Memory hook: Import adopts; move renames; remove forgets.
Must remember
- Import associates an existing remote object with a resource address. The CLI import command updates state but does not write a complete matching configuration. Configuration-driven
importblocks allow adoption to appear in a plan; review any generated configuration before applying it. - Import one real object into one managed address. After adoption, plan again: missing or different arguments can propose changes or replacement. Import is not a backup and does not discover an entire application automatically.
- A moved block records an address change, such as moving a resource into a module, so Terraform can retain its identity. Keep historical moves for consumers who upgrade from older module versions.
terraform state listshows addresses;state show ADDRESSshows a recorded object;terraform showdisplays state or a saved plan. State inspection can reveal secrets.terraform state rm ADDRESSforgets the binding without deleting the remote object. If its configuration remains, a later plan may try to create another object. A reviewedremovedblock with destruction disabled provides a declarative alternative.- Set
TF_LOGto a diagnostic level such as DEBUG or TRACE when troubleshooting;TF_LOG_PATHwrites logs to a file. Disable logging afterward and protect logs because provider requests may contain sensitive data. Inspect initialization, authentication, provider diagnostics and the exact address before changing state.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Rename without recreation | Use a moved block and review the plan. |
| Adopt manually created infrastructure | Import the correct ID into matching configuration. |
| Investigate a recorded instance | Use state list/show before attempting recovery. |
Traps
- Removing state is not resource cleanup.
- Import may succeed while the next plan still proposes destructive changes.
Active recall
1. Does CLI import create the remote object?
No. It records an existing object under a Terraform address.
2. What prevents recreation after a resource rename?
A moved block or a carefully managed equivalent state move.
3. What happens after state rm?
The remote object remains, but Terraform no longer manages that binding.
4. Why plan after import?
To find configuration differences that could update or replace the adopted object.
5. Why should TRACE logs be temporary?
They are verbose and may expose sensitive provider/configuration details.