The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Terraform remote state keeps the state file in a shared backend, such as HCP Terraform or an object-storage bucket, instead of on one engineer’s laptop. Everyone who runs Terraform for a configuration then works from the same record of what Terraform manages. Two things do not follow automatically from “remote”: the backend may or may not lock state during writes, and the stored state is sensitive data that needs its own access and encryption controls.
What Terraform state does
Terraform state maps the resource instances in your configuration to the real objects they represent, such as a virtual machine ID or a database instance name. It also stores the attributes and metadata Terraform needs to calculate the next plan. Without that record, Terraform cannot tell whether a resource already exists, what has changed, or what should be destroyed.
As an Amazon Associate I earn from qualifying purchases.
By default, Terraform writes this data to a local file named terraform.tfstate in the configuration directory. That works for one person on one machine. In a team, each person ends up with a separate copy, copies drift out of date, and two runs started at the same time can write conflicting versions of the same state.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesWhat remote state changes
Remote state moves the state to a backend, which is the component that defines where Terraform stores state and, where supported, how it locks it. Collaborators then read and write one state location. HashiCorp’s documentation lists several storage options, and each one has different operational characteristics:
#1 Best Overall
- Get NVMe solid state performance with up to 1050MB/s read and 1000MB/s write speeds in a portable, high-capacity drive(1) (Based on internal testing; performance may be lower depending on host device & other factors. 1MB=1,000,000 bytes.)
- Up to 3-meter drop protection and IP65 water and dust resistance mean this tough drive can take a beating(3) (Previously rated for 2-meter drop protection and IP55 rating. Now qualified for the higher, stated specs.)
- Use the handy carabiner loop to secure it to your belt loop or backpack for extra peace of mind.
- Help keep private content private with the included password protection featuring 256‐bit AES hardware encryption.(3)
- Easily manage files and automatically free up space with the SanDisk Memory Zone app.(5). Non-Operating Temperature -20°C to 85°C
| Option | What to confirm before adopting it |
|---|---|
| HCP Terraform | Whether you want only state storage or a managed service that also runs Terraform operations and coordinates team workflow. Use the cloud integration (see the version note below). |
| Amazon S3 | Whether locking and encryption are configured for your bucket and backend block. Check the S3 backend reference for the options that apply to your Terraform version. |
| Azure Blob Storage | Locking behavior and the access-control model for the storage account and container, as described in the current Azure backend reference. |
| Google Cloud Storage | Encryption choices. HashiCorp documents support for customer-supplied and customer-managed keys. |
| Consul | Locking support and the access policies in your Consul deployment, per the Consul backend reference. |
| Alibaba Cloud OSS | Locking, encryption and access options in the current OSS backend reference. |
Choose the backend by testing its current documentation against your requirements, not by the word “remote.” The backend you pick determines which safety features you actually get.
How state locking works
When a backend supports locking, Terraform locks state automatically for any operation that can write it, such as terraform apply. A second run that tries to write the same state is blocked until the lock is released. HashiCorp’s state locking documentation states the key rule plainly: “If state locking fails, Terraform does not continue.”
Rank #2
- Solid state performance with up to 800MB/s read speeds in a portable drive. (Based on internal testing; performance may be lower depending on host device, interface, usage conditions and other factors. 1MB=1,000,000 bytes.)
- Back up your content and memories on a storage solution that fits seamlessly into your mobile lifestyle.
- Take it with you on your adventures—up to two-meter drop protection means this durable drive can take a beating. (Based on internal testing.)
- Secure it to your belt loop or backpack for extra peace of mind thanks to the tough rubber hook.
- From Sandisk, a brand professional photographers trust to take on assignments.
Locking is optional across backend types. A remote backend without locking gives you shared storage but no protection against two overlapping writes. Check the backend’s documentation before assuming you have it.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rules for locking
- Do not use
-lock=falseto get past a lock error. It removes the protection the lock exists to provide. - Use
force-unlockonly for a lock that your own run left behind after automatic unlock failed. - Do not force-unlock a lock held by another writer. Doing so can allow conflicting operations against the same state.
- Never make
force-unlocka routine fix for lock errors. A repeated lock error usually means something is still running or failing, and that needs investigation.
Releasing a stale lock you own
- Confirm that no other
terraform planorterraform applyis running against this state, including in CI pipelines and on colleagues’ machines. - Copy the lock ID from the error message Terraform printed when the lock was reported.
- Run
terraform force-unlock LOCK_ID, replacingLOCK_IDwith that value, and confirm the prompt only if the lock is yours. - Run
terraform planand read the output before making any changes, so you know the state is what you expect.
Configuring a backend
A configuration can declare only one backend block, and that block cannot reference input variables, local values, or data source attributes. If you omit it, Terraform uses the local backend. Because the arguments differ by backend, copy them from that backend’s reference page rather than from a generic example.
Rank #3
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Setting up or changing a backend
- Declare the backend in a
terraformblock, using the arguments from the reference page for your chosen backend. Keep secret values out of this block. - Supply credentials through the backend’s conventional mechanisms, such as its standard credential files or environment variables. Avoid passing secrets through
-backend-config. Backend settings can be retained in the.terraformdirectory and in saved plan files. - Before changing anything, back up the current state. For an existing local state, copy
terraform.tfstateto a safe location, or runterraform state pull > backup.tfstateagainst the current backend. - Run
terraform init. It configures and validates the new backend. If Terraform offers to migrate existing state to the new backend, review the prompt and accept only after your backup exists. - Run
terraform planand confirm it shows no unexpected create or destroy actions. A clean plan after migration is the signal that the state moved intact. - Exclude the local
.terraformdirectory and any local state files from version control.
How day-to-day work changes
Remote state does not replace the Terraform CLI. Commands such as terraform console and the terraform state subcommands continue to work with non-local backends. What changes is where the data lives and who can reach it. Every operator who can run those commands against a given backend can read the stored state.
State is sensitive data
State and plan files can contain database passwords, API tokens, and infrastructure details. The sensitive flag hides values in some CLI output, but it does not remove them from state or plan files. Storing state remotely is therefore one control among several.
Rank #4
- NEARLY 2X FASTER THAN OUR PREVIOUS GENERATION(8) – move 1,000 high-res photos in under 60 seconds(6) with up to 2000MB/s transfer speeds(2).
- IP65 RATING AND UP TO 3M DROP PROTECTION(3) – protects against spills and drops.
- POCKET-SIZED – fits easily in pockets and small bags.
- SPACE TO OWN YOUR AI CONTENT – speed and capacity to download your high-res clips and photo edits.
- 256-BIT AES ENCRYPTION(4) – helps keep private files secure with password protection.
A workable baseline includes:
- Encryption at rest: HCP Terraform encrypts state at rest and protects it with TLS in transit, according to HashiCorp. For S3, encryption depends on how the backend and bucket are configured. For Google Cloud Storage, customer-supplied or customer-managed keys are supported. Confirm the behavior for your backend and Terraform version.
- Encryption in transit: Use TLS wherever the backend offers it.
- Narrow access: Limit read and write permissions on the state location to the operators and workspaces that need them. Reading state is as sensitive as writing it.
- Audit logging: Turn on access logs for the storage location so you can see who read or wrote state.
Sharing outputs between configurations
Teams often split infrastructure into several configurations and pass values between them. The built-in terraform_remote_state data source reads the root-module outputs of another configuration. The security trade-off is easy to miss: anyone who can read those outputs can also access the complete state snapshot directly, including values that were never exported.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchHashiCorp’s documentation warns: “Don’t use terraform_remote_state if any of the resources in your configuration work with data that you consider sensitive.”
Best Value
- Easily store and access 5TB of content on the go with the Seagate portable drive, a USB external hard Drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
Choosing an output-sharing method
- HCP Terraform or Terraform Enterprise: Use the
tfe_outputsdata source. HashiCorp recommends it as a more secure way to fetch outputs without requiring full workspace-state access. - Other architectures: Consider a purpose-built configuration store that exposes only the values you intend to share, or query the provider directly for the data you need where that is practical.
- Existing
terraform_remote_stateuse: Limit it to configurations whose state holds no sensitive data, or move the shared values to one of the methods above.
Recovering from a failed state write
If Terraform cannot write state to the backend, it may write the state to a local file to prevent data loss. Do not ignore that file. Resolve the underlying backend error first, such as a permission failure or a network problem, and then push the local state manually.
Be careful with terraform state push. It can overwrite the state held in the remote backend, and HashiCorp describes it as extremely dangerous. Before running it, pull and save the current remote state, compare the two versions, and confirm that the local copy is the one you intend to keep.
Version notes
HashiCorp’s remote backend documentation says that as of Terraform v1.1.0 and Terraform Enterprise v202201-1, the built-in cloud integration is recommended instead of the legacy remote backend option. This guidance is dated to those releases. Confirm the current recommendation in the documentation for the Terraform version your team runs before writing or copying configuration.
Quick Recap
Before you rely on remote state
- Confirm that your chosen backend supports locking, and that locking is active for your configuration.
- Confirm the encryption, transit protection and key-management options for the backend and version you use.
- Restrict who can read and write the state location, and enable access logging.
- Keep credentials out of backend blocks, backend configuration flags and version control.
- Replace any
terraform_remote_stateconsumers that read sensitive data with narrower output sharing. - Store a tested backup of state before every backend migration.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




