terraform apply during an infra migration stopped at Do you want to perform these actions and the agent timed out...
Runs terraform apply non-interactively in agent-driven infra migrations. Use it when apply stalls on the approval prompt with no terminal. Key trigger: apply waits on the Do-you-want-to-perform-these-actions question.
TL;DR: Split the run into plan and apply: terraform plan -out=tfplan first, then terraform apply tfplan - applying a saved plan file never prompts. Review the plan output before approving it, and record that approval in the run log. The prompt exists to stop unreviewed changes; the fix is to move the review earlier, not to blindly auto-approve.
Do you want to perform these actions?- Confirm the stall is the approval prompt: the process is idle and the last output is the plan summary followed by the actions question.
Expected: you can see the full proposed plan in the output above the prompt.
- Kill the hung process - with the prompt unanswered, nothing was applied.
Expected: the process exits and terraform plan afterward shows the same pending changes.
- Generate a saved plan: run
terraform plan -out=tfplan.
Expected: the plan is written to the tfplan file and the summary is printed for review.
- Review the plan output (resources to add, change, and especially destroy) and record the approval decision in the run log.
Expected: a human or policy check has explicitly approved this exact plan.
- Apply the saved plan: run
terraform apply tfplan.
Expected: apply runs to completion with no prompt, since a saved plan is pre-approved.
Use this when
- terraform apply stalls on the approval question in a scripted or agent session
- an infra migration step times out waiting on the prompt
- you want apply to be non-interactive but still reviewed
Not for this skill when
- the plan itself fails - fix the configuration first
- state is locked by another run - resolve the lock, do not force it
- you are applying interactively at a terminal - just answer the prompt
Variant phrasings
- terraform apply hangs waiting for approval in CI
- Do you want to perform these actions with no tty
- agent terraform apply timed out on confirmation
Why it happens
terraform apply without a saved plan file always asks for confirmation before changing infrastructure - it is the last checkpoint between a proposal and real changes. In a headless agent run there is nobody to answer, so it waits until the harness kills it. Applying a saved plan file skips the question because the plan was already reviewed when it was created; the approval moves from apply-time to plan-time, which is exactly where an agent workflow can handle it.
Edge cases
- The -auto-approve flag also skips the prompt but removes the review checkpoint entirely - prefer the saved-plan workflow so every apply traces back to a reviewed plan.
- A stale plan file (configuration changed after planning) is rejected at apply time - regenerate the plan rather than forcing it.
- State locking still applies: if another process holds the state lock, apply waits on the lock, which looks like a hang but is a different problem.
- Destroy operations in a plan deserve a second pair of eyes - require explicit human approval for any plan containing destroys, even in automation.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_lrhRWQZ3aRIzBHFccvKU1g
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.