Q: What is the `terraform_remote_state` data source and what are the risks of using it?
terraform_remote_state lets one Terraform module read outputs from another module's state file.
#Terraform #Security & Best Practices #L2 #IaC #Cloud Infrastructure #S3
🎙️ Candidate Opening & Architectural Context
""When terraform plan shows unexpected changes, my golden rule is: never apply blindly. Investigate the diff first. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
terraform_remote_state lets one Terraform module read outputs from another module's state file.
- Tight coupling — if the VPC module's output changes, the consuming module breaks.
- State access permissions — any module can read any state file it has S3 access to.
- State contains sensitive data — reading another state file may expose passwords, keys.
2️⃣
Remediation & Permanent Safeguards
Risks: Alternative: Use AWS SSM Parameter Store or Secrets Manager to share values between Terraform modules. Less coupling, better access control.
data "terraform_remote_state" "vpc" {
backend = "s3"
config = {
bucket = "my-tfstate"
key = "vpc/terraform.tfstate"
region = "us-east-1"
}
}
# Use VPC ID from another module
subnet_id = data.terraform_remote_state.vpc.outputs.private_subnet_id
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Tight coupling — if the VPC module's output changes, the consuming module breaks.."
⚡ 60-Second Elevator Pitch Talking Points
- Tight coupling — if the VPC module's output changes, the consuming module breaks.
- State access permissions — any module can read any state file it has S3 access to.
- State contains sensitive data — reading another state file may expose passwords, keys.
Advertisement