terraform

Infrastructure & DevOps

terraform release notes.

Latest v1.16.1 · by terraformWritten in GoWebsitehashicorp/terraformRSS

Branches

1.17
v1.17.0-alpha20260827Pre-release
1.16
v1.16.1
1.15
v1.15.9

Release activity

Release activity — 19 releases across 15 days since Jun 17, 2026. Each cell is one day; darker means more releases that day. Nothing is recorded before Jun 17, 2026. Older weeks are hidden at this screen width.
JunJulAugSep
SundayNo releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026No releases on Aug 9, 2026No releases on Aug 16, 2026No releases on Aug 23, 2026No releases on Aug 30, 2026No releases on Sep 6, 2026
MondayNo releases on Jun 22, 2026No releases on Jun 29, 20261 release on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026No releases on Aug 10, 2026No releases on Aug 17, 2026No releases on Aug 24, 2026No releases on Aug 31, 2026No releases on Sep 7, 2026
TuesdayNo releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026No releases on Aug 11, 2026No releases on Aug 18, 2026No releases on Aug 25, 2026No releases on Sep 1, 2026No releases on Sep 8, 2026
Wednesday1 release on Jun 17, 20262 releases on Jun 24, 20261 release on Jul 1, 20262 releases on Jul 8, 20261 release on Jul 15, 2026No releases on Jul 22, 20261 release on Jul 29, 20261 release on Aug 5, 20262 releases on Aug 12, 20262 releases on Aug 19, 20261 release on Aug 26, 20261 release on Sep 2, 2026No releases on Sep 9, 2026
ThursdayNo releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 20261 release on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026No releases on Aug 13, 2026No releases on Aug 20, 20261 release on Aug 27, 2026No releases on Sep 3, 2026
FridayNo releases on Jun 19, 20261 release on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026No releases on Aug 14, 2026No releases on Aug 21, 2026No releases on Aug 28, 2026No releases on Sep 4, 2026
SaturdayNo releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026No releases on Aug 8, 2026No releases on Aug 15, 2026No releases on Aug 22, 2026No releases on Aug 29, 2026No releases on Sep 5, 2026

19 releases since Jun 17, 2026, busiest day 2

Changelog

Filter releases by branch
19 of 19 releases

v1.16.1

Latest
Fixed 7
  • Fixed a bug causing the CLI to pause indefinitely after a run task failure with pending policy evaluations
  • Support referencing modules containing dynamic sources in Terraform Test
  • Fixed validation to ensure the provider versions in the lock file and configuration are compatible
  • Fix panic when import identity references sensitive value
  • Fixed a bug where import blocks would be ignored when multiple imports targeted different instances of a resource config using for_each or count
  • Fix a panic when state show is given an attribute path instead of a resource instance address
  • Fix create_before_destroy ordering in some combinations of changes

From terraform

1.16.1 (September 2, 2026)

BUG FIXES:

  • cloud: Fixed a bug causing the CLI to pause indefinitely after a run task failure with pending policy evaluations (#38751)

  • Support referencing modules containing dynamic sources in Terraform Test (#38950)

  • stacks: Fixed validation to ensure the provider versions in the lock file and configuration are compatible. (#38829)

  • Fix panic when import identity references sensitive value (#39013)

  • import: Fixed a bug where import blocks would be ignored when multiple imports targeted different instances of a resource config using for_each or count. (#39068)

  • state show: Fix a panic when given an attribute path instead of a resource instance address (#39087)

  • Fix create_before_destroy ordering in some combinations of changes (#39091)

View originalPermalink
How v1.16.1 went

v1.17.0-alpha20260827

Pre-release
Added 1
  • A new -minimal-refresh planning option has been added, which will only refresh resources that have proposed changes
Changed 3
  • Enrich init command log messages with provider versions
  • Display warning after successful login if user is subject to an organization's TTL policy
  • JSON output from version command now includes a new format_version field
Fixed 3
  • pow and log functions no longer panic when result is not a number
  • Terraform will now use and display diagnostics raised when renewing an ephemeral resource
  • Fix panic when import identity references sensitive value

From terraform

1.17.0-alpha20260827 (August 27, 2026)

NEW FEATURES:

  • A new -minimal-refresh planning option has been added, which will only refresh resources that have proposed changes. (#35290)

ENHANCEMENTS:

  • command/init: Enrich log messages with provider versions (#38918)

  • command/login: display warning after successful login if user is subject to an organization's TTL policy

BUG FIXES:

  • funcs: pow and log no longer panic when result is not a number (#38912)

  • ephemeral: Terraform will now use and display diagnostics raised when renewing an ephemeral resource. This may cause warnings to appear that previously were lost. We expect that any error diagnostics that were previously lost would have caused confusing downstream errors, so we do not anticipate this change to be breaking. (#38989)

  • Fix panic when import identity references sensitive value (#39013)

NOTES:

  • version: JSON output now includes a new format_version field, which will enable safer future changes of the command's JSON output format. It is assumed existing tooling ignores unknown fields and therefore this change should not be breaking in itself but we advice consumers to pay attention to format_version in future releases and/or use latest version of hashicorp/terraform-json & hashicorp/terraform-exec which does. (#38930)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
  • terraform query: The experimental -policies flag permits specifying one or more policy set directory paths to evaluate policies against resources discovered by list blocks during a query operation.
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

View originalPermalink
How v1.17.0-alpha20260827 went

v1.16.0

Added 10
  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply
  • terraform_data resource now includes a new store block that can hold ephemeral and sensitive values across plan and apply
  • Providers can now use nested blocks as computed values
  • import blocks inside modules are now supported
  • Terraform is now available as a pre-built binary for Linux s390x (zLinux)
  • Resource action triggers can now use on_failure modes of halt, taint, or continue
Changed 9
  • Terraform now reports which resources were left behind when skip_cleanup is set in tests
  • Action configurations now have access to a caller symbol containing the object value of the calling resource
  • Actions can now use before_destroy and after_destroy events
  • Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform
  • Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply
  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings
Fixed 1
  • import blocks now correctly respect provider local names

From terraform

1.16.0 (August 26, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449)

  • stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events. (#38668)

  • cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. (#38715)

  • policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply, rather than requiring the plugin to read credentials itself. (#38716)

  • graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. (#38719)

  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. (#38784)

  • The contains() function can now test for null values. (#38792)

  • console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)

  • -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. (#38845)

  • The terraform stacks command now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set (#38896)

BUG FIXES:

  • import blocks now correctly respect provider local names. (#38338)

  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. (#38586)

  • workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)

  • test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. (#38603)

  • init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override. (#38634)

  • init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. (#38782)

  • The merge() function no longer panics when passed null objects. (#38792)

  • Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid (#38894)

  • test: Optional ephemeral values do not have to be set at plan time (#38974)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

UPGRADE NOTES:

  • bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

View originalPermalink
How v1.16.0 went

v1.15.9

Fixed 1
  • Child module validation now raises errors or warning diagnostics for invalid blocks (list, import, backend, and cloud)
Security 1
  • Update go-slug to v0.18.3 to mitigate CVE-2026-14978, a Unicode normalization issue that could lead to files not being correctly excluded via .terraformignore from upload to Terraform Enterprise or HCP Terraform during a run

From terraform

1.15.9 (August 19, 2026)

BUG FIXES:

  • validate: Child module validation has been fixed and will now raise errors or warning diagnostics for invalid blocks. (list, import, backend, and cloud) (#38994)

NOTES:

  • Update go-slug to v0.18.3 to mitigate CVE-2026-14978, which is a Unicode normalization issue that could lead to files not being correctly excluded via .terraformignore from upload to a Terraform Enterprise or HCP Terraform during a run (#39036)
View originalPermalink
How v1.15.9 went

v1.16.0-rc2

Pre-release
Added 13
  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply
  • The new `store` block in `terraform_data` can hold ephemeral and sensitive values across plan and apply
  • Providers can now use nested blocks as computed values
  • Import blocks inside modules are now supported
  • Terraform is now available as a pre-built binary for Linux s390x (zLinux)
  • Resource action triggers can now use `on_failure` modes of `halt`, `taint`, or `continue`
Changed 6
  • Terraform now displays a summary of policy evaluation outcomes for `plan` and `apply` runs against HCP Terraform
  • Terraform now resolves policy plugin credentials from the configured cloud or remote backend during `init`, `plan`, and `apply`
  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings
  • The `contains()` function can now test for `null` values
  • The `terraform stacks` command now automatically infers the target hostname from the local credentials file when neither `TF_STACKS_HOSTNAME` nor `TF_CLOUD_HOSTNAME` is set
  • Terraform now reports which resources were left behind when `skip_cleanup` is set in tests
Fixed 3
  • Import blocks now correctly respect provider local names
  • Terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has `lifecycle.precondition` or `lifecycle.postcondition` blocks
  • Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes

From terraform

1.16.0-rc2 (August 19, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449)

  • stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events. (#38668)

  • cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. (#38715)

  • policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply, rather than requiring the plugin to read credentials itself. (#38716)

  • graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. (#38719)

  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. (#38784)

  • The contains() function can now test for null values. (#38792)

  • console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)

  • -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. (#38845)

  • The terraform stacks command now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set (#38896)

BUG FIXES:

  • import blocks now correctly respect provider local names. (#38338)

