SkillByAIOpen interactive version →

Lesson 25 / 25

A Terraform Review Checklist

Questions for every change.

Before approving a plan

Are providers and modules pinned, with the lock file committed? Are variables typed, validated and documented, with secrets kept out of code? Does the plan contain only expected changes, and is every destroy or replacement understood? Are refactors covered by moved blocks? Are critical resources protected with prevent_destroy and provider deletion protection? Is state remote, locked, encrypted and access-controlled per environment? Did fmt, validate, linters and policy checks pass in CI?

The checklist

Use it in every infrastructure review.

[ ] provider + module versions pinned; .terraform.lock.hcl committed
[ ] variables typed, validated, described; no secrets in .tf/.tfvars
[ ] plan read: every destroy / replace explained
[ ] refactors use moved blocks; imports end with "no changes"
[ ] for_each for named items; count only for identical copies or toggles
[ ] prevent_destroy + provider deletion protection on critical data
[ ] remote state: locked, encrypted, access-controlled, one per environment
[ ] fmt, validate, linters, policy checks green in CI
[ ] apply only the reviewed saved plan, from CI
[ ] drift detection scheduled

Practise with local providers

The local and random providers used in this course let you try every workflow safely without a cloud bill.

Quick check: Which item belongs on a Terraform review checklist?

  • Applying from laptops without a plan
  • Secrets committed in terraform.tfvars
  • Every destroy or replacement in the plan is understood and intended
  • Unpinned provider versions
Answer

Every destroy or replacement in the plan is understood and intended — Read the plan; pin; protect.