Skip to content

AWS: Migrate AWS infra Terraform state files outside the AWS Org management account #4800

@deobieta

Description

@deobieta

We are currently saving Terraform state files in buckets that live in the AWS management account.

What AWS account do we put the state buckets in?

Long term, it's good if we're not putting the state in the management account. The benefit: a Terraform run that doesn't involve the management account should be able to succeed without interacting with the management account.

Originally posted by @sftim in #4694 (comment)

In general we should stop creating resources inside the management account. Service Control Policies affect only member accounts in the organization. They have no effect on users or roles in the management account.

/area infra
/area infra/aws
/priority important-longterm

Metadata

Metadata

Assignees

Labels

area/infraInfrastructure management, infrastructure design, code in infra/area/infra/awsIssues or PRs related to Kubernetes AWS infrastructurelifecycle/frozenIndicates that an issue or PR should not be auto-closed due to staleness.priority/important-longtermImportant over the long term, but may not be staffed and/or may need multiple releases to complete.sig/k8s-infraCategorizes an issue or PR as relevant to SIG K8s Infra.

Type

No type

Projects

Status

📋 Backlog

Relationships

None yet

Development

No branches or pull requests

Issue actions