A Fast, Minimal terraform state backend server. An easy centralised solution for homelabs
4.6K
A small HTTP backend server for storing Terraform state.
This project implements the Terraform HTTP backend protocol with support for state reads, state updates, and state locking. It is intended for self-hosted environments, homelabs, and small teams that want a simple centralized state backend without running a larger storage platform.
Docker Hub: bencejob/terraform-state-http-backend
Run the backend with Docker:
docker run --rm \
--name terraform-state-http-backend \
-p 8080:8080 \
-v "${PWD}/storage:/storage" \
bencejob/terraform-state-http-backend:latest
Create a Terraform backend configuration:
terraform {
backend "http" {
address = "http://localhost:8080/example/default"
update_method = "POST"
lock_address = "http://localhost:8080/example/default"
lock_method = "PUT"
unlock_address = "http://localhost:8080/example/default"
unlock_method = "DELETE"
}
}
Initialize Terraform:
terraform init
Terraform HTTP backend documentation: HashiCorp HTTP backend
The backend uses this URL pattern:
/:group/:key
Example:
http://localhost:8080/platform/network
With the file driver, this stores state at:
storage/platform-network.json
Lock data is stored separately:
storage/platform-network.lock
Configuration is provided with environment variables.
| Name | Default | Description |
|---|---|---|
HTTP_PORT | 8080 | Port the HTTP server listens on. |
DRIVER | file | Storage driver. Supported values: file, sqlite. |
BASIC_AUTH_USERNAME | unset | Enables HTTP Basic Auth when set with BASIC_AUTH_PASSWORD. |
BASIC_AUTH_PASSWORD | unset | Enables HTTP Basic Auth when set with BASIC_AUTH_USERNAME. |
The file driver is the default.
docker run --rm \
-p 8080:8080 \
-v "${PWD}/storage:/storage" \
bencejob/terraform-state-http-backend:latest
State and lock files are written under /storage. Mount this directory to persistent storage when running in Docker.
Set DRIVER=sqlite to use SQLite:
docker run --rm \
-p 8080:8080 \
-e DRIVER=sqlite \
-v "${PWD}/storage:/storage" \
bencejob/terraform-state-http-backend:latest
SQLite data is stored at:
/storage/database.db
Basic Auth is disabled by default. To enable it, set both username and password:
docker run --rm \
-p 8080:8080 \
-e BASIC_AUTH_USERNAME=terraform \
-e BASIC_AUTH_PASSWORD=change-me \
-v "${PWD}/storage:/storage" \
bencejob/terraform-state-http-backend:latest
Terraform backend configuration with Basic Auth:
terraform {
backend "http" {
address = "http://localhost:8080/example/default"
update_method = "POST"
lock_address = "http://localhost:8080/example/default"
lock_method = "PUT"
unlock_address = "http://localhost:8080/example/default"
unlock_method = "DELETE"
username = "terraform"
password = "change-me"
}
}
For production usage, prefer passing credentials through environment variables, CI secrets, or Terraform partial backend configuration rather than committing them to source control.
| Method | Path | Description |
|---|---|---|
GET | /:group/:key | Read Terraform state. |
POST | /:group/:key | Write Terraform state. |
PUT | /:group/:key | Acquire a Terraform state lock. |
DELETE | /:group/:key | Release a Terraform state lock. |
Common responses:
| Status | Meaning |
|---|---|
200 | Request succeeded. |
404 | State was not found. |
409 | Unlock attempted with the wrong lock ID. |
423 | State is already locked. |
500 | Storage or server error. |
Requirements:
1.26.0Run locally:
go run main.go
Run tests:
go test ./...
Build the Docker image:
docker build -t bencejob/terraform-state-http-backend .
Run the locally built image:
docker run --rm \
-p 8080:8080 \
-v "${PWD}/storage:/storage" \
bencejob/terraform-state-http-backend
Build for the local platform:
docker build -t bencejob/terraform-state-http-backend .
Build for multiple platforms:
docker buildx create --use --name terraform-state-builder
docker buildx build \
--platform linux/amd64,linux/arm64 \
--tag bencejob/terraform-state-http-backend:latest \
.
The repository includes GitHub Actions workflows for:
go test ./... on push and pull requestDocker publishing requires these repository secrets:
DOCKERHUB_USERNAME
DOCKERHUB_TOKEN
Terraform state can contain secrets. Treat the backend storage directory, SQLite database, Docker volumes, logs, backups, and access credentials as sensitive.
Recommended practices:
/storage.This project is licensed under the MIT License. See LICENSE-MIT.
Content type
Image
Digest
sha256:12665477e…
Size
4.2 MB
Last updated
4 months ago
docker pull bencejob/terraform-state-http-backend