Review StackSet stack retention

Decide whether to retain the stack when removing a StackSet instance.

Description

retain_stack controls whether Terraform keeps the stack and its resources when removing a StackSet instance. A retained stack remains but is detached from StackSet management.

Potential impact

Deleting a stack that should be retained can affect services or data. A retained stack instead needs separate management.

Remediation

If the stack must remain, apply retain_stack = true and save it in Terraform state before removing the instance. Define who will manage and eventually clean up the retained stack.

Examples

The examples change only stack retention. Apply the setting first, separately from the change that destroys the resource.

Before

hcl
resource "aws_cloudformation_stack_set_instance" "example" {
  account_id     = "123456789012"
  region         = "us-east-1"
  stack_set_name = aws_cloudformation_stack_set.example.name
  retain_stack   = false
}

After

hcl
resource "aws_cloudformation_stack_set_instance" "example" {
  account_id     = "123456789012"
  region         = "us-east-1"
  stack_set_name = aws_cloudformation_stack_set.example.name
  retain_stack   = true
}

References