Memory hook: Format, initialise, validate, plan, then approve.
Must remember
| Command | What to remember |
|---|---|
terraform fmt -check -recursive |
Checks canonical formatting; does not contact a cloud API. |
terraform init |
Prepares the backend, modules and providers; rerun after their configuration changes. |
terraform validate |
Checks configuration consistency and types using installed dependencies. It does not prove API authorization or service capacity. |
terraform plan -out=review.tfplan |
Refreshes observations by default and saves proposed actions and input values. Treat the file as sensitive. |
terraform show review.tfplan |
Inspects the saved plan. |
terraform apply review.tfplan |
Executes the saved plan without the usual interactive approval prompt. Protect this step in automation. |
terraform destroy |
Plans destruction of objects managed by the current state; it is not an account-wide cleanup. |
+ means create, ~ update, - destroy and a combined delete/create marker means replacement. Values marked unknown become known later. A plan without -out is a preview; a later apply creates a fresh plan.
Practice on paper: trace a provider upgrade, a module-source change and an input change through this sequence. These notes do not ask you to run apply or destroy against a cloud account.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Review precisely what automation executes | Save the plan, protect it and apply that artifact. |
| Catch syntax/type errors early | Initialise dependencies, then validate; also plan in the intended environment. |
Traps
- Plan can read remote APIs and acquire a lock; it is not always offline.
- Destroy cannot remove resources that Terraform has forgotten or never managed.
Active recall
1. Does fmt validate a resource argument?
No. Formatting and semantic validation are separate.
2. Does validate confirm cloud permissions?
No. It checks configuration consistency, not successful remote API execution.
3. Why protect a plan file?
It can contain secrets and detailed configuration/state values.
4. Does applying a saved plan ask for confirmation?
No. Approval must happen before invoking apply with that file.
5. Why can a destroyed lab leave an unmanaged bucket?
Destroy acts on managed state, not every object in an account.