreshing Terraform state in-memory prior to plan... An execution plan has been generated and is shown below. Resource actions are indicated with the following symbols: + create Terraform will perform the following actions: # aws_s3_bucket.example_bucket will be created + resource "aws_s3_bucket" "example_bucket" { + acl = "private" + bucket = "example-terraform-bucket-123456" + force_destroy = false + id = (known after apply) + region = (known after apply) + tags = (known after apply) } Plan: 1 to add, 0 to change, 0 to destroy. ───────────────────────────────────────────────────────────────────────────── Note: You didn't specify an "-out" parameter to save this plan, so Terraform can't guarantee to take exactly these actions if you run "terraform apply" now.
→
-out=planfile - Saves the plan to a file for later apply
This command applies the planned changes to your infrastructure. The -auto-approve flag skips the confirmation prompt to apply immediately.
Terminal
terraform apply -auto-approve
Expected OutputExpected
aws_s3_bucket.example_bucket: Creating... aws_s3_bucket.example_bucket: Creation complete after 2s [id=example-terraform-bucket-123456] Apply complete! Resources: 1 added, 0 changed, 0 destroyed.
→
-auto-approve - Automatically approves the apply without asking for confirmation
Run plan again after apply to confirm no changes are pending. This shows that the infrastructure matches the code.
Terminal
terraform plan
Expected OutputExpected
Refreshing Terraform state in-memory prior to plan... No changes. Infrastructure is up-to-date. This means that Terraform did not detect any differences between your configuration and real physical resources that exist. Your infrastructure matches the configuration.
Key Concept

If you remember nothing else from this pattern, remember: terraform plan shows exactly what changes will happen before you make them, helping you avoid surprises.

Common Mistakes
Running terraform apply without running terraform plan first
You might apply unintended changes or delete resources by accident without reviewing the plan.
Always run terraform plan first to review the planned changes before applying.
Ignoring the plan output and applying blindly
You miss the chance to catch errors or unexpected resource changes that could cause downtime or data loss.
Carefully read the plan output to understand what Terraform will do.
Not initializing Terraform with terraform init before planning
Terraform will fail to run plan or apply because providers are not downloaded and configured.
Run terraform init once before any plan or apply commands in a new working directory.
Summary
terraform init prepares your working directory and downloads providers.
terraform plan shows what changes Terraform will make without applying them.
terraform apply makes the changes to your infrastructure.
Running terraform plan after apply confirms your infrastructure matches your code.

Practice

(1/5)
1. What does the terraform plan command primarily show before applying changes?
easy
A. The current cost of your cloud resources
B. The changes Terraform will make to your infrastructure
C. The list of all Terraform providers installed
D. The history of previous Terraform apply commands

Solution

  1. Step 1: Understand the purpose of terraform plan

    This command previews the changes Terraform will perform on your infrastructure without applying them.
  2. Step 2: Compare options with command purpose

    Only The changes Terraform will make to your infrastructure correctly describes this preview of changes. Other options describe unrelated information.
  3. Final Answer:

    The changes Terraform will make to your infrastructure -> Option B
  4. Quick Check:

    Plan shows changes = B [OK]
Hint: Plan shows what changes will happen before apply [OK]
Common Mistakes:
  • Confusing plan with apply
  • Thinking plan shows costs
  • Assuming plan shows provider list
2. In Terraform plan output, what does the symbol ~ indicate?
easy
A. Resource will be updated
B. Resource will be created
C. Resource will be deleted
D. Resource will be ignored

Solution

  1. Step 1: Recall Terraform plan symbols

    The symbol ~ means a resource will be updated (changed in place).
  2. Step 2: Match symbol to meaning

    + means create, - means delete, so ~ must mean update.
  3. Final Answer:

    Resource will be updated -> Option A
  4. Quick Check:

    ~ means update = A [OK]
Hint: Remember + create, ~ update, - delete symbols [OK]
Common Mistakes:
  • Mixing up ~ with + or -
  • Thinking ~ means delete
  • Assuming ~ means no change
3. Given this Terraform plan output snippet:
  # aws_instance.web will be updated in-place
  ~ resource "aws_instance" "web" {
      instance_type = "t2.micro" -> "t2.small"
    }

What does this output mean?
medium
A. The instance type will change from t2.micro to t2.small
B. No changes will be made to the instance
C. The instance will be deleted and recreated
D. The instance will be created new

Solution

  1. Step 1: Analyze the plan output details

    The symbol ~ shows an in-place update. The instance_type changes from "t2.micro" to "t2.small".
  2. Step 2: Interpret the meaning

    This means the existing instance will be updated to the new type without deletion.
  3. Final Answer:

    The instance type will change from t2.micro to t2.small -> Option A
  4. Quick Check:

    ~ means update, instance_type changed = C [OK]
Hint: Look for ~ and arrow showing old -> new value [OK]
Common Mistakes:
  • Thinking resource will be deleted
  • Ignoring the arrow showing value change
  • Assuming no change because resource exists
4. You see this Terraform plan output:
  # aws_s3_bucket.example will be deleted
  - resource "aws_s3_bucket" "example" {
      bucket = "my-bucket"
    }

But you want to keep the bucket. What should you do?
medium
A. Ignore the plan and continue
B. Remove the resource from your Terraform config
C. Run terraform apply immediately
D. Add lifecycle rule with prevent_destroy to the resource

Solution

  1. Step 1: Understand the delete plan

    The plan shows the bucket will be deleted, but you want to keep it.
  2. Step 2: Use lifecycle prevent_destroy

    Adding a lifecycle block with prevent_destroy = true stops accidental deletion.
  3. Final Answer:

    Add lifecycle rule with prevent_destroy to the resource -> Option D
  4. Quick Check:

    Use prevent_destroy to block deletes = A [OK]
Hint: Use lifecycle prevent_destroy to stop unwanted deletes [OK]
Common Mistakes:
  • Removing resource causes deletion
  • Applying plan deletes bucket
  • Ignoring plan risks data loss
5. You run terraform plan and see:
  # aws_security_group.sg will be replaced
  - resource "aws_security_group" "sg" {
      name = "old-sg"
    }
  + resource "aws_security_group" "sg" {
      name = "new-sg"
    }

What does this mean and why does Terraform replace the resource instead of updating it?
hard
A. Terraform will fail because name change is not allowed
B. Terraform updates the resource in place changing the name
C. Terraform deletes and recreates because the name attribute is immutable
D. Terraform ignores the change because names can be duplicated

Solution

  1. Step 1: Analyze the plan output for replacement

    The plan shows the resource will be deleted (-) and a new one created (+) with a different name.
  2. Step 2: Understand why replacement occurs

    Some attributes like security group name are immutable, so Terraform must replace the resource to change them.
  3. Final Answer:

    Terraform deletes and recreates because the name attribute is immutable -> Option C
  4. Quick Check:

    Immutable attribute change causes replacement = D [OK]
Hint: Immutable attribute changes cause resource replacement [OK]
Common Mistakes:
  • Thinking Terraform updates name in place
  • Assuming name can be duplicated
  • Believing plan will fail on name change