Skip to main content
🎤 Luca Berton is speaking at Red Hat Summit & KubeCon EU 2026!Learn more →
Back to Blog

Terraform State Management

Understand Terraform state — how it tracks resources, why it's critical, and best practices for remote state, locking, and team workflows.

Luca BertonFebruary 24, 20261 min read

What Is Terraform State?

Terraform state is a JSON file (terraform.tfstate) that maps your configuration to real-world resources. It's how Terraform knows what exists, what changed, and what needs updating.

Why State Matters

Without state, Terraform would: - Not know which resources it manages - Recreate everything on every apply - Have no way to detect drift - Be unable to handle dependencies

Related Course

Master this topic with hands-on labs

Go beyond reading — build real projects in sandboxed environments with expert video guidance.

Browse Courses →

State Commands

bash
# List resources in state
terraform state list

# Show details of a resource
terraform state show aws_instance.web

# Remove a resource from state (without destroying it)
terraform state rm aws_instance.legacy

# Move/rename a resource in state
terraform state mv aws_instance.old aws_instance.new

# Pull remote state locally
terraform state pull

Remote State

Never store state locally in a team. Use a remote backend:

hcl
terraform {
  backend "s3" {
    bucket         = "my-terraform-state"
    key            = "prod/terraform.tfstate"
    region         = "eu-west-1"
    encrypt        = true
    dynamodb_table = "terraform-locks"
  }
}

State Locking

Prevents two people from modifying state simultaneously:

hcl
# DynamoDB table for locking (with S3 backend)
resource "aws_dynamodb_table" "terraform_locks" {
  name         = "terraform-locks"
  billing_mode = "PAY_PER_REQUEST"
  hash_key     = "LockID"

  attribute {
    name = "LockID"
    type = "S"
  }
}
Stay Updated

Get weekly IT automation tips

Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.

Subscribe Free →

Best Practices

  1. Always use remote state for team projects
  2. Enable encryption — state contains sensitive data
  3. Enable locking — prevent concurrent modifications
  4. Don't edit state manually — use terraform state commands
  5. Use workspaces for environment separation
  6. Back up state — enable versioning on your S3 bucket

Sensitive Data in State

State can contain passwords, keys, and secrets. Protect it:

hcl
output "db_password" {
  value     = aws_db_instance.main.password
  sensitive = true
}

Learn More

Master state management hands-on in our Terraform for Beginners course.

---

Ready to go deeper? Check out our hands-on course: Terraform for Beginners — practical exercises you can follow along on your own machine.

Ready to learn by doing?

Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.

Share this article
LB
Luca Berton

Docker Captain, IT automation expert, Red Hat Summit & KubeCon speaker. Building hands-on education for DevOps engineers at CopyPasteLearn.

Related Articles

Explore topics

Browse more articles on the topics covered here.