Bird
Raised Fist0
Terraformcloud~5 mins

Terraform destroy for cleanup - Cheat Sheet & Quick Revision

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Recall & Review
beginner
What does the terraform destroy command do?
It removes all the infrastructure resources that were created by Terraform in the current workspace, effectively cleaning up your cloud environment.
Click to reveal answer
beginner
Why should you be careful when running terraform destroy?
Because it permanently deletes all managed resources, which can cause data loss or service downtime if done unintentionally.
Click to reveal answer
intermediate
How can you preview what terraform destroy will delete before actually running it?
By running terraform plan -destroy, which shows a detailed plan of resources that will be destroyed.
Click to reveal answer
intermediate
What is a safe practice to avoid accidental destruction when using terraform destroy?
Use the -auto-approve=false flag to require manual confirmation before destruction happens.
Click to reveal answer
beginner
Can terraform destroy remove resources not managed by Terraform?
No, it only removes resources that are tracked in Terraform's state file. Unmanaged resources remain untouched.
Click to reveal answer
What command shows what will be deleted before running terraform destroy?
Aterraform validate
Bterraform plan -destroy
Cterraform init
Dterraform apply
Which flag helps avoid accidental destruction by requiring confirmation?
A-auto-approve=false
B-auto-approve=true
C-force
D-skip-confirm
What happens if you run terraform destroy in a directory without Terraform state?
AIt does nothing because no resources are tracked
BIt destroys all cloud resources in your account
CIt creates new resources
DIt throws an error and exits
Which of these is NOT a reason to use terraform destroy?
AClean up test environments
BRemove unused resources
CUpdate resource configurations
DSave cloud costs by deleting resources
Does terraform destroy delete resources outside Terraform's control?
AYes, it deletes all resources in the cloud account
BYes, but only if you use a special flag
CNo, it only deletes local files
DNo, only resources tracked in Terraform state are deleted
Explain the purpose and safe usage of terraform destroy.
Think about why and how you would delete cloud resources safely.
You got /5 concepts.
    Describe how Terraform knows which resources to delete when running terraform destroy.
    Consider what Terraform uses to remember your infrastructure.
    You got /4 concepts.

      Practice

      (1/5)
      1. What does the terraform destroy command do?
      easy
      A. It updates existing resources without deleting them.
      B. It deletes all resources created by Terraform in the current workspace.
      C. It creates new resources defined in the configuration.
      D. It shows the current state of resources without making changes.

      Solution

      1. Step 1: Understand the purpose of terraform destroy

        This command is designed to remove all resources that Terraform manages in the current workspace. Unlike terraform apply which creates or updates resources, terraform destroy deletes them. It does not just show state or update resources.
      2. Final Answer:

        It deletes all resources created by Terraform in the current workspace. -> Option B
      3. Quick Check:

        terraform destroy = deletes resources [OK]
      Hint: Destroy means delete all created resources [OK]
      Common Mistakes:
      • Confusing destroy with apply
      • Thinking destroy only shows resources
      • Assuming destroy updates resources
      2. Which of the following is the correct syntax to run terraform destroy without asking for confirmation?
      easy
      A. terraform destroy -force
      B. terraform destroy --yes
      C. terraform destroy --confirm
      D. terraform destroy -auto-approve

      Solution

      1. Step 1: Recall the flag to skip confirmation

        The correct flag to skip the confirmation prompt is -auto-approve. -force, --yes, and --confirm are not valid flags for terraform destroy.
      2. Final Answer:

        terraform destroy -auto-approve -> Option D
      3. Quick Check:

        Skip confirmation = -auto-approve [OK]
      Hint: Use -auto-approve to skip confirmation [OK]
      Common Mistakes:
      • Using -force instead of -auto-approve
      • Typing --yes which is invalid
      • Assuming --confirm works
      3. Given the following Terraform commands run in order:
      terraform apply -auto-approve
      terraform destroy
      What will happen after the second command?
      medium
      A. All resources created by the first command will be deleted after confirmation.
      B. Resources will be updated but not deleted.
      C. Nothing will happen because destroy requires -auto-approve.
      D. Terraform will show an error because destroy must be run before apply.

      Solution

      1. Step 1: Understand the effect of terraform apply -auto-approve

        This command creates or updates resources without asking for confirmation. This command will prompt for confirmation before deleting all resources created by Terraform.
      2. Final Answer:

        All resources created by the first command will be deleted after confirmation. -> Option A
      3. Quick Check:

        Destroy deletes resources after confirmation [OK]
      Hint: Destroy deletes resources after confirmation unless skipped [OK]
      Common Mistakes:
      • Thinking destroy needs -auto-approve to work
      • Believing destroy updates resources
      • Assuming destroy must run before apply
      4. You ran terraform destroy but it failed with an error about a locked state file. What should you do to fix this?
      medium
      A. Run terraform init again to reset the state.
      B. Manually delete the state file from your local machine.
      C. Use terraform force-unlock with the lock ID to unlock the state.
      D. Delete all resources manually in the cloud provider console.

      Solution

      1. Step 1: Understand state locking in Terraform

        Terraform locks the state file during operations to prevent conflicts. If locked, commands like destroy fail. terraform force-unlock with the lock ID safely removes the lock so you can continue.
      2. Final Answer:

        Use terraform force-unlock with the lock ID to unlock the state. -> Option C
      3. Quick Check:

        Unlock state with force-unlock command [OK]
      Hint: Use terraform force-unlock to fix locked state errors [OK]
      Common Mistakes:
      • Deleting state file manually causing data loss
      • Running terraform init which doesn't unlock state
      • Manually deleting cloud resources instead of fixing state
      5. You want to automate cleanup of your test environment using Terraform. Which approach safely destroys all resources without manual confirmation and logs the output to a file?
      hard
      A. Run terraform destroy -auto-approve > destroy.log to skip confirmation and save output.
      B. Run terraform apply -destroy -auto-approve to destroy and log output automatically.
      C. Run terraform destroy --force --log=destroy.log to force destroy and log output.
      D. Run terraform delete -auto-approve > destroy.log to delete resources and log output.

      Solution

      1. Step 1: Identify correct command to destroy without confirmation

        terraform destroy -auto-approve skips confirmation safely. Using shell redirection with > destroy.log saves the command output to a log file.
      2. Final Answer:

        Run terraform destroy -auto-approve > destroy.log to skip confirmation and save output. -> Option A
      3. Quick Check:

        Destroy + auto-approve + output redirection = Run terraform destroy -auto-approve > destroy.log to skip confirmation and save output. [OK]
      Hint: Use -auto-approve and > file to automate and log destroy [OK]
      Common Mistakes:
      • Using invalid flags like --force or --log
      • Confusing apply with destroy for cleanup
      • Using terraform delete which is not a valid command