Concept and mechanism
init prepares the directory, including providers, modules, and backend. fmt handles presentation; validate checks internal validity but does not guarantee credentials, quotas, or acceptance by remote services. plan calculates proposed changes in the context of values and observed objects. apply executes actions and may fail after already changing part of the infrastructure. destroy is destructive within the managed scope and requires its own authorization. A saved plan can connect review with execution, but it contains sensitive information and depends on conditions that may change.
Guided application
Before a storage change, inspect creation, update, and replacement in the plan rather than only resource totals. Confirm changed attributes match the request. If a persistent object is replaced, include data strategy, window, and recovery in the decision. Link the exact artifact to approval and protect it from unauthorized reading. After execution, validate application criteria; Terraform completion alone does not demonstrate that the next batch will succeed.
An attribute change requests replacement. Review turns the request into a continuity and data decision before any apply.
Common pitfalls
Treating validate as a remote-access test; assuming every saved plan remains applicable.
Related topics: Configuration, dependencies, and secrets · Modules and usage contracts
Each command produces bounded evidence; functional acceptance completes execution.
Reference: terraform plan · 004