Bird
Raised Fist0
Terraformcloud~5 mins

Terraform destroy for cleanup - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
Sometimes after creating cloud resources with Terraform, you want to remove them to avoid extra costs or keep your environment clean. Terraform destroy helps you safely delete all resources it created.
When you finish testing infrastructure and want to remove all created resources.
When you want to reset your environment to start fresh without leftover resources.
When you want to avoid paying for cloud resources you no longer need.
When you want to clean up resources after a demo or workshop.
When you want to delete a temporary environment created for a short project.
Config File - main.tf
main.tf
terraform {
  required_providers {
    aws = {
      source  = "hashicorp/aws"
      version = "~> 4.0"
    }
  }
  required_version = ">= 1.0"
}

provider "aws" {
  region = "us-east-1"
}

resource "aws_s3_bucket" "example_bucket" {
  bucket = "example-terraform-destroy-bucket-12345"
  acl    = "private"
}

This file tells Terraform to use the AWS provider in the us-east-1 region. It creates one S3 bucket named "example-terraform-destroy-bucket-12345". This simple resource is what we will create and later destroy.

Commands
This command sets up Terraform in the current folder by downloading the AWS provider plugin. It prepares Terraform to work with the configuration.
Terminal
terraform init
Expected OutputExpected
Initializing the backend... Initializing provider plugins... - Finding hashicorp/aws versions matching "~> 4.0"... - Installing hashicorp/aws v4.0.0... - Installed hashicorp/aws v4.0.0 (signed by HashiCorp) Terraform has been successfully initialized! You may now begin working with Terraform. Try running "terraform plan" to see any changes that are required for your infrastructure.
This command creates the resources defined in the configuration file. The -auto-approve flag skips the confirmation prompt to apply changes immediately.
Terminal
terraform apply -auto-approve
Expected OutputExpected
aws_s3_bucket.example_bucket: Creating... aws_s3_bucket.example_bucket: Creation complete after 2s [id=example-terraform-destroy-bucket-12345] Apply complete! Resources: 1 added, 0 changed, 0 destroyed.
→
-auto-approve - Automatically approve the apply without asking for confirmation
This command deletes all resources created by Terraform in this folder. The -auto-approve flag skips the confirmation prompt to destroy immediately.
Terminal
terraform destroy -auto-approve
Expected OutputExpected
aws_s3_bucket.example_bucket: Destroying... [id=example-terraform-destroy-bucket-12345] aws_s3_bucket.example_bucket: Destruction complete after 1s Destroy complete! Resources: 1 destroyed.
→
-auto-approve - Automatically approve the destroy without asking for confirmation
This command lists all resources Terraform currently manages. After destroy, it should show no resources.
Terminal
terraform state list
Expected OutputExpected
No output (command runs silently)
Key Concept

If you remember nothing else from this pattern, remember: terraform destroy safely removes all resources Terraform created to clean up your environment.

Common Mistakes
Running terraform destroy without confirming the prompt and without -auto-approve flag.
It pauses and waits for manual confirmation, which can confuse beginners expecting immediate action.
Use -auto-approve flag to skip confirmation if you want to automate or speed up the process.
Running terraform destroy in the wrong folder or workspace.
It may destroy resources you did not intend to delete, causing data loss or downtime.
Always check your current directory and workspace with terraform workspace show before destroying.
Not running terraform init before terraform destroy in a new or cleaned folder.
Terraform will not have the provider plugins and will fail to run commands.
Run terraform init first to prepare the working directory.
Summary
terraform init prepares Terraform to work with your cloud provider.
terraform apply creates the resources defined in your configuration.
terraform destroy deletes all resources Terraform manages to clean up.
Use -auto-approve to skip confirmation prompts for apply and destroy.
Check your Terraform state to confirm resources are created or removed.

Practice

(1/5)
1. What does the terraform destroy command do?
easy
A. It updates existing resources without deleting them.
B. It deletes all resources created by Terraform in the current workspace.
C. It creates new resources defined in the configuration.
D. It shows the current state of resources without making changes.

