Bird
Raised Fist0
Terraformcloud~10 mins

Terraform destroy for cleanup - Step-by-Step Execution

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Process Flow - Terraform destroy for cleanup
Start: Terraform destroy command
↓
Load current state file
↓
Plan resource destruction
↓
Show resources to be destroyed
↓
User confirms destruction
Yes↓
Destroy resources in cloud
↓
Update state file to remove destroyed resources
↓
End
Terraform destroy loads the current state, plans resource removal, asks for confirmation, then deletes resources and updates the state.
Execution Sample
Terraform
terraform destroy
# Confirm with 'yes' when prompted
# Resources get deleted
# State file updates
This command deletes all resources tracked by Terraform and cleans up the state.
Process Table
StepActionEvaluationResult
1Run 'terraform destroy'Command startsTerraform loads state file
2Plan destructionIdentify all resourcesList resources to delete
3Prompt userWait for confirmationUser inputs 'yes'
4Destroy resourcesSend delete requestsResources deleted in cloud
5Update stateRemove destroyed resourcesState file updated
6FinishAll resources removedCleanup complete
💡 All resources destroyed and state file cleaned up, process ends.
Status Tracker
VariableStartAfter Step 2After Step 4Final
state_fileContains all resourcesMarked for deletionEmpty or updatedCleaned state
Key Moments - 3 Insights
Why does Terraform ask for confirmation before destroying?
Terraform shows planned deletions (see step 3 in execution_table) to prevent accidental loss of resources.
What happens if you say 'no' at the confirmation prompt?
Terraform stops the destroy process at step 3, so no resources are deleted and state remains unchanged.
Does Terraform delete resources immediately after running the command?
No, it first plans and waits for confirmation (steps 2 and 3), then deletes resources (step 4).
Visual Quiz - 3 Questions
Test your understanding
Look at the execution_table, what happens at step 4?
ATerraform updates the state file
BTerraform sends delete requests to cloud resources
CTerraform waits for user confirmation
DTerraform loads the state file
💡 Hint
Check the 'Action' and 'Result' columns at step 4 in execution_table.
At which step does Terraform ask for user confirmation?
AStep 5
BStep 2
CStep 3
DStep 1
💡 Hint
Look for 'Prompt user' action in execution_table.
If the user inputs 'no' at confirmation, what changes in variable_tracker?
Astate_file remains unchanged
Bstate_file is updated to remove resources
Cstate_file is deleted
Dstate_file is corrupted
💡 Hint
Refer to key_moments about confirmation and step 3 in execution_table.
Concept Snapshot
terraform destroy
- Loads current state
- Plans resource deletion
- Asks for user confirmation
- Deletes resources if confirmed
- Updates state file
Use to clean up all managed infrastructure safely.
Full Transcript
Terraform destroy is a command to remove all resources managed by Terraform. When you run it, Terraform first loads the current state file to know what resources exist. Then it plans which resources will be deleted and shows this list to you. It asks for your confirmation before proceeding. If you type 'yes', Terraform sends delete requests to the cloud provider to remove the resources. After deletion, it updates the state file to reflect that these resources no longer exist. If you say 'no', Terraform stops and does not delete anything. This process helps you clean up your infrastructure safely and avoid accidental deletions.

Practice

(1/5)
1. What does the terraform destroy command do?
easy
A. It updates existing resources without deleting them.
B. It deletes all resources created by Terraform in the current workspace.
C. It creates new resources defined in the configuration.
D. It shows the current state of resources without making changes.

