Terraform State & Drift · Terraform systems note
Terraform State Surgery Should Be Rare, Explicit, and Audited
state mv, state rm, state replace-provider, state pull and state push can change Terraform's ownership model without directly changing remote infrastructure.
Terraform's state subcommands are powerful because they can repair the mapping between code and infrastructure without touching the infrastructure itself.
state mv changes identity
It rebinds a real object from one resource address to another. Modern moved blocks are often preferable because the migration remains visible in source control.
state rm gives up ownership
The remote object stays, but Terraform forgets it. If configuration still declares the resource, a later plan may try to create a replacement.
replace-provider rewrites provider association
This is useful during namespace changes or provider forks, but compatibility has to be verified afterward.
state push is disaster-recovery territory
Terraform checks lineage and serial before accepting a manual push. Forcing past those protections can overwrite newer canonical state.
Audit the operation
Capture a state backup, exact command, change reason, configuration revision and post-change plan. If the operation changes who Terraform thinks owns an object, it deserves the same review as a database migration.