Q: A failed Terraform deployment leaves the remote state locked. Would you run "terraform force-unlock"? What would you verify first?
Safe protocol for handling Terraform state lock errors (Error acquiring the state lock) in Azure Blob Storage or AWS DynamoDB without risking catastrophic concurrent state corruption.
#Terraform #State Lock #Azure #Disaster Prevention #SRE
🎙️ Candidate Opening & Architectural Context
"I would never run 'terraform force-unlock' immediately. State locking prevents concurrent executions from corrupting the state file. I must first verify that no pipeline job or background process is actively modifying infrastructure."
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1
Inspect Lock Metadata
Read the lock error message. It contains the Lock ID, Who acquired it (hostname and user), and When it was acquired.
Error acquiring the state lock: state blob is already locked
Lock Info:
ID: e4b7b2a1-3e4b-4a5f-9e12-88f912c9b4e1
Path: tfstate/prod.terraform.tfstate
Operation: OperationTypeApply
Who: azdo-agent-04@internal
Created: 2026-10-04 02:15:30 UTC
2
Confirm Agent / Process Termination
Log into Azure DevOps or the agent host. Verify that the agent pipeline process was canceled, killed, or timed out, and that no terraform apply process is currently executing in memory.
ps aux | grep terraform
3
Execute Verified Force-Unlock
Once confirmed that the process is 100% dead, execute terraform force-unlock with the specific Lock ID, followed immediately by terraform refresh to verify state consistency.
terraform force-unlock e4b7b2a1-3e4b-4a5f-9e12-88f912c9b4e1
terraform refresh
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Never unlock without verifying that the process listed in Who and Created is completely terminated to avoid irreversible concurrent state corruption."
⚡ 60-Second Elevator Pitch Talking Points
- Inspect Lock ID, Created timestamp, and Who hostname in the error output.
- Verify on the agent host that no terraform process is actively executing (ps aux | grep terraform).
- Confirm that the Azure DevOps pipeline build was genuinely canceled or aborted.
- Execute terraform force-unlock <ID> and immediately run terraform refresh to validate consistency.
Advertisement