  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. (#38586)

  • workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)

  • test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. (#38603)

  • init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override. (#38634)

  • init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. (#38782)

  • The merge() function no longer panics when passed null objects. (#38792)

  • Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid (#38894)

  • test: Optional ephemeral values do not have to be set at plan time (#38974)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

UPGRADE NOTES:

  • bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

View originalPermalink
How v1.16.0-rc2 went

v1.16.0-rc1

Pre-release
Added 14
  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply
  • The new `store` block in `terraform_data` can hold ephemeral and sensitive values across plan and apply
  • Providers can now use nested blocks as computed values
  • import blocks inside modules are now supported
  • Terraform is now available as a pre-built binary for Linux s390x (zLinux)
  • Resource action triggers can now use `on_failure` modes of `halt`, `taint`, or `continue`
Changed 5
  • Terraform now displays a summary of policy evaluation outcomes for `plan` and `apply` runs against HCP Terraform
  • Terraform now resolves policy plugin credentials from the configured cloud or remote backend during `init`, `plan`, and `apply`
  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings
  • The `terraform stacks` command now automatically infers the target hostname from the local credentials file when neither `TF_STACKS_HOSTNAME` nor `TF_CLOUD_HOSTNAME` is set
  • Terraform now reports which resources were left behind when `skip_cleanup` is set in tests
Fixed 1
  • import blocks now correctly respect provider local names

From terraform

1.16.0-rc1 (August 12, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449)

  • stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events. (#38668)

  • cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. (#38715)

  • policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply, rather than requiring the plugin to read credentials itself. (#38716)

  • graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. (#38719)

  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. (#38784)

  • The contains() function can now test for null values. (#38792)

  • console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)

  • -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. (#38845)

  • The terraform stacks command now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set (#38896)

BUG FIXES:

  • import blocks now correctly respect provider local names. (#38338)

  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. (#38586)

  • workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)

  • test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. (#38603)

  • init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override. (#38634)

  • init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. (#38782)

  • The merge() function no longer panics when passed null objects. (#38792)

  • Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid (#38894)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

UPGRADE NOTES:

  • bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

View originalPermalink
How v1.16.0-rc1 went

v1.17.0-alpha20260812

Pre-release
Added 1
  • JSON output from terraform version now includes a new format_version field
Changed 1
  • Enrich log messages in terraform init with provider versions
Fixed 2
  • Fix pow and log functions to no longer panic when result is not a number
  • Terraform will now use and display diagnostics raised when renewing an ephemeral resource

From terraform

1.17.0-alpha20260812 (August 12, 2026)

ENHANCEMENTS:

  • command/init: Enrich log messages with provider versions (#38918)

BUG FIXES:

  • funcs: pow and log no longer panic when result is not a number (#38912)

  • ephemeral: Terraform will now use and display diagnostics raised when renewing an ephemeral resource. This may cause warnings to appear that previously were lost. We expect that any error diagnostics that were previously lost would have caused confusing downstream errors, so we do not anticipate this change to be breaking. (#38989)

NOTES:

  • version: JSON output now includes a new format_version field, which will enable safer future changes of the command's JSON output format. It is assumed existing tooling ignores unknown fields and therefore this change should not be breaking in itself but we advice consumers to pay attention to format_version in future releases and/or use latest version of hashicorp/terraform-json & hashicorp/terraform-exec which does. (#38930)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
  • terraform query: The experimental -policies flag permits specifying one or more policy set directory paths to evaluate policies against resources discovered by list blocks during a query operation.
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

View originalPermalink
How v1.17.0-alpha20260812 went

v1.16.0-beta2

Pre-release
Added 13
  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply
  • The new `store` block in `terraform_data` can hold ephemeral and sensitive values across plan and apply
  • Providers can now use nested blocks as computed values
  • Import blocks inside modules are now supported
  • Terraform is now available as a pre-built binary for Linux s390x (zLinux)
  • Resource action triggers can now use `on_failure` modes of `halt`, `taint`, or `continue`
Changed 6
  • Terraform now displays a summary of policy evaluation outcomes for `plan` and `apply` runs against HCP Terraform
  • Terraform now resolves policy plugin credentials from the configured cloud or remote backend during `init`, `plan`, and `apply`
  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings
  • The `contains()` function can now test for `null` values
  • The `-invoke` flag can now be combined with `-target` to specify the calling resource instance when multiple resources trigger the same action
  • The `terraform stacks` command now automatically infers the target hostname from the local credentials file when neither `TF_STACKS_HOSTNAME` nor `TF_CLOUD_HOSTNAME` is set
Fixed 3
  • Import blocks now correctly respect provider local names
  • Terraform no longer panics when the plan contains a no-op change for a deposed resource that has `lifecycle.precondition` or `lifecycle.postcondition` blocks
  • Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes

