The Terraform provider[1] unfortunately is 3rd party and as such doesn't bring and guarantees of correctness other than that of the maintainer. It would be nice to see Keycloak provide an official solution for configuration management other than the K8s operator which is missing a lot of features.
I suppose you could test your system including the Keycloak configuration to make sure things work as expected after a TF change. You probably want to be doing that anyway, though. It's a fairly comprehensive Terraform provider under active development, I recommend it.