Bird
Raised Fist0
Terraformcloud~10 mins

Plan output reading in Terraform - Step-by-Step Execution

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Process Flow - Plan output reading
Run terraform plan
↓
Terraform analyzes config
↓
Detect changes: add, modify, delete
↓
Generate plan output
↓
User reads plan output
↓
Decide to apply or not
Terraform plan reads your config, compares with current state, and shows what will change before applying.
Execution Sample
Terraform
terraform plan

# Sample output snippet:
# + aws_instance.example
# - aws_s3_bucket.old_bucket
# ~ aws_security_group.sg
Shows what resources will be added (+), removed (-), or changed (~) before applying.
Process Table
StepActionResourceChange TypeDetails
1Detect new resourceaws_instance.exampleAdd (+)Will create new EC2 instance
2Detect resource to removeaws_s3_bucket.old_bucketDelete (-)Will delete old S3 bucket
3Detect resource to updateaws_security_group.sgModify (~)Will update security group rules
4Show plan summaryPlan: 1 to add, 1 to change, 1 to destroy
5Wait for user decisionUser decides to apply or not
💡 Plan output complete, user can review changes before apply
Status Tracker
VariableStartAfter Step 1After Step 2After Step 3Final
Resources to Add01111
Resources to Change00011
Resources to Delete00111
Key Moments - 3 Insights
Why do some resources have a '+' sign and others '-' or '~' in the plan output?
The '+' means a resource will be created, '-' means it will be deleted, and '~' means it will be modified. See execution_table rows 1-3 for examples.
Does terraform apply changes automatically after plan?
No, terraform plan only shows what will happen. The user must run 'terraform apply' to make changes. See execution_table row 5.
What if the plan shows no changes?
If no resources are added, changed, or deleted, terraform will show 'No changes. Infrastructure is up-to-date.' This means your config matches the current state.
Visual Quiz - 3 Questions
Test your understanding
Look at the execution_table, what change type is assigned to 'aws_security_group.sg' at step 3?
AAdd (+)
BDelete (-)
CModify (~)
DNo change
💡 Hint
Check the 'Change Type' column in execution_table row 3.
At which step does terraform detect a resource to delete?
AStep 2
BStep 3
CStep 1
DStep 4
💡 Hint
Look for 'Delete (-)' in the 'Change Type' column in execution_table.
If no resources need to be added, changed, or deleted, how would the variable 'Resources to Add' look after step 3?
A1
B0
CDepends on user input
DUndefined
💡 Hint
Refer to variable_tracker row 'Resources to Add' values after step 3.
Concept Snapshot
terraform plan shows what changes will happen without applying them
+ means add, - means delete, ~ means modify
Review plan output carefully before running terraform apply
Plan output helps avoid surprises in your cloud infrastructure
Always read plan output to confirm changes
Full Transcript
Terraform plan reads your configuration and compares it to the current cloud state. It detects which resources will be added, changed, or deleted. The plan output uses symbols: plus (+) for new resources, minus (-) for deletions, and tilde (~) for modifications. This output helps you understand what terraform will do before you apply changes. You must run 'terraform apply' to make the changes happen. If no changes are needed, terraform will say the infrastructure is up-to-date. Reading the plan output carefully helps avoid mistakes and surprises in your cloud setup.

Practice

(1/5)
1. What does the terraform plan command primarily show before applying changes?
easy
A. The current cost of your cloud resources
B. The changes Terraform will make to your infrastructure
C. The list of all Terraform providers installed
D. The history of previous Terraform apply commands

Solution

  1. Step 1: Understand the purpose of terraform plan

    This command previews the changes Terraform will perform on your infrastructure without applying them.
  2. Step 2: Compare options with command purpose

    Only The changes Terraform will make to your infrastructure correctly describes this preview of changes. Other options describe unrelated information.
  3. Final Answer:

    The changes Terraform will make to your infrastructure -> Option B
  4. Quick Check:

