Explain Terraform lifecycle meta-arguments.
The lifecycle block controls how Terraform creates, updates, and destroys a resource.
- create_before_destroy: create the replacement before destroying the old one, reducing downtime for resources that must be replaced.
- prevent_destroy: fails the plan if the resource would be destroyed. Useful for databases and state buckets.
- ignore_changes: ignores changes to listed attributes, useful when an external system or autoscaler modifies them.
- replace_triggered_by: forces replacement when a referenced resource or attribute changes.
- precondition and postcondition: validate assumptions before or after an operation.
resource "aws_db_instance" "db" {
lifecycle {
prevent_destroy = true
ignore_changes = [tags["LastModified"]]
}
}
Caveats: prevent_destroy does not protect against state removal or CLI deletes. ignore_changes can hide real drift. create_before_destroy requires no name conflicts. Use these deliberately and document why.