Lab / lab

Stable Terraform resource names across regeneration

The problem that nearly killed ARCH: regenerating a design must not produce a destroy-and-recreate diff.

01Hypothesis

Deriving Terraform resource addresses from an immutable node identifier, rather than from the human-visible label, keeps a regenerated configuration plan-clean when a node is renamed.

02Method

Generated a three-tier topology, applied it against a scratch AWS account, renamed nodes on the canvas, regenerated and ran plan. Repeated with resource names derived from the label, then from an immutable identifier assigned at node creation.

03Findings

Label-derived naming produced exactly the disaster expected: renaming a subnet node changed the resource address, so plan proposed destroying and recreating the subnet and everything depending on it.

Identifier-derived naming produced a plan containing only tag changes, which is the correct outcome. The human label travels as a Name tag, where changing it is free.

The cost is that generated addresses are less readable. Mitigated by emitting the label as a comment above each resource block, which costs nothing and makes the output reviewable.

04Record