Skip to content
EgyKode
04 · Infrastructure as CodeLab 22 / 59
Challengeterraform

Terraform Remote State & Locking — Challenge

Move state off your laptop into an encrypted, versioned, locked backend — and prove the lock works by breaking it deliberately.

Time
45 min
Level
Intermediate
Objectives
4 objectives
Cost
Low cost

Where this fits in the platform

This lab adds

  • State in S3 with locking — safe for more than one person

Before you start

You will need

  • Terraform >= 1.6
  • AWS CLI v2, configured

You will be able to

  • Migrate local state to an S3 backend without recreating resources
  • Prove a concurrent apply is blocked rather than corrupting state
  • Recover from a stale lock safely

CostLow cost

— an S3 bucket and a PAY_PER_REQUEST DynamoDB table. A few applies a week costs effectively nothing.

How to clean up

The goal#

Achieve the same outcome as Terraform Remote State & Locking, from an empty starting point, without the steps.

State is on your laptop. A colleague runs terraform apply from theirs, sees none of your resources, and creates a second copy of everything — or worse, destroys yours.

This is the lab that makes Terraform usable by more than one person.

Hands-on environment

Run this lab in a real terminal, free and in your browser. The environment is temporary and yours alone — break it as much as you like.

Start the challenge

Opens in Killercoda, in a new tab — keep this page open for the steps.

This is the guided lab's environment — the same machine, with its walkthrough on the left. Work from the task above and leave those steps alone until you are done, or you are reading the answers.

Run it on AWS

This lab builds real cloud infrastructure, so it needs your own AWS account. Follow the cost and cleanup notes above — the resources are yours, and so is the bill.

Anything you tick here is your own record. EgyKode cannot see inside that terminal, so the success criteria stay self-assessed even when the environment checks your work for you.

What must be true when you are done

Step 1 of 3

What must be true when you are done#

  • State lives in S3, and terraform.tfstate is no longer written locally.
  • The bucket has versioning and encryption enabled, and blocks public access.
  • A second apply started while the first is running fails with a lock error rather than proceeding.
  • You migrated existing state without any resource being destroyed and recreated.

Rules#

  • Do not open the guided lab until you are finished, or until the same problem has held you up for 20 minutes.
  • Documentation is allowed. In the job it is the first thing you open.
  • Verify every criterion with a command whose output you can read.

If you get stuck#

  1. What did you expect, exactly?
  2. What happened instead — the error text, not a paraphrase?
  3. Which layer is that error from?
  4. What is the smallest command that proves the layer below is fine?

You are done when

0 of 4

The concept behind it

Stuck?Open the guided lab

Next up

Lab 22 of 59 on the project path

AWS VPC, Subnets, Gateways & Route TablesRebuild the network you made by hand as Terraform modules, and see the plan account for every subnet and route.47 minIntermediateBillable — destroy resources when you finish