Memory hook: One binding, one writer, protected history.
Must remember
State maps configured instances to remote object IDs and stores attributes needed for planning. The default local backend uses a local state file. Remote backends place state in shared storage; locking, encryption and access-control behavior depend on the selected backend.
Locking prevents concurrent writers corrupting a state snapshot. Do not disable locks just to get past a busy run. Force-unlock is a recovery operation for your own stale lock after confirming no writer remains. It does not roll back infrastructure.
Configure storage in a backend block; backend configuration cannot refer to normal variables or resource outputs. Supply authentication through the recommended external credential mechanism. Hard-coded or command-line backend secrets may be cached or captured in plans. init -migrate-state transfers state after a reviewed backend change; -reconfigure treats the configuration as new rather than migrating existing state.
Drift is found when providers read real objects during planning. Decide whether configuration should restore the intended value or be updated to accept the external change. A refresh-only plan proposes state/output updates without proposing remote infrastructure changes; applying it still writes state.
CLI workspaces provide separate state instances for one configuration, but shared credentials/backend access can remain. Use separate roots and permissions when environments need strong isolation. Consumers of terraform_remote_state need access to the underlying snapshot, even though the data source exposes only root outputs.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Team collaboration | Shared protected state with supported locking and a controlled apply process. |
| Deliberate external change | Review drift and update configuration or deliberately reconcile state. |
Traps
- Remote state storage does not always mean remote execution.
- Copying state into Git exposes historical secrets and provides poor locking.
Active recall
1. What does a lock protect?
A state operation against competing writers; it is not a cloud-resource lock.
2. Can backend settings use var.bucket?
No. Backend initialization occurs before normal variable/resource evaluation.
3. Does refresh-only rebuild deleted resources?
No. It reconciles recorded state and outputs with observations.
4. Are CLI workspaces a complete security boundary?
No. Their backend credentials and access controls may be shared.
5. Can remote-state consumers access more than declared outputs?
Their storage access generally permits reading the full snapshot; outputs are not a secret boundary.