random provider makes the flow easy to test because planning it does not need cloud credentials.
Run an offline plan
1
Create a test configuration
main.tf
2
Download and snapshot the provider
terraform init downloads the provider and creates .terraform.lock.hcl. The copy on the host is ready to review and commit when adapting this to a real module.3
Plan offline
Restore applies the offline policy and restricted guest profile before boot. It creates an idle detached sandbox; The provider loads and creates a plan, but it cannot contact any remote API. Providers, data sources, or validation rules that require a service will fail offline; that failure is the point of this vetting mode.
exec runs the plan separately. The destination name must be unused, so remove a previous stopped terraform-vet explicitly before repeating this step.4
Clean up