Reference¶
Scope
Look-up facts for Terraform: release history and current versions, HCP Terraform and Terraform Enterprise plans and limits, file types, CLI flags and exit codes, backend matrix, plugin protocol, access-control roles, hardening checklists, and (unsourced) performance estimates. Tasks live in How-to Guides; the why lives in Explanation.
Current Versions¶
| Line | Latest | Date | Status |
|---|---|---|---|
| Terraform CLI 1.16 | 1.16.4 | 2026-09-23 | Current stable |
| Terraform CLI 1.17 | 1.17.0-beta2 | 2026-09 | Pre-release (alpha builds from 2026-07-29) |
| Terraform CLI 1.15 | 1.15.9 | 2026-08-19 | Previous minor |
| Terraform CLI 1.14 | 1.14.9 | 2026-04-20 | Older minor |
| Terraform CLI 1.5 | 1.5.7 | 2023-09-07 | Last MPL 2.0 licensed release |
| Terraform Enterprise | 2.0.8 | 2026-09-23 | Self-managed; 2.0.0 shipped 2026-04; see TFE releases |
Sources: releases.hashicorp.com/terraform (index checked 2026-09-25), v1.16 CHANGELOG, v1.15 CHANGELOG.
Patch support pattern (observed, not a published policy)
In the 1.13-1.16 cycle, a minor line stopped receiving patches around the time the next minor went GA (1.13.5 on 2025-11-05 before 1.14.0 on 2025-11-19; 1.14.9 on 2026-04-20 before 1.15.0 on 2026-04-29; 1.15.9 on 2026-08-19 before 1.16.0 on 2026-08-26). Plan to track the newest minor. HashiCorp's published Support Period and EOL policy supports GA releases for up to two years and ships fixes as patch releases "for up to two releases from the most current major release", where a change in X or Y of X.Y.Z counts as a major release. endoflife.date applies that policy to the CLI as end of life = GA of the minor two lines later (1.14 ended 2026-08-26 with 1.16.0). In practice the CLI has shipped patches only on the newest line (checked 2026-09-27).
Release History (1.5 to 1.17)¶
Minor releases arrive roughly every 3-5 months. Dates and features come from the per-branch CHANGELOG.md files in hashicorp/terraform.
| Version | GA date | Headline changes |
|---|---|---|
| 1.5 | 2023-06-12 | import blocks, -generate-config-out, check blocks, plantimestamp, strcontains |
| 1.6 | 2023-10-04 | terraform test GA (new .tftest.hcl model); S3 backend config overhaul (assume_role block, endpoints block); first BSL 1.1 release |
| 1.7 | 2024-01-17 | Test mocking (mock_provider, override_*); removed block; for_each on import blocks |
| 1.8 | 2024-04-10 | Provider-defined functions; cross-type resource moves; issensitive |
| 1.9 | 2024-06-26 | Input variable validation can reference other objects; templatestring |
| 1.10 | 2024-11-27 | Ephemeral resources and ephemeral variables/outputs; ephemeralasnull; S3 native locking introduced; terraform modules -json |
| 1.11 | 2025-02-27 | Write-only resource attributes; S3 use_lockfile GA and DynamoDB locking arguments deprecated; terraform test -junit-xml GA |
| 1.12 | 2025-05-14 | OCI Object Storage backend; terraform test -parallelism; import by resource identity; short-circuiting &&/\|\| |
| 1.13 | 2025-08-20 | terraform stacks CLI subcommand; test-file variable definitions; terraform rpcapi GA; high-cardinality performance fix |
| 1.14 | 2025-11-19 | List resources (.tfquery.hcl) and terraform query; action blocks and -invoke; GenerateResourceConfiguration RPC |
| 1.15 | 2026-04-29 | Variables and locals in module source/version; deprecated on variables/outputs; convert function; typed outputs; validate checks backend; Windows ARM64 builds |
| 1.16 | 2026-08-26 | terraform_data store block for ephemeral/sensitive values; import blocks inside modules; lifecycle { destroy = false }; terraform graph -format=mermaid; state show -json; console -scope; Linux s390x builds |
| 1.17 | Unreleased (beta) | Variables/locals in provider requirements; -minimal-refresh; Terraform Policy (-policies) GA; mock_provider support for ephemeral resources |
Still Experimental (alpha builds only, as of 1.18.0-dev)¶
| Feature | What it does |
|---|---|
Deferred actions (-allow-deferral) |
Unknown values allowed in count/for_each on modules, resources, data blocks |
terraform test cleanup |
Cleans up state left behind by failed test teardown |
Test backend blocks and skip_cleanup |
Keep long-lived test infrastructure between runs |
Source: main CHANGELOG.
Notable Security Fixes¶
| Advisory | Affected | Fixed in | Summary |
|---|---|---|---|
| CVE-2026-14978 (go-slug) | Uploads to HCP Terraform / TFE | 1.15.9; 1.16.0+ ships go-slug v0.18.3 | Unicode normalization issue could let files escape .terraformignore exclusion during upload |
Source: v1.15 CHANGELOG, 1.15.9 notes; go.mod on the v1.16 branch pins github.com/hashicorp/go-slug v0.18.3.
File Types¶
| File / pattern | Purpose | Since |
|---|---|---|
*.tf, *.tf.json |
Configuration (root and child modules) | 0.x |
*.tfvars, *.auto.tfvars |
Input variable values | 0.x |
.terraform.lock.hcl |
Dependency lock file: provider versions and checksums (not modules) | 0.14 |
terraform.tfstate |
State (JSON, format version 4) | 0.12 (v4) |
*.tftest.hcl |
terraform test files (run, assert, mock_provider) |
1.6 |
*.tfquery.hcl |
list blocks for terraform query |
1.14 |
*.tfcomponent.hcl |
Stacks component configuration | Stacks GA (renamed from .tfstack.hcl) |
*.tfdeploy.hcl |
Stacks deployment configuration | Stacks |
.terraformignore |
Excludes files from uploads to HCP Terraform / TFE | - |
CLI Quick Reference¶
| Command / flag | Behavior |
|---|---|
plan -detailed-exitcode |
Exit 0 = no changes, 1 = error, 2 = changes present |
-parallelism=n |
Concurrent graph operations; default 10 (DefaultParallelism in source) |
plan -refresh=false |
Skip refresh of prior state |
plan -refresh-only / apply -refresh-only |
Replacement for the deprecated terraform refresh |
plan -generate-config-out=PATH |
Write HCL for import blocks that have no resource config (1.5+) |
plan -replace=ADDR |
Force replacement (replacement for terraform taint) |
apply -invoke=ADDR |
Invoke an action directly (1.14+) |
query |
Run list blocks against real infrastructure (1.14+) |
test [-filter] [-junit-xml] [-parallelism] |
Run .tftest.hcl suites |
graph -format=mermaid |
Mermaid output of the resource graph (1.16+) |
state show -json, workspace list -json |
Machine-readable output (1.16+) |
console -scope=<module> |
Evaluate expressions in a module's scope (1.16+) |
stacks <subcommand> |
Stacks operations via the stacks plugin (1.13+) |
providers lock -platform=... |
Pre-populate lock file checksums for several platforms |
force-unlock <LOCK_ID> |
Release a stuck state lock |
State Backends¶
| Backend | Locking | Encryption at rest | Notes |
|---|---|---|---|
local |
Local file lock | None | Default; terraform.tfstate on disk |
s3 |
S3 native lockfile (use_lockfile, GA 1.11); DynamoDB (dynamodb_table, deprecated) |
SSE-S3 / SSE-KMS (encrypt, kms_key_id) |
Most common on AWS |
gcs |
Native | Google-managed or CMEK | Google Cloud |
azurerm |
Blob lease | Storage service encryption | Azure |
oci |
Native | OCI-managed | OCI Object Storage (1.12+) |
oss |
Tablestore | SSE | Alibaba Cloud |
consul |
Session | Optional | HashiCorp Consul |
pg |
Advisory lock | Database-level | PostgreSQL |
http |
Optional (lock/unlock endpoints) | Server-defined | Generic REST |
cloud block / remote |
Yes | Encrypted at rest (HYOK optional) | HCP Terraform / TFE |
No client-side state encryption in the Terraform CLI
Terraform relies on backend encryption at rest. OpenTofu added native client-side state encryption in 1.7; HCP Terraform offers Hold Your Own Key (HYOK, GA 2025-09). See OpenTofu.
Plugin Protocol and SDKs¶
| Protocol | Transport | Notes |
|---|---|---|
| v1-v4 | net/rpc |
Pre-0.12, legacy |
v5 (tfplugin5) |
gRPC | Introduced in 0.12; still widely used via SDKv2 |
v6 (tfplugin6) |
gRPC | Adds nested attributes; used by terraform-plugin-framework; requires Terraform 1.0+ |
| SDK | Status | Usage |
|---|---|---|
terraform-plugin-framework |
Recommended | New providers; ephemeral resources, write-only attributes, functions, actions, list resources |
terraform-plugin-sdk/v2 |
Maintenance | Many existing providers |
terraform-plugin-mux |
Active | Combine SDKv2 and framework in one provider binary |
Source: plugin-protocol docs in the repo.
HCP Terraform Plans and Pricing¶
HCP Terraform (renamed from Terraform Cloud in 2024) bills on resources under management (RUM), counted on the peak hourly managed-resource count.
| Plan | List price | Notes |
|---|---|---|
| Free | $0 | Up to 500 managed resources, unlimited users, 1 concurrent run, SSO, policy as code (Sentinel and OPA), run tasks |
| Essentials | from $0.10 per resource/month (~$0.00013/h) | Remote state, VCS connection, secure variables |
| Standard | from $0.47 per resource/month (~$0.00064/h) | Higher tiers add team notifications, no-code provisioning, Waypoint integrations |
| Premium | from $0.99 per resource/month (~$0.00135/h) | Most complete HCP feature set (check the pricing page for the exact split) |
| Enterprise | Custom | Self-managed Terraform Enterprise |
Sources: HashiCorp pricing (checked 2026-09-25), enhanced free tier post (2025-12-17), HCP Terraform limits.
Legacy Free plan retired
The legacy (non-RUM) Free plan reached end of life on 2026-03-31; remaining organizations moved automatically to the enhanced Free tier (EOL notice). Since Stacks GA, Stacks resources count toward RUM (they were free during the beta).
Terraform Enterprise Releases¶
| Item | Fact |
|---|---|
| Versioning | Date-based (v202507-1 was the last) until 2025-08, then semantic x.y.z |
| Cadence | Quarterly feature releases, monthly patches until the next quarterly |
| Recent lines | 1.1.0 (2025-11), 1.2.0 (2026-02), 2.0.0 (2026-04), 2.0.8 (2026-09-23, bundles Terraform CLI 1.15.9) |
| Stacks | Requires TFE 2.0 or later (per HashiCorp Stacks docs; verify for your version) |
| Replicated installs | Final Replicated release 2025-03; support ended 2026-04-01 |
Sources: TFE releases, TFE 2.0.0 announcement. No 2.1.0 line had shipped by 2026-09-27: the TFE 2.0.x release notes source lists 2.0.0 to 2.0.8, and the docs have no 2.1.x version folder.
HCP Terraform Access Roles¶
Workspace permissions come in fixed sets; custom sets pick individual permissions.
| Scope | Role / permission set | Allows |
|---|---|---|
| Organization | Owners team | Everything, including billing, SSO, teams, org tokens |
| Organization | Org-level permissions (manage workspaces, projects, policies, VCS, providers/modules) | Granted per team |
| Project | Read / Write / Maintain / Admin (+ custom) | Workspaces in a project |
| Workspace | Read | View runs, state versions, outputs |
| Workspace | Plan | Read + queue plans |
| Workspace | Write | Plan + approve applies, lock workspace, edit variables |
| Workspace | Admin | Write + settings, team access, delete workspace |
Sentinel Enforcement Levels¶
| Level | Effect on a failing policy |
|---|---|
advisory |
Logs a warning; run continues |
soft-mandatory |
Blocks until a user with override permission overrides |
hard-mandatory |
Blocks the run; cannot be overridden |
Common Sentinel Policy Categories¶
| Category | Example rule |
|---|---|
| Resource restrictions | Only allow approved instance types |
| Encryption enforcement | Require KMS encryption on S3, EBS, RDS |
| Network security | Deny public S3 buckets and 0.0.0.0/0 ingress |
| Tagging compliance | Require cost-center and environment tags |
| Version pinning | Enforce minimum Terraform or provider versions |
HashiCorp also publishes pre-written Sentinel policy sets, including 350+ policies for NIST SP 800-53 on AWS (GA at HashiConf 2025).
Hardening Checklist¶
- Use a remote backend with locking (HCP Terraform, or S3 with
use_lockfile, GCS, AzureRM) - Encrypt state at rest with customer-managed keys; enable bucket versioning and access logs
- Use dynamic provider credentials (OIDC workload identity) instead of static keys
- Prefer ephemeral values and write-only attributes so secrets never reach state or plan files (1.10+/1.11+)
- Commit
.terraform.lock.hcl; pre-hash for all CI platforms withterraform providers lock - Pin module versions (registry
versionor Git?ref=tag or commit SHA) - Mark secret variables and outputs
sensitive = true - Enforce policies (Sentinel/OPA, or Terraform Policy in 1.17+) at
hard-mandatoryfor critical rules - Enable SSO and team-level RBAC; restrict Write/Admin on production workspaces
- Rotate API tokens and set organization token TTL policies
- Enable audit logging (TFE) or the HCP Terraform audit trail API
- Keep Terraform on a patched release (see Notable Security Fixes)
Module Security Checklist¶
- Module source is a trusted registry or an internal repository
- Module version pinned to a specific tag
- Provider versions constrained with
>=and<bounds - No default credentials in variable definitions
- Sensitive variables declared with
sensitive = true(orephemeral = truewhere only needed during the run)
Known Pitfalls¶
| Pitfall | Risk | Mitigation |
|---|---|---|
| Plaintext secrets in state | Credential exposure | Ephemeral values / write-only attributes; encrypt and restrict state |
terraform state pull to local disk |
Unencrypted copy of state | Use remote backends; avoid local copies |
| Unpinned module versions | Supply-chain changes | Pin versions; commit the lock file |
| Broad workspace Write access | Unauthorized changes | Least-privilege team access per workspace |
| Missing state locking | Concurrent apply corruption | Enable backend locking |
| Long-lived provider keys | Key compromise | OIDC dynamic credentials |
.terraformignore bypass (CVE-2026-14978) |
Unintended files uploaded | Upgrade to 1.15.9+ / 1.16.x |
Performance Estimates (Unsourced)¶
Unsourced performance data
Do not plan capacity from these numbers. They were estimated from vendor documentation, community reports, and engineering judgment, not controlled benchmarks; hardware, versions, and methodology were not recorded. Run your own measurements.
| State size | Plan time | Apply time | Memory |
|---|---|---|---|
| 50 resources | < 5s | 1-3m | 100MB |
| 500 resources | 15-60s | 5-15m | 500MB |
| 2,000 resources | 2-10m | 15-45m | 2GB |
| 10,000 resources | 10-30m | 1-3h | 8GB+ |
| Module count | Init time | Plan overhead |
|---|---|---|
| 5 | 5-10s | Negligible |
| 20 | 10-30s | 10-20% slower |
| 50+ | 30-120s | Consider splitting |
| State file size | Read / write | Full plan |
|---|---|---|
| Small (< 1MB) | < 1s | < 30s |
| Medium (1-10MB) | 1-5s | 30s-5m |
| Large (10-100MB) | 5-30s | 5-30m |
| Provider | Rate limit (approximate) | Impact on large plans |
|---|---|---|
| AWS | Varies per API (tens of req/s) | High -parallelism can hit throttling |
| Azure | Per-subscription ARM request quotas | Large plans may need throttling |
| GCP | Per-API quotas | Moderate limitation |
Not published: HashiCorp publishes no controlled performance benchmark for Terraform 1.16 (checked 2026-09-27). The 1.17 pre-release adds a -minimal-refresh planning option that refreshes only resources with proposed changes (v1.17 CHANGELOG), which should cut refresh cost on large states.
Sources¶
- Terraform releases index
- hashicorp/terraform CHANGELOG (main) and per-branch changelogs (v1.13-v1.17)
- HashiCorp pricing
- HCP Terraform limits
- Terraform Enterprise releases
- HashiConf 2025 Terraform announcements