Do you have an example to back this up?
Do you have an example to back this up?
IAM Users are taggable, but to get the tags on a given user, you must request them one user at a time from a known list of users. The "List all users" call doesn't return their tags. Obviously this is less of an issue for the TF state use case, but does add to the API call overhead for any tag-based approach.
Cloud providers having bad APIs is definitely the default state.
terraform is more than just cloud providers https://registry.terraform.io/browse/providers
The article explicitly mentions OctoDNS as a stateless configuration management system for DNS as a good solution.
I guess it lets an attacker know that you're using Terraform, which might help them target their attacks.
Yes, if that's the case, then TXT records could easily be unsuitable. Depends exactly what metadata needs to be attached to your DNS records.
It's true that nothing extra is needed for simple/standard records, but once you start doing GeoDNS, failover, health check, etc. it's required.
In all cases thus far we've been able to find a way to store/indicate whatever we need.
(maintainer of octoDNS)