6 ms·
In modest, small team use, a remote state file on s3 served me well. Did you run into problems with it?
by DerpyBaby123 8y ago
In modest, small team use, a remote state file on s3 served me well. Did you run into problems with it?
- SteveNuts 8y agoAs a general rule I try to avoid putting sensitive information onto services that could accidentally be turned public facing.
- mike-cardwell 8y agoYou can (should) use client side encryption on the state terraform state bucket.
- kitotik 8y agoExactly. I’m a little surprised to hear that this one of the biggest feature requests from the community. Once you are in hashicorp-land it’s not a big jump to spin up a consul+vault cluster and store your encrypted state remotely.
- jen20 8y agoThere is still a chicken-and-egg problem assuming you want to use Terraform to spin up the Consul+Vault clusters, though.
- marenkay 8y agoWhy worry about that? Has anyone ever solved the chicken-and-egg problem in it? Can it even be solved? Seriously, is there any other approach from declaring a new egg as new baseline chicken?