From terraform

1.16.0-beta2 (August 05, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449)

  • stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events. (#38668)

  • cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. (#38715)

  • policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply, rather than requiring the plugin to read credentials itself. (#38716)

  • graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. (#38719)

  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. (#38784)

  • The contains() function can now test for null values. (#38792)

  • console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)

  • -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. (#38845)

  • The terraform stacks command now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set (#38896)

BUG FIXES:

  • import blocks now correctly respect provider local names. (#38338)

  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. (#38586)

  • workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)

  • test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. (#38603)

  • init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override. (#38634)

  • init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. (#38782)

  • The merge() function no longer panics when passed null objects. (#38792)

  • Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid (#38894)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

UPGRADE NOTES:

  • bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

View originalPermalink
How v1.16.0-beta2 went

v1.17.0-alpha20260729

Pre-release
Added 5
  • Experimental deferred actions feature enabled with -allow-deferral option to terraform plan permits count and for_each arguments in module, resource, and data blocks to have unknown values
  • Experimental terraform test cleanup command to clean up local state files left behind from failed cleanup operations
  • Experimental backend blocks within run blocks in Terraform Test files to load state from specified backend instead of starting from empty state
  • Experimental skip_cleanup attributes in test files and run blocks to prevent cleanup of state files produced by specified run blocks
  • Experimental -policies flag for terraform query to specify policy set directory paths for policy evaluation
Changed 1
  • Enrich log messages in terraform init with provider versions
Fixed 1
  • pow and log functions no longer panic when result is not a number

From terraform

1.17.0-alpha20260729 (July 29, 2026)

ENHANCEMENTS:

  • command/init: Enrich log messages with provider versions (#38918)

BUG FIXES:

  • funcs: pow and log no longer panic when result is not a number (#38912)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
  • terraform query: The experimental -policies flag permits specifying one or more policy set directory paths to evaluate policies against resources discovered by list blocks during a query operation.
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

View originalPermalink
How v1.17.0-alpha20260729 went

v1.16.0-beta1

Pre-release
Added 6
  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply
  • The new `store` block in `terraform_data` can hold ephemeral and sensitive values across plan and apply
  • Providers can now use nested blocks as computed values
  • Import blocks inside modules are now supported
  • Terraform is now available as a pre-built binary for Linux s390x (zLinux)
  • Resource action triggers can now use `on_failure` modes of `halt`, `taint`, or `continue`
Changed 14
  • The `state show` command can now produce machine-readable output when supplied with the `-json` flag
  • The `workspace list` command can now produce machine-readable output when supplied with the `-json` flag
  • Terraform now reports which resources were left behind when `skip_cleanup` is set in tests
  • Action configurations in stacks now have access to a `caller` symbol containing the object value of the calling resource
  • Actions can now use `before_destroy` and `after_destroy` events
  • Terraform now displays a summary of policy evaluation outcomes for `plan` and `apply` runs against HCP Terraform
Fixed 9
  • Import blocks now correctly respect provider local names
  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has `lifecycle.precondition` or `lifecycle.postcondition` blocks
  • Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes
  • Terraform now raises a warning when a file referenced via the `-filter` flag does not exist
  • Terraform no longer removes locks from the dependency lock file for providers configured as `dev_override`
  • Terraform now warns when unmanaged providers are in use and may impact provider installation

From terraform

1.16.0-beta1 (July 23, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449)

  • stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events. (#38668)

  • cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. (#38715)

  • policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply, rather than requiring the plugin to read credentials itself. (#38716)

  • graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. (#38719)

  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. (#38784)

  • The contains() function can now test for null values. (#38792)

  • console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)

  • -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. (#38845)

  • The terraform stacks command now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set (#38896)

BUG FIXES:

  • import blocks now correctly respect provider local names. (#38338)

  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. (#38586)

  • workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)

  • test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. (#38603)

  • init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override. (#38634)

  • init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. (#38782)

  • The merge() function no longer panics when passed null objects. (#38792)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

UPGRADE NOTES:

  • bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

View originalPermalink
How v1.16.0-beta1 went

v1.16.0-alpha20260715

Pre-release
Added 7
  • Store PlannedPrivate data for providers
  • New store block in terraform_data that can handle ephemeral and sensitive values
  • Providers can now use nested blocks as computed values
  • Add support for import blocks inside modules
  • Produce builds for Linux s390x (zLinux)
  • The workspace list command can now produce machine-readable output when supplied with the -json flag
  • Resource action triggers can now use on_failure modes of halt, taint, or continue
Changed 10
  • terraform state show accepts a -json flag
  • Show info when resources are left behind due to skip_cleanup
  • Action configuration now has a new caller symbol which contains the object value from the calling resource
  • Actions can now use before_destroy and after_destroy events
  • Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform
  • Resolve the policy plugin entitlement from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself
Fixed 3
  • Import blocks no longer ignore provider local names
  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition
  • Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band

