Q: Your remote module source points to a Git branch, and a new commit on that branch changed production plans unexpectedly. How do you prevent this?
Pin module sources to immutable versions such as tags or commit SHAs. Use a release process for shared modules, test the new version in n...
#Terraform #Use VPC ID from another module #L3 #IaC #Cloud Infrastructure #Git
🎙️ Candidate Opening & Architectural Context
""Treat Terraform code with the same rigor as application code: pre-merge plans, state locks, and automated drift detection. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Production Solution & Architecture
Pin module sources to immutable versions such as tags or commit SHAs. Use a release process for shared modules, test the new version in non-production first, and update module references intentionally. Branch-based module sources are convenient during development, but they make production infrastructure depend on whatever code happens to be at the branch head.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Pin module sources to immutable versions such as tags or commit SHAs. Use a release process for shared modules, test the new versi."
⚡ 60-Second Elevator Pitch Talking Points
- Immediate Triage: Pin module sources to immutable versions such as tags or commit SHAs. Use a release process for
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement