↓メインコンテンツへスキップ

Terraform コマンド一覧・チートシート【用途別・実務向け】

0222-nnn
著者
0222-nnn
猫が好き
目次

Terraformで使いたいコマンドを、目的からすぐに探せるCLIリファレンスです。

初期化や実行計画の確認など、実務でよく使う操作ごとに「やりたいこと → 実行するコマンド」の順で並べています。

このページの位置づけ
#

Terraform CLI チートシート(このページ)
    ↓
[Terraform × Google Cloud シリーズ](/terraform-google-cloud/)
    ↓
各 GCP 検証記事(22本)

Google Cloudの検証記事はTerraform × Google Cloud シリーズにまとめてあります。

Terraform 基本ワークフロー
#

コードを書く
    ↓
terraform fmt
    ↓
terraform init
    ↓
terraform validate
    ↓
terraform plan
    ↓
terraform apply
    ↓
terraform output

不要になったら
    ↓
terraform destroy

超速見表
#

やりたいこと コマンド
初期化する terraform init
コードを整形する terraform fmt
文法・設定を検証する terraform validate
変更内容を見る terraform plan
変更を適用する terraform apply
Outputを見る terraform output
管理中Resourceを見る terraform state list
Resource詳細を見る terraform state show ADDRESS
既存ResourceをTerraform管理に入れる import block(推奨)/ terraform import
実環境との差分だけ確認する terraform plan -refresh-only
リソースを作り直す terraform plan -replace=ADDRESS
式や関数を対話的に試す terraform console
全Resourceを削除する terraform destroy

1. 普段使う基本コマンド
#

terraform init
#

terraform init

Provider・Module・Backendを初期化します。Repositoryをcloneした直後も、まずここから。繰り返し実行しても安全なコマンドです。

よく使うオプション:

terraform init -upgrade
terraform init -reconfigure
terraform init -migrate-state
terraform init -backend-config=backend.hcl
オプション いつ使う?
-upgrade ProviderやModuleのバージョンを更新したい
-reconfigure Backend設定を変更し、既存Backend設定を無視して再初期化したい
-migrate-state Local State → GCS Backendなど、Stateを移行したい
-backend-config Backend設定を外部ファイルや変数で渡したい(環境ごとの切り替え)

関連記事:

terraform fmt / validate
#

terraform fmt
terraform validate

CI向け:

terraform fmt -check
terraform validate

ディレクトリ全体を整形する場合:

terraform fmt -recursive

2. plan
#

このページで最も参照される章です。

terraform plan

変数ファイルを指定:

terraform plan -var-file="terraform.tfvars"

Planを保存:

terraform plan -out=tfplan

保存したPlanを確認:

terraform show tfplan

JSONで確認:

terraform show -json tfplan

実環境との差分を確認する(Stateも実インフラも書き換えません):

terraform plan -refresh-only

plan -refresh-only は差分を表示するだけで、Stateは書き換えません。反映するのは terraform apply -refresh-only のほうです(第6章参照)。

特定Resourceだけ対象:

terraform plan -target=google_compute_instance.example

⚠️ -target は障害復旧などの例外時だけ使ってください。 公式ドキュメントでも日常運用では推奨されていません。検知されないDriftの原因になります。

大きな構成を分けて扱いたいときは、Configuration自体を小さく分割し、data sourceで参照します。

Resourceを再作成:

terraform plan -replace=google_compute_instance.example

-out=tfplan でPlanを保存し、terraform apply tfplan で適用します。レビューした内容がそのまま適用されるため、CI/CDではこの形が基本になります。

関連記事:

3. apply
#

通常:

terraform apply

保存したPlanを適用:

terraform apply tfplan

自動承認:

terraform apply -auto-approve

⚠️ -auto-approve は承認プロンプトを省略します。 手元での作業では使わないでください。外部変更が紛れ込んでいても、そのまま適用されます。

Refresh Onlyの結果をStateへ反映:

terraform apply -refresh-only

4. State確認
#

State の中身を確認するコマンドです。トラブル対応でよく使います。

terraform state list
terraform state show google_compute_instance.example
terraform state pull
terraform show
terraform output
terraform output -raw project_id

関連記事:

5. State操作・トラブル対応
#

⚠️ ここから先はStateを書き換えます。 実行前に影響範囲を確認してください。

terraform state mv
terraform state rm
terraform import
terraform force-unlock

terraform state rm が消すのはStateの記録だけで、Cloud Resourceは残ります。

Terraformの管理対象から外す
Resource自体は残る

Terraform 1.7以降は removed block が推奨です。Plan/Apply を経由するため、変更をレビューできます。

removed {
  from = google_compute_instance.example

  lifecycle {
    destroy = false
  }
}

⚠️ lifecycle blockは必須です。 destroy = false を書き忘れると、State から外れるだけでは済まず、実Resourceが削除されます。

