Every Terraform horror story starts the same way: someone ran apply from a laptop, the state file was local, and two engineers created the same VPC at the same time. State is the single source of truth Terraform has about your infrastructure — treat it like a production database, because that is exactly what it is.
Rules that have kept me sane
- Always use remote state (S3 + DynamoDB locking, or Terraform Cloud) — never commit .tfstate anywhere
- One state per environment per domain: network, compute and data never share a state file
- Enable versioning and encryption on the state bucket; you will need yesterday's copy someday
- Pin provider versions — a surprise major upgrade mid-refactor is nobody's friend
A minimal backend block worth copying
hcl
terraform {
backend "s3" {
bucket = "vsp-tfstate-prod"
key = "network/terraform.tfstate"
region = "ap-south-1"
dynamodb_table = "tf-locks"
encrypt = true
}
}The day you need terraform state pull to diff what actually exists versus what you believe exists, you'll be grateful the state lives somewhere safe, locked and versioned. Your weekend self says thanks.