Terraform CI/CD · Terraform systems note
A Saved Terraform Plan Is a Deployment Artifact, Not Just Pretty Diff Output
A saved plan captures the exact actions Terraform intends to apply. In CI/CD it becomes the handoff between review and execution—and a sensitive artifact that must be protected.
A common pipeline runs terraform plan in one job, shows the text to a reviewer, and later runs a fresh terraform apply. Those two commands can produce different plans.
Speculative plans are for review
An unsaved plan describes what Terraform would do at that moment. Remote infrastructure can drift, input values can change, provider versions can differ, or a different commit can reach the apply stage later.
-out creates the executable handoff
terraform plan -out=tfplan writes a saved plan. Applying that file executes the operations captured in the plan rather than calculating a new one. This is the cleanest basis for “review exactly what we will execute.”
The plan file is sensitive
HashiCorp warns not to commit saved plans—binary or JSON—to version control because they can contain cleartext values needed by providers. CI artifact permissions, retention and encryption therefore matter.
Approval should bind to commit and plan
A strong pipeline records source revision, environment inputs, provider lock file and saved plan together. If code changes after approval, regenerate the plan.
Saved-plan apply does not prompt
Passing a plan file to terraform apply skips the normal confirmation prompt. Your pipeline approval is therefore the human safety gate.
A saved plan is best treated like a release artifact: immutable, short-lived, protected and tied to one deployment decision.