AWS ALB deletion protection disabled

Enable deletion protection for AWS ALBs.

Description

Deletion protection prevents a load balancer from being removed accidentally or by faulty automation. Enable enable_deletion_protection for production ALBs.

Potential impact

Deleting an ALB that serves as the entry point to a production service can interrupt the entire service. Recreating it and restoring its connections also takes time.

Remediation

Set enable_deletion_protection = true. If you use a module, check its deletion-protection input. Disable protection for a planned deletion through an approved change process.

Examples

The examples enable deletion protection on the same ALB.

Before

hcl
resource "aws_lb" "app_lb" {
  name                       = "test-lb-tf"
  load_balancer_type         = "application"
  subnets                    = aws_subnet.public.*.id
  enable_deletion_protection = false
}

After

hcl
resource "aws_lb" "app_lb" {
  name                       = "test-lb-tf"
  load_balancer_type         = "application"
  subnets                    = aws_subnet.public.*.id
  enable_deletion_protection = true
}

References