You want Terraform to stop managing something — a database another team adopted, a resource you now manage by hand — without terraform destroy touching it.
Removing the block from config tells Terraform it should delete the real object. That is the default — and the trap.
terraform state rm aws_instance.legacy_app
terraform plan # should no longer mention the resource
terraform state mv 'aws_instance.app' 'module.app.aws_instance.app'
terraform import aws_instance.legacy_app i-0abc123
state rm is a state operation only — the provider never gets called, so nothing in the cloud changes. That is exactly why it is the right tool and exactly why you should back up state first.
terraform state rm <resource.address> removes it from management only — the real infrastructure keeps running, now unmanaged. Next plans won't touch it.
Import the drift: terraform import, or in newer versions update the state to match reality. Alternatively `lifecycle { ignore_changes = [...] }` for fields that legitimately change outside Terraform's control.
An opinionated VPC module: per-AZ NAT, explicit dependencies, EKS-ready outputs.
Terraform AWS Foundation — $37 →One-time. Yours to modify. Instant download from the NinjaOps template store.