Treat state as sensitive operational data
Terraform state can contain resource identifiers, configuration values and sometimes sensitive values returned by providers. Production state should use a controlled remote backend with encryption, access logging, least privilege and state locking.
Separate environments and permissions
Production, test and development estates should use deliberately separated state and identities. CI/CD identities should receive only the permissions required for approved deployment workflows.
Design recovery before automation depends on it
State loss or corruption can block safe infrastructure changes. Remote state should be versioned or backed up and the recovery procedure tested before the platform becomes business critical.
AL Group can assess, design, implement and operate the underlying technology rather than stopping at advice.
Talk to an engineer