アドレスの変更(リネーム)も同じく、state mv より moved block(Terraform 1.1以降)を使います。

moved {
  from = google_compute_instance.old_name
  to   = google_compute_instance.new_name
}
やりたいこと 従来のCLI 推奨(Config駆動)
アドレスを変更する terraform state mv moved block(1.1+)
管理対象から外す terraform state rm removed block(1.7+)
既存Resourceを取り込む terraform import import block(1.5+)

Config駆動なら変更がPlanに現れ、Gitの差分としても残ります。

Lockが残った場合:

terraform force-unlock LOCK_ID

6. Drift・Refresh
#

通常の terraform plan も、実環境をRefreshしてから比較しています。

Stateだけ同期したい場合:

terraform plan -refresh-only
terraform apply -refresh-only

terraform refresh について:

方法 状態
terraform refresh 非推奨(deprecated)
terraform plan -refresh-only → terraform apply -refresh-only 推奨

terraform refresh は現在 terraform apply -refresh-only -auto-approve のエイリアスです。承認プロンプトが常にスキップされます。

そのため、Providerの認証情報が誤っていると危険です。Terraformが「全Resourceが削除された」と誤認し、Stateから一括で取り除いてしまいます。

古い記事で terraform refresh を見かけたら、こちらに読み替えてください。

7. Resourceを再作成したい
#

方法 状態
terraform taint ADDRESS 非推奨(deprecated)
terraform plan -replace=ADDRESS 推奨(v0.15.2以降)

現在の手順:

terraform plan -replace=google_compute_instance.example
terraform apply -replace=google_compute_instance.example

8. CI/CD用コマンド
#

GitHub Actionsなどでの基本フロー:

terraform init -input=false
terraform fmt -check
terraform validate
terraform plan -input=false -out=tfplan
terraform apply -input=false tfplan

公式のAutomation workflowも init → plan保存 → review → apply の順です。

Planに差分があるかどうかで分岐したい場合は -detailed-exitcode を使います。

terraform plan -input=false -detailed-exitcode -out=tfplan
終了コード 意味
0 差分なし
1 エラー
2 差分あり

set -e を使うCIでは終了コード 2 も失敗と見なされます。明示的にハンドリングしてください。

関連記事:

9. その他よく使うコマンド
#

terraform console
#

式や関数の振る舞いをその場で試せます。for 式や cidrsubnet() を書く前の確認に便利です。

terraform console
> upper("gce-instance")
"GCE-INSTANCE"
> cidrsubnet("10.0.0.0/16", 8, 1)
"10.0.1.0/24"

terraform workspace
#

同じConfigurationで複数のStateを切り替えます。

terraform workspace list
terraform workspace new dev
terraform workspace select dev

ただし本番と検証を分けるなら、ディレクトリ分割やBackend分割のほうが安全です。Workspaceは一時的な切り替えに向いています。

terraform providers lock
#

複数OS向けのProviderハッシュを .terraform.lock.hcl に記録します。LinuxのCIと手元のmacOS/Windowsが混在するなら必要になります。

terraform providers lock -platform=linux_amd64 -platform=darwin_arm64

terraform version
#

バージョン差で挙動が変わったと疑うときは、まずこれを確認します。

terraform version

10. 逆引き
#

状況 使うコマンド
cloneして最初に何をする? terraform init
.tfを書き換えた terraform fmt → validate → plan
Providerを更新したい terraform init -upgrade
Backendを変更した terraform init -reconfigure / -migrate-state
実環境との差分を調べたい terraform plan
Stateだけ同期したい terraform plan -refresh-only
Resourceだけ再作成したい terraform plan -replace=ADDRESS
Terraform管理対象を確認したい terraform state list
ResourceのStateを確認したい terraform state show ADDRESS
既存ResourceをTerraform管理にしたい import block / terraform import
Resourceのアドレスを変えたい moved block / terraform state mv
Terraform管理だけ解除したい removed block / terraform state rm
式や関数の振る舞いを確かめたい terraform console
環境ごとにStateを分けたい ディレクトリ分割 / terraform workspace
Lockが残ってしまった terraform force-unlock LOCK_ID
Planを保存したい terraform plan -out=tfplan
保存したPlanを実行したい terraform apply tfplan
全部削除したい terraform destroy

11. サイト内リンク(CLI → GCP記事)
#

CLIのテーマ 関連する検証記事
init / Provider Project情報を取得する
plan / apply Google Cloud APIを有効化する
output 各GCP構築記事(シリーズ一覧)
state / Backend Terraform StateをGCSで管理する
CI/CD GitHub Actions + WIF

次に読むページ
#

Google Cloudの検証記事は、次のハブページからたどれます。

→ Terraform × Google Cloud シリーズ

参考資料
#