The Homelab Notebook

Terraform Lock File Checksums: zh and h1 Hashes
Overview The .terraform.lock.hcl file stores cryptographic hashes that verify the integrity of downloaded providers. Two hash schemes exist: zh: (a legacy scheme tied to zip archives) and h1: (a directory hash of the unpacked provider). Understanding how these are calculated helps when debugging lock file mismatches or verifying providers manually. zh and h1 Checksums The terraform init command downloads the provider and verifies that it matches one of the checksums in the lock file, then extracts the package into .terraform/providers.