Skip to content

infra(terraform): Migrate state locking from DynamoDB to S3-native - #85

Merged
be-wise-be-kind merged 2 commits into
mainfrom
infra/s3-native-locking
Feb 22, 2026
Merged

be-wise-be-kind merged 2 commits into
mainfrom
infra/s3-native-locking

Conversation

@be-wise-be-kind

Copy link
Copy Markdown
Owner

Summary

  • Replaces DynamoDB-based Terraform state locking with S3-native locking (use_lockfile=true), available since Terraform 1.10+, which uses S3 conditional writes instead of a separate DynamoDB table
  • Adds -lock-timeout=120s to all plan/apply/destroy commands so operations wait for stale locks to clear instead of failing immediately
  • Removes the DynamoDB IAM policy from the GitHub Actions OIDC role and updates TERRAFORM_VERSION to match the installed 1.14.5

Why

Interrupted terraform apply operations (Ctrl+C, timeouts, crashes) left orphaned lock entries in DynamoDB that blocked all subsequent operations. S3-native locking eliminates this class of issue entirely, and the lock timeout provides a safety net for any remaining contention.

Test plan

  • just infra init runtime succeeds with new backend config
  • just infra plan runtime succeeds with S3-native locking (no DynamoDB lock errors)
  • just infra up runtime true deploys successfully (4 added, 1 replaced)
  • just infra up bootstrap true removes DynamoDB IAM policy cleanly
  • Verify just infra up works end-to-end after PR merge

Note: The DynamoDB table durable-code-terraform-locks still exists in AWS but is no longer referenced. It can be deleted manually when ready.

🤖 Generated with Claude Code

@github-actions

Copy link
Copy Markdown

Terraform Validation Results - RUNTIME Workspace

Check Status
Format ✅ terraform fmt
Init ✅ terraform init
Validate ✅ terraform validate
Security ✅ tfsec

Workspace: infra/terraform/workspaces/runtime

✅ All checks passed for runtime workspace!

@github-actions

Copy link
Copy Markdown

Terraform Validation Results - BASE Workspace

Check Status
Format ✅ terraform fmt
Init ✅ terraform init
Validate ✅ terraform validate
Security ✅ tfsec

Workspace: infra/terraform/workspaces/base

✅ All checks passed for base workspace!

@github-actions

Copy link
Copy Markdown

Terraform Validation Results - BASE Workspace

Check Status
Format ✅ terraform fmt
Init ✅ terraform init
Validate ✅ terraform validate
Security ✅ tfsec

Workspace: infra/terraform/workspaces/base

✅ All checks passed for base workspace!

@github-actions

Copy link
Copy Markdown

Terraform Validation Results - RUNTIME Workspace

Check Status
Format ✅ terraform fmt
Init ✅ terraform init
Validate ✅ terraform validate
Security ✅ tfsec

Workspace: infra/terraform/workspaces/runtime

✅ All checks passed for runtime workspace!

Steve Jackson and others added 2 commits February 21, 2026 20:03
Replace DynamoDB-based state locking with Terraform 1.10+ S3-native
locking (use_lockfile=true) which uses S3 conditional writes. This
eliminates stale lock issues caused by interrupted operations leaving
orphaned DynamoDB entries. Also adds -lock-timeout=120s to all
plan/apply/destroy commands for resilience against brief lock contention.

- Replace dynamodb_table with use_lockfile=true in all backend configs
- Add -lock-timeout=120s to plan, apply, destroy, force-destroy recipes
- Remove DynamoDB IAM policy from GitHub Actions OIDC role
- Update TERRAFORM_VERSION from 1.9.8 to 1.14.5
- Clean up DynamoDB references in comments and scripts

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Grafana resources were extracted to a separate workspace in PR #86.
The runtime workspace no longer needs the Grafana provider.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

Terraform Validation Results - RUNTIME Workspace

Check Status
Format ✅ terraform fmt
Init ✅ terraform init
Validate ✅ terraform validate
Security ✅ tfsec

Workspace: infra/terraform/workspaces/runtime

✅ All checks passed for runtime workspace!

@github-actions

Copy link
Copy Markdown

Terraform Validation Results - BASE Workspace

Check Status
Format ✅ terraform fmt
Init ✅ terraform init
Validate ✅ terraform validate
Security ✅ tfsec

Workspace: infra/terraform/workspaces/base

✅ All checks passed for base workspace!

@be-wise-be-kind
be-wise-be-kind merged commit 1efbc33 into main Feb 22, 2026
8 checks passed
@be-wise-be-kind
be-wise-be-kind deleted the infra/s3-native-locking branch February 22, 2026 03:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant