Skip to content
Release Radar

Infrastructure as code for any cloud

v1.16.47 days after v1.16.3
View on GitHub

Release history

v1.16.4

CompareGitHub

1.16.4 (September 23, 2026)

BUG FIXES:

  • Fixed an issue where Terraform fails when rendering policy evaluation outcomes for older versions of Terraform Enterprise (#39095)

  • stacks: Fix invalid deferred error triggered by provider returning a deferral when a resource also has an unknown count/for_each. (#39237)

1.16.3 (September 16, 2026)

BUG FIXES:

  • Fix handling of destroy=false around create_before_destroy instances (#39169)

  • Fix function result comparison when there are multiple marks (#39170)

  • Filter logic for marks could cause values with multiple marks to erroneously fail validations (#39171)

  • Fix issue with import provider resolution (#39185)

1.16.2 (September 9, 2026)

BUG FIXES:

  • Fix panic in module installation when encoutering invalid module calls (#39129)

1.16.1 (September 2, 2026)

BUG FIXES:

  • cloud: Fixed a bug causing the CLI to pause indefinitely after a run task failure with pending policy evaluations (#38751)

  • Support referencing modules containing dynamic sources in Terraform Test (#38950)

  • stacks: Fixed validation to ensure the provider versions in the lock file and configuration are compatible. (#38829)

  • Fix panic when import identity references sensitive value (#39013)

  • import: Fixed a bug where import blocks would be ignored when multiple imports targeted different instances of a resource config using for_each or count. (#39068)

  • state show: Fix a panic when given an attribute path instead of a resource instance address (#39087)

  • Fix create_before_destroy ordering in some combinations of changes (#39091)

1.16.0 (August 26, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449)

  • stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. (#38668)

  • Actions can now use before_destroy and after_destroy events. (#38668)

  • cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. (#38715)

  • policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply, rather than requiring the plugin to read credentials itself. (#38716)

  • graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. (#38719)

  • Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)

  • Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. (#38784)

  • The contains() function can now test for null values. (#38792)

  • console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)

  • -invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. (#38845)

  • The terraform stacks command now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set (#38896)

BUG FIXES:

  • import blocks now correctly respect provider local names. (#38338)

  • terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. (#38586)

  • workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)

  • test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. (#38603)

  • init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override. (#38634)

  • init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)

  • Actions are now invoked with respect to all resource dependencies. (#38668)

  • Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. (#38782)

  • The merge() function no longer panics when passed null objects. (#38792)

  • Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid (#38894)

  • test: Optional ephemeral values do not have to be set at plan time (#38974)

NOTES:

  • init: Errors due to incompatible -upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)

UPGRADE NOTES:

  • bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)

Previous Releases

For information on prior major and minor releases, refer to their changelogs:

1.15.9 (August 19, 2026)

BUG FIXES:

  • validate: Child module validation has been fixed and will now raise errors or warning diagnostics for invalid blocks. (list, import, backend, and cloud) (#38994)

NOTES:

  • Update go-slug to v0.18.3 to mitigate CVE-2026-14978, which is a Unicode normalization issue that could lead to files not being correctly excluded via .terraformignore from upload to a Terraform Enterprise or HCP Terraform during a run (#39036)

1.15.8 (July 8, 2026)

BUG FIXES:

  • Fix terraform init error when installing providers sourced from a service-discovery alias advertised by the configured backend (such as localterraform.com)

NOTES:

  • command/init: Provider installation was changed to enable future enhancements in the area. This effectively reverses the log message changes from v1.15. initializing_provider_plugin_message is being re-introduced to replace the short-lived two message types initializing_provider_plugin_from_config_message & initializing_provider_plugin_from_state_message. The change should not have any significant end-user impact aside from the command output. (#38838)

  • command/init: Provider installation was changed to enable future enhancements in the area. This partially reverses the init event order changes from v1.15; module installation will now occur after the backend is initialized. The change should not have any significant end-user impact aside from the command output. (#38838)

1.15.7 (June 24, 2026)

BUG FIXES:

  • Add concurrency safety to configs.Parser and SourceBundleParser (#38745)

  • Fix submodule variable validation during init (#38770)