Q: An engineer ran `terraform apply` with the wrong AWS profile and created resources in the wrong account. How do you reduce the chance of this happening again?
Make the account context explicit in CI and local workflows. Use assume_role with fixed account IDs, print the current caller identity in...
#Terraform #Use VPC ID from another module #L2 #IaC #Cloud Infrastructure
🎙️ Candidate Opening & Architectural Context
""When terraform plan shows unexpected changes, my golden rule is: never apply blindly. Investigate the diff first. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Production Solution & Architecture
Make the account context explicit in CI and local workflows. Use assume_role with fixed account IDs, print the current caller identity in pipeline logs, and prefer OIDC or dedicated roles over manually exported credentials. Some teams also add validation checks that compare the expected account ID against data.aws_caller_identity.current.account_id and fail if they do not match.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Make the account context explicit in CI and local workflows. Use assume_role with fixed account IDs, print the current caller iden."
⚡ 60-Second Elevator Pitch Talking Points
- Immediate Triage: Make the account context explicit in CI and local workflows. Use assume_role with fixed account
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement