# Plan-Based Review in CI — Terraform

Source: https://www.skillbyai.com/en/terraform/q-ci

> Every change through a pull request.

## fmt, validate, plan, review, apply

A common workflow: on every pull request, CI runs fmt -check, validate, linters and `terraform plan -out=tfplan`, posts the plan summary for review, and runs policy checks on the plan JSON. After approval and merge, CI applies the saved plan with credentials scoped to that environment (ideally short-lived OIDC credentials, not stored keys). Tools such as Atlantis, HCP Terraform, Spacelift or plain CI pipelines implement this pattern.

## A pipeline outline

Adapt to your CI system.

```text
on pull request:
  terraform fmt -check -recursive
  terraform init -input=false
  terraform validate
  tflint / checkov                      # lint + security rules
  terraform plan -input=false -out=tfplan
  terraform show -json tfplan | policy-check   # e.g. block deletes of databases
  post plan summary to the PR
on merge to main (per environment, with approval for prod):
  terraform apply -input=false tfplan  # the reviewed plan, short-lived credentials
```

## No applies from laptops

Route all applies through the pipeline so every change has a reviewed plan and an audit trail.

**Quiz:** Why apply from CI rather than from developer laptops?

- [ ] CI is always faster
- [ ] Laptops cannot run Terraform
- [x] Changes get a reviewed plan, consistent tooling and an audit trail
- [ ] It removes the need for state

*Answer:* Changes get a reviewed plan, consistent tooling and an audit trail. Process makes infrastructure changes safe.
