To quote the article itself:
an attacker can modify the Terraform state file it’s game over and bad times ahead.
However, in the very end, this article provides some suggestions that I never saw implemented IRL:
- Store the state lock in a separately permissioned location
- Use a read-only role for t
erraform plan executions#terraform