Terraform: Remove a Resource Without Destroying It

You want Terraform to stop managing something — a database another team adopted, a resource you now manage by hand — without terraform destroy touching it.

What you'll see

Root causes

Resource moved out of Terraform management scope

Removing the block from config tells Terraform it should delete the real object. That is the default — and the trap.

Fix it

  1. Remove the resource from state, keeping the real object
    terraform state rm aws_instance.legacy_app
  2. Then delete the block from your config and run plan
    terraform plan   # should no longer mention the resource
  3. For moved/renamed blocks, use mv instead of remove+import
    terraform state mv 'aws_instance.app' 'module.app.aws_instance.app'
  4. To adopt an existing resource later, import it
    terraform import aws_instance.legacy_app i-0abc123

Field note

state rm is a state operation only — the provider never gets called, so nothing in the cloud changes. That is exactly why it is the right tool and exactly why you should back up state first.

Common questions

How do I remove one resource from state without deleting it?

terraform state rm <resource.address> removes it from management only — the real infrastructure keeps running, now unmanaged. Next plans won't touch it.

How do I stop Terraform from recreating a resource I edited manually?

Import the drift: terraform import, or in newer versions update the state to match reality. Alternatively `lifecycle { ignore_changes = [...] }` for fields that legitimately change outside Terraform's control.

Ship it right the first time

An opinionated VPC module: per-AZ NAT, explicit dependencies, EKS-ready outputs.

Terraform AWS Foundation — $37 →

One-time. Yours to modify. Instant download from the NinjaOps template store.