Documentation · Use it

Recover an estate

You have lost the cache, the record store, or both, and the live resources are still there. Work out which you lost, then follow the steps in order.

What you lost

LostWhat it costsWhat to do
The cache, .terraform/choudoufu-cache.tfstateOne slower planNothing. Run choudoufu plan
Your whole working copyThe sameCheck the configuration out again and plan
Markers on live resourcesThose resources look unownedSomebody untagged them. See the ownership policy
The record storeRecord-backed resources, and the identity of a few AWS types with no tagsThe rest of this page

Most resources come back from their markers alone. Claim 5 deletes every local file and the next plan is No changes. Run it with just smoke recovery-is-a-rerun.

The procedure

  1. Change nothing by hand. Do not edit records or strip tags to start clean. The markers are what still works.
  2. Restore the record store if you can. In a bucket, every deleted record is still there as a noncurrent version until the lifecycle rule expires it. Removing the delete marker brings it back, and that takes s3:ListBucketVersions and s3:DeleteObjectVersion, which the estate’s own role does not have (IAM). If this works, you are done.
  3. Run choudoufu init, then choudoufu plan -adoption-only. That prints which live resource each declared instance binds to, which is what you need. The full plan’s diff is the wrong tool here.
  4. Read each instance’s class.
ClassMeaningWhat to do
already markedThe marker is on the live resourceNothing
adoptable nowA live resource sits at the declared identity with no markerRun the tag write the report prints
waits on parentA parent it derives from did not resolveFix the parent first
no pathIt needs a record and there is noneSteps 5 and 6
in the wayAnother estate owns the live resourceStop
nothing liveNothing was found, so an apply creates itCheck that it really does not exist
  1. If any terraform.tfstate that holds these instances still exists, an old backup or a colleague’s copy, run choudoufu live-import on it. It is the only command that writes an identity record outside an apply.
  2. Plan again and read the reason on anything still unbound.

What does not come back

A record-backed resource whose record is gone is gone: a random_pet regenerates, and everything named after it is proposed for create under the new name. A server-minted credential such as aws_iam_access_key keeps working for whoever holds it, and its secret cannot be read again.

live/RECOVERY.md has the full inventory: which types need a record and which do not, the 96 AWS types whose identity is only in the record, and the worked example.