Description
Deletion protection prevents a load balancer from being removed accidentally or by faulty automation. Enable enable_deletion_protection for production ALBs.
Potential impact
Deleting an ALB that serves as the entry point to a production service can interrupt the entire service. Recreating it and restoring its connections also takes time.
Remediation
Set enable_deletion_protection = true. If you use a module, check its deletion-protection input. Disable protection for a planned deletion through an approved change process.
Examples
The examples enable deletion protection on the same ALB.
Before
hcl
resource "aws_lb" "app_lb" {
name = "test-lb-tf"
load_balancer_type = "application"
subnets = aws_subnet.public.*.id
enable_deletion_protection = false
}
After
hcl
resource "aws_lb" "app_lb" {
name = "test-lb-tf"
load_balancer_type = "application"
subnets = aws_subnet.public.*.id
enable_deletion_protection = true
}