Bird
Raised Fist0
Terraformcloud~5 mins

Why the workflow matters in Terraform - Why It Works

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
When you manage infrastructure with code, following the right steps in order is very important. This helps avoid mistakes and keeps your cloud resources safe and organized.
When you want to create a new server or database in the cloud using code.
When you need to update your cloud resources without breaking anything.
When you want to see what changes will happen before applying them.
When you want to keep track of your infrastructure changes over time.
When you want to share your infrastructure setup with your team safely.
Config File - main.tf
main.tf
terraform {
  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 4.0"
    }
  }
  required_version = ">= 1.3.0"
}

provider "aws" {
  region = "us-east-1"
}

resource "aws_s3_bucket" "example_bucket" {
  bucket = "example-terraform-bucket-12345"
  acl    = "private"
}

This file tells Terraform to use the AWS provider in the us-east-1 region. It defines one resource: an S3 bucket named "example-terraform-bucket-12345" with private access.

The terraform block sets the provider version and Terraform version requirements.

Commands
This command sets up Terraform in your folder. It downloads the AWS provider plugin so Terraform can talk to AWS.
Terminal
terraform init
Expected OutputExpected
Initializing the backend... Initializing provider plugins... - Finding hashicorp/aws versions matching "~> 4.0"... - Installing hashicorp/aws v4.60.0... - Installed hashicorp/aws v4.60.0 (signed by HashiCorp) Terraform has been successfully initialized! You may now begin working with Terraform. Try running "terraform plan" to see any changes that are required for your infrastructure.
This command shows what Terraform will do if you apply your changes. It helps you check before making any real changes.
Terminal
terraform plan
Expected OutputExpected
An execution plan has been generated and is shown below. Resource actions are indicated with the following symbols: + create Terraform will perform the following actions: # aws_s3_bucket.example_bucket will be created + resource "aws_s3_bucket" "example_bucket" { + acl = "private" + bucket = "example-terraform-bucket-12345" + force_destroy = false + id = (known after apply) + region = (known after apply) } Plan: 1 to add, 0 to change, 0 to destroy.
This command makes the changes in your cloud. The flag skips asking for confirmation to speed up the process.
Terminal
terraform apply -auto-approve
Expected OutputExpected
aws_s3_bucket.example_bucket: Creating... aws_s3_bucket.example_bucket: Creation complete after 2s [id=example-terraform-bucket-12345] Apply complete! Resources: 1 added, 0 changed, 0 destroyed.
→
-auto-approve - Skip confirmation prompt to apply changes immediately
This command removes the resources you created. The flag skips confirmation to delete immediately.
Terminal
terraform destroy -auto-approve
Expected OutputExpected
aws_s3_bucket.example_bucket: Refreshing state... [id=example-terraform-bucket-12345] An execution plan has been generated and is shown below. Resource actions are indicated with the following symbols: - destroy Terraform will perform the following actions: # aws_s3_bucket.example_bucket will be destroyed - resource "aws_s3_bucket" "example_bucket" { - acl = "private" -> null - bucket = "example-terraform-bucket-12345" -> null - force_destroy = false -> null - id = "example-terraform-bucket-12345" -> null - region = "us-east-1" -> null } Plan: 0 to add, 0 to change, 1 to destroy. aws_s3_bucket.example_bucket: Destroying... aws_s3_bucket.example_bucket: Destruction complete after 1s Destroy complete! Resources: 1 destroyed.
→
-auto-approve - Skip confirmation prompt to destroy resources immediately
Key Concept

If you remember nothing else from this pattern, remember: always initialize, plan, apply, and destroy in order to safely manage your infrastructure.

Common Mistakes
Running 'terraform apply' without running 'terraform init' first
Terraform won't have the necessary provider plugins downloaded, so it will fail to apply changes.
Always run 'terraform init' once before planning or applying changes.
Skipping 'terraform plan' and applying changes directly
You might make unintended changes or delete resources by accident.
Run 'terraform plan' to review changes before applying them.
Not destroying resources when cleaning up
Resources stay running and can cost money or cause conflicts.
Use 'terraform destroy' to remove resources when you no longer need them.
Summary
Run 'terraform init' to set up Terraform and download providers.
Use 'terraform plan' to preview changes before applying.
Apply changes with 'terraform apply' to create or update resources.
Clean up with 'terraform destroy' to remove resources safely.

