पाठ 11 / 25

What State Is and How to Inspect It

The mapping between code and reality.

terraform.tfstate

Terraform records every managed resource in state: its address, the real-world id, and its last known attributes. Plans compare configuration, state and (after refresh) reality. State is JSON, but never edit it by hand; use terraform state list, state show, and for refactors moved blocks or state mv. State often contains secrets (passwords, keys) in plain text, so protect it like a secret.

Terraform's memory of what it manages

State maps configuration to real resources; drift is when reality changes behind Terraform's back.

Three ideas: inspecting state, drift, remote state and locking.
Figure 4.1 — State, drift and remote backends.

Listing and showing state, run

I ran this with Terraform 1.16.4 and the hashicorp/local 2.9.1 and hashicorp/random 3.9.1 providers, which manage local files and random values, so no cloud account was needed; each example starts from a fresh directory. After apply, state lists one resource; state show displays its recorded attributes, including the id (for local_file, a hash of the content).

terraform state list
terraform state show -no-color local_file.config | grep -E "filename|content  |id "

Output:

local_file.config
    content              = <<-EOT
    filename             = "./out/shop-dev.conf"
    id                   = "ce111bb38dc4e0fa677e86ae961666e1f43ef91a"

Never edit state by hand

Use moved blocks, import blocks and terraform state commands; hand edits corrupt state easily.

त्वरित जाँच: What does Terraform state record?

  • User passwords for the console only
  • Only the provider version
  • The Git history
  • Which real resources correspond to each resource in the configuration, with their attributes
Answer

Which real resources correspond to each resource in the configuration, with their attributes — State is the mapping layer.