⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Senior DevOps / SRE Terraform IaC Drift & State Consistency Enterprise Azure

Q: "terraform plan" suddenly shows 6 production resources will be destroyed, although no Terraform code was changed. What would you check first?

Triage runbook when terraform plan unexpectedly proposes destroying production resources (subnets, databases, VMs) without code changes, handling provider upgrades, remote changes, and lockfile validation.

#Terraform #Azure #State Drift #IaC #Disaster Prevention
🎙️ Candidate Opening & Architectural Context
"When terraform plan proposes destroying production resources without code edits, NEVER apply. The cause is either an unpinned provider update with breaking attribute schema changes, out-of-band manual edits in the Azure Portal, or state backend corruption."
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1

Examine the Exact Forces Replacement Trigger

Inspect the plan output line by line looking for `# forces replacement`. Terraform explicitly denotes which attribute change forces resource recreation (~ versus -/+).

terraform plan -out=tfplan
terraform show -no-color tfplan | grep -B 2 -A 5 "forces replacement"
2

Check .terraform.lock.hcl & Provider Version Drift

Verify if the azurerm provider version upgraded unexpectedly. Often a new provider version introduces default attribute values or renames fields that cause existing resources to be recreated.

3

Audit Azure Activity Logs for Manual Portal Modifications

Check Azure Activity Log on the 6 target resources. If an engineer manually modified a subnet CIDR, SKU, or tag via Azure Portal, Terraform detects drift and attempts to restore the declared state by recreating the resource.

Pro Tip: Use lifecycle { prevent_destroy = true } on all mission-critical production resources to prevent accidental destruction.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Search the plan output for '# forces replacement' to identify the exact trigger. Check provider version drift in .terraform.lock.hcl and Azure Activity Log for manual changes."
⚡ 60-Second Elevator Pitch Talking Points
  • Check the plan output for # forces replacement to identify the exact attribute causing destruction.
  • Verify provider version pinning in .terraform.lock.hcl against unexpected azurerm provider upgrades.
  • Inspect Azure Activity Log to see if someone made manual changes in the Azure Portal that caused drift.
  • Protect production resources using lifecycle { prevent_destroy = true } blocks.
Advertisement
Want more Terraform scenarios?
Explore our complete collection of scenario-based Terraform interview runbooks.
Browse All Terraform Questions →

📚 Related Production Scenarios in Terraform