From terraform

1.16.0-alpha20260715 (July 15, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events (#38668)

  • cloud: Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform (#38715)

  • policy: Resolve the policy plugin entitlement (host, token, organization) from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself (#38716)

  • The 'terraform graph' command now accepts a -format flag, and can output graphs in Mermaid format (#38719)

  • child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • Support destroy=false in resource lifecycle blocks. (#38784)

  • contains() function can now test for null (#38792)

  • The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)

  • If -invoke results in multiple resource calls triggering the action, it can now be combined with -target to specify the calling resource instance (#38845)

BUG FIXES:

  • import blocks no longer ignore provider local names (#38338)

  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition (#38586)

  • workspace: Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band (#38594)

  • test: Terraform will now raise a warning when a file referenced via -filter flag does not exist. (#38603)

  • init: Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override (#38634)

  • init: Add warnings when unmanaged providers are in use and will impact provider installation processes. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • return correct error when import target exists in state, but not config (#38782)

  • merge no longer panics with null objects (#38792)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

UPGRADE NOTES:

  • Provisioner bastion_host_key is now correctly applied. Existing usage of bastion_host_key should verify the configured key is correct. (#38318)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
  • terraform query: The experimental -policies flag permits specifying one or more policy set directory paths to evaluate policies against resources discovered by list blocks during a query operation.
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

View originalPermalink
How v1.16.0-alpha20260715 went

v1.15.8

Changed 2
  • Provider installation logging re-introduces initializing_provider_plugin_message to replace initializing_provider_plugin_from_config_message and initializing_provider_plugin_from_state_message
  • Module installation now occurs after the backend is initialized during provider installation
Fixed 1
  • Fix terraform init error when installing providers sourced from a service-discovery alias advertised by the configured backend

From terraform

1.15.8 (July 8, 2026)

BUG FIXES:

  • Fix terraform init error when installing providers sourced from a service-discovery alias advertised by the configured backend (such as localterraform.com)

NOTES:

  • command/init: Provider installation was changed to enable future enhancements in the area. This effectively reverses the log message changes from v1.15. initializing_provider_plugin_message is being re-introduced to replace the short-lived two message types initializing_provider_plugin_from_config_message & initializing_provider_plugin_from_state_message. The change should not have any significant end-user impact aside from the command output. (#38838)

  • command/init: Provider installation was changed to enable future enhancements in the area. This partially reverses the init event order changes from v1.15; module installation will now occur after the backend is initialized. The change should not have any significant end-user impact aside from the command output. (#38838)

View originalPermalink
How v1.15.8 went

v1.16.0-alpha20260708

Pre-release
Added 7
  • Store PlannedPrivate data for providers
  • New store block in terraform_data that can handle ephemeral and sensitive values
  • Providers can now use nested blocks as computed values
  • Add support for import blocks inside modules
  • Produce builds for Linux s390x (zLinux)
  • The workspace list command can now produce machine-readable output when supplied with the -json flag
  • Resource action triggers can now use on_failure modes of halt, taint, or continue
Changed 10
  • terraform state show command accepts a -json flag
  • Show info when resources are left behind due to skip_cleanup
  • Action configuration now has a new caller symbol which contains the object value from the calling resource
  • Actions can now use before_destroy and after_destroy events
  • Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform
  • Resolve the policy plugin entitlement from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself
Fixed 3
  • Import blocks no longer ignore provider local names
  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition
  • Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band

From terraform

1.16.0-alpha20260708 (July 08, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events (#38668)

  • cloud: Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform (#38715)

  • policy: Resolve the policy plugin entitlement (host, token, organization) from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself (#38716)

  • The 'terraform graph' command now accepts a -format flag, and can output graphs in Mermaid format (#38719)

  • child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • Support destroy=false in resource lifecycle blocks. (#38784)

  • contains() function can now test for null (#38792)

BUG FIXES:

  • import blocks no longer ignore provider local names (#38338)

  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition (#38586)

  • workspace: Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band (#38594)

  • test: Terraform will now raise a warning when a file referenced via -filter flag does not exist. (#38603)

  • init: Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override (#38634)

  • init: Add warnings when unmanaged providers are in use and will impact provider installation processes. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • return correct error when import target exists in state, but not config (#38782)

  • merge no longer panics with null objects (#38792)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

