Concept and mechanism
State binds configuration addresses to remote objects and stores information needed by later operations. It does not replace application-data backup or establish that every remote object is correct. Maintain a coherent association between each managed instance and its corresponding object. An old state copy does not undo operations already performed in the cloud. For collaboration, define backend, access, retention, recovery, and supported locking. A state lock coordinates writers; it differs from the file pinning providers. If another process holds a lock, starting a second run with lock=false may create unsafe concurrency. Investigate owner and execution state before attempting an unlock.
Guided application
In a fictional scenario, an operator’s terminal lost connectivity during apply and another team encounters the lock. Lost connectivity does not establish that execution ended. Confirm the process on its executor and remote state; force-unlock is appropriate only for one’s own lock whose automatic release failed, without an active writer. On the S3 backend, use_lockfile enables locking and needs specific lock-object permissions; remote state storage does not independently enable every control. The documented DynamoDB locking mechanism is deprecated; review migration rather than adopting an old template unchanged. During backend migration, migrate-state attempts to copy state while reconfigure does not migrate existing state. Choose with confirmed source, destination, and backup. CLI workspaces share a backend and do not provide strong isolation for separate credentials and teams.
Lost terminal connectivity is an observation symptom; apply may continue on the executor.
Common pitfalls
State as database backup; force-unlock through impatience; workspace as a security boundary.
Related topics: Configuration and dependencies · Plans and validation · Modules and identity
Preserve bindings and ensure coordinated writing to state.
Reference: State bindings and secure storage · Terraform v1.16 concepts; official documentation consulted 2026-09-30; provider and backend capabilities must be confirmed