What is Terraform state and why should it be remote?
Terraform state is a JSON file that maps your configuration to real infrastructure. It stores resource IDs, attribute values, and dependency metadata so Terraform knows what exists and how to change it.
Why remote state:
- Team collaboration: everyone reads and writes the same state instead of overwriting each other.
- Locking: backends such as S3 with DynamoDB, Azure Blob, or Terraform Cloud lock state during operations, preventing concurrent corruption.
- Durability and security: state often contains secrets, so store it in encrypted, access-controlled storage with versioning.
- CI/CD: pipelines can use the same state from any runner.
terraform {
backend "s3" {
bucket = "my-tf-state"
key = "app/terraform.tfstate"
region = "us-east-1"
dynamodb_table = "tf-locks"
encrypt = true
}
}
Never commit state to Git. Back it up and treat it as sensitive.