Checks HCL for structural syntax errors and flags common best-practice issues like hardcoded values and missing descriptions.
Paste Terraform configuration into this online validator to run a quick static check before using the Terraform CLI. The tool checks common structural problems such as unmatched braces and quotes, reviews Terraform block labels, and reports selected maintainability or security warnings, including missing version constraints, undocumented variables, sensitive-looking defaults, hardcoded identifiers and missing tags on common resources.
Important: This browser-based checker is a fast pre-check, not the official terraform validate command. It does not install providers or modules, load an entire working directory, contact provider APIs, inspect remote state, or guarantee that terraform plan will succeed.
terraform validate Do?The official terraform validate command checks the configuration files in a directory for syntax validity and internal consistency. It can detect problems such as invalid argument names, incorrect value types and inconsistent module configuration after the required providers and modules are installed. It does not validate remote services, provider APIs or remote state.
Validation is useful as a local development check, editor integration or CI step. For validation in the context of real input values, a selected workspace and existing state, use terraform plan, which includes an implied validation check.
Open a terminal in the root module directory and initialize the project before running validation:
terraform init -backend=false
terraform validate
The -backend=false option is useful when preparing a directory for validation without accessing its configured backend. Terraform still needs referenced providers and modules to be available. For machine-readable diagnostics in automation, run:
terraform validate -json
The JSON output can contain validity status, error and warning counts, diagnostics, source ranges and code snippets. Automation should also handle failures that happen before Terraform can produce valid JSON.
| Category | Checks Performed |
|---|---|
| Structure | Balanced braces and quotation marks, plus recognizable labels for resource, data, variable, output, module and provider blocks. |
| Versioning | Presence of a Terraform block, required_version and required_providers. |
| Variables | Missing descriptions or type constraints and sensitive-looking variables with hardcoded defaults. |
| Resources | Hardcoded AMI IDs, IP addresses and account IDs, plus missing tags on common taggable resources. |
This configuration is structurally readable, but it contains several maintainability and security concerns:
terraform {
required_version = ">= 1.5.0"
}
variable "db_password" {
default = "example-password"
}
resource "aws_instance" "web" {
ami = "ami-0c55b159cbfafe1f0"
instance_type = "t3.micro"
}
The online check can warn that required_providers is missing, the variable has no description or type, a sensitive-looking value has a hardcoded default, the AMI ID is hardcoded, and the resource has no tags. A safer revision can declare the provider, define a sensitive input without a secret default, use variables for environment-specific identifiers and add appropriate tags.
| Command or Tool | Primary Purpose |
|---|---|
terraform fmt | Rewrites Terraform files into Terraform’s canonical formatting style. |
terraform validate | Checks configuration syntax and internal consistency in an initialized directory. |
| TFLint | Adds lint rules and can perform provider-specific checks when configured. |
terraform plan | Evaluates the configuration for a particular run and previews proposed infrastructure changes. |
| This online validator | Provides an immediate static review of pasted code using the checks listed above. |
description and an explicit type.terraform fmt -check and terraform validate before opening a pull request.sensitive = true mainly redacts display output.terraform plan and review the proposed changes before terraform apply.A pasted snippet cannot represent every file, module, provider plugin, variable value or state dependency in a Terraform project. This tool performs only the checks explicitly listed on this page. Always use HashiCorp Terraform or your compatible Terraform workflow for authoritative project validation, planning and deployment.
terraform validate inside an initialized Terraform working directory. Use terraform validate -json when an editor or CI system needs machine-readable diagnostics.terraform init -backend=false.terraform plan to evaluate the configuration with a workspace, state and run-specific inputs.terraform fmt for canonical formatting. Validation and formatting solve different problems.terraform apply or create, update or delete cloud resources.