Skip to content

ADR-0012: Remove the teardown gate

  • Status: accepted (supersedes the gate part of ADR-0008)
  • Date: 2026-09-30
  • Deciders: maintainer

Context

ADR-0008 put runbook step 5 (teardown) behind --i-understand-teardown-is-unverified until a real AWS end-to-end run settled PLAN §6. The run on 2026-09-30 passed. Retain suppresses custom-resource Delete handlers, policy-only change sets are applied, nested patches cause no Dynamic entries, and a real Copilot app was torn down with no data or traffic loss (report).

Decision

  • Step 5 is always emitted.
  • The flag is still accepted as a hidden no-op, so existing scripts keep working.
  • The runbook's banner now states what the AWS run verified, and lists what it did not cover: custom domains and ACM certificates, Aurora addons, private placement with NAT, and partial migrations. For those, the banner advises running on a non-production copy first.

Consequences

The machine checks remain the safety mechanism: verify-retain before every delete, and the change-set, plan and state gates. The banner should be revisited when those features are covered by a real run.