Lesson 2 / 25

init, plan, apply

The core loop.

Three commands

terraform init prepares a working directory: downloads the required providers and modules and configures the backend where state is stored. terraform plan compares the configuration with the recorded state (and refreshes real resources) and shows what would change, without changing anything. terraform apply executes a plan after confirmation. terraform destroy removes everything the configuration manages. Run plan often and read it carefully; it is your safety net.

Initialising a working directory, run

I ran this with Terraform 1.16.4 and the hashicorp/local 2.9.1 and hashicorp/random 3.9.1 providers, which manage local files and random values, so no cloud account was needed; each example starts from a fresh directory. init downloads the providers named in required_providers, verifying their signatures, and records exact versions in .terraform.lock.hcl.

terraform init -no-color | grep -E "Installing|Installed|initialized"

Output:

- Installing hashicorp/local v2.9.1...
- Installed hashicorp/local v2.9.1 (signed by HashiCorp)
- Installing hashicorp/random v3.9.1...
- Installed hashicorp/random v3.9.1 (signed by HashiCorp)
Terraform has been successfully initialized!

Commit the lock file

Commit .terraform.lock.hcl so everyone and CI use the same provider versions; do not commit the .terraform directory.

Quick check: Which command shows proposed changes without making them?

  • terraform plan
  • terraform apply -auto-approve
  • terraform destroy
  • terraform init only
Answer

terraform plan — Plan before apply.