What’s New

terraform

Developer Tools

terraform release notes.

Latest v1.15.8 · by terraformWebsitehashicorp/terraform

Changelog

v1.16.0-beta1

Pre-release
Added
  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply
  • The new `store` block in `terraform_data` can hold ephemeral and sensitive values across plan and apply
  • Providers can now use nested blocks as computed values
  • Import blocks inside modules are now supported
  • Terraform is now available as a pre-built binary for Linux s390x (zLinux)
  • Resource action triggers can now use `on_failure` modes of `halt`, `taint`, or `continue`
Changed
  • The `state show` command can now produce machine-readable output when supplied with the `-json` flag
  • The `workspace list` command can now produce machine-readable output when supplied with the `-json` flag
  • Terraform now reports which resources were left behind when `skip_cleanup` is set in tests
  • Action configurations in stacks now have access to a `caller` symbol containing the object value of the calling resource
  • Actions can now use `before_destroy` and `after_destroy` events
  • Terraform now displays a summary of policy evaluation outcomes for `plan` and `apply` runs against HCP Terraform
  • Terraform now resolves policy plugin credentials from the configured cloud or remote backend during `init`, `plan`, and `apply`
  • The `terraform graph` command can now output graphs in Mermaid format using the `-format=mermaid` flag
  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings
  • Resource `lifecycle` blocks now support `destroy = false` to prevent a resource from being destroyed
  • The `contains()` function can now test for `null` values
  • The `terraform console` command now accepts an optional `-scope=<module address>` flag to evaluate expressions within the scope of a module or module instance
  • The `-invoke` flag can now be combined with `-target` to specify the calling resource instance when multiple resources trigger the same action
  • The `terraform stacks` command now automatically infers the target hostname from the local credentials file when neither `TF_STACKS_HOSTNAME` nor `TF_CLOUD_HOSTNAME` is set
Fixed
  • Import blocks now correctly respect provider local names
  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has `lifecycle.precondition` or `lifecycle.postcondition` blocks
  • Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes
  • Terraform now raises a warning when a file referenced via the `-filter` flag does not exist
  • Terraform no longer removes locks from the dependency lock file for providers configured as `dev_override`
  • Terraform now warns when unmanaged providers are in use and may impact provider installation
  • Actions are now invoked with respect to all resource dependencies
  • Terraform now returns the correct error when an `import` target exists in state but has no corresponding configuration
  • The `merge()` function no longer panics when passed `null` objects
1.16.0-beta1 (July 23, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449)

  • stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events. (#38668)

  • cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. (#38715)

  • policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply, rather than requiring the plugin to read credentials itself. (#38716)

  • graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. (#38719)

  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. (#38784)

  • The contains() function can now test for null values. (#38792)

  • console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)

  • -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. (#38845)

  • The terraform stacks command now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set (#38896)

BUG FIXES:

  • import blocks now correctly respect provider local names. (#38338)

  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. (#38586)

  • workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)

  • test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. (#38603)

  • init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override. (#38634)

  • init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. (#38782)

  • The merge() function no longer panics when passed null objects. (#38792)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

UPGRADE NOTES:

  • bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.16.0-alpha20260715

Pre-release
Added
  • Store PlannedPrivate data for providers
  • New store block in terraform_data that can handle ephemeral and sensitive values
  • Providers can now use nested blocks as computed values
  • Add support for import blocks inside modules
  • Produce builds for Linux s390x (zLinux)
  • The workspace list command can now produce machine-readable output when supplied with the -json flag
  • Resource action triggers can now use on_failure modes of halt, taint, or continue
Changed
  • terraform state show accepts a -json flag
  • Show info when resources are left behind due to skip_cleanup
  • Action configuration now has a new caller symbol which contains the object value from the calling resource
  • Actions can now use before_destroy and after_destroy events
  • Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform
  • Resolve the policy plugin entitlement from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself
  • The terraform graph command now accepts a -format flag, and can output graphs in Mermaid format
  • The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance
  • Support destroy=false in resource lifecycle blocks
  • The contains() function can now test for null
Fixed
  • Import blocks no longer ignore provider local names
  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition
  • Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band
1.16.0-alpha20260715 (July 15, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events (#38668)

  • cloud: Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform (#38715)

