.changes/1.16.0.md
NEW FEATURES:
Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)
terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)
Providers can now use nested blocks as computed values (#38305)
import: import blocks inside modules are now supported. (#38352)
Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)
Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)
ENHANCEMENTS:
state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)
workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)
test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449)
stacks: Action configurations now have access to a caller symbol containing the object value of the calling resource. (#38668)
Actions can now use before_destroy and after_destroy events. (#38668)
cloud: Terraform now displays a summary of policy evaluation outcomes for plan and apply runs against HCP Terraform. (#38715)
policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during init, plan, and apply, rather than requiring the plugin to read credentials itself. (#38716)
graph: The terraform graph command can now output graphs in Mermaid format using the -format=mermaid flag. (#38719)
Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)
Resource lifecycle blocks now support destroy = false to prevent a resource from being destroyed. (#38784)
The contains() function can now test for null values. (#38792)
console: The terraform console command now accepts an optional -scope=<module address> flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)
-invoke can now be combined with -target to specify the calling resource instance when multiple resources trigger the same action. (#38845)
The terraform stacks command now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neither TF_STACKS_HOSTNAME nor TF_CLOUD_HOSTNAME is set (#38896)
BUG FIXES:
import blocks now correctly respect provider local names. (#38338)
terraform apply no longer panics when the plan contains a no-op change for a deposed resource that has lifecycle.precondition or lifecycle.postcondition blocks. (#38586)
workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)
test: Terraform now raises a warning when a file referenced via the -filter flag does not exist. (#38603)
init: Terraform no longer removes locks from the dependency lock file for providers configured as dev_override. (#38634)
init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)
Actions are now invoked with respect to all resource dependencies. (#38668)
Terraform now returns the correct error when an import target exists in state but has no corresponding configuration. (#38782)
The merge() function no longer panics when passed null objects. (#38792)
Allow underscores in provider source address namespaces, so private registry provider addresses are no longer rejected as invalid (#38894)
test: Optional ephemeral values do not have to be set at plan time (#38974)
NOTES:
-upgrade and -lockfile=readonly flags are now raised earlier in the init process. (#38561)UPGRADE NOTES:
bastion_host_key is now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)