What does the `terraform graph` command produce, and how do you actually make use of its output?
answer
- prints text, draws nothing itself
- DOT language, needs Graphviz
- pipe into dot -Tsvg
- -draw-cycles highlights the loop
- hairball on a real root module
basics
~20 sterraform graph prints Terraform's internal dependency graph to stdout in Graphviz DOT format. You pipe it into the dot tool to render a picture, typically to confirm why an unexpected edge exists or, with -draw-cycles, to see a loop.
solid answer
~50 s`terraform graph` writes the dependency graph as Graphviz DOT text on stdout — it does not draw anything itself, so you pipe it into Graphviz: `terraform graph | dot -Tsvg > graph.svg`. `-type=plan` selects which graph to emit, and `-draw-cycles` highlights loops, which is the single most useful thing it does. Treat it as a debugging aid rather than documentation. The output includes internal nodes such as provider and variable nodes, so a real root module renders as a hairball you cannot read end to end. It is good for confirming a specific suspicion — why does this resource wait on that one, where is the cycle — and poor for browsing. As of Terraform 1.x the exact shape of the output is an internal detail that changes between versions, so do not build tooling that parses it.
code
bash · 8 lines# Render the plan graph to an SVG (requires Graphviz)
terraform graph -type=plan | dot -Tsvg > graph.svg
# Highlight the edges that form a cycle
terraform graph -draw-cycles | dot -Tpng > cycles.png
# No Graphviz? Just grep the DOT text for one resource's edges
terraform graph | grep aws_instance.appgo deeper
Know that the command prints DOT text rather than an image, and that you pipe it into Graphviz's dot to see anything. Being able to say terraform graph | dot -Tsvg > graph.svg is the whole expected answer.
Add the useful flags — -type to pick the graph, -draw-cycles to highlight a loop — and be candid that the output includes internal nodes and is unreadable on a real root module.
Place it correctly among the tools: a debugging aid for a specific suspicion, not documentation and not a CI input. Point at terraform show -json on a saved plan as the stable machine-readable surface instead.
Judge what the team actually needs. If people keep reaching for graph output to understand the estate, the real problem is module structure and documentation, and no renderer will fix it.
## What the command does `terraform graph` asks Terraform to build its dependency graph and then serialise it in the DOT language, the plain-text format Graphviz reads. It prints that text to stdout and stops. There is no window, no image, no interactive viewer — rendering is your job: ``` terraform graph | dot -Tsvg > graph.svg ``` That requires Graphviz installed locally (`dot` is its command-line renderer). Without it you just get several hundred lines of `"node_a" -> "node_b"` on your terminal, which is occasionally enough: grepping the DOT text for a resource address shows every edge it participates in, without rendering anything. ## The options worth knowing `-type=plan` selects which of Terraform's internal graphs to emit; the plan graph is the one that matches what you are usually reasoning about. `-plan=path` builds the graph from a saved plan file instead of from the configuration. And `-draw-cycles` colours the edges that form a loop, which turns a wall of nodes into a picture with an obvious red ring: ``` terraform graph -draw-cycles | dot -Tpng > cycles.png ``` That last one is the reason most engineers ever run the command. When `Error: Cycle:` lists a dozen members and the mutual reference is buried inside a `for` expression or a generated module, the drawing finds it faster than reading code. ## Why the output is harder to use than people expect The graph Terraform walks is not the tidy diagram of your resources. It contains nodes for provider configurations, variables, locals, outputs, module expansion and internal bookkeeping, and it does not collapse them for presentation. A root module with sixty resources produces a picture with several hundred nodes and no useful layout — technically correct, humanly unreadable. So the honest framing is: `terraform graph` answers a question you already have. "Why does this instance wait for that policy?" or "where does this loop close?" are answerable. "Show me how my infrastructure fits together" is not — for that, a hand-drawn architecture diagram or the module structure itself communicates far better. It is also worth saying plainly that the output format is an implementation detail. As of Terraform 1.x the command remains available, but the node naming and structure have changed across versions and are not a stable contract. Parsing it in CI to enforce a rule is a fragile idea; the plan file (via `terraform show -json`) is the machine-readable surface, not this. ## Alternatives people reach for When the goal is understanding rather than debugging, most teams get further with cheaper tools: reading the plan output, which already lists what will change and in what shape; grepping for a resource address to find every reference to it; or keeping a diagram of modules and their inputs and outputs, which is the level a human actually reasons at. Third-party visualisers exist and consume the JSON plan rather than DOT, which is the more durable input. ## In an interview This is a small question, and the strong answer is small and honest: DOT to stdout, pipe to Graphviz, `-draw-cycles` for loops, unreadable at scale, do not depend on the format. Candidates who oversell it — claiming they generate architecture diagrams from it for stakeholders — usually have not run it on anything large.
- Would you build a CI check that parses terraform graph output to enforce a dependency rule?No. The DOT output is an internal representation with no stability guarantee, so the check breaks on a Terraform upgrade for reasons unrelated to your infrastructure. If you need machine-readable facts about a change, run `terraform show -json` on a saved plan — that is the documented, versioned interface.
- When is terraform graph genuinely the fastest tool to reach for?When you have a cycle error whose member list is long or whose references are generated, `terraform graph -draw-cycles` piped into Graphviz shows the loop immediately. It is also useful for confirming a single suspected edge. For anything broader, reading the plan or grepping for the resource address is faster.
saying these in an interview costs you the question
- terraform graph opens a diagram window
- It produces an architecture diagram for stakeholders
- The DOT output is a stable format you can parse
- It shows only your resources, nothing internal
- You need it to understand ordering day to day