# Terraform Backend

> A Terraform backend defines where the state is stored and how operations run. Learn the S3 backend, locking and how to migrate between backends.

- Source: https://www.itwonderlab.com/terraform-backend/
- Published: 2026-07-29
- Updated: 2026-07-29
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

A **Terraform backend** (also used by OpenTofu) is the part of the configuration that defines where the [state](https://www.itwonderlab.com/terraform-state/) is stored and, for some backends, where the operations run. The default is the `local` backend, a file in the working directory, which is not suitable for teams.

Remote backends store the state in a shared place, add **locking** so two people cannot apply at the same time, and often versioning and encryption. The most used on AWS is S3:

```hcl title="backend.tf"
terraform {
  backend "s3" {
    bucket       = "ditwl-tfstate"
    key          = "pro/network/terraform.tfstate"
    region       = "eu-west-1"
    encrypt      = true
    use_lockfile = true
  }
}
```

Other backends include `azurerm`, `gcs`, `http`, `pg` and HCP Terraform. Changing the backend requires `terraform init -migrate-state`. The backend block cannot use normal variables (OpenTofu 1.8 and later allows early-evaluated ones). The arguments change between versions, so check the documentation of yours.

Learn how to create one in the [backends tutorial](https://www.itwonderlab.com/aws-terraform-tutorial-terraform-backends/) and see [secrets management](https://www.itwonderlab.com/terraform-secrets-management/) to protect it.
