Files

3.8 KiB

Assignment

During the migration process, several resources were created under the AWS account. Some of these test resources are no longer needed at the moment, so we need to clean them up temporarily. One such instance is currently unused and should be deleted.

  1. Delete the ec2 instance named devops-ec2 present in us-east-1 region using terraform. Make sure to keep the provisioning code, as we might need to provision this instance again later.

  2. Before submitting your task, make sure instance is in terminated state.

The Terraform working directory is /home/bob/terraform.

Note: Right-click under the EXPLORER section in VS Code and select Open in Integrated Terminal to launch the terminal.

Solution

Delete EC2 Instance (Keep Code) — devops-ec2

The requirement has two halves that seem to conflict: terminate the instance, but keep its provisioning code in main.tf for later. The resolution is a targeted destroy — it operates on the real resource and Terraform state only, and never touches your .tf files. So main.tf stays exactly as-is.

main.tf — leave unchanged

Do not delete or comment out the block. It stays exactly as given:

# Provision EC2 instance
resource "aws_instance" "ec2" {
  ami           = "ami-0c101f26f147fa7fd"
  instance_type = "t2.micro"
  vpc_security_group_ids = [
    "sg-6593a59fe82db4400"
  ]

  tags = {
    Name = "devops-ec2"
  }
}

How to run

cd /home/bob/terraform

# Terminate ONLY this instance; leaves the code in main.tf intact.
terraform destroy -target=aws_instance.ec2 -auto-approve

How it works

Targeted destroy vs. the wrong approaches

Three ways you might try to delete the instance, and why only one fits:

Approach Result
Delete the resource block, then apply Instance is destroyed, but the code is gone — violates "keep the provisioning code."
terraform destroy (no target) Destroys everything in the config, not just this instance.
terraform destroy -target=aws_instance.ec2 Destroys only this instance; code stays in main.tf.

The -target flag scopes the operation to a single resource address (aws_instance.ec2). Terraform terminates that instance, removes its entry from state, and leaves every line of your configuration file exactly where it was — because destroy acts on infrastructure and state, never on source code.

Why the code surviving matters

Keeping the block means the instance is trivially re-creatable later: a plain terraform apply will see the resource declared in config but absent from state and recreate it. That's the "we might need to provision this again" requirement — the declaration is preserved as the reusable blueprint.

Reaching terminated state (requirement #2)

terraform destroy -target calls TerminateInstances and waits until the instance reaches terminated before returning. When the command completes, the instance is terminated — no manual polling needed. (A terminated instance lingers as a read-only entry in the console for a while before disappearing; that's normal.)

Expected state afterward

After the targeted destroy, the config declares a resource that no longer exists in state. So terraform plan will show Terraform wants to create devops-ec2 again (+ 1 to add). That's expected and correct — do not apply it. The task wants the instance terminated with the code retained, which is exactly this state.

Verify

aws ec2 describe-instances \
  --filters Name=tag:Name,Values=devops-ec2 \
  --query 'Reservations[*].Instances[*].{Id:InstanceId,State:State.Name}' \
  --output table

Expected — the instance shows State: terminated. Also confirm the code is still present:

grep -A12 'resource "aws_instance" "ec2"' /home/bob/terraform/main.tf