Bird
Raised Fist0
Terraformcloud~5 mins

Terraform CLI overview - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
Terraform CLI helps you create and manage cloud resources by running simple commands. It solves the problem of manually setting up infrastructure by automating the process with code.
When you want to create a virtual server in the cloud quickly and repeatedly.
When you need to update your cloud resources safely without breaking anything.
When you want to see what changes will happen before applying them.
When you want to keep track of your infrastructure setup in files.
When you want to destroy cloud resources you no longer need to save costs.
Config File - main.tf
main.tf
terraform {
  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 4.0"
    }
  }
  required_version = ">= 1.0"
}

provider "aws" {
  region = "us-east-1"
}

resource "aws_s3_bucket" "example_bucket" {
  bucket = "example-terraform-cli-bucket-12345"
  acl    = "private"
}

This file tells Terraform to use the AWS provider in the us-east-1 region. It defines one resource: an S3 bucket with a unique name and private access. The terraform block sets the provider version and Terraform version requirements.

Commands
This command sets up Terraform in your folder by downloading the AWS provider plugin. It prepares your environment to run Terraform commands.
Terminal
terraform init
Expected OutputExpected
Initializing the backend... Initializing provider plugins... - Finding hashicorp/aws versions matching "~> 4.0"... - Installing hashicorp/aws v4.60.0... - Installed hashicorp/aws v4.60.0 (signed by HashiCorp) Terraform has been successfully initialized! You may now begin working with Terraform. Try running "terraform plan" to see any changes that are required for your infrastructure.
This command shows what Terraform will do if you apply the changes. It helps you check before making any real changes.
Terminal
terraform plan
Expected OutputExpected
Refreshing Terraform state in-memory prior to plan... An execution plan has been generated and is shown below. Resource actions are indicated with the following symbols: + create Terraform will perform the following actions: # aws_s3_bucket.example_bucket will be created + resource "aws_s3_bucket" "example_bucket" { + acl = "private" + bucket = "example-terraform-cli-bucket-12345" + id = (known after apply) } Plan: 1 to add, 0 to change, 0 to destroy.
This command applies the planned changes and creates the S3 bucket. The flag skips the confirmation prompt to speed up the process.
Terminal
terraform apply -auto-approve
Expected OutputExpected
aws_s3_bucket.example_bucket: Creating... aws_s3_bucket.example_bucket: Creation complete after 2s [id=example-terraform-cli-bucket-12345] Apply complete! Resources: 1 added, 0 changed, 0 destroyed.
→
-auto-approve - Skip manual approval prompt
This command deletes the S3 bucket and cleans up your cloud resources. The flag skips the confirmation prompt.
Terminal
terraform destroy -auto-approve
Expected OutputExpected
aws_s3_bucket.example_bucket: Destroying... aws_s3_bucket.example_bucket: Destruction complete after 1s Destroy complete! Resources: 1 destroyed.
→
-auto-approve - Skip manual approval prompt
Key Concept

If you remember nothing else from this pattern, remember: Terraform CLI commands let you safely create, preview, change, and delete cloud resources using simple steps.

Common Mistakes
Running terraform apply before terraform init
Terraform needs to download provider plugins first; without init, apply will fail.
Always run terraform init once before any other Terraform commands in a new folder.
Not running terraform plan before apply
You might apply unexpected changes without reviewing them first.
Run terraform plan to see what will change before applying.
Using terraform apply without -auto-approve and expecting no prompt
Terraform will pause and ask for confirmation, which can interrupt automation.
Use -auto-approve flag to skip confirmation in scripts or when you want faster apply.
Summary
terraform init prepares your folder by downloading needed plugins.
terraform plan shows what changes Terraform will make without applying them.
terraform apply creates or updates resources as defined in your files.
terraform destroy removes resources you no longer need.

Practice

(1/5)
1. What is the primary purpose of the terraform init command?
easy
A. To show the planned changes without applying them
B. To apply changes to cloud infrastructure
C. To destroy all managed resources
D. To initialize a working directory and download required provider plugins

Solution

  1. Step 1: Understand the role of terraform init

    This command sets up the working directory by downloading necessary provider plugins and preparing the environment.
  2. Step 2: Differentiate from other commands

    Commands like apply and destroy perform changes, while init only prepares the setup.
  3. Final Answer:

    To initialize a working directory and download required provider plugins -> Option D
  4. Quick Check:

    terraform init prepares environment [OK]
Hint: Init sets up your folder and downloads plugins [OK]
Common Mistakes:
  • Confusing init with apply
  • Thinking init changes infrastructure
  • Mixing init with destroy
2. Which of the following is the correct syntax to preview changes without applying them?
easy
A. terraform plan
B. terraform apply --preview
C. terraform preview
D. terraform show

Solution

  1. Step 1: Identify the command to preview changes

    terraform plan shows what changes will happen without applying them.
  2. Step 2: Check other options for correctness

    apply --preview and preview are not valid commands; show displays current state, not planned changes.
  3. Final Answer:

    terraform plan -> Option A
  4. Quick Check:

    Preview changes = terraform plan [OK]
Hint: Plan shows changes without applying [OK]
Common Mistakes:
  • Using apply --preview which is invalid
  • Confusing show with plan
  • Assuming preview is a Terraform command
3. Given the following sequence of commands:
terraform init
tf plan
terraform apply

What will happen when you run these commands?
medium
A. Only initialize the directory and apply changes, skipping the plan
B. Initialize the directory, show planned changes, then apply those changes
C. Initialize the directory, apply changes immediately, then show the plan
D. Show planned changes without initializing or applying

Solution

  1. Step 1: Understand each command's role

    terraform init sets up the environment, terraform plan shows what will change, and terraform apply makes those changes.
  2. Step 2: Analyze the sequence

    The commands run in order: initialize, plan, then apply, which is the recommended workflow.
  3. Final Answer:

    Initialize the directory, show planned changes, then apply those changes -> Option B
  4. Quick Check:

    Init -> Plan -> Apply = safe workflow [OK]
Hint: Init, then plan, then apply changes [OK]
Common Mistakes:
  • Running apply before plan
  • Skipping init before plan
  • Confusing plan and apply order
4. You run terraform apply but get an error saying the backend is not configured. What is the most likely cause?
medium
A. You need to run terraform destroy first
B. You used the wrong syntax for apply
C. You forgot to run terraform init first
D. Your cloud provider credentials are missing

Solution

  1. Step 1: Understand backend configuration role

    The backend stores state remotely and must be set up before applying changes.
  2. Step 2: Identify how backend is configured

    terraform init configures the backend; skipping it causes errors.
  3. Final Answer:

    You forgot to run terraform init first -> Option C
  4. Quick Check:

    Init configures backend before apply [OK]
Hint: Always run init before apply to configure backend [OK]
Common Mistakes:
  • Skipping init and running apply directly
  • Assuming credentials cause backend error
  • Thinking destroy fixes backend issues
5. You want to safely remove all cloud resources managed by Terraform. Which command sequence ensures this with minimal risk?
hard
A. terraform destroy after terraform plan to review changes
B. terraform apply followed by terraform destroy
C. terraform init then terraform apply
D. terraform plan then terraform init

Solution

  1. Step 1: Understand the purpose of terraform destroy

    This command deletes all resources managed by Terraform.
  2. Step 2: Use terraform plan before destroy

    Planning shows what will be destroyed, helping avoid mistakes.
  3. Step 3: Confirm the sequence

    Running terraform plan first, then terraform destroy is the safest approach.
  4. Final Answer:

    terraform destroy after terraform plan to review changes -> Option A
  5. Quick Check:

    Plan before destroy to avoid surprises [OK]
Hint: Plan first, then destroy to confirm changes [OK]
Common Mistakes:
  • Destroying without planning first
  • Applying changes before destroying
  • Running init after plan