Q: You want `terraform destroy` to remove a temporary application stack but keep the shared DNS zone and shared VPC. How should the state be structured?
Shared infrastructure should live in separate root modules and state files from temporary application environments. The app stack can rea...
#Terraform #Use VPC ID from another module #L2 #IaC #Cloud Infrastructure #VPC
🎙️ Candidate Opening & Architectural Context
""In our enterprise Terraform repository, we designed reusable modules and remote backends to prevent this exact issue. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Production Solution & Architecture
Shared infrastructure should live in separate root modules and state files from temporary application environments. The app stack can read shared IDs through data sources, SSM parameters, or remote outputs, but it should not own those shared resources. Add prevent_destroy on critical shared resources as a guardrail, but rely primarily on state boundaries.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Shared infrastructure should live in separate root modules and state files from temporary application environments. The app stack ."
⚡ 60-Second Elevator Pitch Talking Points
- Immediate Triage: Shared infrastructure should live in separate root modules and state files from temporary appli
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement