TGViewer
CatOps CatOps @catops · 5.07K subscribers
Post #2411 2.67K
The core idea of this article is pretty simple: you need to protect your Terraform states. I don't think this is a debatable topic, and anyone has a different opinion on this matter.

To quote the article itself:

 an attacker can modify the Terraform state file it’s game over and bad times ahead.


However, in the very end, this article provides some suggestions that I never saw implemented IRL:

- Store the state lock in a separately permissioned location
- Use a read-only role for terraform plan executions

#terraform
Plerion Hacking Terraform State for Privilege Escalation | Plerion What can an attacker do if they can edit Terraform state? The answer should be 'nothing' but is actually 'take over your CI/CD pipeline'.
  • 👍 4
More from @catops
  1. Oct 8, 2026I’m going on a vacation, which means that I likely won’t post at all or post something ver…
  2. Oct 6, 2026A colleague of mine wrote an article about data migrations. Handling data migrations witho…
  3. Oct 1, 2026​​I traded my personal information for this report, so you don’t have to! DataDog presents…
  4. Sep 29, 2026A Cybersecurity books bundle by O’Reilly on Humble Bundle. The bundle is fresh and is stil…
  5. Sep 28, 2026​​For today’s Donations Monday, I’d like to remind you about a fundraiser for a pickup tru…
  6. Sep 26, 2026Here’s Datadog’s take on the increased load on CI. In this article they explain how their…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →