Chapter 12: Terraform Introduction
12.5 Workflow — init, plan, apply, destroy
cd terraform-badge-api-lab
# create terraform.tfvars (gitignored) with vpc_id and my_ip_cidr
terraform init # download providers
terraform plan # read the diff — REQUIRED habit
terraform apply # type yes after reading plan
terraform destroy # when lab is done — do not skip
| Command | Purpose |
|---|---|
init |
Backend + providers ready |
plan |
Show create/change/destroy before it happens |
apply |
Execute the approved plan |
destroy |
Remove resources this state tracks |
fmt / validate |
Style + basic config checks |
Steps — SG lab end-to-end
- Install Terraform CLI for your OS (HashiCorp docs).
- Create a small project folder with
versions.tf,main.tf,variables.tf,outputs.tf. - Add
terraform.tfvars(gitignored) with realvpc_idandmy_ip_cidr(x.x.x.x/32). - Ensure AWS CLI credentials work (
aws sts get-caller-identity) the way you already use in AWS labs. terraform initterraform plan— confirm 1 to add (SG), nothing surprise-destroying.terraform apply- Note the output SG id; verify in AWS console or CLI.
terraform destroywhen finished — confirm empty plan afterward or console absence.
What you see on plan: resource address aws_security_group.badge-api_lab planned for creation. On destroy: planned destruction of that SG. Never ignore a plan that destroys resources you did not expect.
Ravindra Bagale's Tip
apply agodar plan skip karane — classic chuk. Plan madhe destroy disale tar thamba. Lakshat theva!