Documentation · What it is

What changes from a state file

What a state file holds, and where each part goes

terraform.tfstateunder choudoufu
The permission unitone fileone resource
Who may change the RDS but not the subnetsanyone who can write the filewhoever your IAM says
To narrow accesssplit the statewrite a policy
A role over three estatesthree files, sharedone policy
Handoverexport, migrate, re-importgrant a role
What is in itopen the JSONaws resourcegroupstaggingapi get-resources
Two applies at oncea lock, which a crash can orphana conditional write per record, and nothing held
Losing ityou no longer know what you owna slower plan

Every team has had the argument about how to split their state, and the answer has always shaped the repository more than the system. That argument goes away when the permission boundary stops having to match the file. How to scope a role to an estate has the policies, and where AWS honours the condition has the two limits that decide whether this works for your estate.

Because ownership rides on the resources, everything derived from it may go stale: a record of an ordinary resource, the cache, a projection. Losing one costs a read. The stale-state ruling (#604) states that and its one hard limit: a marker’s absence proves nothing, so an entry that cannot be confirmed is re-read and never assumed.

Migrate an existing estate is the procedure.