Terraform v1.16.4 - Policy Outcomes and Stack Deferrals


HashiCorp published Terraform v1.16.4 on September 23, 2026. The patch on the 1.16 line is two bug fixes. plan and apply stop exiting with status 1 while rendering policy evaluation outcomes against older Terraform Enterprise, and stacks stop raising an invalid deferred error when a provider returns a deferral next to an unknown count or for_each.

The full release notes and downloads are on the GitHub release page. The tag is a final release. The prerelease flag is false.

#39095 corrects the error check used when the CLI renders policy evaluation outcomes. The failure shows up with a cloud backend pointed at a Terraform Enterprise version that rejects the policy details query. Both terraform plan and terraform apply take that path. The remote run has already started streaming, and the local process then asks for policy evaluations.

The diagnostic in the failing output is:

Error: Failed to retrieve Terraform policy evaluations: invalid value for "include" field

Terraform wraps that response as an unexpected Terraform Enterprise error. The wrapper text points at a network problem or a support ticket. The actual payload is the include parameter. Older Terraform Enterprise answers that the value is invalid. The go-tfe client already turns that backend response into its own error value. The render path was still matching a different error, so a known compatibility case became exit status 1.

The patch compares against the error variable go-tfe returns. On an older server the CLI skips the policy outcome block and the command exits cleanly. A policy that the server itself rejected still fails the run. When the server accepts the query, the summary text is unchanged, because the diff is only the error comparison. The cloud block gains no new argument, and the CLI gains no new flag.

The report attached to the fix used Terraform v1.16.0 and go-tfe v1.108.0. v1.16.4 is the 1.16 build that carries the corrected check. Logs that contain the include field error on plan or apply against Terraform Enterprise are the ones this binary changes. Workspaces whose server already returns policy outcomes keep the same summary.

#39237 is the stacks fix, and it covers two RPC calls that omitted client capabilities. A provider can return a deferral from configure. The patch description names the Helm provider and the Kubernetes provider as examples of that behavior. The deferral is a valid answer when the call tells the provider that this Terraform client supports deferrals.

The broken case adds an unknown count or for_each on a resource in the same plan. Unknown expansion means the instance keys are not available yet. Terraform still has to consult the provider, and it does that through a narrower partial plan call. That call was not attaching client capabilities. The provider then treated deferrals as unsupported and returned an error. Core surfaced the result as an invalid deferred error. The plan stopped. The same missing capabilities field was present on the open ephemeral resource call. One patch fills in both calls.

With v1.16.4, those two calls carry the capabilities message Terraform already defined. A provider that defers during configure can return the deferral, and the stack plan records the resource as deferred. A review of the change records a full stack reproduction that planned the deferred resources and finished the plan. The changelog scopes the fix to stacks. A configuration that never uses stacks does not enter this branch. A provider that never returns a deferral does not enter it either. An unknown count or for_each paired with a provider that plans in the normal way was already working.

The notes list no removed argument, no state format change, and no migration step. Move the CLI pin to v1.16.4 in the wrapper image, the CI tool cache, or the stacks runtime that already invokes Terraform. Provider plugins stay on their current builds. The wire change is the client capabilities message on two calls that used to send it empty.

Match the check to the symptom. For the policy bug, run terraform plan again on the cloud workspace that exited 1 with the include field error. The command should finish, and policy output for that older server should be skipped. For the stacks bug, run the plan again on the resource whose count or for_each was unknown and whose provider returned a deferral from configure. The plan should record that resource as deferred and complete.

Installs that have never logged either diagnostic still pick up the current 1.16 patch. Nothing in the notes is a setting to flip. The behavior change is limited to the two failure paths above.