DevOps Practitioner · Module 4: Infrastructure as Code · Lab
Stop an Unexpected Destroy Plan with Safe Design
50 min hands-on · Advanced
A local machine with OpenTofu or Terraform installed; a fixture stateful resource holding irreplaceable demo content.
Local guide: run the steps below on your own machine in order, then check the validation list.
Objectives
- Stage a renaming edit that plans destruction of stateful data
- Show prevent_destroy failing the plan with a quoted error
- Complete the deliberate migration path with the rule restored
Step 1
Stage the accident
Put prevent_destroy on the stateful fixture resource. Rename it the naive way and run plan. Quote the error that stops the destruction.
Step 2
Migrate deliberately
Walk the reviewed path: lift the rule explicitly, move state to the new address, verify content intact, restore the rule. Record each step with its command.
Step 3
Prove the seatbelt
Show the final clean plan with protection restored, and write one paragraph on what would have happened without the rule on a Friday afternoon.
How to confirm it worked
- Plan error quoting the rule shown before any apply
- Migration steps recorded with content verified intact
- Rule restored with a clean final plan
- Friday-afternoon paragraph present