Skip to main content

Run Terraform locally against Spacelift remote state without using private workers

We want to run plans or other commands against the remote state that Spacelift manages, we have to go through Spacectl and the private worker. That means a lot of development and testing work is also counted against our worker usage and P95, even when it is not production critical.

What we would like is a way to run Terraform locally, against the same remote state that Spacelift manages, without consuming private worker capacity. Think about the way Terraform Cloud or Terraform Enterprise let you use the CLI locally, still talking to remote state. Our ideal flow would be

  • Developers run day to day commands locally, against Spacelift remote state

  • Production and more critical workloads continue to run on the private workers

  • We keep the same security model, audit and access control, just without having to push every single run through the workers

This would let us keep the worker focused on the important workloads, while still using Spacelift as the source of truth for state.

Status: ❌ Rejected1 comment

Log in to comment and vote

Comments1

  • Black Breeze

    •

    Nov 27, 2025

    Thank you for the detailed feedback and for explaining your use case!
    We understand the desire to keep worker capacity focused on production-critical workloads. However, the current design where all state writes go through Spacelift workers is intentional - it ensures that your state history remains fully auditable with a complete record of every change, who made it, and when.


    For external read access to Spacelift-managed state, you can already reference it externally by configuring a remote backend for read operations. This allows local development workflows that need to reference existing state without consuming worker capacity.


    For workflows that require external write access to state, we'd recommend using an external backend like S3 (with state locking via DynamoDB). This gives you the flexibility to run Terraform locally with full read/write access, though it does mean managing state versioning and audit trails yourself.


    The tradeoff Spacelift makes is prioritizing auditability and security guarantees over the flexibility of arbitrary external writes. We appreciate you sharing this use case, and we'll keep it in mind as we continue to evolve the platform.