Terraform执行中断或失败时如何自动回滚已创建资源?
I'm working with a .tf file that includes logic to create an S3 Bucket, EC2 instance, and security group. Here's my configuration:
provider "aws" { } resource "aws_instance" "example" { ami = "ami-2757f631" instance_type = "t2.micro" } resource "aws_s3_bucket" "b" { bucket = "my-tf-test-bucket" acl = "private" tags = { Name = "My bucket" Environment = "Dev" } } resource "aws_security_group" "allow_rdp" { name = "allow_rdp" description = "Allow rdp traffic" ingress { from_port = 3389 # By default, the windows server listens on TCP port 3389 for RDP to_port = 3389 protocol = "tcp" } }
My questions are:
- If
terraform applygets interrupted after successfully creating the S3 Bucket, how do I roll back all changes from this apply? I manually terminated the execution before, but the already created changes weren't rolled back. - I want to implement automatic rollback of all changes if the Terraform job fails between steps.
Great question—let’s break this down clearly, since this is a common pain point with Terraform’s incremental execution model.
First, let’s address why your manual termination didn’t trigger a rollback: Terraform doesn’t work like a transactional database. Once a resource is successfully provisioned and its state is saved to the terraform.tfstate file, Terraform considers that resource "live" and won’t automatically undo it, even if subsequent steps fail or you kill the process mid-run.
Manual Rollback After Interrupted Apply
If you need to clean up resources created during the failed apply, follow these steps:
- First, confirm which resources were actually created by checking the state file:
This will output all resources that Terraform has tracked as successfully provisioned (in your case, likely just the S3 bucket).terraform state list - To fully roll back by destroying all created resources, run:
Terraform will use the state file to identify and destroy every resource it created during the partial apply, in the correct dependency order.terraform destroy - If you only want to destroy specific resources (instead of all), target them directly:
terraform destroy -target=aws_s3_bucket.b
Automatic Rollback on Failure
Terraform’s open-source core doesn’t have a native auto-rollback feature, but you can set this up with a few practical workarounds:
Wrap Terraform in a shell script
Create a simple script that runsterraform apply, and automatically triggers a destroy if the apply fails. For example:#!/bin/bash terraform apply -auto-approve if [ $? -ne 0 ]; then echo "Apply failed—initiating rollback..." terraform destroy -auto-approve fiThis will clean up all resources created up to the failure point automatically.
Use Terraform Cloud/Enterprise
If you’re using HashiCorp’s managed Terraform service, it has built-in automation features for rollbacks. You can configure run policies that automatically destroy resources if an apply fails, or set up run tasks to enforce rollback logic for your workflows.State file safeguards
Always ensure your state file is backed up (either via remote state storage like S3 with versioning, or Terraform Cloud) before running rollback commands. A corrupted state file can prevent Terraform from correctly identifying which resources to destroy.
内容的提问来源于stack exchange,提问作者Sonu Prajapati

