Repository navigation
infra(terraform): Migrate state locking from DynamoDB to S3-native - #85
Merged
Merged
Conversation
Terraform Validation Results - RUNTIME Workspace
Workspace:
|
Terraform Validation Results - BASE Workspace
Workspace:
|
be-wise-be-kind
force-pushed
the
infra/s3-native-locking
branch
from
February 22, 2026 02:37
0f10572 to
6448796
Compare
Terraform Validation Results - BASE Workspace
Workspace:
|
Terraform Validation Results - RUNTIME Workspace
Workspace:
|
Replace DynamoDB-based state locking with Terraform 1.10+ S3-native locking (use_lockfile=true) which uses S3 conditional writes. This eliminates stale lock issues caused by interrupted operations leaving orphaned DynamoDB entries. Also adds -lock-timeout=120s to all plan/apply/destroy commands for resilience against brief lock contention. - Replace dynamodb_table with use_lockfile=true in all backend configs - Add -lock-timeout=120s to plan, apply, destroy, force-destroy recipes - Remove DynamoDB IAM policy from GitHub Actions OIDC role - Update TERRAFORM_VERSION from 1.9.8 to 1.14.5 - Clean up DynamoDB references in comments and scripts Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
Grafana resources were extracted to a separate workspace in PR #86. The runtime workspace no longer needs the Grafana provider. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
be-wise-be-kind
force-pushed
the
infra/s3-native-locking
branch
from
February 22, 2026 03:07
6448796 to
b8fe64d
Compare
Terraform Validation Results - RUNTIME Workspace
Workspace:
|
Terraform Validation Results - BASE Workspace
Workspace:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
use_lockfile=true), available since Terraform 1.10+, which uses S3 conditional writes instead of a separate DynamoDB table-lock-timeout=120sto all plan/apply/destroy commands so operations wait for stale locks to clear instead of failing immediatelyTERRAFORM_VERSIONto match the installed 1.14.5Why
Interrupted
terraform applyoperations (Ctrl+C, timeouts, crashes) left orphaned lock entries in DynamoDB that blocked all subsequent operations. S3-native locking eliminates this class of issue entirely, and the lock timeout provides a safety net for any remaining contention.Test plan
just infra init runtimesucceeds with new backend configjust infra plan runtimesucceeds with S3-native locking (no DynamoDB lock errors)just infra up runtime truedeploys successfully (4 added, 1 replaced)just infra up bootstrap trueremoves DynamoDB IAM policy cleanlyjust infra upworks end-to-end after PR merge🤖 Generated with Claude Code