1.16.0-beta1 (July 23, 2026)
NEW FEATURES:
-
Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)
-
terraform_data: The newstoreblock can hold ephemeral and sensitive values across plan and apply. (#38298) -
Providers can now use nested blocks as computed values (#38305)
-
import:
importblocks inside modules are now supported. (#38352) -
Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)
-
Resource action triggers can now use
on_failuremodes ofhalt,taint, orcontinue. (#38722)
ENHANCEMENTS:
-
state show: The
state showcommand can now produce machine-readable output when supplied with the-jsonflag (#23940) -
workspace: The
workspace listcommand can now produce machine-readable output when supplied with the-jsonflag (#38397) -
test: Terraform now reports which resources were left behind when
skip_cleanupis set. (#38449) -
stacks: Action configurations now have access to a
callersymbol containing the object value of the calling resource. (#38668) -
Actions can now use
before_destroyandafter_destroyevents. (#38668) -
cloud: Terraform now displays a summary of policy evaluation outcomes for
planandapplyruns against HCP Terraform. (#38715) -
policy: Terraform now resolves policy plugin credentials from the configured cloud or remote backend during
init,plan, andapply, rather than requiring the plugin to read credentials itself. (#38716) -
graph: The
terraform graphcommand can now output graphs in Mermaid format using the-format=mermaidflag. (#38719) -
Child module outputs with unreferenced deprecated nested attributes no longer return deprecation warnings. (#38778)
-
Resource
lifecycleblocks now supportdestroy = falseto prevent a resource from being destroyed. (#38784) -
The
contains()function can now test fornullvalues. (#38792) -
console: The
terraform consolecommand now accepts an optional-scope=<module address>flag, which can be used to evaluate expressions within the scope of a module or a specific module instance. (#31861) -
-invokecan now be combined with-targetto specify the calling resource instance when multiple resources trigger the same action. (#38845) -
The
terraform stackscommand now automatically infers the target hostname from the local credentials file (credentials.tfrc.json) when neitherTF_STACKS_HOSTNAMEnorTF_CLOUD_HOSTNAMEis set (#38896)
BUG FIXES:
-
importblocks now correctly respect provider local names. (#38338) -
terraform applyno longer panics when the plan contains a no-op change for a deposed resource that haslifecycle.preconditionorlifecycle.postconditionblocks. (#38586) -
workspace: Terraform now raises an error if an invalid workspace name becomes selected due to out-of-band changes. (#38594)
-
test: Terraform now raises a warning when a file referenced via the
-filterflag does not exist. (#38603) -
init: Terraform no longer removes locks from the dependency lock file for providers configured as
dev_override. (#38634) -
init: Terraform now warns when unmanaged providers are in use and may impact provider installation. (#38656)
-
Actions are now invoked with respect to all resource dependencies. (#38668)
-
Terraform now returns the correct error when an
importtarget exists in state but has no corresponding configuration. (#38782) -
The
merge()function no longer panics when passednullobjects. (#38792)
NOTES:
- init: Errors due to incompatible
-upgradeand-lockfile=readonlyflags are now raised earlier in the init process. (#38561)
UPGRADE NOTES:
bastion_host_keyis now correctly applied by provisioners. Review your provisioner configurations to verify the configured key is correct before upgrading. (#38318)
Previous Releases
For information on prior major and minor releases, refer to their changelogs: