Skip to content
EgyKode
11 · Operating itLab 57 / 59
ChallengeterraformDestructive

Terraform Drift & State Recovery — Challenge

Someone changed AWS by hand and someone else deleted the state. Recover from both without rebuilding anything.

Time
27 min
Level
Advanced
Objectives
4 objectives
Cost
Low cost

Where this fits in the platform

This lab adds

  • State recovered after the failure everyone hopes to avoid

Which lets you

Before you start

You will need

  • Terraform >= 1.6
  • AWS CLI v2, configured

You will be able to

  • Detect drift and decide whether to adopt or revert it
  • Import an existing resource into state
  • Recover a state file from a versioned backend

CostLow cost

— the exercises use an S3 bucket and a `t3.micro`. Nothing here bills hourly beyond the instance.

How to clean up

The goal#

Achieve the same outcome as Terraform Drift & State Recovery, from an empty starting point, without the steps.

Someone widened a security group in the console during an incident. Someone else ran terraform apply a week later and closed it again, causing a second incident.

Then the state file was deleted.

All three are recoverable. None of them require rebuilding the infrastructure — which is what people do when they do not know these commands.

Hands-on environment

Run this lab in a real terminal, free and in your browser. The environment is temporary and yours alone — break it as much as you like.

Start the challenge

Opens in Killercoda, in a new tab — keep this page open for the steps.

This is the guided lab's environment — the same machine, with its walkthrough on the left. Work from the task above and leave those steps alone until you are done, or you are reading the answers.

Run it on AWS

This lab builds real cloud infrastructure, so it needs your own AWS account. Follow the cost and cleanup notes above — the resources are yours, and so is the bill.

Anything you tick here is your own record. EgyKode cannot see inside that terminal, so the success criteria stay self-assessed even when the environment checks your work for you.

What must be true when you are done

Step 1 of 3

What must be true when you are done#

  • You detected a manual change and can explain both ways to resolve it.
  • A resource created outside Terraform is imported and plan reports no changes.
  • A deleted state file is restored from S3 versioning and matches reality.
  • Nothing was destroyed and recreated during any of it.

Rules#

  • Do not open the guided lab until you are finished, or until the same problem has held you up for 20 minutes.
  • Documentation is allowed and encouraged.
  • Verify every criterion with a command whose output you can read.

If you get stuck#

  1. What did you expect, exactly?
  2. What happened instead — the error text, not a paraphrase?
  3. Which layer is that error from?
  4. What is the smallest command that proves the layer below is fine?

You are done when

0 of 4

The concept behind it

Stuck?Open the guided lab

Next up

Lab 57 of 59 on the project path

Node Drain, Upgrade & RecoveryTake a node out of service without taking the application with it, and find out which workloads were never ready for it.55 minAdvanced