← Files Platform Engineering CopilotARCHIVED FILE

skills/platform-engineering/references/terraform_iac_change_safety.md

2.13 KB · Sep 30, 2026 · 23:18 UTC

↓ Download file

# Terraform / IaC Change Safety

## Standard workflow

1. `terraform fmt`
2. `terraform validate`
3. initialize with intended backend/providers
4. `terraform plan`
5. inspect plan
6. policy/security checks
7. approval
8. apply the reviewed plan
9. verify infrastructure and workload behavior

In automation, applying the exact saved/approved plan can reduce plan/apply drift.

## Plan review

Classify:
- create;
- in-place update;
- replacement;
- destroy;
- data-source read;
- unknown-at-plan-time.

High-risk signals:
- broad replacement;
- network/IAM changes;
- stateful resources;
- database/storage deletion;
- region/account move;
- policy changes;
- unexpectedly large plan.

## State

Treat state as sensitive operational data.

Use:
- remote backend appropriate to environment;
- encryption;
- access control;
- versioning/backup;
- locking where supported.

Do not:
- commit state;
- casually disable state locking;
- force-unlock without proving a stale lock and correct workspace;
- edit state manually unless the exact recovery procedure requires it.

## Secrets

Avoid secrets in:
- committed tfvars;
- outputs;
- plan artifacts where exposure matters;
- CI logs.

Use provider/workload identity or secret managers where appropriate.

## Versions

Pin:
- Terraform version range;
- provider versions;
- module versions;

to avoid accidental uncontrolled upgrades.

Commit the dependency lock file when appropriate to the workflow.

## Module design

Prefer:
- clear inputs/outputs;
- typed variables;
- documented ownership;
- focused module responsibility;
- tests/validation;
- low surprise.

Do not make one universal module with dozens of switches.

## Destructive changes

Before destroy/replace:
- verify exact resource and environment;
- identify dependent workloads;
- ensure data backup/recovery;
- plan sequencing;
- define rollback/forward recovery;
- use lifecycle protections when justified.

## Drift

Detect drift through regular plan/reconciliation.

Do not automatically "fix" drift until you know whether:
- infrastructure changed out of band accidentally;
- emergency/manual change was intentional;
- desired configuration should be updated.

SHA-256: 608211a83f4eb0c3377514be482aa3e38295fc2c58539d505a9beba49f7789bf