Bird
Raised Fist0
Terraformcloud~5 mins

Terraform plan for preview - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
When you want to see what changes Terraform will make to your cloud resources before actually applying them, you use the terraform plan command. This helps avoid surprises by previewing the changes safely.
Before creating new cloud resources to check what will be added.
Before updating existing infrastructure to see what will change.
Before deleting resources to confirm what will be removed.
When collaborating with a team to review planned changes.
To verify your Terraform code logic without making real changes.
Config File - main.tf
main.tf
terraform {
  required_version = ">= 1.0"
  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 4.0"
    }
  }
}

provider "aws" {
  region = "us-east-1"
}

resource "aws_s3_bucket" "example_bucket" {
  bucket = "example-terraform-bucket-12345"
  acl    = "private"
}

This file tells Terraform to use AWS as the cloud provider in the us-east-1 region. It defines one resource: an S3 bucket named "example-terraform-bucket-12345" with private access. The terraform block sets the required Terraform and provider versions.

Commands
This command sets up Terraform in the current folder by downloading the AWS provider plugin and preparing the environment.
Terminal
terraform init
Expected OutputExpected
Initializing the backend... Initializing provider plugins... - Finding hashicorp/aws versions matching "~> 4.0"... - Installing hashicorp/aws v4.50.0... - Installed hashicorp/aws v4.50.0 (signed by HashiCorp) Terraform has been successfully initialized! You may now begin working with Terraform. Try running "terraform plan" to see any changes that are required for your infrastructure.
This command previews the changes Terraform will make to your cloud resources based on your configuration, without applying them.
Terminal
terraform plan
Expected OutputExpected
Refreshing Terraform state in-memory prior to plan... An execution plan has been generated and is shown below. Resource actions are indicated with the following symbols: + create Terraform will perform the following actions: # aws_s3_bucket.example_bucket will be created + resource "aws_s3_bucket" "example_bucket" { + acl = "private" + bucket = "example-terraform-bucket-12345" + force_destroy = false + id = (known after apply) + region = (known after apply) + tags = (known after apply) } Plan: 1 to add, 0 to change, 0 to destroy. ───────────────────────────────────────────────────────────────────────────── Note: You didn't specify an "-out" parameter to save this plan, so Terraform can't guarantee that exactly these actions will be performed if "terraform apply" is subsequently run.
→
-out=planfile - Save the plan to a file for later apply
This command creates a plan and saves it to a file named preview.plan. You can apply this exact plan later to ensure the changes match the preview.
Terminal
terraform plan -out=preview.plan
Expected OutputExpected
Refreshing Terraform state in-memory prior to plan... An execution plan has been generated and saved to preview.plan. To perform exactly these actions, run the following command to apply: terraform apply "preview.plan"
→
-out=preview.plan - Save the plan to a file for exact apply later
Key Concept

If you remember nothing else from this pattern, remember: terraform plan shows you exactly what changes will happen before you make them.

Common Mistakes
Running terraform apply without running terraform plan first
You might make unexpected changes or delete resources without knowing.
Always run terraform plan to preview changes before applying.
Not running terraform init before terraform plan
Terraform won't have the necessary provider plugins and will fail.
Run terraform init once per project folder before planning or applying.
Ignoring the plan output and applying blindly
You might miss warnings or unintended resource changes.
Carefully read the plan output to confirm changes are expected.
Summary
terraform init prepares Terraform and downloads provider plugins.
terraform plan previews the changes Terraform will make without applying them.
terraform plan -out=filename saves the plan to apply exactly later.

Practice

(1/5)
1. What is the main purpose of the terraform plan command?
easy
A. To destroy all existing infrastructure
B. To apply changes directly to cloud resources
C. To initialize the Terraform working directory
D. To preview changes Terraform will make without applying them

Solution

  1. Step 1: Understand the role of terraform plan

    This command shows what changes Terraform will make but does not apply them.
  2. Step 2: Compare with other commands

    terraform apply applies changes, terraform destroy removes resources, and terraform init initializes the directory.
  3. Final Answer:

    To preview changes Terraform will make without applying them -> Option D
  4. Quick Check:

    Preview changes = terraform plan [OK]
Hint: Plan previews changes, apply makes changes [OK]
Common Mistakes:
  • Confusing plan with apply
  • Thinking plan modifies resources
  • Mixing plan with init or destroy
2. Which of the following is the correct syntax to run a Terraform plan with a specific variable file named vars.tfvars?
easy
A. terraform plan --vars-file=vars.tfvars
B. terraform plan --varfile vars.tfvars
C. terraform plan -var-file=vars.tfvars
D. terraform plan -varfile=vars.tfvars

Solution

  1. Step 1: Recall correct flag for variable files

    The correct flag is -var-file with a hyphen between var and file.
  2. Step 2: Check syntax correctness

    terraform plan -var-file=vars.tfvars uses -var-file=vars.tfvars, which is the official syntax. Other options use incorrect flags.
  3. Final Answer:

    terraform plan -var-file=vars.tfvars -> Option C
  4. Quick Check:

    Use -var-file=filename for variable files [OK]
Hint: Use -var-file=filename to specify variable files [OK]
Common Mistakes:
  • Using --varfile instead of -var-file
  • Mixing underscores or missing hyphens
  • Using --vars-file which is invalid
3. Given this Terraform plan output snippet:
  # aws_instance.example will be created
  + resource "aws_instance" "example" {
      + ami           = "ami-123456"
      + instance_type = "t2.micro"
    }

What does the plus sign (+) before the resource indicate?
medium
A. The resource will be created
B. The resource will be destroyed
C. The resource will be updated in place
D. The resource is unchanged

Solution

  1. Step 1: Understand Terraform plan symbols

    The plus sign (+) means Terraform plans to add or create the resource.
  2. Step 2: Differentiate from other symbols

    Minus (-) means destroy, ~ means update, no symbol means unchanged.
  3. Final Answer:

    The resource will be created -> Option A
  4. Quick Check:

    Plus sign (+) = create resource [OK]
Hint: Plus (+) means create, minus (-) means destroy [OK]
Common Mistakes:
  • Confusing + with update or destroy
  • Ignoring symbols and guessing
  • Assuming no symbol means create
4. You run terraform plan but get this error:
Error: No configuration files found!

What is the most likely cause?
medium
A. You ran the command outside the Terraform configuration directory
B. You forgot to run terraform init first
C. Your Terraform version is outdated
D. Your cloud provider credentials are missing

Solution

  1. Step 1: Analyze the error message

    The error says no configuration files found, meaning Terraform can't find .tf files.
  2. Step 2: Identify common causes

    This usually happens if you run the command outside the folder containing Terraform files.
  3. Final Answer:

    You ran the command outside the Terraform configuration directory -> Option A
  4. Quick Check:

    No config files = wrong directory [OK]
Hint: Run plan inside folder with .tf files [OK]
Common Mistakes:
  • Assuming init fixes missing files
  • Blaming credentials for config file errors
  • Ignoring current working directory
5. You want to preview changes only for a specific resource named aws_s3_bucket.mybucket without affecting others. Which command achieves this?
hard
A. terraform plan -only=aws_s3_bucket.mybucket
B. terraform plan -target=aws_s3_bucket.mybucket
C. terraform plan --filter=aws_s3_bucket.mybucket
D. terraform plan -resource=aws_s3_bucket.mybucket

Solution

  1. Step 1: Recall how to target specific resources in plan

    The -target flag limits the plan to specified resources.
  2. Step 2: Verify correct flag usage

    terraform plan -target=aws_s3_bucket.mybucket uses -target=aws_s3_bucket.mybucket, which is the correct syntax. Other options are invalid flags.
  3. Final Answer:

    terraform plan -target=aws_s3_bucket.mybucket -> Option B
  4. Quick Check:

    Use -target to preview specific resources [OK]
Hint: Use -target=resource_name to limit plan scope [OK]
Common Mistakes:
  • Using non-existent flags like -only or --filter
  • Forgetting to specify resource type and name
  • Assuming plan always shows all resources