  • policy: Resolve the policy plugin entitlement (host, token, organization) from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself (#38716)

  • The 'terraform graph' command now accepts a -format flag, and can output graphs in Mermaid format (#38719)

  • child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • Support destroy=false in resource lifecycle blocks. (#38784)

  • contains() function can now test for null (#38792)

  • The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)

  • If -invoke results in multiple resource calls triggering the action, it can now be combined with -target to specify the calling resource instance (#38845)

BUG FIXES:

  • import blocks no longer ignore provider local names (#38338)

  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition (#38586)

  • workspace: Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band (#38594)

  • test: Terraform will now raise a warning when a file referenced via -filter flag does not exist. (#38603)

  • init: Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override (#38634)

  • init: Add warnings when unmanaged providers are in use and will impact provider installation processes. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • return correct error when import target exists in state, but not config (#38782)

  • merge no longer panics with null objects (#38792)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

UPGRADE NOTES:

  • Provisioner bastion_host_key is now correctly applied. Existing usage of bastion_host_key should verify the configured key is correct. (#38318)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
  • terraform query: The experimental -policies flag permits specifying one or more policy set directory paths to evaluate policies against resources discovered by list blocks during a query operation.
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.15.8

Changed
  • Provider installation logging re-introduces initializing_provider_plugin_message to replace initializing_provider_plugin_from_config_message and initializing_provider_plugin_from_state_message
  • Module installation now occurs after the backend is initialized during provider installation
Fixed
  • Fix terraform init error when installing providers sourced from a service-discovery alias advertised by the configured backend
1.15.8 (July 8, 2026)

BUG FIXES:

  • Fix terraform init error when installing providers sourced from a service-discovery alias advertised by the configured backend (such as localterraform.com)

NOTES:

  • command/init: Provider installation was changed to enable future enhancements in the area. This effectively reverses the log message changes from v1.15. initializing_provider_plugin_message is being re-introduced to replace the short-lived two message types initializing_provider_plugin_from_config_message & initializing_provider_plugin_from_state_message. The change should not have any significant end-user impact aside from the command output. (#38838)

  • command/init: Provider installation was changed to enable future enhancements in the area. This partially reverses the init event order changes from v1.15; module installation will now occur after the backend is initialized. The change should not have any significant end-user impact aside from the command output. (#38838)

v1.16.0-alpha20260708

Pre-release
Added
  • Store PlannedPrivate data for providers
  • New store block in terraform_data that can handle ephemeral and sensitive values
  • Providers can now use nested blocks as computed values
  • Add support for import blocks inside modules
  • Produce builds for Linux s390x (zLinux)
  • The workspace list command can now produce machine-readable output when supplied with the -json flag
  • Resource action triggers can now use on_failure modes of halt, taint, or continue
Changed
  • terraform state show command accepts a -json flag
  • Show info when resources are left behind due to skip_cleanup
  • Action configuration now has a new caller symbol which contains the object value from the calling resource
  • Actions can now use before_destroy and after_destroy events
  • Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform
  • Resolve the policy plugin entitlement from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself
  • The terraform graph command now accepts a -format flag, and can output graphs in Mermaid format
  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings
  • Support destroy=false in resource lifecycle blocks
  • The contains() function can now test for null
Fixed
  • Import blocks no longer ignore provider local names
  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition
  • Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band
1.16.0-alpha20260708 (July 08, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events (#38668)

  • cloud: Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform (#38715)

  • policy: Resolve the policy plugin entitlement (host, token, organization) from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself (#38716)

  • The 'terraform graph' command now accepts a -format flag, and can output graphs in Mermaid format (#38719)

  • child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • Support destroy=false in resource lifecycle blocks. (#38784)

  • contains() function can now test for null (#38792)

BUG FIXES:

  • import blocks no longer ignore provider local names (#38338)

  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition (#38586)

  • workspace: Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band (#38594)

  • test: Terraform will now raise a warning when a file referenced via -filter flag does not exist. (#38603)

  • init: Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override (#38634)

  • init: Add warnings when unmanaged providers are in use and will impact provider installation processes. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • return correct error when import target exists in state, but not config (#38782)

  • merge no longer panics with null objects (#38792)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

