Documentation · Use it

Reading a value from another estate

An estate reads another estate’s value from the live resource, with an ordinary data source filtered by the producer’s marker tags.

data "aws_vpc" "network" {
  filter {
    name   = "tag:tofu-estate"
    values = ["network"]
  }
  filter {
    name   = "tag:tofu-address"
    values = ["aws_vpc.main"]
  }
}

resource "aws_subnet" "app" {
  vpc_id = data.aws_vpc.network.id
}

Both tags are already on the producer’s resource, and the pair is unique in an account by construction. The producer publishes nothing and does not know it is being read. live/OUTPUTS.md is the decision, and examples/cross-estate-dependency runs it with two estates and an ordered pipeline.

Why not an output

Stock passes values with terraform_remote_state, which reads the producer’s state file. It is admitted here and reads whatever its backend holds, but a live root has no state file of record, and one left from before a migration returns a snapshot frozen on that day.

What it needs

The consumer’s role needs permission to describe the producer’s resource type, and nothing on the record store beyond its own estate’s policy.

A producer that has not applied fails the consumer’s plan, so order the pipeline producer first, as the example does.

A value no live resource holds

Such a value, like a name the producer chose, is read from the root outputs the producer recorded at its last apply:

data "terraform_estate_outputs" "cluster" {
  estate = "cluster-infrastructure"
  names  = ["services_namespace"]
}

The plan warns that it is as of that apply. The producer’s destroy deletes it. Sensitive outputs never cross. The bucket policy needs --reads-outputs-of cluster-infrastructure, or the plan stops naming that estate.

On record_store "kubernetes" each estate’s records sit in a namespace of their own, so the consumer names the producer in its record_store block:

record_store "kubernetes" {
  reads_outputs_of "cluster-infrastructure" {}
}

The read goes to tofu-records-cluster-infrastructure (set namespace inside the block if the producer’s records are elsewhere) and can only get. Without the block, the plan stops before reading anything. Without a Role granting get on the producer’s output Secrets, the plan stops and prints the kubectl lines that grant it.