Terraform Backend
A Terraform backend (also used by OpenTofu) is the part of the configuration that defines where the state is stored and, for some backends, where the operations run. The default is the local backend, a file in the working directory, which is not suitable for teams.
Remote backends store the state in a shared place, add locking so two people cannot apply at the same time, and often versioning and encryption. The most used on AWS is S3:
terraform {
backend "s3" {
bucket = "ditwl-tfstate"
key = "pro/network/terraform.tfstate"
region = "eu-west-1"
encrypt = true
use_lockfile = true
}
}Other backends include azurerm, gcs, http, pg and HCP Terraform. Changing the backend requires terraform init -migrate-state. The backend block cannot use normal variables (OpenTofu 1.8 and later allows early-evaluated ones). The arguments change between versions, so check the documentation of yours.
Learn how to create one in the backends tutorial and see secrets management to protect it.