# Anatomy of a Plan — Terraform

Source: https://www.skillbyai.com/en/terraform/p-anatomy

> Symbols and summaries.

## + create, ~ update, -/+ replace, - destroy

A plan lists each affected resource with a symbol: `+` create, `~` update in place, `-/+` destroy and re-create (replacement), `-` destroy. Values shown as `(known after apply)` are computed by the provider. The summary line counts adds, changes and destroys. Read destroys and replacements especially carefully: for a database or a load balancer, a replacement can mean downtime or data loss.

## Know exactly what will happen

Plans mark each change as create, update, replace or destroy; reading them carefully prevents outages.

![Three ideas: plan anatomy, idempotent applies, replacement.](assets/figures/terraform/section-3-map.svg) — Figure 3.1 — Plan anatomy, idempotence and replacement.

## The first plan for the demo, run

I ran this with Terraform 1.16.4 and the hashicorp/local 2.9.1 and hashicorp/random 3.9.1 providers, which manage local files and random values, so no cloud account was needed; each example starts from a fresh directory. The plan will create one file. The content and filename come from configuration; hashes and the id are only known after apply.

```bash
terraform plan -no-color | sed -n "/Terraform will perform/,/Changes to Outputs/p"
```

Output:

```
Terraform will perform the following actions:

  # local_file.config will be created
  + resource "local_file" "config" {
      + content              = <<-EOT
            app=shop
            env=dev
        EOT
      + content_base64sha256 = (known after apply)
      + content_base64sha512 = (known after apply)
      + content_md5          = (known after apply)
      + content_sha1         = (known after apply)
      + content_sha256       = (known after apply)
      + content_sha512       = (known after apply)
      + directory_permission = "0777"
      + file_permission      = "0777"
      + filename             = "./out/shop-dev.conf"
      + id                   = (known after apply)
    }

Plan: 1 to add, 0 to change, 0 to destroy.

Changes to Outputs:
```

## Search plans for destroy

In large plans, search for "destroy" and "must be replaced" before approving.

**Quiz:** Which symbol in a plan means destroy and re-create?

- [ ] ~
- [ ] +
- [x] -/+
- [ ] <=

*Answer:* -/+. Replacement can cause downtime.
