Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Terraform ignore_changes: name the second owner of every ignored field

Last updated: 1 Oct 20266 min read
tutorial
AdvancedBy AITrove Editorial

The ignore_changes lifecycle rule tells Terraform not to plan updates for selected existing-resource attributes, though those arguments still matter during creation. It can reduce a fight with an autoscaler or another controller, but it can also hide an unauthorized edit. An ignored field needs an explicit owner, a desired range, an independent drift signal, and a procedure for returning control to Terraform. Otherwise a clean plan becomes false reassurance.

Operational decision

A receipt worker pool is scaled by an autoscaling controller. Terraform creates the pool with a starting desired capacity, but the controller adjusts that value while traffic changes. The fragment limits the exception to desired_capacity; other pool settings remain managed by Terraform. Record the controller identity, permitted bounds, emergency override path, and the metric that catches capacity outside the contract. In a test environment, change desired capacity through the controller and confirm Terraform does not fight it. Then change an unrelated security setting outside Terraform and confirm the plan still proposes correction. Also simulate the controller being disabled: the ignored capacity can remain wrong without a Terraform diff, so alert from observed capacity and SLOs. Review every ignore rule when ownership changes, and remove it with a planned handover rather than silently adding more ignored fields.

hcl
resource "aws_autoscaling_group" "receipt_workers" {
  name_prefix         = "receipt-workers-"
  max_size            = 8
  min_size            = 2
  desired_capacity    = 3
  vpc_zone_identifier = var.worker_subnet_ids

  lifecycle {
    ignore_changes = [desired_capacity]
  }
}

Cost and verification

Ignoring one attribute reduces noisy plans and needless API writes. The cost is a second control loop and separate monitoring. Ignoring all attributes can make the plan nearly useless for detecting unauthorized updates, while leaving the team responsible for their effects. Measure controller changes, capacity outside declared bounds, and time since the last ownership review. A nightly drift report must compare actual values with the external owner's contract, not rely solely on Terraform's no-op result.

Common Mistakes

  • Do not ignore an entire resource to silence a recurring drift alert.
  • Do not leave an ignored field without a named controller and alert.
  • Do not assume ignore_changes prevents Terraform from using the value on creation.

Connected lessons

Practice and check

devops
operations
Storage details