certslothcertsloth
004/Topic 06

HashiCorp / Associate

State, Backends and Drift

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: One binding, one writer, protected history.

Must remember

State maps configured instances to remote object IDs and stores attributes needed for planning. The default local backend uses a local state file. Remote backends place state in shared storage; locking, encryption and access-control behavior depend on the selected backend.

Locking prevents concurrent writers corrupting a state snapshot. Do not disable locks just to get past a busy run. Force-unlock is a recovery operation for your own stale lock after confirming no writer remains. It does not roll back infrastructure.

Configure storage in a backend block; backend configuration cannot refer to normal variables or resource outputs. Supply authentication through the recommended external credential mechanism. Hard-coded or command-line backend secrets may be cached or captured in plans. init -migrate-state transfers state after a reviewed backend change; -reconfigure treats the configuration as new rather than migrating existing state.

Drift is found when providers read real objects during planning. Decide whether configuration should restore the intended value or be updated to accept the external change. A refresh-only plan proposes state/output updates without proposing remote infrastructure changes; applying it still writes state.

CLI workspaces provide separate state instances for one configuration, but shared credentials/backend access can remain. Use separate roots and permissions when environments need strong isolation. Consumers of terraform_remote_state need access to the underlying snapshot, even though the data source exposes only root outputs.

Choose under exam pressure

Requirement Choice and reason
Team collaboration Shared protected state with supported locking and a controlled apply process.
Deliberate external change Review drift and update configuration or deliberately reconcile state.

Traps

  • Remote state storage does not always mean remote execution.
  • Copying state into Git exposes historical secrets and provides poor locking.

Active recall

1. What does a lock protect?

A state operation against competing writers; it is not a cloud-resource lock.

2. Can backend settings use var.bucket?

No. Backend initialization occurs before normal variable/resource evaluation.

3. Does refresh-only rebuild deleted resources?

No. It reconciles recorded state and outputs with observations.

4. Are CLI workspaces a complete security boundary?

No. Their backend credentials and access controls may be shared.

5. Can remote-state consumers access more than declared outputs?

Their storage access generally permits reading the full snapshot; outputs are not a secret boundary.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.