6 ms·
We had the same issue with DynamoDB, that Terraform is all to happy to delete a table it deems acceptable to delete. Which in 99 out of 100 cases is never the
by bwship 5y ago
We had the same issue with DynamoDB, that Terraform is all to happy to delete a table it deems acceptable to delete. Which in 99 out of 100 cases is never the case. It is a very aggressive IaC tool.
- notwedtm 5y agoIt's a very powerful tool. Just like any other (well designed) tool, it's only going to do what the operator tells it to do. Terraform will never delete something you don't tell it to.
- anonydsfsfs 5y ago> Terraform will never delete something you don't tell it to. Not necessarily. With some providers (e.g. Azure), Terraform will fail to recognize automated behind-the-scenes changes and try to revert them, causing serious breakage. This is why the "ignore_changes" meta-argument exists. See https://itnext.io/how-and-when-to-ignore-lifecycle-changes-in-terraform-ed5bfb46e7ae https://itnext.io/how-and-when-to-ignore-lifecycle-changes-i...
- throwaway290232 5y agoAlso why the create_before_destroy argument exists. Often you have to apply one or the other to a resource, or it simply falls into an infinite loop of creating and deleting the same resource.
- throwaway290232 5y agoActually that's impossible to know. Terraform doesn't delete anything at all. It asks provider plugins to remove a logical concept/placeholder, and the provider issues API calls (based on various criteria, some of which is not known until apply time, even with a plan run) and those API servers then do various things in the background based on criteria Terraform doesn't know about. Sometimes you need it to delete something, and it won't. And sometimes something else in the background gets removed by the provider or API service handling the first delete. Terraform is "powerful" in the sense that a 6'11 230lbs 30 year old blind man with an IQ of 85 is "powerful". And it's definitely not well designed, or there wouldn't be multiple large projects dedicated to fixing its many problems and missing features (terragrunt, terraformer, etc)
- andrew_ 5y agoInstances like this is where CDK is superior to Terraform imho. There are many resources which are difficult (or impossible) to delete or modify once created with CDK, and for good reason. Secrets also fall into this category.
- bwship 5y agoWe also ran into issues with the CDK, that it errors out if the resource already exists and was not created with the CDK. We end up using Ansible for the DynamoDB. Though Ansible can't deploy to LocalStack. So, it seems that we are still in a world where you have to use a couple different IaC tools depending on the needs.
- Bellyache5 5y agoWhat's the use-case for creating resources outside of--but also defining them in--CDK in this case? That's generally an anti-pattern.
- andrew_ 5y agoIt's actually not an anti-pattern. CDK provides many methods (e.g. `StringParameter.valueForStringParameter`) for accessing deployed resources from other stacks, or those deployed by other tools or manually. IaC can get in the way or that, but it's not forbidden, nor discouraged.
- marcinzm 5y agoYou could tag everything you care about with lifecycle rules to not delete but it'd be nicer if they were the default for certain resources.