  • command/init: Provider installation was changed to enable future enhancements in the area. This effectively reverses the log message changes from v1.15. initializing_provider_plugin_message is being re-introduced to replace the short-lived two message types initializing_provider_plugin_from_config_message & initializing_provider_plugin_from_state_message. The change should not have any significant end-user impact aside from the command output. (#38648)

  • command/init: Provider installation was changed to enable future enhancements in the area. This partially reverses the init event order changes from v1.15; module installation will now occur after the backend is initialized. The change should not have any significant end-user impact aside from the command output. (#38699)

UPGRADE NOTES:

  • Provisioner bastion_host_key is now correctly applied. Existing usage of bastion_host_key should verify the configured key is correct. (#38318)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
  • terraform query: The experimental -policies flag permits specifying one or more policy set directory paths to evaluate policies against resources discovered by list blocks during a query operation.
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.16.0-alpha20260706

Pre-release
Added
  • Store PlannedPrivate data for providers
  • New store block in terraform_data that can handle ephemeral and sensitive values
  • Providers can now use nested blocks as computed values
  • Add support for import blocks inside modules
  • Produce builds for Linux s390x (zLinux)
  • The workspace list command can now produce machine-readable output when supplied with the -json flag
  • Resource action triggers can now use on_failure modes of halt, taint, or continue
  • The terraform state show command accepts a -json flag
  • The terraform graph command now accepts a -format flag and can output graphs in Mermaid format
Changed
  • Show info when resources are left behind due to skip_cleanup
  • Action configuration now has a new caller symbol which contains the object value from the calling resource
  • Actions can now use before_destroy and after_destroy events
  • Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform
  • Resolve the policy plugin entitlement from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself
  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings
  • The contains() function can now test for null
Fixed
  • Import blocks no longer ignore provider local names
  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition
  • Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band
  • Terraform will now raise a warning when a file referenced via -filter flag does not exist
  • Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override
1.16.0-alpha20260706 (July 06, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events (#38668)

  • cloud: Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform (#38715)

  • policy: Resolve the policy plugin entitlement (host, token, organization) from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself (#38716)

  • The 'terraform graph' command now accepts a -format flag, and can output graphs in Mermaid format (#38719)

  • child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • contains() function can now test for null (#38792)

BUG FIXES:

  • import blocks no longer ignore provider local names (#38338)

  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition (#38586)

  • workspace: Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band (#38594)

  • test: Terraform will now raise a warning when a file referenced via -filter flag does not exist. (#38603)

  • init: Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override (#38634)

  • init: Add warnings when unmanaged providers are in use and will impact provider installation processes. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • merge no longer panics with null objects (#38792)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

  • command/init: Provider installation was changed to enable future enhancements in the area. This effectively reverses the log message changes from v1.15. initializing_provider_plugin_message is being re-introduced to replace the short-lived two message types initializing_provider_plugin_from_config_message & initializing_provider_plugin_from_state_message. The change should not have any significant end-user impact aside from the command output. (#38648)

  • command/init: Provider installation was changed to enable future enhancements in the area. This partially reverses the init event order changes from v1.15; module installation will now occur after the backend is initialized. The change should not have any significant end-user impact aside from the command output. (#38699)

UPGRADE NOTES:

  • Provisioner bastion_host_key is now correctly applied. Existing usage of bastion_host_key should verify the configured key is correct. (#38318)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
  • terraform query: The experimental -policies flag permits specifying one or more policy set directory paths to evaluate policies against resources discovered by list blocks during a query operation.
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.16.0-alpha20260701

Pre-release
Added
  • Store PlannedPrivate data for providers
  • New store block in terraform_data that can handle ephemeral and sensitive values
  • Providers can now use nested blocks as computed values
  • Add support for import blocks inside modules
  • Produce builds for Linux s390x (zLinux)
  • The workspace list command can now produce machine-readable output when supplied with the -json flag
  • Resource action triggers can now use on_failure modes of halt, taint, or continue
Changed
  • terraform state show accepts a -json flag
  • Show info when resources are left behind due to skip_cleanup
  • Action configuration now has a new caller symbol which contains the object value from the calling resource
  • Actions can now use before_destroy and after_destroy events
  • Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform
  • Resolve the policy plugin entitlement from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself
  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings
  • contains() function can now test for null
Fixed
  • Import blocks no longer ignore provider local names
  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition
  • Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band
  • Terraform will now raise a warning when a file referenced via -filter flag does not exist
  • Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override
1.16.0-alpha20260701 (July 01, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events (#38668)

