Release Notes
1.16.0-beta1 (July 23, 2026)
NEW FEATURES:
Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)
terraform_data: The newstoreblock can hold ephemeral and sensitive values across plan and apply. (#38298)Providers can now use nested blocks as computed values (#38305)
import:
importblocks inside modules are now supported. (#38352)Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)
Resource action triggers can now use
on_failuremodes ofhalt,taint, orcontinue. (#38722)
ENHANCEMENTS:
state show: The
state showcommand can now produce machine-readable output when supplied with the-jsonflag (#23940)workspace: The
workspace listcommand can now produce machine-readable output when supplied with the-jsonflag (#38397)test: Terraform now reports which resources were left behind when
skip_cleanupis set. (#38449)stacks: Action configurations now have access to a
callersymbol containing the object value of the calling resource. (#38668)Actions can now use
before_destroyandafter_destroyevents. (#38668)cloud: Terraform now displays a summary of policy evaluation outcomes for
planandapplyruns against HCP Terraform. (#38715)policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during
init,plan, andapply, rather than requiring the plugin to read credentials itself. (#38716)graph: The
terraform graphcommand can now output graphs in Mermaid format using the-format=mermaidflag. (#38719)Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)
Resource
lifecycleblocks now supportdestroy = falseto prevent a resource from being destroyed. (#38784)The
contains()function can now test fornullvalues. (#38792)console: The
terraform consolecommand now accepts an optional-scope=<module address>flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861)-invokecan now be combined with-targetto specify the calling resource instance when multiple resources trigger the same action. (#38845)The
terraform stackscommand now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neitherTF_STACKS_HOSTNAMEnorTF_CLOUD_HOSTNAMEis set (#38896)
BUG FIXES:
importblocks now correctly respect provider local names. (#38338)terraform applyno longer panics when the plan contains a no-op change for a deposed resource that haslifecycle.preconditionorlifecycle.postconditionblocks. (#38586)workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)
test: Terraform now raises a warning when a file referenced via the
-filterflag does not exist. (#38603)init: Terraform no longer removes locks from the dependency lock file for providers configured as
dev_override. (#38634)init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)
Actions are now invoked with respect to all resource dependencies. (#38668)
Terraform now returns the correct error when an
importtarget exists in state but has no corresponding configuration. (#38782)The
merge()function no longer panics when passednullobjects. (#38792)
NOTES:
- init: Errors due to incompatible
-upgradeand-lockfile=readonlyflags are now raised earlier in the init process. (#38561)
UPGRADE NOTES:
bastion_host_keyis now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)
Previous Releases
For information on prior major and minor releases, refer to their changelogs: