Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Terraform replacement: prove old and new can coexist

Last updated: 5 Oct 20266 min read
tutorial
AdvancedBy AITrove Editorial

Some remote properties cannot change in place. Terraform then plans to replace the object. The create-before-destroy lifecycle rule changes operation order, but it cannot make a unique name reusable while the old object exists or grant extra provider quota. It may also affect dependencies. A replacement review must identify the actual coexistence requirement and the user-facing handover, not stop at the plan symbol indicating a replacement.

Operational decision

A receipt worker pool needs a launch-template change. In an isolated environment, plan the replacement and list every new instance, address, disk, and dependent object that must exist while the old pool serves traffic. Reserve quota for overlap, use distinct names where required, and verify readiness before redirecting work. The fragment is only an operation-order rule; the deployment still needs a data and traffic migration. If the object is a stateful database, decide whether replication, snapshot restore, or a maintenance window is needed before selecting the rule. Simulate failure after creation but before old-resource deletion and record how to identify and retire the stray replacement. Compare the final plan with actual provider inventory after apply. A prevent-destroy guard can block an accidental replacement while present, but removing that resource block removes the guard's protection.

hcl
resource "aws_autoscaling_group" "receipt_workers" {
  name_prefix         = "receipt-workers-"
  max_size            = 6
  min_size            = 3
  desired_capacity    = 3
  vpc_zone_identifier = var.worker_subnet_ids

  lifecycle {
    create_before_destroy = true
  }
}

Cost and verification

Overlap can temporarily double compute, addresses, volume attachments, and load on a shared database. Quota requests and data synchronization may take longer than the apply itself. Destroy-first avoids overlap but can create downtime; create-first reduces that window only when both generations can coexist and cutover is verified. Track peak resource count, ready capacity, old-generation traffic, and orphan count. A low-cost test should deliberately exhaust one quota to prove the rollback path retains the old generation.

Common Mistakes

  • Do not assume create-before-destroy solves a globally unique name conflict.
  • Do not rely on prevent-destroy after removing the resource block.
  • Do not mark the replacement complete before traffic and data have moved.

Connected lessons

Practice and check

Continue with: Infrastructure plans: classify every action before apply.

devops
operations
Storage details