Does Terraform Work in China? Data Residency, Localization & PIPL Cross-Border
The Terraform CLI runs anywhere, but HCP Terraform (formerly Terraform Cloud) stores your state, variables and secrets in the United States with no mainland-China region — and that state maps your whole infrastructure, often with credentials in plaintext. A compliance-first look at where Terraform state and secrets may lawfully rest under PIPL and China's data-localization rules, and the in-country path.
Does Terraform work in China?
The Terraform CLI runs anywhere — but HCP Terraform, the managed service, stores your state, variables and secrets in the United States with no mainland-China region, and that state maps your entire infrastructure, often with credentials in plaintext.
Whether Terraform is reachable was never the question; where its state is allowed to rest is. HashiCorp's Trust Center says HCP Terraform "is a multi-tenant service. Customer data is stored in the United States. Customers cannot choose a different hosting location." Where that state, its variables, or the resources it describes carry personal information collected in the mainland, keeping it offshore is a cross-border transfer under PIPL (notice, a separate consent, a transfer mechanism); and for a critical information infrastructure operator or high-volume handler, data the Cybersecurity Law says must stay in the mainland (Article 39, formerly Article 37; PIPL Article 40). The lawful lever is Terraform's own: the CLI runs in-country and the backend you choose decides where state lives, so a self-managed, in-country state backend keeps state and secrets on mainland soil.
This is a risk map, not a verdict — whether you owe in-country storage, a transfer mechanism, or both turns on your entity, your data volumes and whose personal information your infrastructure touches. Our China team can map your exposure →
What Terraform's own documentation says about China
| Fact | Primary source |
|---|---|
| HCP Terraform stores your state, variables and secrets in the United States — with no mainland-China region. HashiCorp's Trust Center states HCP Terraform (formerly Terraform Cloud) "is a multi-tenant service. Customer data is stored in the United States. Customers cannot choose a different hosting location." A separate EU data-residency option stores that data in Europe, but there is no mainland-China region either way, so the state and secrets you push to HCP come to rest offshore. | HashiCorp Trust Center — HCP data location overview (hashicorp.com), retrieved 2026-10-10 |
| Terraform state maps your whole infrastructure and can store secrets in plaintext. HashiCorp's own docs say state and plan files "contain detailed information about your infrastructure, including resource attributes and metadata that can contain sensitive values, such as initial database passwords or API tokens," and that run locally "Terraform stores your state in a plaintext file, which includes any secret values you defined in your configuration." Wherever that state rests, your infrastructure topology and its credentials rest with it. | Terraform docs — Manage sensitive data in your configuration (developer.hashicorp.com), retrieved 2026-10-10 |
| The CLI runs anywhere, and the backend you choose decides where state rests. HashiCorp's docs say "the backend defines where Terraform stores its state data files," and that you can "define a backend block to store state in a remote object" instead of HCP Terraform. That makes a self-managed, in-country state backend the lawful lever: keep Terraform and your workflow, and keep state and secrets on mainland infrastructure rather than in an offshore service. | Terraform docs — Backend block configuration overview (developer.hashicorp.com), retrieved 2026-10-10 |
| Offshore state carrying China personal information is a cross-border transfer — and some handlers owe in-country storage. Where state, variables, logs or the resources they describe carry personal information collected in the mainland, keeping them in a US service is a cross-border transfer under PIPL (Articles 38–40) — notice, separate consent, and one transfer mechanism. If you are a critical information infrastructure operator or a high-volume handler, that data must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)), which an offshore HCP service cannot satisfy. | PIPL Articles 38–40 and 40; Cybersecurity Law Article 39 (formerly Article 37) (gov.cn) |
Sources verified by the 21YunBox compliance team on 2026-10-10.
Whether Terraform runs in China is the wrong question. The Terraform CLI is a binary that executes wherever you put it — a laptop in Shenzhen, a build agent in Shanghai — so reachability is not the issue. What a China-facing team actually has to decide is where Terraform’s state is allowed to come to rest. A state file is not a log; it is a map of your entire infrastructure — every resource, its attributes and metadata — and, in HashiCorp’s own words, it “can contain sensitive values, such as initial database passwords or API tokens,” frequently stored in plaintext. HCP Terraform, the managed service formerly called Terraform Cloud, stores that state, your variables and your provider credentials in the United States, and customers cannot choose a different hosting location. That is the residency gap — and it is about where your infrastructure map and its secrets live, not about speed.
Terraform in China at a glance
| What decides it | In Terraform's own terms — and China's law |
|---|---|
| Where your state actually rests | HCP Terraform (formerly Terraform Cloud) is the managed service that stores your Terraform state, variables and provider credentials. HashiCorp's Trust Center: HCP Terraform "is a multi-tenant service. Customer data is stored in the United States. Customers cannot choose a different hosting location." A separate EU data-residency option stores that data in Europe — but there is no mainland-China region either way. |
| What Terraform state holds | State is a map of your whole infrastructure. HashiCorp's docs say state and plan files "contain detailed information about your infrastructure, including resource attributes and metadata that can contain sensitive values, such as initial database passwords or API tokens," and that locally "Terraform stores your state in a plaintext file." Where the resources it manages hold customer records or user accounts, that personal information sits in or behind the state. |
| Your China data crossing the border | When state, variables, logs or the resources they describe carry personal information collected in the mainland, keeping them in HCP Terraform's US service moves that data offshore — a cross-border transfer under PIPL (Articles 38–40): notice, a separate consent, and one transfer mechanism (a CAC security assessment, the CAC standard contract, or certification). |
| The in-country storage duty | If you operate critical information infrastructure, or handle personal information above the regulated volumes, data collected in the mainland must be stored in the mainland (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37) — the 2025 Cybersecurity Law amendment, in force January 1, 2026, renumbered the data-localization article from 37 to 39, with the substance unchanged). A US-only HCP service has no mainland region in which to hold it. |
| Reachability is not the axis | Terraform is not "blocked" — the CLI runs wherever you deploy it, and HCP is reachable from the mainland. The decision is residency of state and secrets. The lawful lever: run the CLI with a self-managed, in-country state backend so state never leaves the mainland, and put any China-facing surface in front of your stack on ICP-filed, in-country delivery. |
Where the data actually rests
The Terraform CLI itself is residency-neutral: it runs on whatever machine you run it on, and the backend you configure decides where state is kept. HashiCorp’s documentation is explicit — “the backend defines where Terraform stores its state data files,” and you can either integrate with HCP Terraform or “define a backend block to store state in a remote object.” Choose HCP Terraform and that remote object is HashiCorp’s multi-tenant service. Its Trust Center is unambiguous about where that lands: HCP Terraform “is a multi-tenant service. Customer data is stored in the United States. Customers cannot choose a different hosting location.” HashiCorp’s data-security documentation shows exactly what the service holds — your Terraform state file and plan results in blob storage, your variables and provider credentials in its database, and cloud backups in Amazon S3. HashiCorp has since introduced an EU data-residency option that keeps that data in Europe, but there is no mainland-China region in either case. So state, variables and secrets pushed to HCP Terraform rest offshore, and your Chinese users’ personal information — wherever it sits in or behind that infrastructure — rests offshore with it. That is a data-residency fact before it is anything else.
What it holds is personal information
Dismissing Terraform state as “just config” is the mistake. HashiCorp’s own guidance says state and plan files “contain detailed information about your infrastructure, including resource attributes and metadata that can contain sensitive values, such as initial database passwords or API tokens,” and that when you work locally “Terraform stores your state in a plaintext file, which includes any secret values you defined in your configuration.” Even with the recommended guardrails, it warns that Terraform “stores values with the sensitive argument in both state and plan files, and anyone who can access those files can access your sensitive values.” So the state is two sensitive things at once: a complete topology of your infrastructure — a trade-secret exposure on its own — and a container for credentials and tokens. Layer in the data the infrastructure describes — databases of customer records, user accounts, application secrets — and personal information is squarely in scope.
When personal information collected in the mainland is stored in, or reachable from, an offshore service, PIPL governs the move as a cross-border transfer: Articles 38–40 require notice, a separate consent, and one transfer mechanism — a CAC security assessment, the CAC standard contract, or certification. And if you operate critical information infrastructure, or handle personal information above the regulated volumes, a data-localization duty applies: personal information and important data collected in-country must be stored in-country (PIPL Article 40; Cybersecurity Law Article 39 (formerly Article 37)). An offshore, US-hosted HCP service structurally cannot satisfy that duty — there is no mainland region to hold the data in.
Running it on a no-China-region managed service doesn’t meet the residency duty — and what does
Put the two facts together and the conclusion is narrow and practical. HCP Terraform has no mainland-China region, so it cannot hold mainland data in-country; and Terraform state carries both your infrastructure topology and its secrets. For a handler that owes data localization, an offshore HCP workspace is therefore structurally unable to meet the duty — not because Terraform is deficient, but because the managed service keeps the data in the United States.
The lawful lever is Terraform’s own design. The CLI runs wherever you deploy it, including on mainland infrastructure, and because “the backend defines where Terraform stores its state data files,” you can point it at a self-managed, in-country state backend — an in-country object store or a self-hosted backend — instead of HCP Terraform. State and secrets then stay on mainland soil, and you keep Terraform, your modules and your workflow exactly as they are. This is not a migration off Terraform; it is a decision about where state rests. (Two facts worth noting and setting aside: Terraform’s license changed from MPL 2.0 to the Business Source License in August 2023, which spawned the OpenTofu fork now stewarded by the Linux Foundation; and HashiCorp was acquired by IBM, announced in 2024 and closed in February 2025. Neither changes the residency analysis — the CLI still runs where you deploy it, and the backend still decides where state lives.)
None of this is a ruling. Whether you owe in-country storage, a cross-border transfer mechanism, or both turns on your entity, your data volumes, and whose personal information your infrastructure actually touches — settle the specifics with your counsel against your real data flows, and treat this page as a map of the exposure, not a verdict.
The lawful path — map, localize, deliver
21YunBox is a compliant overlay, not a migration — and a partner to HashiCorp’s tooling, not a competitor to it. Our job is to make the Terraform you already run lawful and durable for mainland China, in three moves.
Map. We read the PIPL cross-border, data-residency and data-localization (CII) obligations against your actual setup — your entity, your data volumes, what your Terraform state and variables contain, and whose personal information your infrastructure touches — so you and your counsel can see the exposure precisely.
Localize. We help you keep state and secrets in-country: run the Terraform CLI with a self-managed, in-country state backend on mainland infrastructure, or a licensed in-country / sovereign-cloud option where that fits. Localize means standing up a lawful in-country home for your state — not tunnelling back to the offshore HCP endpoint.
Deliver. Any China-facing surface in front of the stack your Terraform provisions — the app, the API edge, the admin or reporting portal your mainland users hit — runs over ICP-filed, in-country delivery (the 21YunBox Optimizer), in front of the stack you already run, with no rebuild and no second codebase. That China-facing property still carries an ICP filing (备案) duty, and that part we own outright.
The result runs legally and compliantly for your users in China, on infrastructure that stays lawful at every node. 21YunBox never uses or suggests circumvention of any kind.
Related reading:
- Cross-border data transfers under PIPL
- China’s Cybersecurity Law (data localization, Article 39, formerly Article 37)
- China’s data export security assessment measures
- How to get an ICP filing for China
