Skip to content

Terraform

Summary

Terraform is HashiCorp's declarative infrastructure-as-code CLI: you describe resources in HCL, terraform plan shows the diff against recorded state, and terraform apply drives provider plugins to create, change, or delete them. It has the largest provider and module ecosystem in IaC. Since 1.6 (2023-10) it is source-available under BSL 1.1, and since 2025-02-27 HashiCorp is part of IBM. The current stable line is 1.16 (1.16.4, 2026-09-23); 1.17 is in beta.

Key Facts

Attribute Detail
Latest Version 1.16.4 (2026-09-23); next: 1.17.0-beta2
Release cadence New minor every ~3-5 months (1.14: 2025-11-19, 1.15: 2026-04-29, 1.16: 2026-08-26)
License BSL 1.1 for 1.6.0+ (source-available, not OSI open source); each version converts to MPL 2.0 after 4 years; 1.5.7 was the last MPL release
Owner HashiCorp, an IBM company (acquisition closed 2025-02-27)
Repository github.com/hashicorp/terraform (~44k+ stars)
Language Go; configuration in HCL (or JSON)
Providers Thousands on the public registry: the registry home page showed 7,335 providers in a search-engine snapshot seen 2026-09-27
Platforms HCP Terraform (SaaS; Free up to 500 managed resources), Terraform Enterprise (self-managed, 2.0.x in 2026)
Recent headline features Ephemeral values (1.10), write-only attributes (1.11), Stacks GA (2025-09), terraform query and actions (1.14), dynamic module sources (1.15), import in modules and lifecycle { destroy = false } (1.16)

Architecture at a Glance

The CLI parses HCL, builds a dependency graph, calls provider plugins over gRPC, and persists state to a backend; HCP Terraform or TFE can run the same engine remotely.

flowchart LR
    HCL["*.tf (HCL)"] --> CORE["terraform core<br/>(graph + plan/apply)"]
    CORE <-->|"gRPC"| PROV["Provider plugins<br/>(aws, google, azurerm)"]
    PROV --> API["Cloud / SaaS APIs"]
    CORE <--> STATE["State backend<br/>(s3, gcs, azurerm, cloud)"]
    REG["registry.terraform.io"] -->|"terraform init"| CORE
    HCP["HCP Terraform / TFE<br/>(remote runs, policy, Stacks)"] -.->|"cloud block"| CORE

Details: Explanation: Component Overview.

When It Fits

  • Multi-cloud or multi-SaaS provisioning where one workflow must cover AWS, Azure, Google Cloud, Kubernetes, DNS, identity, and observability vendors.
  • Teams that want a declarative, reviewable plan before every change, with policy gates (Sentinel/OPA) on HCP Terraform or TFE.
  • Organizations that are fine with BSL 1.1 for internal use and value HashiCorp/IBM support, HCP Terraform Stacks, and the private registry.

Consider alternatives when you need an OSI-licensed engine or native client-side state encryption (OpenTofu), general-purpose languages and unit tests in code (Pulumi), or continuous Kubernetes-style reconciliation (Crossplane).

Evaluation

Pros Cons
Largest provider and module ecosystem BSL 1.1: not open source; restricts competing hosted/embedded offerings
Huge community knowledge base, hiring pool HCL has limited programming constructs (improving: functions, convert, dynamic module sources)
Mature plan/apply model and state handling State can hold secrets unless ephemeral values / write-only attributes are used
Built-in testing (terraform test, mocks) No native client-side state encryption in the CLI
HCP Terraform / TFE: Stacks, policy, dynamic credentials, HYOK Single-vendor roadmap (IBM/HashiCorp); CDKTF was sunset
Frequent releases with clear changelogs RUM-based pricing can get costly at large resource counts

Licensing and Pricing

  • CLI: free to use under BSL 1.1 for internal production use; the Additional Use Grant forbids offering it to third parties in a paid product that significantly overlaps with IBM's paid Terraform versions. See Explanation: Licensing and Governance.
  • HCP Terraform: Free (up to 500 managed resources, 1 concurrent run), then Essentials / Standard / Premium from $0.10 / $0.47 / $0.99 per managed resource per month; the legacy Free plan ended 2026-03-31. Table: Reference: HCP Terraform Plans and Pricing.
  • Terraform Enterprise: custom pricing, quarterly semantic-versioned releases since 2025-08.

Recent Developments (2025-2026)

Date Event
2025-02-27 IBM completes the HashiCorp acquisition
2025-08-20 Terraform 1.13: terraform stacks subcommand in core
2025-09-25 HashiConf 2025: Stacks GA; Terraform Search and Actions public beta on HCP; HYOK GA
2025-11-19 Terraform 1.14: list resources, terraform query, action blocks
2025-12-10 CDKTF archived (migrate with cdktf synth --hcl)
2026-03-31 HCP Terraform legacy Free plan end of life
2026-04 Terraform Enterprise 2.0.0
2026-04-29 Terraform 1.15: variables in module source/version, deprecated attribute, Windows ARM64
2026-08-26 Terraform 1.16: terraform_data store block, import in modules, destroy = false, Mermaid graph output
2026-09 1.17 beta: Terraform Policy GA, -minimal-refresh, variables in provider requirements

Full per-version table: Reference: Release History.

Alternatives and Migration

Alternative Relationship Migration effort
OpenTofu MPL 2.0 fork of 1.5.x; same HCL and providers, diverging features Low for configs using features common to both; check newer 1.6+ Terraform-only features
Pulumi General-purpose languages; can bridge Terraform providers and convert HCL Medium to high (rewrite, state import)
Crossplane Kubernetes-native continuous reconciliation High (different model)
AWS CDK / Bicep Single-cloud tools High; loses multi-cloud coverage

Lock-in is mostly in HCP Terraform features (Stacks, Sentinel, no-code modules, run tasks); plain HCL plus a self-managed backend stays portable.

Topic Map

  • How-to Guides: install/upgrade, S3 native locking migration, import and terraform query, CI/CD, dynamic credentials, ephemeral secrets, tests, CDKTF migration, troubleshooting, Commands & Recipes
  • Reference: versions and release history, file types, CLI flags, backends, plugin protocol, HCP pricing, TFE releases, access roles, checklists, performance estimates
  • Explanation: internals, plugin protocol, plan/apply and state, ephemeral values, testing model, Stacks, licensing and IBM, security model

Sources

Questions

Answered

  • Can I still use Terraform commercially? Yes. BSL 1.1 allows internal production use; it restricts offering Terraform to third parties in a paid product that significantly overlaps with IBM's paid Terraform versions (see LICENSE).
  • How does dynamic module sourcing (1.15) change composition? source and version can now use variables and locals, so one root module can select module versions per environment; the trade-off is that init and most commands need those variable values, and pins become less visible in code review.
  • Is CDKTF still an option? No new development: archived on 2025-12-10; migrate with cdktf synth --hcl.
  • What is HashiCorp's formal support window for Terraform CLI minor versions? HashiCorp's Support Period and EOL policy supports GA releases for up to two years, with fixes for up to two releases back from the current X.Y line. In practice the CLI has shipped patches only on the newest minor (see Reference).

Open

  • Where exactly is the "competitive offering" line for managed service providers and internal platforms sold to customers? The license FAQ gives guidance, but edge cases (paid support bundles, embedded runners) still need legal review.
  • Will IBM change Terraform's license or pricing further? No announcement as of 2026-09; watch HCP Terraform RUM pricing and TFE packaging.
  • How far will Terraform and OpenTofu diverge? Terraform-only features since 1.6 (Stacks, actions, list resources) versus OpenTofu-only features (client-side state encryption) make two-way portability harder each release.