Q: A resource was renamed in configuration, but there was no real infrastructure change. How do you make Terraform understand it is the same object?
Use a moved block in Terraform 1.1+:
#Terraform #Use VPC ID from another module #L3 #IaC #Cloud Infrastructure #Terraform State
🎙️ Candidate Opening & Architectural Context
""In our enterprise Terraform repository, we designed reusable modules and remote backends to prevent this exact issue. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Production Solution & Architecture
Use a moved block in Terraform 1.1+: This records the rename in code and prevents destroy/create behavior. Older workflows can use terraform state mv, but moved blocks are better because the refactor is documented and repeatable in CI.
moved {
from = aws_security_group.old_name
to = aws_security_group.new_name
}
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Use a moved block in Terraform 1.1+:."
⚡ 60-Second Elevator Pitch Talking Points
- Immediate Triage: Use a moved block in Terraform 1.1+:
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement