DevOps & Cloud · Cheatsheet
Terraform Commands Cheatsheet
Infrastructure as Code: init, plan, apply, state management, workspaces, and modules
59 commands 9 sections
No entry matches that filter.
-
terraform initInitialize working directory and download providers -
terraform planPreview changes before applying -
terraform applyApply changes to infrastructure -
terraform apply -auto-approveApply without confirmation prompt -
terraform destroyDestroy all managed infrastructure -
terraform destroy -target=aws_instance.webDestroy specific resource -
terraform validateValidate configuration syntax -
terraform fmtFormat .tf files to canonical style -
terraform fmt -recursiveFormat all .tf files recursively
-
terraform state listList all resources in state -
terraform state show aws_instance.webShow details of a resource in state -
terraform state mv old_name new_nameRename a resource in state -
terraform state rm aws_instance.webRemove resource from state (keep infra) -
terraform state pullOutput current state to stdout -
terraform state push local.tfstateOverwrite remote state (dangerous) -
terraform refreshDeprecated; prefer terraform plan/apply -refresh-only to review state changes -
terraform import aws_instance.web i-abc123Import existing resource into state
-
terraform plan -out=plan.tfplanSave plan to file -
terraform apply plan.tfplanApply a saved plan file -
terraform plan -target=aws_instance.webPlan for specific resource only -
terraform plan -var="region=us-west-2"Pass variable on command line -
terraform plan -var-file="prod.tfvars"Use variable file -
terraform plan -destroyPreview what destroy would do -
terraform plan -refresh-onlyDetect drift without changes
-
terraform workspace listList all workspaces -
terraform workspace new stagingCreate a new workspace -
terraform workspace select productionSwitch to a workspace -
terraform workspace showShow current workspace -
terraform workspace delete stagingDelete a workspace -
terraform.workspaceReference workspace name in config
-
resource "aws_instance" "web" { ami = "..." }Define a resource -
variable "region" { default = "us-east-1" }Declare an input variable -
output "ip" { value = aws_instance.web.public_ip }Define an output value -
data "aws_ami" "latest" { ... }Define a data source query -
locals { env = "prod" }Define local values -
module "vpc" { source = "./modules/vpc" }Use a module -
terraform { required_version = ">= 1.5" }Set required Terraform version
-
terraform init -upgradeUpgrade providers to latest allowed -
terraform providersShow required providers -
terraform providers lockGenerate lock file for providers -
terraform getDownload and update modules -
terraform get -updateForce update modules -
source = "hashicorp/aws"Use provider from Terraform Registry -
source = "git::https://example.com/module.git"Use module from Git repo
-
terraform outputShow all output values -
terraform output -jsonShow outputs as JSON -
terraform output ip_addressShow specific output value -
terraform showShow current state in human-readable form -
terraform show -json plan.tfplanShow plan as JSON -
terraform graph | dot -Tpng > graph.pngGenerate resource dependency graph -
terraform consoleInteractive expression evaluator
-
terraform { backend "s3" { ... } }Use remote state backend -
terraform plan -detailed-exitcodeExit code 2 if changes detected (CI) -
TF_LOG=DEBUG terraform planEnable debug logging -
TF_VAR_region="us-west-2" terraform planSet variable via environment -
-lock=falseSkip state locking (use with caution) -
-parallelism=10Set the concurrent operation limit to 10, the documented default
-
https://developer.hashicorp.com/terraform/cli/commands/planTerraform plan: review workflow, targeting limits, and parallelism settings. -
https://developer.hashicorp.com/terraform/cli/commands/refreshTerraform refresh: deprecated command and the refresh-only alternative.