Terraform 1.17.0-rc1 Lists Terraform Policy as Generally Available, Plus Provider-Requirement Variables and a -minimal-refresh Plan Option
Terraform 1.17.0-rc1, dated October 7, 2026, adds variables in provider requirements and -minimal-refresh, and its notes call Terraform Policy generally available.
Overview
HashiCorp’s Terraform repository carries a 1.17.0-rc1 tag dated October 7, 2026. Its release notes list three new features: support for variables and locals in provider requirements, a -minimal-refresh planning option, and the statement that “Terraform Policy is now generally available.” As of October 11, 2026, the project’s GitHub releases listing shows no final 1.17.0 build, and the notes give no date for one.
What We Know
The notes say Terraform “now supports variables and locals in provider requirements.” They describe -minimal-refresh as a planning option that “will only refresh resources that have proposed changes.”
On policy, the rc1 notes say the -policies flag for plan, apply, and query “no longer requires an experimental build or the -allow-experimental-features flag.” They add that query policies “evaluate resources discovered by list blocks and report human-readable or JSON results.” A related fix says terraform query -policies now rejects a path that is not a directory, “instead of passing it on to the policy engine.”
Smaller items in the same notes include provider versions in init log messages and mock_provider support for ephemeral resources. The terraform login command will display a warning if the user is subject to an organization’s TTL policy. A fix means pow and log no longer panic when the result is not a number.
One note is aimed at tooling authors. The version command’s JSON output gains a format_version field, and the notes say it is assumed that existing tooling ignores unknown fields, so the change should not be breaking in itself. They advise consumers to pay attention to format_version in future releases.
Another fix may change what operators see. Terraform will now display diagnostics raised when renewing an ephemeral resource, and the notes say this “may cause warnings to appear that previously were lost.”
How the Notes Changed Across Pre-releases
The same feature list appears in earlier pre-releases, so rc1 does not introduce the headline items. The 1.17.0-beta1 notes, dated September 9, 2026, already state that Terraform Policy is generally available, but they name the plan, apply, and init commands for the -policies flag and say nothing about query policies. The 1.17.0-beta2 notes, dated September 23, 2026, use the plan, apply, and query wording and the query-policy sentence that rc1 repeats. The beta1 notes also lack the fix for rejecting a non-directory path in terraform query -policies, which beta2 lists.
The wording therefore changed between beta1 and beta2, and the rc1 notes match beta2. Readers who followed the beta1 notes for which commands accept -policies should check the later text.
HashiCorp separately published the 1.16.5 patch release, whose notes are dated September 30, 2026. It lists two fixes: a crash when a tainted instance state is seen without a valid status, and a nil resource identity during delete.
What We Don’t Know
The release notes do not say when 1.17.0 will ship in final form. Nothing in the sources reports adoption of Terraform Policy or measures the effect of -minimal-refresh on plan times.
HashiCorp has previously argued that policy as code must gate AI-driven infrastructure changes on its HCP Terraform platform. The 1.17 release notes do not mention that platform or AI agents.