The ignore_changes lifecycle rule tells Terraform not to plan updates for selected existing-resource attributes, though those arguments still matter during creation. It can reduce a fight with an autoscaler or another controller, but it can also hide an unauthorized edit. An ignored field needs an explicit owner, a desired range, an independent drift signal, and a procedure for returning control to Terraform. Otherwise a clean plan becomes false reassurance.
Terraform ignore_changes: name the second owner of every ignored field
Operational decision
A receipt worker pool is scaled by an autoscaling controller. Terraform creates the pool with a starting desired capacity, but the controller adjusts that value while traffic changes. The fragment limits the exception to desired_capacity; other pool settings remain managed by Terraform. Record the controller identity, permitted bounds, emergency override path, and the metric that catches capacity outside the contract. In a test environment, change desired capacity through the controller and confirm Terraform does not fight it. Then change an unrelated security setting outside Terraform and confirm the plan still proposes correction. Also simulate the controller being disabled: the ignored capacity can remain wrong without a Terraform diff, so alert from observed capacity and SLOs. Review every ignore rule when ownership changes, and remove it with a planned handover rather than silently adding more ignored fields.
resource "aws_autoscaling_group" "receipt_workers" {
name_prefix = "receipt-workers-"
max_size = 8
min_size = 2
desired_capacity = 3
vpc_zone_identifier = var.worker_subnet_ids
lifecycle {
ignore_changes = [desired_capacity]
}
}Cost and verification
Ignoring one attribute reduces noisy plans and needless API writes. The cost is a second control loop and separate monitoring. Ignoring all attributes can make the plan nearly useless for detecting unauthorized updates, while leaving the team responsible for their effects. Measure controller changes, capacity outside declared bounds, and time since the last ownership review. A nightly drift report must compare actual values with the external owner's contract, not rely solely on Terraform's no-op result.
Common Mistakes
- Do not ignore an entire resource to silence a recurring drift alert.
- Do not leave an ignored field without a named controller and alert.
- Do not assume ignore_changes prevents Terraform from using the value on creation.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Infrastructure drift: distinguish emergency repair from unauthorized change
- Terraform state: shared ownership and safe plans
- Horizontal autoscaling: choose a signal tied to demand
- Terraform replacement: prove old and new can coexist
