Use this guide when you want to stop monitoring OCI with New Relic. It walks you through removing the resources the integration created in your OCI tenancy, then disconnecting your account from New Relic.
Delete your OCI resources before you unlink the account in New Relic. Unlinking deletes the record that stores your compartment and stack OCIDs, and you need those to find the resources.
How you remove the metrics resources depends on how you created them. Select the option that matches your setup:
If you set the integration up through the Oracle Resource Manager stack, Terraform created every resource and tracks it in the stack's state. Destroying the stacks removes everything in the correct dependency order.
In the OCI Console, go to Developer Services > Resource Manager > Stacks.
Select your region, then open the New Relic metrics stack.
Select Destroy and wait for the job to reach Succeeded.
Select Delete stack.
Repeat steps 2–4 for the logging stack in that region.
Repeat steps 1–5 for every region you instrumented.
Switch to your home region and destroy the policy stack and the WIF setup stack the same way.
Tip
If every stack destroyed successfully, you're done — skip to Verify nothing is left. Use Option 3 only if a stack is missing, has drifted, or its destroy job failed.
Use this if you applied New Relic's Terraform configuration yourself rather than through Resource Manager.
You need the original working directory and its state — the local terraform.tfstate file, or access to the remote backend you configured it with. Terraform can only destroy what its state describes.
Change into the configuration you applied, initialize it, and select the workspace if you used one:
bash
$
cd<path-to-your-newrelic-oci-configuration>
$
terraform init
$
terraform workspace select<workspace>
Confirm the state still describes your resources:
bash
$
terraform state list
If this returns nothing, or far fewer resources than you expect, the state is gone or incomplete. Use Option 3 instead — destroying from a partial state leaves resources behind and still costs you money.
Destroy each configuration, supplying the same variable values you applied with:
Review the plan before confirming. Different variable values can point the run at the wrong region or fail to resolve resources, leaving them orphaned.
Work in reverse dependency order. For each region you instrumented, destroy the logging configuration first, then metrics. Only once every region is clear, destroy the policy configuration and then the workload identity federation configuration, both in your home region.
Important
Don't use terraform destroy -target to pick off individual resources. It skips the dependency graph, and on this configuration that strands the VCN gateways and the connector hubs — the two things that keep costing you money.
Tip
If every destroy completed cleanly, skip to Verify nothing is left. If any run errored partway, re-run it once — OCI occasionally rejects a delete while a dependent resource is still terminating — then fall back to Option 3 for whatever remains.
Use these steps if any of the following apply:
You set the integration up by hand rather than through Resource Manager or Terraform.
The Resource Manager stack record no longer exists, or its destroy job failed.
Your Terraform state file is missing, incomplete, or has drifted from what is actually deployed.
A destroy run from either option left resources behind.
Work through the steps in order — later steps depend on earlier ones.
All resources live in the New Relic compartment. It's named newrelic_compartment_ORM_DO_NOT_REMOVE_<id> when Resource Manager or Terraform created it, and newrelic_compartment_DO_NOT_REMOVE if you created it by hand. Match on the prefix rather than the full name — see Resource name reference.
Delete the Service Connector Hubs
This is the step that stops data flowing and stops the recurring cost. Do it first.
In the OCI Console, go to Analytics & AI > Messaging > Connectors.
Set the compartment to the New Relic compartment.
Delete every connector whose target is a New Relic function — there is one for metrics and, if you enabled logs, one for logging.
Repeat for every region you instrumented.
Delete the functions and function applications
Go to Developer Services > Functions > Applications.
Open newrelic-<prefix>-<region>-metrics-function-app and delete the function newrelic-<prefix>-<region>-metrics-function, then delete the application.
If you enabled logs, delete the logging function and its application the same way.
Repeat for every instrumented region.
Delete the VCN, subnet, and gateways
Go to Networking > Virtual cloud networks.
Open newrelic-<prefix>-<region>-metrics-vcn.
Delete the NAT gateway, service gateway, and the internet gateway named NRMetricsInternetGateway.
Delete the private subnet newrelic-<prefix>-<region>-metrics-vcn-private-subnet.
Delete the VCN.
Repeat for the logging VCN and for every instrumented region.
Delete the vault, key, and secrets
Go to Identity & Security > Vault in your home region.
Open newrelic_vault_ORM_DO_NOT_REMOVE_<id>.