    Plan shows changes = B [OK]
Hint: Plan shows what changes will happen before apply [OK]
Common Mistakes:
  • Confusing plan with apply
  • Thinking plan shows costs
  • Assuming plan shows provider list
2. In Terraform plan output, what does the symbol ~ indicate?
easy
A. Resource will be updated
B. Resource will be created
C. Resource will be deleted
D. Resource will be ignored

Solution

  1. Step 1: Recall Terraform plan symbols

    The symbol ~ means a resource will be updated (changed in place).
  2. Step 2: Match symbol to meaning

    + means create, - means delete, so ~ must mean update.
  3. Final Answer:

    Resource will be updated -> Option A
  4. Quick Check:

    ~ means update = A [OK]
Hint: Remember + create, ~ update, - delete symbols [OK]
Common Mistakes:
  • Mixing up ~ with + or -
  • Thinking ~ means delete
  • Assuming ~ means no change
3. Given this Terraform plan output snippet:
  # aws_instance.web will be updated in-place
  ~ resource "aws_instance" "web" {
      instance_type = "t2.micro" -> "t2.small"
    }

What does this output mean?
medium
A. The instance type will change from t2.micro to t2.small
B. No changes will be made to the instance
C. The instance will be deleted and recreated
D. The instance will be created new

Solution

  1. Step 1: Analyze the plan output details

    The symbol ~ shows an in-place update. The instance_type changes from "t2.micro" to "t2.small".
  2. Step 2: Interpret the meaning

    This means the existing instance will be updated to the new type without deletion.
  3. Final Answer:

    The instance type will change from t2.micro to t2.small -> Option A
  4. Quick Check:

    ~ means update, instance_type changed = C [OK]
Hint: Look for ~ and arrow showing old -> new value [OK]
Common Mistakes:
  • Thinking resource will be deleted
  • Ignoring the arrow showing value change
  • Assuming no change because resource exists
4. You see this Terraform plan output:
  # aws_s3_bucket.example will be deleted
  - resource "aws_s3_bucket" "example" {
      bucket = "my-bucket"
    }

But you want to keep the bucket. What should you do?
medium
A. Ignore the plan and continue
B. Remove the resource from your Terraform config
C. Run terraform apply immediately
D. Add lifecycle rule with prevent_destroy to the resource

Solution

  1. Step 1: Understand the delete plan

    The plan shows the bucket will be deleted, but you want to keep it.
  2. Step 2: Use lifecycle prevent_destroy

    Adding a lifecycle block with prevent_destroy = true stops accidental deletion.
  3. Final Answer:

    Add lifecycle rule with prevent_destroy to the resource -> Option D
  4. Quick Check:

    Use prevent_destroy to block deletes = A [OK]
Hint: Use lifecycle prevent_destroy to stop unwanted deletes [OK]
Common Mistakes:
  • Removing resource causes deletion
  • Applying plan deletes bucket
  • Ignoring plan risks data loss
5. You run terraform plan and see:
  # aws_security_group.sg will be replaced
  - resource "aws_security_group" "sg" {
      name = "old-sg"
    }
  + resource "aws_security_group" "sg" {
      name = "new-sg"
    }

What does this mean and why does Terraform replace the resource instead of updating it?
hard
A. Terraform will fail because name change is not allowed
B. Terraform updates the resource in place changing the name
C. Terraform deletes and recreates because the name attribute is immutable
D. Terraform ignores the change because names can be duplicated

Solution

  1. Step 1: Analyze the plan output for replacement

    The plan shows the resource will be deleted (-) and a new one created (+) with a different name.
  2. Step 2: Understand why replacement occurs

    Some attributes like security group name are immutable, so Terraform must replace the resource to change them.
  3. Final Answer:

    Terraform deletes and recreates because the name attribute is immutable -> Option C
  4. Quick Check:

    Immutable attribute change causes replacement = D [OK]
Hint: Immutable attribute changes cause resource replacement [OK]
Common Mistakes:
  • Thinking Terraform updates name in place
  • Assuming name can be duplicated
  • Believing plan will fail on name change