Practice

(1/5)
1. Why is it important to run terraform plan before terraform apply?
easy
A. It shows the changes Terraform will make before applying them
B. It automatically applies changes without confirmation
C. It deletes all existing resources immediately
D. It skips validation of the configuration files

Solution

  1. Step 1: Understand the purpose of terraform plan

    This command previews the changes Terraform will make to your infrastructure without applying them.
  2. Step 2: Compare with terraform apply

    terraform apply actually makes the changes, so planning first helps avoid mistakes.
  3. Final Answer:

    It shows the changes Terraform will make before applying them -> Option A
  4. Quick Check:

    Plan previews changes = D [OK]
Hint: Plan first to preview changes, avoid surprises [OK]
Common Mistakes:
  • Skipping plan and applying directly
  • Thinking plan applies changes
  • Confusing plan with destroy
2. Which command correctly initializes a Terraform working directory before planning or applying?
easy
A. terraform init
B. terraform start
C. terraform deploy
D. terraform configure

Solution

  1. Step 1: Identify the initialization command

    terraform init sets up the working directory by downloading providers and preparing backend.
  2. Step 2: Check other options

    Commands like terraform start, deploy, or configure do not exist in Terraform.
  3. Final Answer:

    terraform init -> Option A
  4. Quick Check:

    Initialize with init = B [OK]
Hint: Init first to prepare your workspace [OK]
Common Mistakes:
  • Using non-existent commands
  • Trying to apply before init
  • Confusing init with plan
3. Given this Terraform workflow:
terraform init
tf plan
tf apply

What will happen if you run terraform apply without running terraform plan first?
medium
A. Terraform will apply changes immediately without preview
B. Terraform will show an error and stop
C. Terraform will automatically run plan before apply
D. Terraform will delete all resources

Solution

  1. Step 1: Understand terraform apply behavior

    Terraform always performs an internal plan, shows the execution plan (preview of changes), and prompts for confirmation before applying.
  2. Step 2: Check if plan is mandatory

    Running terraform plan first is recommended for detailed review and saving plans, but terraform apply automatically runs the plan step.
  3. Final Answer:

    Terraform will automatically run plan before apply -> Option C
  4. Quick Check:

    Apply auto-runs plan [OK]
Hint: Apply always plans first internally [OK]
Common Mistakes:
  • Assuming apply always errors without plan
  • Thinking apply auto-runs plan silently
  • Believing apply deletes resources by default
4. You ran terraform apply but noticed unexpected resource deletions. What is the most likely cause related to workflow?
medium
A. Running terraform init twice
B. Skipping terraform plan and not reviewing changes
C. Using an outdated Terraform version
D. Not setting environment variables

Solution

  1. Step 1: Identify workflow mistake

    Skipping terraform plan means you miss previewing changes, leading to surprises like deletions.
  2. Step 2: Evaluate other options

    Running init twice, outdated version, or missing env vars usually cause errors, not unexpected deletions.
  3. Final Answer:

    Skipping terraform plan and not reviewing changes -> Option B
  4. Quick Check:

    Skip plan = risk of unwanted deletions [OK]
Hint: Always plan and review before applying [OK]
Common Mistakes:
  • Ignoring plan output
  • Blaming init for deletions
  • Assuming version causes deletions
5. You want to safely update your cloud infrastructure with Terraform. Which workflow sequence best prevents downtime and mistakes?
hard
A. terraform plan -> terraform apply -> terraform init
B. terraform apply -> terraform plan -> terraform init
C. terraform apply -> terraform init -> terraform plan
D. terraform init -> terraform plan -> review plan -> terraform apply

Solution

  1. Step 1: Understand the correct workflow order

    First, terraform init prepares the workspace, then terraform plan previews changes, followed by reviewing the plan carefully.
  2. Step 2: Apply changes only after review

    Applying changes after review ensures safety and avoids downtime or mistakes.
  3. Final Answer:

    terraform init -> terraform plan -> review plan -> terraform apply -> Option D
  4. Quick Check:

    Init, plan, review, apply = C [OK]
Hint: Init, plan, review, then apply for safe updates [OK]
Common Mistakes:
  • Applying before planning
  • Skipping plan review
  • Running commands in wrong order