Solution

  1. Step 1: Understand the purpose of terraform destroy

    This command is designed to remove all resources that Terraform manages in the current workspace. Unlike terraform apply which creates or updates resources, terraform destroy deletes them. It does not just show state or update resources.
  2. Final Answer:

    It deletes all resources created by Terraform in the current workspace. -> Option B
  3. Quick Check:

    terraform destroy = deletes resources [OK]
Hint: Destroy means delete all created resources [OK]
Common Mistakes:
  • Confusing destroy with apply
  • Thinking destroy only shows resources
  • Assuming destroy updates resources
2. Which of the following is the correct syntax to run terraform destroy without asking for confirmation?
easy
A. terraform destroy -force
B. terraform destroy --yes
C. terraform destroy --confirm
D. terraform destroy -auto-approve

Solution

  1. Step 1: Recall the flag to skip confirmation

    The correct flag to skip the confirmation prompt is -auto-approve. -force, --yes, and --confirm are not valid flags for terraform destroy.
  2. Final Answer:

    terraform destroy -auto-approve -> Option D
  3. Quick Check:

    Skip confirmation = -auto-approve [OK]
Hint: Use -auto-approve to skip confirmation [OK]
Common Mistakes:
  • Using -force instead of -auto-approve
  • Typing --yes which is invalid
  • Assuming --confirm works
3. Given the following Terraform commands run in order:
terraform apply -auto-approve
terraform destroy
What will happen after the second command?
medium
A. All resources created by the first command will be deleted after confirmation.
B. Resources will be updated but not deleted.
C. Nothing will happen because destroy requires -auto-approve.
D. Terraform will show an error because destroy must be run before apply.

Solution

  1. Step 1: Understand the effect of terraform apply -auto-approve

    This command creates or updates resources without asking for confirmation. This command will prompt for confirmation before deleting all resources created by Terraform.
  2. Final Answer:

    All resources created by the first command will be deleted after confirmation. -> Option A
  3. Quick Check:

    Destroy deletes resources after confirmation [OK]
Hint: Destroy deletes resources after confirmation unless skipped [OK]
Common Mistakes:
  • Thinking destroy needs -auto-approve to work
  • Believing destroy updates resources
  • Assuming destroy must run before apply
4. You ran terraform destroy but it failed with an error about a locked state file. What should you do to fix this?
medium
A. Run terraform init again to reset the state.
B. Manually delete the state file from your local machine.
C. Use terraform force-unlock with the lock ID to unlock the state.
D. Delete all resources manually in the cloud provider console.

Solution

  1. Step 1: Understand state locking in Terraform

    Terraform locks the state file during operations to prevent conflicts. If locked, commands like destroy fail. terraform force-unlock with the lock ID safely removes the lock so you can continue.
  2. Final Answer:

    Use terraform force-unlock with the lock ID to unlock the state. -> Option C
  3. Quick Check:

    Unlock state with force-unlock command [OK]
Hint: Use terraform force-unlock to fix locked state errors [OK]
Common Mistakes:
  • Deleting state file manually causing data loss
  • Running terraform init which doesn't unlock state
  • Manually deleting cloud resources instead of fixing state
5. You want to automate cleanup of your test environment using Terraform. Which approach safely destroys all resources without manual confirmation and logs the output to a file?
hard
A. Run terraform destroy -auto-approve > destroy.log to skip confirmation and save output.
B. Run terraform apply -destroy -auto-approve to destroy and log output automatically.
C. Run terraform destroy --force --log=destroy.log to force destroy and log output.
D. Run terraform delete -auto-approve > destroy.log to delete resources and log output.

Solution

  1. Step 1: Identify correct command to destroy without confirmation

    terraform destroy -auto-approve skips confirmation safely. Using shell redirection with > destroy.log saves the command output to a log file.
  2. Final Answer:

    Run terraform destroy -auto-approve > destroy.log to skip confirmation and save output. -> Option A
  3. Quick Check:

    Destroy + auto-approve + output redirection = Run terraform destroy -auto-approve > destroy.log to skip confirmation and save output. [OK]
Hint: Use -auto-approve and > file to automate and log destroy [OK]
Common Mistakes:
  • Using invalid flags like --force or --log
  • Confusing apply with destroy for cleanup
  • Using terraform delete which is not a valid command