Schedule deletion for both secrets: newrelic_ingest_api_key_ORM_DO_NOT_REMOVE_<id> and newrelic_user_api_key_ORM_DO_NOT_REMOVE_<id>.
Schedule deletion for the key newrelic_key_ORM_DO_NOT_REMOVE_<id>.
Schedule deletion for the vault.
Important
OCI schedules vault, key, and secret deletion rather than deleting immediately. The minimum waiting period is 7 days.
Delete the dynamic group and policies
Go to Identity & Security > Domains > Dynamic groups.
Go to Identity & Security > Policies and delete these three, if present:
newrelic_metrics_policy_ORM_DO_NOT_REMOVE_<id>
newrelic_logs_policy_ORM_DO_NOT_REMOVE_<id>
newrelic_common_policy_ORM_DO_NOT_REMOVE_<id>
Delete the workload identity federation resources
You created these when you set up authentication. Deleting them permanently revokes New Relic's ability to authenticate to your tenancy.
Go to Identity & Security > Domains and open the identity domain you used.
Under Integrated applications, deactivate then delete:
newrelic-ida-app-orm
newrelic-token-exchange-app-orm
Under Users, delete newrelic-wif-svc-user-orm.
Under Groups, delete newrelic-svc-user-group-orm.
Under Settings > Identity propagation trust, delete the New Relic trust configurations.
Go to Identity & Security > Policies and delete newrelic-svc-user-policy-orm.
Delete the New Relic compartment
A compartment must be empty before you can delete it, so do this last.
Go to Identity & Security > Compartments.
Open the New Relic compartment and confirm it contains no resources.
Select Delete.
Uninstall logs resources
How you remove the logs resources depends on how you created them. Select the option that matches your setup:
If you onboarded using the guided setup wizard and an OCI Resource Manager stack:
In the OCI Console, go to Developer Services > Resource Manager > Stacks.
Select the compartment where you deployed the logging integration stack (for example, newrelic-compartment). If you don't recall the compartment, check the original deployment job's logs — Resource Manager > Jobs > (your deployment job) > Logs — which record the compartment used.
Select the stack named oci-log-integration (or your custom stack name).
Select Terraform Actions, then select Destroy.
Confirm the destroy job. Resource Manager automatically deletes the Service Connector Hub instances (including audit connectors), the OCI forwarder function and its application, the log groups and Object Storage buckets the stack created, and the associated IAM policies and dynamic groups.
Once the destroy job completes successfully, select Edit Stack, then Delete Stack, to remove the stack definition.
Use this if you deployed the integration with your own Terraform or OpenTofu modules rather than through Resource Manager.
From your OCI Terraform workspace, run a plan check to review what it will remove:
bash
$
terraform plan -destroy
Change into the folder containing the Terraform configuration for this integration, then destroy it:
bash
$
terraform destroy -auto-approve
Confirm OCI destroyed every provisioned resource: oci_service_connector_hub, oci_functions_function, oci_identity_policy, and oci_identity_dynamic_group.
If you used the newrelic Terraform provider to link the account, remove the newrelic_cloud_oci_integrations resource block from your configuration and reapply — otherwise, follow Unlink the account in New Relic.
Use these steps if you created the logging resources by hand, following the step-by-step setup guide. Work through them in order to avoid dependency locks.
Delete the service connectors. Select the compartment you used when you manually created the integration (for example, newrelic-compartment), go to Analytics & AI > Messaging > Service Connector Hub, and delete every connector that streams to the New Relic function — for example, newrelic-logs-* and newrelic-logs-*-audit.
Delete the OCI function and application. With the same compartment selected, go to Developer Services > Functions, delete the function oci-log-forwarder, then delete its parent function application.
Delete the secret, and the vault if it's dedicated. Go to Identity & Security > Vault and schedule deletion for the New Relic ingest key secret stored there. If you created a vault specifically for this integration, delete the vault too — if you reused an existing vault, delete only the secret.
Delete the IAM policies and dynamic group. Go to Identity & Security > Identities > Policies and delete the integration policy that grants the dynamic group access (typically created under the root compartment), then go to Identity & Security > Dynamic Groups and delete the forwarder dynamic group.
To confirm a clean teardown, check both platforms:
No inbound log volume — in New Relic, open Logs and query oracle.tenantid = '<YOUR_TENANCY_OCID>'. Confirm no new log events arrive after your teardown timestamp.
Zero function invocations — in the OCI Console, under Metrics, confirm FunctionInvocationCount for the log forwarder function drops to 0.
No orphaned IAM resources — confirm no dynamic groups or policies referencing newrelic remain under Identity & Security.
Troubleshoot deprovisioning issues
If teardown doesn't go cleanly, match what you're seeing to one of these causes:
OCI Resource Manager returns a 409 conflict or active-lock error
Destroying the stack fails with HTTP 409 Conflict: Resource is being used by another process. This usually means an active Service Connector Hub batch or function execution is holding a lock on the underlying compartment or subnet resources. In Analytics & AI > Messaging > Service Connector Hub, select the connector and select Deactivate, wait 2–3 minutes for active function invocations to drain, then re-run the ORM Destroy action.
IAM policy deletion fails with AuthorizationFailed or a scope lock
The stack destroy fails when deleting oci_identity_policy or oci_identity_dynamic_group. This usually means the user or service principal running the destroy job lacks tenancy-level policy management rights — for example, policies deployed at the tenancy root require manage policies in tenancy. Confirm the user performing the teardown belongs to the Administrators group, or has these tenancy-root rights directly:
Allow group <Admin_Group> to manage policies in tenancy
Allow group <Admin_Group> to manage dynamic-groups in tenancy
If that doesn't resolve it, delete the policy statement manually in the OCI Console under Identity & Security > Identities > Policies, then re-run the destroy operation to clear the state.
You delete a stack, but New Relic still shows partial log volume or historical metric cards
This usually means a secondary connector — an audit connector or a manual log connector created outside the ORM stack — is still active. Run an OCI Search query across the tenancy to find active connectors:
query serviceconnector resources
Delete any connector whose target is Functions pointing to oci-log-forwarder.
A vault secret shows "Pending Deletion" instead of OCI removing it immediately
This is expected OCI behavior, not an error. OCI Vault secrets enforce a mandatory minimum 7-day retention period before hard deletion, to prevent accidental key destruction — but OCI disables the secret payload for reads as soon as you schedule deletion, so the log forwarder can't use it during the retention window either.
Verify nothing is left
Resources created by Resource Manager or Terraform carry a freeform tag. In the OCI Console, go to Governance & Administration > Search and run each of these structured queries:
query all resources where(freeformTags.key='newrelic-orm-terraform'&& freeformTags.value='true')
query all resources where(freeformTags.key='newrelic-terraform'&& freeformTags.value='true')
Two different tag keys are in use: the metrics and policy stacks tag newrelic-orm-terraform, and the logging stack tags newrelic-terraform. Run both, in every region you instrumented.
Important
An empty result doesn't mean your tenancy is clean. These queries won't find:
The workload identity federation resources from Step 6, which neither setup method tags.
Anything you created by hand, which carries no Terraform tag at all.
Go to one.newrelic.com > All capabilities > Infrastructure > Oracle Cloud Infrastructure.
Select your linked account.
Select Unlink this account, then confirm.
This disables all OCI monitoring for that account and affects any dashboards, alerts, and tags that depended on it. You can't undo this.
Resource name reference
<id> is a short random suffix generated at deploy time, so match on the prefix rather than the full name. <prefix> defaults to newrelic.
Stack
Scope
Tag key
Resources
Policy
Tenancy
newrelic-orm-terraform
Compartment, KMS vault, KMS key, ingest secret, user secret, dynamic group, and the metrics, logs, and common policies — all named newrelic_*_ORM_DO_NOT_REMOVE_<id>
Metrics
Per region
newrelic-orm-terraform
Service Connector Hub, newrelic-<prefix>-<region>-metrics-function-app, newrelic-<prefix>-<region>-metrics-function, newrelic-<prefix>-<region>-metrics-vcn plus its NAT gateway, service gateway, NRMetricsInternetGateway, and private subnet
Logs
Per region
newrelic-terraform
Service Connector Hub, logging function application, logging function, log group, log, VCN, and gateways
Identity federation
Tenancy
none
newrelic-ida-app-orm, newrelic-token-exchange-app-orm, newrelic-wif-svc-user-orm, newrelic-svc-user-group-orm, newrelic-svc-user-policy-orm, and the identity propagation trust configurations