  • command/init: Provider installation was changed to enable future enhancements in the area. This effectively reverses the log message changes from v1.15. initializing_provider_plugin_message is being re-introduced to replace the short-lived two message types initializing_provider_plugin_from_config_message & initializing_provider_plugin_from_state_message. The change should not have any significant end-user impact aside from the command output. (#38648)

  • command/init: Provider installation was changed to enable future enhancements in the area. This partially reverses the init event order changes from v1.15; module installation will now occur after the backend is initialized. The change should not have any significant end-user impact aside from the command output. (#38699)

UPGRADE NOTES:

  • Provisioner bastion_host_key is now correctly applied. Existing usage of bastion_host_key should verify the configured key is correct. (#38318)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
  • terraform query: The experimental -policies flag permits specifying one or more policy set directory paths to evaluate policies against resources discovered by list blocks during a query operation.
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

View originalPermalink
How v1.16.0-alpha20260708 went

v1.16.0-alpha20260706

Pre-release
Added 9
  • Store PlannedPrivate data for providers
  • New store block in terraform_data that can handle ephemeral and sensitive values
  • Providers can now use nested blocks as computed values
  • Add support for import blocks inside modules
  • Produce builds for Linux s390x (zLinux)
  • The workspace list command can now produce machine-readable output when supplied with the -json flag
Changed 7
  • Show info when resources are left behind due to skip_cleanup
  • Action configuration now has a new caller symbol which contains the object value from the calling resource
  • Actions can now use before_destroy and after_destroy events
  • Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform
  • Resolve the policy plugin entitlement from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself
  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings
  • The contains() function can now test for null
Fixed 5
  • Import blocks no longer ignore provider local names
  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition
  • Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band
  • Terraform will now raise a warning when a file referenced via -filter flag does not exist
  • Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override

From terraform

1.16.0-alpha20260706 (July 06, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events (#38668)

  • cloud: Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform (#38715)

  • policy: Resolve the policy plugin entitlement (host, token, organization) from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself (#38716)

  • The 'terraform graph' command now accepts a -format flag, and can output graphs in Mermaid format (#38719)

  • child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • contains() function can now test for null (#38792)

BUG FIXES:

  • import blocks no longer ignore provider local names (#38338)

  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition (#38586)

  • workspace: Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band (#38594)

  • test: Terraform will now raise a warning when a file referenced via -filter flag does not exist. (#38603)

  • init: Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override (#38634)

  • init: Add warnings when unmanaged providers are in use and will impact provider installation processes. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • merge no longer panics with null objects (#38792)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

  • command/init: Provider installation was changed to enable future enhancements in the area. This effectively reverses the log message changes from v1.15. initializing_provider_plugin_message is being re-introduced to replace the short-lived two message types initializing_provider_plugin_from_config_message & initializing_provider_plugin_from_state_message. The change should not have any significant end-user impact aside from the command output. (#38648)

  • command/init: Provider installation was changed to enable future enhancements in the area. This partially reverses the init event order changes from v1.15; module installation will now occur after the backend is initialized. The change should not have any significant end-user impact aside from the command output. (#38699)

UPGRADE NOTES:

  • Provisioner bastion_host_key is now correctly applied. Existing usage of bastion_host_key should verify the configured key is correct. (#38318)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
  • terraform query: The experimental -policies flag permits specifying one or more policy set directory paths to evaluate policies against resources discovered by list blocks during a query operation.
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

View originalPermalink
How v1.16.0-alpha20260706 went

v1.16.0-alpha20260701

Pre-release
Added 7
  • Store PlannedPrivate data for providers
  • New store block in terraform_data that can handle ephemeral and sensitive values
  • Providers can now use nested blocks as computed values
  • Add support for import blocks inside modules
  • Produce builds for Linux s390x (zLinux)
  • The workspace list command can now produce machine-readable output when supplied with the -json flag
  • Resource action triggers can now use on_failure modes of halt, taint, or continue
Changed 8
  • terraform state show accepts a -json flag
  • Show info when resources are left behind due to skip_cleanup
  • Action configuration now has a new caller symbol which contains the object value from the calling resource
  • Actions can now use before_destroy and after_destroy events
  • Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform
  • Resolve the policy plugin entitlement from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself
  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings
  • contains() function can now test for null
Fixed 5
  • Import blocks no longer ignore provider local names
  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition
  • Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band
  • Terraform will now raise a warning when a file referenced via -filter flag does not exist
  • Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override

From terraform

1.16.0-alpha20260701 (July 01, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events (#38668)

  • cloud: Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform (#38715)

  • policy: Resolve the policy plugin entitlement (host, token, organization) from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself (#38716)

  • child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • contains() function can now test for null (#38792)

BUG FIXES:

  • import blocks no longer ignore provider local names (#38338)

  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition (#38586)

  • workspace: Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band (#38594)

  • test: Terraform will now raise a warning when a file referenced via -filter flag does not exist. (#38603)

  • init: Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override (#38634)

  • init: Add warnings when unmanaged providers are in use and will impact provider installation processes. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • merge no longer panics with null objects (#38792)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

  • command/init: Provider installation was changed to enable future enhancements in the area. This effectively reverses the log message changes from v1.15. initializing_provider_plugin_message is being re-introduced to replace the short-lived two message types initializing_provider_plugin_from_config_message & initializing_provider_plugin_from_state_message. The change should not have any significant end-user impact aside from the command output. (#38648)

  • command/init: Provider installation was changed to enable future enhancements in the area. This partially reverses the init event order changes from v1.15; module installation will now occur after the backend is initialized. The change should not have any significant end-user impact aside from the command output. (#38699)

UPGRADE NOTES:

  • Provisioner bastion_host_key is now correctly applied. Existing usage of bastion_host_key should verify the configured key is correct. (#38318)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

View originalPermalink
How v1.16.0-alpha20260701 went

v1.16.0-alpha20260626

Pre-release
Added 10
  • Store PlannedPrivate data for providers
  • New store block in terraform_data that can handle ephemeral and sensitive values
  • Providers can now use nested blocks as computed values
  • Add support for import blocks inside modules
  • Produce builds for Linux s390x (zLinux)
  • The workspace list command can now produce machine-readable output when supplied with the -json flag
Changed 3
  • Show info when resources are left behind due to skip_cleanup
  • Action configuration now has a new caller symbol which contains the object value from the calling resource
  • Resolve the policy plugin entitlement (host, token, organization) from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself
Fixed 7
  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings
  • Import blocks no longer ignore provider local names
  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition
  • Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band
  • Terraform will now raise a warning when a file referenced via -filter flag does not exist
  • Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override
  • Add warnings when unmanaged providers are in use and will impact provider installation processes

From terraform

1.16.0-alpha20260626 (June 26, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events (#38668)

  • cloud: Render a summary of Terraform policy evaluation outcomes for plan and apply runs against HCP Terraform (#38715)

  • policy: Resolve the policy plugin entitlement (host, token, organization) from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself (#38716)

  • child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

BUG FIXES:

  • import blocks no longer ignore provider local names (#38338)

  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition (#38586)

  • workspace: Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band (#38594)

  • test: Terraform will now raise a warning when a file referenced via -filter flag does not exist. (#38603)

  • init: Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override (#38634)

  • init: Add warnings when unmanaged providers are in use and will impact provider installation processes. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

  • command/init: Provider installation was changed to enable future enhancements in the area. This effectively reverses the log message changes from v1.15. initializing_provider_plugin_message is being re-introduced to replace the short-lived two message types initializing_provider_plugin_from_config_message & initializing_provider_plugin_from_state_message. The change should not have any significant end-user impact aside from the command output. (#38648)

  • command/init: Provider installation was changed to enable future enhancements in the area. This partially reverses the init event order changes from v1.15; module installation will now occur after the backend is initialized. The change should not have any significant end-user impact aside from the command output. (#38699)

UPGRADE NOTES:

  • Provisioner bastion_host_key is now correctly applied. Existing usage of bastion_host_key should verify the configured key is correct. (#38318)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

View originalPermalink
How v1.16.0-alpha20260626 went

v1.15.7

Fixed 2
  • Add concurrency safety to configs.Parser and SourceBundleParser
  • Fix submodule variable validation during init

From terraform

1.15.7 (June 24, 2026)

BUG FIXES:

  • Add concurrency safety to configs.Parser and SourceBundleParser (#38745)

  • Fix submodule variable validation during init (#38770)

View originalPermalink
How v1.15.7 went

v1.16.0-alpha20260624

Pre-release
Added 7
  • Store PlannedPrivate data for providers
  • New store block in terraform_data that can handle ephemeral and sensitive values
  • Providers can now use nested blocks as computed values
  • Support for import blocks inside modules
  • Produce builds for Linux s390x (zLinux)
  • The workspace list command can now produce machine-readable output when supplied with the -json flag
  • Resource action triggers can now use on_failure modes of halt, taint, or continue
Changed 5
  • The terraform state show command now accepts a -json flag
  • Show info when resources are left behind due to skip_cleanup
  • Action configuration now has a new caller symbol which contains the object value from the calling resource
  • Actions can now use before_destroy and after_destroy events
  • Policy plugin entitlement is now resolved from the configured cloud/remote backend for init, plan, and apply instead of the plugin reading credentials itself
Fixed 7
  • Import blocks no longer ignore provider local names
  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition
  • Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band
  • Terraform will now raise a warning when a file referenced via -filter flag does not exist
  • Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override
  • Add warnings when unmanaged providers are in use and will impact provider installation processes
  • Actions are now invoked with respect to all resource dependencies

