पाठ 19 / 25
prevent_destroy and Other Lifecycle Rules
Guard critical resources.
lifecycle settings
The lifecycle block changes how Terraform handles a resource: prevent_destroy = true makes any plan that would destroy it fail (protecting databases and state buckets), create_before_destroy replaces without a gap, ignore_changes stops Terraform reverting attributes changed by something else (such as an autoscaler's desired count), and replace_triggered_by forces replacement when another resource changes. Also enable deletion protection at the provider level where it exists.
A destroy plan blocked by prevent_destroy, run
I ran this with Terraform 1.16.4 and the hashicorp/local 2.9.1 and hashicorp/random 3.9.1 providers, which manage local files and random values, so no cloud account was needed; each example starts from a fresh directory. Planning a destroy of the protected file fails with "Instance cannot be destroyed". To remove it deliberately you must first change the configuration, which is reviewed like any other change.
terraform plan -destroy -no-color 2>&1 | grep -E "Error|prevent_destroy"
Output:
Error: Instance cannot be destroyed Resource local_file.important has lifecycle.prevent_destroy set, but the plan with the plan, either disable lifecycle.prevent_destroy or reduce the scope
Combine with provider deletion protection
prevent_destroy only guards Terraform; deletion protection on the database itself also guards against console and API mistakes.
त्वरित जाँच: What does ignore_changes do?
- Prevents all updates to every resource
- Deletes the resource
- Hides the resource from state
- Stops Terraform reverting specified attributes changed outside Terraform
Answer
Stops Terraform reverting specified attributes changed outside Terraform — Use it for attributes managed by other systems.