Solution

  1. Step 1: Understand the purpose of terraform destroy

    This command is designed to remove all resources that Terraform manages in the current workspace. Unlike terraform apply which creates or updates resources, terraform destroy deletes them. It does not just show state or update resources.
  2. Final Answer:

    It deletes all resources created by Terraform in the current workspace. -> Option B
  3. Quick Check:

    terraform destroy = deletes resources [OK]
Hint: Destroy means delete all created resources [OK]
Common Mistakes:
  • Confusing destroy with apply
  • Thinking destroy only shows resources
  • Assuming destroy updates resources
2. Which of the following is the correct syntax to run terraform destroy without asking for confirmation?
easy
A. terraform destroy -force
B. terraform destroy --yes
C. terraform destroy --confirm
D. terraform destroy -auto-approve

Solution

  1. Step 1: Recall the flag to skip confirmation

    The correct flag to skip the confirmation prompt is -auto-approve. -force, --yes, and --confirm are not valid flags for terraform destroy.
  2. Final Answer:

    terraform destroy -auto-approve -> Option D
  3. Quick Check:

    Skip confirmation = -auto-approve [OK]
Hint: Use -auto-approve to skip confirmation [OK]
Common Mistakes:
  • Using -force instead of -auto-approve
  • Typing --yes which is invalid
  • Assuming --confirm works
3. Given the following Terraform commands run in order:
terraform apply -auto-approve
terraform destroy
What will happen after the second command?
medium
A. All resources created by the first command will be deleted after confirmation.
B. Resources will be updated but not deleted.
C. Nothing will happen because destroy requires -auto-approve.
D. Terraform will show an error because destroy must be run before apply.

Solution

  1. Step 1: Understand the effect of terraform apply -auto-approve

    This command creates or updates resources without asking for confirmation. This command will prompt for confirmation before deleting all resources created by Terraform.
  2. Final Answer:

    All resources created by the first command will be deleted after confirmation. -> Option A
  3. Quick Check:

    Destroy deletes resources after confirmation [OK]
Hint: Destroy deletes resources after confirmation unless skipped [OK]
Common Mistakes:
  • Thinking destroy needs -auto-approve to work
  • Believing destroy updates resources
  • Assuming destroy must run before apply
4. You ran terraform destroy but it failed with an error about a locked state file. What should you do to fix this?
medium
A. Run terraform init again to reset the state.
B. Manually delete the state file from your local machine.
C. Use terraform force-unlock with the lock ID to unlock the state.
D. Delete all resources manually in the cloud provider console.

Solution

  1. Step 1: Understand state locking in Terraform

    Terraform locks the state file during operations to prevent conflicts. If locked, commands like destroy fail. terraform force-unlock with the lock ID safely removes the lock so you can continue.
  2. Final Answer:

    Use terraform force-unlock with the lock ID to unlock the state. -> Option C
  3. Quick Check:

    Unlock state with force-unlock command [OK]
Hint: Use terraform force-unlock to fix locked state errors [OK]
Common Mistakes:
  • Deleting state file manually causing data loss
  • Running terraform init which doesn't unlock state
  • Manually deleting cloud resources instead of fixing state
5. You want to automate cleanup of your test environment using Terraform. Which approach safely destroys all resources without manual confirmation and logs the output to a file?
hard
A. Run terraform destroy -auto-approve > destroy.log to skip confirmation and save output.
B. Run terraform apply -destroy -auto-approve to destroy and log output automatically.
C. Run terraform destroy --force --log=destroy.log to force destroy and log output.
D. Run terraform delete -auto-approve > destroy.log to delete resources and log output.

Solution

  1. Step 1: Identify correct command to destroy without confirmation

    terraform destroy -auto-approve skips confirmation safely. Using shell redirection with > destroy.log saves the command output to a log file.
  2. Final Answer:

    Run terraform destroy -auto-approve > destroy.log to skip confirmation and save output. -> Option A
  3. Quick Check:

    Destroy + auto-approve + output redirection = Run terraform destroy -auto-approve > destroy.log to skip confirmation and save output. [OK]
Hint: Use -auto-approve and > file to automate and log destroy [OK]
Common Mistakes:
  • Using invalid flags like --force or --log
  • Confusing apply with destroy for cleanup
  • Using terraform delete which is not a valid command