  • cloud: Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform (#38715)

  • policy: Resolve the policy plugin entitlement (host, token, organization) from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself (#38716)

  • child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • contains() function can now test for null (#38792)

BUG FIXES:

  • import blocks no longer ignore provider local names (#38338)

  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition (#38586)

  • workspace: Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band (#38594)

  • test: Terraform will now raise a warning when a file referenced via -filter flag does not exist. (#38603)

  • init: Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override (#38634)

  • init: Add warnings when unmanaged providers are in use and will impact provider installation processes. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • merge no longer panics with null objects (#38792)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

  • command/init: Provider installation was changed to enable future enhancements in the area. This effectively reverses the log message changes from v1.15. initializing_provider_plugin_message is being re-introduced to replace the short-lived two message types initializing_provider_plugin_from_config_message & initializing_provider_plugin_from_state_message. The change should not have any significant end-user impact aside from the command output. (#38648)

  • command/init: Provider installation was changed to enable future enhancements in the area. This partially reverses the init event order changes from v1.15; module installation will now occur after the backend is initialized. The change should not have any significant end-user impact aside from the command output. (#38699)

UPGRADE NOTES:

  • Provisioner bastion_host_key is now correctly applied. Existing usage of bastion_host_key should verify the configured key is correct. (#38318)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.16.0-alpha20260626

Pre-release
Added
  • Store PlannedPrivate data for providers
  • New store block in terraform_data that can handle ephemeral and sensitive values
  • Providers can now use nested blocks as computed values
  • Add support for import blocks inside modules
  • Produce builds for Linux s390x (zLinux)
  • The workspace list command can now produce machine-readable output when supplied with the -json flag
  • Resource action triggers can now use on_failure modes of halt, taint, or continue
  • terraform state show accepts a -json flag
  • Actions can now use before_destroy and after_destroy events
  • Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform
Changed
  • Show info when resources are left behind due to skip_cleanup
  • Action configuration now has a new caller symbol which contains the object value from the calling resource
  • Resolve the policy plugin entitlement (host, token, organization) from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself
Fixed
  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings
  • Import blocks no longer ignore provider local names
  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition
  • Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band
  • Terraform will now raise a warning when a file referenced via -filter flag does not exist
  • Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override
  • Add warnings when unmanaged providers are in use and will impact provider installation processes
1.16.0-alpha20260626 (June 26, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events (#38668)

  • cloud: Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform (#38715)

  • policy: Resolve the policy plugin entitlement (host, token, organization) from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself (#38716)

  • child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

BUG FIXES:

  • import blocks no longer ignore provider local names (#38338)

  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition (#38586)

  • workspace: Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band (#38594)

  • test: Terraform will now raise a warning when a file referenced via -filter flag does not exist. (#38603)

  • init: Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override (#38634)

  • init: Add warnings when unmanaged providers are in use and will impact provider installation processes. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

  • command/init: Provider installation was changed to enable future enhancements in the area. This effectively reverses the log message changes from v1.15. initializing_provider_plugin_message is being re-introduced to replace the short-lived two message types initializing_provider_plugin_from_config_message & initializing_provider_plugin_from_state_message. The change should not have any significant end-user impact aside from the command output. (#38648)

  • command/init: Provider installation was changed to enable future enhancements in the area. This partially reverses the init event order changes from v1.15; module installation will now occur after the backend is initialized. The change should not have any significant end-user impact aside from the command output. (#38699)

UPGRADE NOTES:

  • Provisioner bastion_host_key is now correctly applied. Existing usage of bastion_host_key should verify the configured key is correct. (#38318)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.15.7

Fixed
  • Add concurrency safety to configs.Parser and SourceBundleParser
  • Fix submodule variable validation during init
1.15.7 (June 24, 2026)

BUG FIXES:

  • Add concurrency safety to configs.Parser and SourceBundleParser (#38745)

  • Fix submodule variable validation during init (#38770)

v1.16.0-alpha20260624

Pre-release
Added
  • Store PlannedPrivate data for providers
  • New store block in terraform_data that can handle ephemeral and sensitive values
  • Providers can now use nested blocks as computed values
  • Support for import blocks inside modules
  • Produce builds for Linux s390x (zLinux)
  • The workspace list command can now produce machine-readable output when supplied with the -json flag
  • Resource action triggers can now use on_failure modes of halt, taint, or continue
Changed
  • The terraform state show command now accepts a -json flag
  • Show info when resources are left behind due to skip_cleanup
  • Action configuration now has a new caller symbol which contains the object value from the calling resource
  • Actions can now use before_destroy and after_destroy events
  • Policy plugin entitlement is now resolved from the configured cloud/remote backend for init, plan, and apply instead of the plugin reading credentials itself
Fixed
  • Import blocks no longer ignore provider local names
  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition
  • Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band
  • Terraform will now raise a warning when a file referenced via -filter flag does not exist
  • Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override
  • Add warnings when unmanaged providers are in use and will impact provider installation processes
  • Actions are now invoked with respect to all resource dependencies
1.16.0-alpha20260624 (June 24, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events (#38668)

  • policy: Resolve the policy plugin entitlement (host, token, organization) from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself (#38716)

BUG FIXES:

  • import blocks no longer ignore provider local names (#38338)

  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition (#38586)

  • workspace: Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band (#38594)

  • test: Terraform will now raise a warning when a file referenced via -filter flag does not exist. (#38603)

  • init: Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override (#38634)

  • init: Add warnings when unmanaged providers are in use and will impact provider installation processes. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

  • command/init: Provider installation was changed to enable future enhancements in the area. This effectively reverses the log message changes from v1.15. initializing_provider_plugin_message is being re-introduced to replace the short-lived two message types initializing_provider_plugin_from_config_message & initializing_provider_plugin_from_state_message. The change should not have any significant end-user impact aside from the command output. (#38648)

  • command/init: Provider installation was changed to enable future enhancements in the area. This partially reverses the init event order changes from v1.15; module installation will now occur after the backend is initialized. The change should not have any significant end-user impact aside from the command output. (#38699)

UPGRADE NOTES:

  • Provisioner bastion_host_key is now correctly applied. Existing usage of bastion_host_key should verify the configured key is correct. (#38318)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.16.0-alpha20260617

Pre-release
Added
  • Store PlannedPrivate data for providers
  • New store block in terraform_data that can handle ephemeral and sensitive values
  • Providers can now use nested blocks as computed values
  • Support for import blocks inside modules
  • Produce builds for Linux s390x (zLinux)
  • The workspace list command can now produce machine-readable output when supplied with the -json flag
  • Resource action triggers can now use on_failure modes of halt, taint, or continue
Changed
  • terraform state show command accepts a -json flag
  • Show info when resources are left behind due to skip_cleanup
  • Action configuration now has a new caller symbol which contains the object value from the calling resource
  • Actions can now use before_destroy and after_destroy events
  • Actions are now invoked with respect to all resource dependencies
  • Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process
Fixed
  • Import blocks no longer ignore provider local names
  • Fix terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition
  • Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band
  • Terraform will now raise a warning when a file referenced via -filter flag does not exist
  • Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override
  • Add warnings when unmanaged providers are in use and will impact provider installation processes
1.16.0-alpha20260617 (June 17, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events (#38668)

BUG FIXES:

  • import blocks no longer ignore provider local names (#38338)

  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition (#38586)

  • workspace: Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band (#38594)

  • test: Terraform will now raise a warning when a file referenced via -filter flag does not exist. (#38603)

  • init: Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override (#38634)

  • init: Add warnings when unmanaged providers are in use and will impact provider installation processes. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

  • command/init: Provider installation was changed to enable future enhancements in the area. This effectively reverses the log message changes from v1.15. initializing_provider_plugin_message is being re-introduced to replace the short-lived two message types initializing_provider_plugin_from_config_message & initializing_provider_plugin_from_state_message. The change should not have any significant end-user impact aside from the command output. (#38648)

  • command/init: Provider installation was changed to enable future enhancements in the area. This partially reverses the init event order changes from v1.15; module installation will now occur after the backend is initialized. The change should not have any significant end-user impact aside from the command output. (#38699)

UPGRADE NOTES:

  • Provisioner bastion_host_key is now correctly applied. Existing usage of bastion_host_key should verify the configured key is correct. (#38318)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
Previous Releases

For information on prior major and minor releases, refer to their changelogs: