Skip to content

Releases: hashicorp/terraform

v1.16.1

Choose a tag to compare

@hc-github-team-es-release-engineering hc-github-team-es-release-engineering released this 02 Sep 14:49
58e916f

1.16.1 (September 2, 2026)

BUG FIXES:

  • cloud: Fixed a bug causing the CLI to pause indefinitely after a run task failure with pending policy evaluations (#38751)

  • Support referencing modules containing dynamic sources in Terraform Test (#38950)

  • stacks: Fixed validation to ensure the provider versions in the lock file and configuration are compatible. (#38829)

  • Fix panic when import identity references sensitive value (#39013)

  • import: Fixed a bug where import blocks would be ignored when multiple imports targeted different instances of a resource config using for_each or count. (#39068)

  • state show: Fix a panic when given an attribute path instead of a resource instance address (#39087)

  • Fix create_before_destroy ordering in some combinations of changes (#39091)

v1.17.0-alpha20260827

v1.17.0-alpha20260827 Pre-release
Pre-release

Choose a tag to compare

1.17.0-alpha20260827 (August 27, 2026)

NEW FEATURES:

  • A new -minimal-refresh planning option has been added, which will only refresh resources that have proposed changes. (#35290)

ENHANCEMENTS:

  • command/init: Enrich log messages with provider versions (#38918)

  • command/login: display warning after successful login if user is subject to an organization's TTL policy

BUG FIXES:

  • funcs: pow and log no longer panic when result is not a number (#38912)

  • ephemeral: Terraform will now use and display diagnostics raised when renewing an ephemeral resource. This may cause warnings to appear that previously were lost. We expect that any error diagnostics that were previously lost would have caused confusing downstream errors, so we do not anticipate this change to be breaking. (#38989)

  • Fix panic when import identity references sensitive value (#39013)

NOTES:

  • version: JSON output now includes a new format_version field, which will enable safer future changes of the command's JSON output format. It is assumed existing tooling ignores unknown fields and therefore this change should not be breaking in itself but we advice consumers to pay attention to format_version in future releases and/or use latest version of hashicorp/terraform-json & hashicorp/terraform-exec which does. (#38930)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
  • terraform query: The experimental -policies flag permits specifying one or more policy set directory paths to evaluate policies against resources discovered by list blocks during a query operation.

Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.16.0

Choose a tag to compare

1.16.0 (August 26, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449)

  • stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events. (#38668)

  • cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. (#38715)

  • policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply, rather than requiring the plugin to read credentials itself. (#38716)

  • graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. (#38719)

  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. (#38784)

  • The contains() function can now test for null values. (#38792)

  • console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)

  • -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. (#38845)

  • The terraform stacks command now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set (#38896)

BUG FIXES:

  • import blocks now correctly respect provider local names. (#38338)

  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. (#38586)

  • workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)

  • test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. (#38603)

  • init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override. (#38634)

  • init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. (#38782)

  • The merge() function no longer panics when passed null objects. (#38792)

  • Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid (#38894)

  • test: Optional ephemeral values do not have to be set at plan time (#38974)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

UPGRADE NOTES:

  • bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)

Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.16.0-rc2

v1.16.0-rc2 Pre-release
Pre-release

Choose a tag to compare

@hc-github-team-es-release-engineering hc-github-team-es-release-engineering released this 19 Aug 12:08
9df35d7

1.16.0-rc2 (August 19, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449)

  • stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events. (#38668)

  • cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. (#38715)

  • policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply, rather than requiring the plugin to read credentials itself. (#38716)

  • graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. (#38719)

  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. (#38784)

  • The contains() function can now test for null values. (#38792)

  • console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)

  • -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. (#38845)

  • The terraform stacks command now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set (#38896)

BUG FIXES:

  • import blocks now correctly respect provider local names. (#38338)

  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. (#38586)

  • workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)

  • test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. (#38603)

  • init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override. (#38634)

  • init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. (#38782)

  • The merge() function no longer panics when passed null objects. (#38792)

  • Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid (#38894)

  • test: Optional ephemeral values do not have to be set at plan time (#38974)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

UPGRADE NOTES:

  • bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)

Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.15.9

Choose a tag to compare

@hc-github-team-es-release-engineering hc-github-team-es-release-engineering released this 19 Aug 14:29
8748897

1.15.9 (August 19, 2026)

BUG FIXES:

  • validate: Child module validation has been fixed and will now raise errors or warning diagnostics for invalid blocks. (list, import, backend, and cloud) (#38994)

NOTES:

  • Update go-slug to v0.18.3 to mitigate CVE-2026-14978, which is a Unicode normalization issue that could lead to files not being correctly excluded via .terraformignore from upload to a Terraform Enterprise or HCP Terraform during a run (#39036)

v1.17.0-alpha20260812

v1.17.0-alpha20260812 Pre-release
Pre-release

Choose a tag to compare

@hc-github-team-es-release-engineering hc-github-team-es-release-engineering released this 12 Aug 12:01
5e83043

1.17.0-alpha20260812 (August 12, 2026)

ENHANCEMENTS:

  • command/init: Enrich log messages with provider versions (#38918)

BUG FIXES:

  • funcs: pow and log no longer panic when result is not a number (#38912)

  • ephemeral: Terraform will now use and display diagnostics raised when renewing an ephemeral resource. This may cause warnings to appear that previously were lost. We expect that any error diagnostics that were previously lost would have caused confusing downstream errors, so we do not anticipate this change to be breaking. (#38989)

NOTES:

  • version: JSON output now includes a new format_version field, which will enable safer future changes of the command's JSON output format. It is assumed existing tooling ignores unknown fields and therefore this change should not be breaking in itself but we advice consumers to pay attention to format_version in future releases and/or use latest version of hashicorp/terraform-json & hashicorp/terraform-exec which does. (#38930)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
  • terraform query: The experimental -policies flag permits specifying one or more policy set directory paths to evaluate policies against resources discovered by list blocks during a query operation.

Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.16.0-rc1

v1.16.0-rc1 Pre-release
Pre-release

Choose a tag to compare

@hc-github-team-es-release-engineering hc-github-team-es-release-engineering released this 12 Aug 15:22
a95c888

1.16.0-rc1 (August 12, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449)

  • stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events. (#38668)

  • cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. (#38715)

  • policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply, rather than requiring the plugin to read credentials itself. (#38716)

  • graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. (#38719)

  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. (#38784)

  • The contains() function can now test for null values. (#38792)

  • console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)

  • -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. (#38845)

  • The terraform stacks command now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set (#38896)

BUG FIXES:

  • import blocks now correctly respect provider local names. (#38338)

  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. (#38586)

  • workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)

  • test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. (#38603)

  • init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override. (#38634)

  • init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. (#38782)

  • The merge() function no longer panics when passed null objects. (#38792)

  • Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid (#38894)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

UPGRADE NOTES:

  • bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)

Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.16.0-beta2

v1.16.0-beta2 Pre-release
Pre-release

Choose a tag to compare

@hc-github-team-es-release-engineering hc-github-team-es-release-engineering released this 05 Aug 18:07
bc517be

1.16.0-beta2 (August 05, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449)

  • stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events. (#38668)

  • cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. (#38715)

  • policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply, rather than requiring the plugin to read credentials itself. (#38716)

  • graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. (#38719)

  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. (#38784)

  • The contains() function can now test for null values. (#38792)

  • console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)

  • -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. (#38845)

  • The terraform stacks command now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set (#38896)

BUG FIXES:

  • import blocks now correctly respect provider local names. (#38338)

  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. (#38586)

  • workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)

  • test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. (#38603)

  • init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override. (#38634)

  • init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. (#38782)

  • The merge() function no longer panics when passed null objects. (#38792)

  • Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid (#38894)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

UPGRADE NOTES:

  • bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)

Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.17.0-alpha20260729

v1.17.0-alpha20260729 Pre-release
Pre-release

Choose a tag to compare

@hc-github-team-es-release-engineering hc-github-team-es-release-engineering released this 29 Jul 19:38
dfdd475

1.17.0-alpha20260729 (July 29, 2026)

ENHANCEMENTS:

  • command/init: Enrich log messages with provider versions (#38918)

BUG FIXES:

  • funcs: pow and log no longer panic when result is not a number (#38912)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes:
    • Test authors can now specify backend blocks within run blocks in Terraform Test files. Run blocks with backend blocks will load state from the specified backend instead of starting from empty state on every execution. This allows test authors to keep long-running test infrastructure alive between test operations, saving time during regular test operations.
    • Test authors can now specify skip_cleanup attributes within test files and within run blocks. The skip_cleanup attribute tells terraform test not to clean up state files produced by run blocks with this attribute set to true. The state files for affected run blocks will be written to disk within the .terraform directory, where they can then be cleaned up manually using the also experimental terraform test cleanup command.
  • terraform query: The experimental -policies flag permits specifying one or more policy set directory paths to evaluate policies against resources discovered by list blocks during a query operation.

Previous Releases

For information on prior major and minor releases, refer to their changelogs:

v1.16.0-beta1

v1.16.0-beta1 Pre-release
Pre-release

Choose a tag to compare

@hc-github-team-es-release-engineering hc-github-team-es-release-engineering released this 23 Jul 16:51
e721df8

1.16.0-beta1 (July 23, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449)

  • stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events. (#38668)

  • cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. (#38715)

  • policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply, rather than requiring the plugin to read credentials itself. (#38716)

  • graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. (#38719)

  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. (#38784)

  • The contains() function can now test for null values. (#38792)

  • console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)

  • -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. (#38845)

  • The terraform stacks command now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set (#38896)

BUG FIXES:

  • import blocks now correctly respect provider local names. (#38338)

  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. (#38586)

  • workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)

  • test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. (#38603)

  • init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override. (#38634)

  • init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. (#38782)

  • The merge() function no longer panics when passed null objects. (#38792)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

UPGRADE NOTES:

  • bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)

Previous Releases

For information on prior major and minor releases, refer to their changelogs: