पाठ 10 / 25

Saved Plans and JSON Output

Apply exactly what was reviewed.

plan -out and show -json

terraform plan -out=tfplan saves a plan; terraform apply tfplan applies exactly that plan, failing if the state changed in between. This is the basis of safe CI workflows: plan on a pull request, review, then apply the saved plan. terraform show -json tfplan turns the plan into machine-readable JSON for policy checks (for example, block any destroy of a database) and summaries.

Summarising a saved plan with jq, run

I ran this with Terraform 1.16.4 and the hashicorp/local 2.9.1 and hashicorp/random 3.9.1 providers, which manage local files and random values, so no cloud account was needed; each example starts from a fresh directory. The saved plan for the for_each and count demo is converted to JSON and summarised as one line per resource change: six creates.

terraform plan -no-color -out=tfplan >/dev/null
terraform show -json tfplan | jq -r '.resource_changes[] | "\(.change.actions[0]) \(.address)"'

Output:

create local_file.by_index[0]
create local_file.by_index[1]
create local_file.by_index[2]
create local_file.by_key["api"]
create local_file.by_key["web"]
create local_file.by_key["worker"]

Gate destroys in CI

Scan plan JSON for delete actions on critical resource types and require extra approval when found.

त्वरित जाँच: Why apply a saved plan file in CI?

  • It applies exactly what was reviewed and fails if state changed meanwhile
  • It is faster to type
  • It skips providers
  • It deletes the state
Answer

It applies exactly what was reviewed and fails if state changed meanwhile — Review and apply the same thing.