Bird
Raised Fist0
Terraformcloud~5 mins

Plan output reading in Terraform - Cheat Sheet & Quick Revision

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Recall & Review
beginner
What does the 'terraform plan' command do?
It shows what changes Terraform will make to your infrastructure without applying them. Think of it like a preview before you make changes.
Click to reveal answer
beginner
What information can you find in the output of 'terraform plan'?
You can see which resources will be added, changed, or destroyed. It tells you exactly what Terraform plans to do.
Click to reveal answer
beginner
In Terraform plan output, what does a line starting with '+' mean?
It means a resource will be created (added). The '+' sign shows new resources.
Click to reveal answer
beginner
What does a line starting with '-' indicate in Terraform plan output?
It means a resource will be destroyed (removed). The '-' sign shows resources that will be deleted.
Click to reveal answer
beginner
Why is reading the Terraform plan output important before applying changes?
Because it helps you avoid mistakes by showing what will happen. You can catch unwanted deletions or changes before they happen.
Click to reveal answer
What does the '+' symbol mean in Terraform plan output?
ANo change to resource
BResource will be destroyed
CResource will be updated
DResource will be created
Which command shows the planned changes without applying them?
Aterraform plan
Bterraform init
Cterraform destroy
Dterraform apply
If you see a '-' sign next to a resource in the plan output, what does it mean?
AResource will be unchanged
BResource will be created
CResource will be destroyed
DResource will be renamed
Why should you always read the plan output before applying?
ATo check for syntax errors
BTo preview changes and avoid mistakes
CTo speed up deployment
DTo update Terraform version
What does Terraform show if a resource will be changed but not created or destroyed?
A~
B-
C+
D!
Explain how to interpret the symbols '+' , '-' , and '~' in Terraform plan output.
Think of these symbols as signs showing what Terraform will do to each resource.
You got /3 concepts.
    Describe why it is important to review the Terraform plan output before running 'terraform apply'.
    It's like checking your work before pressing 'send' or 'submit'.
    You got /3 concepts.

      Practice

      (1/5)
      1. What does the terraform plan command primarily show before applying changes?
      easy
      A. The current cost of your cloud resources
      B. The changes Terraform will make to your infrastructure
      C. The list of all Terraform providers installed
      D. The history of previous Terraform apply commands

      Solution

      1. Step 1: Understand the purpose of terraform plan

        This command previews the changes Terraform will perform on your infrastructure without applying them.
      2. Step 2: Compare options with command purpose

        Only The changes Terraform will make to your infrastructure correctly describes this preview of changes. Other options describe unrelated information.
      3. Final Answer:

        The changes Terraform will make to your infrastructure -> Option B
      4. Quick Check:

        Plan shows changes = B [OK]
      Hint: Plan shows what changes will happen before apply [OK]
      Common Mistakes:
      • Confusing plan with apply
      • Thinking plan shows costs
      • Assuming plan shows provider list
      2. In Terraform plan output, what does the symbol ~ indicate?
      easy
      A. Resource will be updated
      B. Resource will be created
      C. Resource will be deleted
      D. Resource will be ignored

      Solution

      1. Step 1: Recall Terraform plan symbols

        The symbol ~ means a resource will be updated (changed in place).
      2. Step 2: Match symbol to meaning

        + means create, - means delete, so ~ must mean update.
      3. Final Answer:

        Resource will be updated -> Option A
      4. Quick Check:

        ~ means update = A [OK]
      Hint: Remember + create, ~ update, - delete symbols [OK]
      Common Mistakes:
      • Mixing up ~ with + or -
      • Thinking ~ means delete
      • Assuming ~ means no change
      3. Given this Terraform plan output snippet:
        # aws_instance.web will be updated in-place
        ~ resource "aws_instance" "web" {
            instance_type = "t2.micro" -> "t2.small"
          }

      What does this output mean?
      medium
      A. The instance type will change from t2.micro to t2.small
      B. No changes will be made to the instance
      C. The instance will be deleted and recreated
      D. The instance will be created new

      Solution

      1. Step 1: Analyze the plan output details

        The symbol ~ shows an in-place update. The instance_type changes from "t2.micro" to "t2.small".
      2. Step 2: Interpret the meaning

        This means the existing instance will be updated to the new type without deletion.
      3. Final Answer:

        The instance type will change from t2.micro to t2.small -> Option A
      4. Quick Check:

        ~ means update, instance_type changed = C [OK]
      Hint: Look for ~ and arrow showing old -> new value [OK]
      Common Mistakes:
      • Thinking resource will be deleted
      • Ignoring the arrow showing value change
      • Assuming no change because resource exists
      4. You see this Terraform plan output:
        # aws_s3_bucket.example will be deleted
        - resource "aws_s3_bucket" "example" {
            bucket = "my-bucket"
          }

      But you want to keep the bucket. What should you do?
      medium
      A. Ignore the plan and continue
      B. Remove the resource from your Terraform config
      C. Run terraform apply immediately
      D. Add lifecycle rule with prevent_destroy to the resource

      Solution

      1. Step 1: Understand the delete plan

        The plan shows the bucket will be deleted, but you want to keep it.
      2. Step 2: Use lifecycle prevent_destroy

        Adding a lifecycle block with prevent_destroy = true stops accidental deletion.
      3. Final Answer:

        Add lifecycle rule with prevent_destroy to the resource -> Option D
      4. Quick Check:

        Use prevent_destroy to block deletes = A [OK]
      Hint: Use lifecycle prevent_destroy to stop unwanted deletes [OK]
      Common Mistakes:
      • Removing resource causes deletion
      • Applying plan deletes bucket
      • Ignoring plan risks data loss
      5. You run terraform plan and see:
        # aws_security_group.sg will be replaced
        - resource "aws_security_group" "sg" {
            name = "old-sg"
          }
        + resource "aws_security_group" "sg" {
            name = "new-sg"
          }

      What does this mean and why does Terraform replace the resource instead of updating it?
      hard
      A. Terraform will fail because name change is not allowed
      B. Terraform updates the resource in place changing the name
      C. Terraform deletes and recreates because the name attribute is immutable
      D. Terraform ignores the change because names can be duplicated

      Solution

      1. Step 1: Analyze the plan output for replacement

        The plan shows the resource will be deleted (-) and a new one created (+) with a different name.
      2. Step 2: Understand why replacement occurs

        Some attributes like security group name are immutable, so Terraform must replace the resource to change them.
      3. Final Answer:

        Terraform deletes and recreates because the name attribute is immutable -> Option C
      4. Quick Check:

        Immutable attribute change causes replacement = D [OK]
      Hint: Immutable attribute changes cause resource replacement [OK]
      Common Mistakes:
      • Thinking Terraform updates name in place
      • Assuming name can be duplicated
      • Believing plan will fail on name change