What is the difference between terraform plan and apply?
Assesses fundamental understanding of Terraform & IaC conventions, runtime behavior, and memory/performance considerations.
Hiring managers look for precision, avoidance of ambiguous jargon, and ability to explain trade-offs under real production conditions.
plan is a dry run; apply makes changes.
- terraform plan refreshes state, compares configuration to reality, and shows what will be created, updated, or destroyed. It does not change infrastructure. Use -out to save the plan.
- terraform apply executes the proposed actions and calls provider APIs. With a saved plan it applies exactly what you reviewed.
terraform plan -out=tfplan
terraform apply tfplan
terraform plan -detailed-exitcode
The detailed exit code helps CI: 0 means no changes, 1 is an error, and 2 means changes are present. Review plans carefully, especially destroys and replacements marked -/+. A resource that changes a force-new attribute is destroyed and recreated, which can cause downtime. Use -target only for emergencies, since it can leave state inconsistent. In automation, always apply the reviewed plan file.
Candidate Response Strategy & Interview Tips
- Start with a concise one-sentence summary: Deliver a direct, confident answer first before expanding into nuances.
- Demonstrate real-world trade-offs: Discuss where this approach excels and when you would avoid it in production systems.
- Discuss complexity & edge cases: Proactively explain time/space complexity or boundary conditions (null values, scale limits).
- Prepare for interviewer follow-ups: Technical hiring panels frequently probe deeper into concurrency, backward compatibility, or alternative libraries.