Skip to content

Backport of Cloud, backend/remote: forward -minimal-refresh to HCPT and TFE into v1.17 - #39321

Merged
austinvalle merged 10 commits into
v1.17from
backport/shweta/minimal-refresh-remote/ultimately-factual-chow
Oct 2, 2026
Merged

austinvalle merged 10 commits into
v1.17from
backport/shweta/minimal-refresh-remote/ultimately-factual-chow

Conversation

@github-actions

@github-actions github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Backport

This PR is auto-generated from #39310 to be assessed for backporting due to the inclusion of the label 1.17-backport.

The below text is copied from the body of the original PR.


Forwards the -minimal-refresh planning option to HCP Terraform / Terraform Enterprise through the cloud block and the legacy remote backend.

Core already supports -minimal-refresh locally, but remote operations reject it with a temporary "Minimal refresh mode is currently not supported" error, because HCP Terraform and go-tfe didn't support it yet. HCP Terraform's Runs API now accepts a minimal-refresh run attribute, and go-tfe v1.112.0 exposes it (hashicorp/go-tfe#1502).

Changes Made

  • go-tfe: bumps github.com/hashicorp/go-tfe from v1.110.0 to v1.112.0
  • Forwarding (cloud and remote): sets MinimalRefresh = true on the run create options only when -minimal-refresh is requested. It stays nil otherwise, so ordinary runs never send the attribute and older servers see no change.
  • Server capability check: replaces the temporary rejection with a check on the server's TFP-API-Version, following the existing -target / -replace / -refresh-only pattern in the remote backend. If the version is below MinimalRefreshMinAPIVersion (2.7) or can't be parsed, Terraform returns an error before any run is created:

    The host does not support the -minimal-refresh option. If you use Terraform Enterprise, upgrade to a version that supports minimal refresh. Otherwise, run without -minimal-refresh.

Older servers silently drop unknown run attributes, so without this check a run on an older server would quietly do a full refresh.

Tests

Manual testing

Terraform built from this branch against a local HCP Terraform stack

API 2.6: plan -minimal-refresh and apply -minimal-refresh are rejected by Core before any run is created:

Error: Minimal refresh is not supported

The host <host> does not support the -minimal-refresh option. If you use
Terraform Enterprise, upgrade to a version that supports minimal refresh.
Otherwise, run without -minimal-refresh.

-minimal-refresh with -refresh=false or -refresh-only is still rejected by argument parsing and a plain plan works as before.

API 2.7:

Command minimal-refresh plan-only Status
plan -minimal-refresh true true planned_and_finished
apply -minimal-refresh true false applied
plan false true planned_and_finished

All runs had refresh: true, refresh-only: false. Atlas validation errors still reach the user.

Specs
New tests in internal/cloud/backend_minimal_refresh_test.go and internal/backend/remote/backend_minimal_refresh_test.go, using the mock client:

  • plan/apply with -minimal-refresh → MinimalRefresh == true; without it → nil (not false)
  • plan stays speculative, apply is applicable
  • API version below the minimum, or unparseable → error, no run created
  • API version at or above the minimum → forwarded

The mock runs client now records MinimalRefresh from the create options.

Manual testing against a local HCP Terraform stack: see below / to be added.

Follow-ups (not in this PR)

  • Add the minimum Terraform Enterprise version to the docs once the TFE release is known.

Target Release

1.17.x

Rollback Plan

  • If a change needs to be reverted, we will roll out an update to the code within 7 days.

Changes to Security Controls

Are there any changes to security controls (access controls, encryption, logging) in this pull request? If so, explain.

CHANGELOG entry

  • This change is user-facing and I added a changelog entry.
  • This change is not user-facing.

Overview of commits

@github-actions
github-actions Bot requested a review from austinvalle October 2, 2026 13:15
@austinvalle
austinvalle marked this pull request as ready for review October 2, 2026 13:16
@austinvalle
austinvalle requested review from a team as code owners October 2, 2026 13:16

@austinvalle austinvalle left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR just enables the -minimal-refresh flag in HCPT, of which the feature has already been merged to v1.17 👍🏻

@austinvalle austinvalle added the no-changelog-needed Add this to your PR if the change does not require a changelog entry label Oct 2, 2026
@austinvalle
austinvalle merged commit e432e7e into v1.17 Oct 2, 2026
18 of 19 checks passed
@austinvalle
austinvalle deleted the backport/shweta/minimal-refresh-remote/ultimately-factual-chow branch October 2, 2026 13:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-changelog-needed Add this to your PR if the change does not require a changelog entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants