What Are Lifecycle Rules?
Lifecycle rules control how Terraform creates, updates, and destroys resources. They're essential for safe production infrastructure management.
prevent_destroy
Protect critical resources from accidental deletion:
resource "aws_db_instance" "production" {
engine = "postgres"
instance_class = "db.t3.medium"
lifecycle {
prevent_destroy = true
}
}Running terraform destroy will fail with an error. You must remove the rule first — a deliberate, visible action.
Master this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →create_before_destroy
Ensure zero-downtime updates by creating the replacement before destroying the old resource:
resource "aws_instance" "web" {
ami = var.ami_id
instance_type = "t2.micro"
lifecycle {
create_before_destroy = true
}
}The flow: create new → update references → destroy old.
ignore_changes
Ignore changes made outside Terraform (manual edits, auto-scaling):
resource "aws_instance" "web" {
ami = var.ami_id
instance_type = "t2.micro"
lifecycle {
ignore_changes = [
tags,
ami,
]
}
}Use sparingly — ignoring too many changes defeats the purpose of IaC.
replace_triggered_by
Force resource replacement when a dependency changes:
resource "aws_instance" "web" {
ami = var.ami_id
instance_type = "t2.micro"
lifecycle {
replace_triggered_by = [
aws_security_group.web.id,
]
}
}Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →precondition and postcondition
Validate assumptions:
resource "aws_instance" "web" {
instance_type = var.instance_type
lifecycle {
precondition {
condition = contains(["t2.micro", "t2.small", "t2.medium"], var.instance_type)
error_message = "Only t2 instances are allowed."
}
postcondition {
condition = self.public_ip != ""
error_message = "Instance must have a public IP."
}
}
}When to Use Each
- prevent_destroy — databases, S3 buckets with important data
- create_before_destroy — load-balanced instances, DNS records
- ignore_changes — auto-scaled resources, externally managed tags
- replace_triggered_by — instances that must restart on config change
- precondition/postcondition — input validation and sanity checks
Learn More
Master lifecycle rules with hands-on exercises in our Terraform for Beginners course.
---
Ready to go deeper? Check out our hands-on course: Terraform for Beginners — practical exercises you can follow along on your own machine.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Tofu vs Terraform Comparison
OpenTofu forked Terraform after the BSL license change. Compare features, compatibility, licensing, and ecosystem to decide which IaC tool fits your team.
Ansible vs Terraform When to Use
Ansible and Terraform solve different infrastructure problems. Learn when to use each, when to use both together, and how they complement each other.
GitHub Actions CI/CD for Terraform
Automate Terraform with GitHub Actions. Plan on PR, apply on merge, remote state locking, and secure secrets for IaC pipelines.
Terraform Loops and Conditionals
Terraform loops and conditionals. count, for_each, for expressions, dynamic blocks, and advanced patterns for DRY config code.
Terraform Modules Best Practices
Write reusable Terraform modules. Structure, variables, outputs, semantic versioning, automated testing, and registry publishing.
Terraform Modules Guide
Learn how to create and use Terraform modules to organize, share, and reuse infrastructure code across projects and teams.
Explore topics
Browse more articles on the topics covered here.