From terraform

1.16.0-alpha20260624 (June 24, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events (#38668)

  • policy: Resolve the policy plugin entitlement (host, token, organization) from the configured cloud/remote backend for init, plan, and apply, instead of the plugin reading credentials itself (#38716)

BUG FIXES:

  • import blocks no longer ignore provider local names (#38338)

  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition (#38586)

  • workspace: Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band (#38594)

  • test: Terraform will now raise a warning when a file referenced via -filter flag does not exist. (#38603)

  • init: Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override (#38634)

  • init: Add warnings when unmanaged providers are in use and will impact provider installation processes. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

  • command/init: Provider installation was changed to enable future enhancements in the area. This effectively reverses the log message changes from v1.15. initializing_provider_plugin_message is being re-introduced to replace the short-lived two message types initializing_provider_plugin_from_config_message & initializing_provider_plugin_from_state_message. The change should not have any significant end-user impact aside from the command output. (#38648)

  • command/init: Provider installation was changed to enable future enhancements in the area. This partially reverses the init event order changes from v1.15; module installation will now occur after the backend is initialized. The change should not have any significant end-user impact aside from the command output. (#38699)

UPGRADE NOTES:

  • Provisioner bastion_host_key is now correctly applied. Existing usage of bastion_host_key should verify the configured key is correct. (#38318)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

View originalPermalink
How v1.16.0-alpha20260624 went

v1.16.0-alpha20260617

Pre-release
Added 7
  • Store PlannedPrivate data for providers
  • New store block in terraform_data that can handle ephemeral and sensitive values
  • Providers can now use nested blocks as computed values
  • Support for import blocks inside modules
  • Produce builds for Linux s390x (zLinux)
  • The workspace list command can now produce machine-readable output when supplied with the -json flag
  • Resource action triggers can now use on_failure modes of halt, taint, or continue
Changed 6
  • terraform state show command accepts a -json flag
  • Show info when resources are left behind due to skip_cleanup
  • Action configuration now has a new caller symbol which contains the object value from the calling resource
  • Actions can now use before_destroy and after_destroy events
  • Actions are now invoked with respect to all resource dependencies
  • Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process
Fixed 6
  • Import blocks no longer ignore provider local names
  • Fix terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition
  • Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band
  • Terraform will now raise a warning when a file referenced via -filter flag does not exist
  • Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override
  • Add warnings when unmanaged providers are in use and will impact provider installation processes

From terraform

1.16.0-alpha20260617 (June 17, 2026)

NEW FEATURES:

  • Store PlannedPrivate data for providers (#37986)

  • New store block in terraform_data that can handle ephemeral and sensitive values (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: add support for import blocks inside modules (#38352)

  • We now produce builds for Linux s390x (zLinux) (#38384)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue (#38722)

ENHANCEMENTS:

  • feat(cli): terraform state show accepts a -json flag (#23940)

  • Show info when resources are left behind due to skip_cleanup (#38449)

  • Action configuration now has a new caller symbol which contains the object value from the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events (#38668)

BUG FIXES:

  • import blocks no longer ignore provider local names (#38338)

  • Fix a terraform apply panic when the plan contained a no-op change for a deposed object on a resource whose configuration declared a lifecycle.precondition or lifecycle.postcondition (#38586)

  • workspace: Terraform will now error if an invalid workspace name becomes selected due to actions performed out-of-band (#38594)

  • test: Terraform will now raise a warning when a file referenced via -filter flag does not exist. (#38603)

  • init: Stop removing locks from the dependency lock file corresponding to providers configured as a dev_override (#38634)

  • init: Add warnings when unmanaged providers are in use and will impact provider installation processes. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

  • command/init: Provider installation was changed to enable future enhancements in the area. This effectively reverses the log message changes from v1.15. initializing_provider_plugin_message is being re-introduced to replace the short-lived two message types initializing_provider_plugin_from_config_message & initializing_provider_plugin_from_state_message. The change should not have any significant end-user impact aside from the command output. (#38648)

  • command/init: Provider installation was changed to enable future enhancements in the area. This partially reverses the init event order changes from v1.15; module installation will now occur after the backend is initialized. The change should not have any significant end-user impact aside from the command output. (#38699)

UPGRADE NOTES:

  • Provisioner bastion_host_key is now correctly applied. Existing usage of bastion_host_key should verify the configured key is correct. (#38318)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
Previous Releases

For information on prior major and minor releases, refer to their changelogs:

View originalPermalink
How v1.16.0-alpha20260617 went
View all

Discussion

If you publish terraform, you can claim this product by proving you administer its repository.