Skip to main content
🎤 Luca Berton is speaking at Red Hat Summit & KubeCon EU 2026!Learn more →
Back to Blog

Terraform Lifecycle Rules

Master Terraform lifecycle rules — prevent_destroy, create_before_destroy, ignore_changes, and replace_triggered_by for safe infrastructure updates.

Luca BertonFebruary 18, 20261 min read

What Are Lifecycle Rules?

Lifecycle rules control how Terraform creates, updates, and destroys resources. They're essential for safe production infrastructure management.

prevent_destroy

Protect critical resources from accidental deletion:

hcl
resource "aws_db_instance" "production" {
  engine         = "postgres"
  instance_class = "db.t3.medium"

  lifecycle {
    prevent_destroy = true
  }
}

Running terraform destroy will fail with an error. You must remove the rule first — a deliberate, visible action.

Related Course

Master this topic with hands-on labs

Go beyond reading — build real projects in sandboxed environments with expert video guidance.

Browse Courses →

create_before_destroy

Ensure zero-downtime updates by creating the replacement before destroying the old resource:

hcl
resource "aws_instance" "web" {
  ami           = var.ami_id
  instance_type = "t2.micro"

  lifecycle {
    create_before_destroy = true
  }
}

The flow: create new → update references → destroy old.

ignore_changes

Ignore changes made outside Terraform (manual edits, auto-scaling):

hcl
resource "aws_instance" "web" {
  ami           = var.ami_id
  instance_type = "t2.micro"

  lifecycle {
    ignore_changes = [
      tags,
      ami,
    ]
  }
}

Use sparingly — ignoring too many changes defeats the purpose of IaC.

replace_triggered_by

Force resource replacement when a dependency changes:

hcl
resource "aws_instance" "web" {
  ami           = var.ami_id
  instance_type = "t2.micro"

  lifecycle {
    replace_triggered_by = [
      aws_security_group.web.id,
    ]
  }
}
Stay Updated

Get weekly IT automation tips

Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.

Subscribe Free →

precondition and postcondition

Validate assumptions:

hcl
resource "aws_instance" "web" {
  instance_type = var.instance_type

  lifecycle {
    precondition {
      condition     = contains(["t2.micro", "t2.small", "t2.medium"], var.instance_type)
      error_message = "Only t2 instances are allowed."
    }

    postcondition {
      condition     = self.public_ip != ""
      error_message = "Instance must have a public IP."
    }
  }
}

When to Use Each

  • prevent_destroy — databases, S3 buckets with important data
  • create_before_destroy — load-balanced instances, DNS records
  • ignore_changes — auto-scaled resources, externally managed tags
  • replace_triggered_by — instances that must restart on config change
  • precondition/postcondition — input validation and sanity checks

Learn More

Master lifecycle rules with hands-on exercises in our Terraform for Beginners course.

---

Ready to go deeper? Check out our hands-on course: Terraform for Beginners — practical exercises you can follow along on your own machine.

Ready to learn by doing?

Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.

Share this article
LB
Luca Berton

Docker Captain, IT automation expert, Red Hat Summit & KubeCon speaker. Building hands-on education for DevOps engineers at CopyPasteLearn.

Related Articles

Explore topics

Browse more articles on the topics covered here.