> ## Documentation Index
> Fetch the complete documentation index at: https://docs.microsandbox.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Vet a Terraform provider offline

> Download a provider once, then validate and plan without network access

<Tooltip tip="This workflow uses local snapshot verification and destination security/network controls."><span className="msb-badge-local">Local-only <Icon icon="circle-info" size={11} /></span></Tooltip>

Terraform providers are native executables. Prepare the provider in one microVM, snapshot it, then run validation and planning in a fresh networkless worker.

The `random` provider makes the flow easy to test because planning it does not need cloud credentials.

## Run an offline plan

<Steps>
  <Step title="Create a test configuration">
    ```hcl main.tf theme={null}
    terraform {
      required_providers {
        random = {
          source  = "hashicorp/random"
          version = "3.7.2"
        }
      }
    }

    resource "random_pet" "example" {
      prefix = "microsandbox"
    }
    ```
  </Step>

  <Step title="Download and snapshot the provider">
    <CodeGroup>
      ```sh macOS & Linux theme={null}
      msb run --name terraform-base --replace \
        --memory 768M --root-disk 2G --max-duration 5m \
        --copy-file ./main.tf:/workspace/main.tf \
        --workdir /workspace \
        --entrypoint sh \
        hashicorp/terraform:1.13.5 -- -lc \
          'terraform init -backend=false -input=false && chown -R 65534:65534 /workspace'
      ```

      ```powershell Windows theme={null}
      msb run --name terraform-base --replace `
        --memory 768M --root-disk 2G --max-duration 5m `
        --copy-file ./main.tf:/workspace/main.tf `
        --workdir /workspace `
        --entrypoint sh `
        hashicorp/terraform:1.13.5 -- -lc `
          'terraform init -backend=false -input=false && chown -R 65534:65534 /workspace'
      ```
    </CodeGroup>

    Copy the generated dependency lock file to the host:

    ```sh theme={null}
    msb cp terraform-base:/workspace/.terraform.lock.hcl ./.terraform.lock.hcl
    ```

    Capture the downloaded provider:

    <CodeGroup>
      ```sh macOS & Linux theme={null}
      msb snap create terraform-runtime \
        --sandbox terraform-base --integrity
      ```

      ```powershell Windows theme={null}
      msb snap create terraform-runtime `
        --sandbox terraform-base --integrity
      ```
    </CodeGroup>

    Verify the snapshot before using it:

    ```sh theme={null}
    msb snap verify terraform-base:terraform-runtime
    ```

    `terraform init` downloads the provider and creates `.terraform.lock.hcl`. The copy on the host is ready to review and commit when adapting this to a real module.
  </Step>

  <Step title="Plan offline">
    Restore applies the offline policy and restricted guest profile before boot. It creates an idle detached sandbox; `exec` runs the plan separately. The destination name must be unused, so remove a previous stopped `terraform-vet` explicitly before repeating this step.

    <CodeGroup>
      ```sh macOS & Linux theme={null}
      msb snap restore terraform-base:terraform-runtime --name terraform-vet \
        --user 65534:65534 --cpus 1 --memory 512M \
        --no-net --security restricted --max-duration 1m
      msb exec --workdir /workspace --user 65534:65534 --env HOME=/tmp \
        --timeout 1m terraform-vet -- sh -lc \
          'terraform fmt -check && terraform validate && terraform plan -refresh=false -input=false -lock=false'
      msb stop terraform-vet
      ```

      ```powershell Windows theme={null}
      msb snap restore terraform-base:terraform-runtime --name terraform-vet `
        --user 65534:65534 --cpus 1 --memory 512M `
        --no-net --security restricted --max-duration 1m
      msb exec --workdir /workspace --user 65534:65534 --env HOME=/tmp `
        --timeout 1m terraform-vet -- sh -lc `
          'terraform fmt -check && terraform validate && terraform plan -refresh=false -input=false -lock=false'
      msb stop terraform-vet
      ```
    </CodeGroup>

    The provider loads and creates a plan, but it cannot contact any remote API. Providers, data sources, or validation rules that require a service will fail offline; that failure is the point of this vetting mode.

    <Warning>
      `-refresh=false` is not a network boundary. `--no-net` is. If you give a provider credentials and egress, changes it makes through an external API outlive the microVM.
    </Warning>
  </Step>

  <Step title="Clean up">
    ```sh theme={null}
    msb rm -f terraform-base terraform-vet
    ```

    Remove the reusable snapshot:

    ```sh theme={null}
    msb snap rm terraform-base:terraform-runtime
    ```
  </Step>
</Steps>

## Reference

* [How Terraform works with plugins](https://developer.hashicorp.com/terraform/plugin/how-terraform-works)
* [Provider dependency lock file](https://developer.hashicorp.com/terraform/language/files/dependency-lock)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.