---
title: Uninstall the OCI integration
source: https://docs.newrelic.com/docs/infrastructure/oci/uninstall
---

Use this guide when you want to stop monitoring OCI with New Relic. It walks you through removing the resources the integration created in your OCI tenancy, then disconnecting your account from New Relic.

Delete your OCI resources before you unlink the account in New Relic. Unlinking deletes the record that stores your compartment and stack OCIDs, and you need those to find the resources.

Work through [Uninstall metrics resources](#metrics) and [Uninstall logs resources](#logs) for whichever data types you instrumented.

## Uninstall metrics resources [#metrics]

How you remove the metrics resources depends on how you created them. Select the option that matches your setup:

**Option 1: Delete with Oracle Resource Manager (ORM)**

If you set the integration up through the Oracle Resource Manager stack, Terraform created every resource and tracks it in the stack's state. Destroying the stacks removes everything in the correct dependency order.

1.  In the OCI Console, go to **Developer Services > Resource Manager > Stacks**.
2.  Select your region, then open the New Relic metrics stack.
3.  Select **Destroy** and wait for the job to reach **Succeeded**.
4.  Select **Delete stack**.
5.  Repeat steps 2–4 for the logging stack in that region.
6.  Repeat steps 1–5 for every region you instrumented.
7.  Switch to your home region and destroy the policy stack and the WIF setup stack the same way.

    > #### 💡 TIP
    >
    > If every stack destroyed successfully, you're done — skip to [Verify nothing is left](#verify-nothing-is-left). Use Option 3 only if a stack is missing, has drifted, or its destroy job failed.

**Option 2: Destroy with Terraform**

Use this if you applied New Relic's Terraform configuration yourself rather than through Resource Manager.

You need the original working directory and its state — the local `terraform.tfstate` file, or access to the remote backend you configured it with. Terraform can only destroy what its state describes.

1.  Change into the configuration you applied, initialize it, and select the workspace if you used one:

    ```shell
    cd <path-to-your-newrelic-oci-configuration>
    terraform init
    terraform workspace select <workspace>
    ```

2.  Confirm the state still describes your resources:

    ```shell
    terraform state list
    ```

    If this returns nothing, or far fewer resources than you expect, the state is gone or incomplete. Use Option 3 instead — destroying from a partial state leaves resources behind and still costs you money.

3.  Destroy each configuration, supplying the same variable values you applied with:

    ```shell
    terraform destroy -var-file=<your-vars-file>.tfvars
    ```

    Review the plan before confirming. Different variable values can point the run at the wrong region or fail to resolve resources, leaving them orphaned.

4.  Work in reverse dependency order. For each region you instrumented, destroy the logging configuration first, then metrics. Only once every region is clear, destroy the policy configuration and then the workload identity federation configuration, both in your home region.

    > #### ⚠️ IMPORTANT
    >
    > Don't use `terraform destroy -target` to pick off individual resources. It skips the dependency graph, and on this configuration that strands the VCN gateways and the connector hubs — the two things that keep costing you money.

    > #### 💡 TIP
    >
    > If every destroy completed cleanly, skip to [Verify nothing is left](#verify-nothing-is-left). If any run errored partway, re-run it once — OCI occasionally rejects a delete while a dependent resource is still terminating — then fall back to Option 3 for whatever remains.

**Option 3: Delete manually in the OCI Console**

Use these steps if any of the following apply:

-   You set the integration up by hand rather than through Resource Manager or Terraform.
-   The Resource Manager stack record no longer exists, or its destroy job failed.
-   Your Terraform state file is missing, incomplete, or has drifted from what is actually deployed.
-   A destroy run from either option left resources behind.

    Work through the steps in order — later steps depend on earlier ones.

    All resources live in the New Relic compartment. It's named `newrelic_compartment_ORM_DO_NOT_REMOVE_<id>` when Resource Manager or Terraform created it, and `newrelic_compartment_DO_NOT_REMOVE` if you created it by hand. Match on the prefix rather than the full name — see [Resource name reference](#resource-name-reference).

    #### Delete the Service Connector Hubs [#connector-hubs]

    This is the step that stops data flowing and stops the recurring cost. Do it first.

    1.  In the OCI Console, go to **Analytics & AI > Messaging > Connectors**.
    2.  Set the compartment to the New Relic compartment.
    3.  Delete every connector whose target is a New Relic function — there is one for metrics and, if you enabled logs, one for logging.
    4.  Repeat for every region you instrumented.

    #### Delete the functions and function applications [#functions]

    1.  Go to **Developer Services > Functions > Applications**.
    2.  Open `newrelic-<prefix>-<region>-metrics-function-app` and delete the function `newrelic-<prefix>-<region>-metrics-function`, then delete the application.
    3.  If you enabled logs, delete the logging function and its application the same way.
    4.  Repeat for every instrumented region.

    #### Delete the VCN, subnet, and gateways [#vcn]

    1.  Go to **Networking > Virtual cloud networks**.
    2.  Open `newrelic-<prefix>-<region>-metrics-vcn`.
    3.  Delete the NAT gateway, service gateway, and the internet gateway named `NRMetricsInternetGateway`.
    4.  Delete the private subnet `newrelic-<prefix>-<region>-metrics-vcn-private-subnet`.
    5.  Delete the VCN.
    6.  Repeat for the logging VCN and for every instrumented region.

    #### Delete the vault, key, and secrets [#vault]

    1.  Go to **Identity & Security > Vault** in your home region.
    2.  Open `newrelic_vault_ORM_DO_NOT_REMOVE_<id>`.
    3.  Schedule deletion for both secrets: `newrelic_ingest_api_key_ORM_DO_NOT_REMOVE_<id>` and `newrelic_user_api_key_ORM_DO_NOT_REMOVE_<id>`.
    4.  Schedule deletion for the key `newrelic_key_ORM_DO_NOT_REMOVE_<id>`.
    5.  Schedule deletion for the vault.

        > #### ⚠️ IMPORTANT
        >
        > OCI schedules vault, key, and secret deletion rather than deleting immediately. The minimum waiting period is 7 days.

    #### Delete the dynamic group and policies [#iam]

    1.  Go to **Identity & Security > Domains > Dynamic groups**.
    2.  Delete `newrelic_dynamic_group_ORM_DO_NOT_REMOVE_<id>`.
    3.  Go to **Identity & Security > Policies** and delete these three, if present:
        -   `newrelic_metrics_policy_ORM_DO_NOT_REMOVE_<id>`
        -   `newrelic_logs_policy_ORM_DO_NOT_REMOVE_<id>`
        -   `newrelic_common_policy_ORM_DO_NOT_REMOVE_<id>`

    #### Delete the workload identity federation resources [#step-6-delete-the-workload-identity-federation-resources]

    You created these when you set up authentication. Deleting them permanently revokes New Relic's ability to authenticate to your tenancy.

    1.  Go to **Identity & Security > Domains** and open the identity domain you used.
    2.  Under **Integrated applications**, deactivate then delete:
        -   `newrelic-ida-app-orm`
        -   `newrelic-token-exchange-app-orm`
    3.  Under **Users**, delete `newrelic-wif-svc-user-orm`.
    4.  Under **Groups**, delete `newrelic-svc-user-group-orm`.
    5.  Under **Settings > Identity propagation trust**, delete the New Relic trust configurations.
    6.  Go to **Identity & Security > Policies** and delete `newrelic-svc-user-policy-orm`.

    #### Delete the New Relic compartment [#compartment]

    A compartment must be empty before you can delete it, so do this last.

    1.  Go to **Identity & Security > Compartments**.
    2.  Open the New Relic compartment and confirm it contains no resources.
    3.  Select **Delete**.

## Uninstall logs resources [#logs]

How you remove the logs resources depends on how you created them. Select the option that matches your setup:

**Option 1: Delete with Oracle Resource Manager (ORM)**

If you onboarded using the guided setup wizard and an OCI Resource Manager stack:

1.  In the OCI Console, go to **Developer Services > Resource Manager > Stacks**.
2.  Select the compartment where you deployed the logging integration stack (for example, `newrelic-compartment`). If you don't recall the compartment, check the original deployment job's logs — **Resource Manager > Jobs > (your deployment job) > Logs** — which record the compartment used.
3.  Select the stack named `oci-log-integration` (or your custom stack name).
4.  Select **Terraform Actions**, then select **Destroy**.
5.  Confirm the destroy job. Resource Manager automatically deletes the Service Connector Hub instances (including audit connectors), the OCI forwarder function and its application, the log groups and Object Storage buckets the stack created, and the associated IAM policies and dynamic groups.
6.  Once the destroy job completes successfully, select **Edit Stack**, then **Delete Stack**, to remove the stack definition.

    > #### 💡 TIP
    >
    > Then follow [Verify the logs teardown](#logs-verify) and [Unlink the account in New Relic](#unlink). If the destroy job fails or the stack is missing, see [Troubleshoot deprovisioning issues](#logs-troubleshooting) or fall back to Option 3.

**Option 2: Destroy with Terraform or OpenTofu**

Use this if you deployed the integration with your own Terraform or OpenTofu modules rather than through Resource Manager.

1.  From your OCI Terraform workspace, run a plan check to review what it will remove:

    ```shell
    terraform plan -destroy
    ```

2.  Change into the folder containing the Terraform configuration for this integration, then destroy it:

    ```shell
    terraform destroy -auto-approve
    ```

3.  Confirm OCI destroyed every provisioned resource: `oci_service_connector_hub`, `oci_functions_function`, `oci_identity_policy`, and `oci_identity_dynamic_group`.

4.  If you used the `newrelic` Terraform provider to link the account, remove the `newrelic_cloud_oci_integrations` resource block from your configuration and reapply — otherwise, follow [Unlink the account in New Relic](#unlink).

    > #### 💡 TIP
    >
    > Then follow [Verify the logs teardown](#logs-verify). If a destroy run errors partway or leaves resources behind, see [Troubleshoot deprovisioning issues](#logs-troubleshooting) or fall back to Option 3.

**Option 3: Delete manually in the OCI Console**

Use these steps if you created the logging resources by hand, following the step-by-step setup guide. Work through them in order to avoid dependency locks.

1.  **Delete the service connectors.** Select the compartment you used when you manually created the integration (for example, `newrelic-compartment`), go to **Analytics & AI > Messaging > Service Connector Hub**, and delete every connector that streams to the New Relic function — for example, `newrelic-logs-*` and `newrelic-logs-*-audit`.
2.  **Delete the OCI function and application.** With the same compartment selected, go to **Developer Services > Functions**, delete the function `oci-log-forwarder`, then delete its parent function application.
3.  **Delete the secret, and the vault if it's dedicated.** Go to **Identity & Security > Vault** and schedule deletion for the New Relic ingest key secret stored there. If you created a vault specifically for this integration, delete the vault too — if you reused an existing vault, delete only the secret.
4.  **Delete the IAM policies and dynamic group.** Go to **Identity & Security > Identities > Policies** and delete the integration policy that grants the dynamic group access (typically created under the root compartment), then go to **Identity & Security > Dynamic Groups** and delete the forwarder dynamic group.

    > #### 💡 TIP
    >
    > Then follow [Verify the logs teardown](#logs-verify) and [Unlink the account in New Relic](#unlink).

### Verify the logs teardown [#logs-verify]

To confirm a clean teardown, check both platforms:

-   **No inbound log volume** — in New Relic, open **Logs** and query `oracle.tenantid = '<YOUR_TENANCY_OCID>'`. Confirm no new log events arrive after your teardown timestamp.
-   **Zero function invocations** — in the OCI Console, under **Metrics**, confirm `FunctionInvocationCount` for the log forwarder function drops to 0.
-   **No orphaned IAM resources** — confirm no dynamic groups or policies referencing `newrelic` remain under **Identity & Security**.

### Troubleshoot deprovisioning issues [#logs-troubleshooting]

If teardown doesn't go cleanly, match what you're seeing to one of these causes:

**OCI Resource Manager returns a 409 conflict or active-lock error**

Destroying the stack fails with `HTTP 409 Conflict: Resource is being used by another process`. This usually means an active Service Connector Hub batch or function execution is holding a lock on the underlying compartment or subnet resources. In **Analytics & AI > Messaging > Service Connector Hub**, select the connector and select **Deactivate**, wait 2–3 minutes for active function invocations to drain, then re-run the ORM **Destroy** action.

**IAM policy deletion fails with `AuthorizationFailed` or a scope lock**

The stack destroy fails when deleting `oci_identity_policy` or `oci_identity_dynamic_group`. This usually means the user or service principal running the destroy job lacks tenancy-level policy management rights — for example, policies deployed at the tenancy root require `manage policies in tenancy`. Confirm the user performing the teardown belongs to the `Administrators` group, or has these tenancy-root rights directly:

```
Allow group <Admin_Group> to manage policies in tenancy
Allow group <Admin_Group> to manage dynamic-groups in tenancy
```

If that doesn't resolve it, delete the policy statement manually in the OCI Console under **Identity & Security > Identities > Policies**, then re-run the destroy operation to clear the state.

**You delete a stack, but New Relic still shows partial log volume or historical metric cards**

This usually means a secondary connector — an audit connector or a manual log connector created outside the ORM stack — is still active. Run an OCI Search query across the tenancy to find active connectors:

```sql
query serviceconnector resources
```

Delete any connector whose target is **Functions** pointing to `oci-log-forwarder`.

**A vault secret shows "Pending Deletion" instead of OCI removing it immediately**

This is expected OCI behavior, not an error. OCI Vault secrets enforce a mandatory minimum 7-day retention period before hard deletion, to prevent accidental key destruction — but OCI disables the secret payload for reads as soon as you schedule deletion, so the log forwarder can't use it during the retention window either.

## Verify nothing is left [#verify-nothing-is-left]

Resources created by Resource Manager or Terraform carry a freeform tag. In the OCI Console, go to **Governance & Administration > Search** and run each of these structured queries:

```sql
query all resources where (freeformTags.key = 'newrelic-orm-terraform' && freeformTags.value = 'true')
```

```sql
query all resources where (freeformTags.key = 'newrelic-terraform' && freeformTags.value = 'true')
```

Two different tag keys are in use: the metrics and policy stacks tag `newrelic-orm-terraform`, and the logging stack tags `newrelic-terraform`. Run both, in every region you instrumented.

> #### ⚠️ IMPORTANT
>
> An empty result doesn't mean your tenancy is clean. These queries won't find:
>
> -   The workload identity federation resources from [Step 6](#step-6-delete-the-workload-identity-federation-resources), which neither setup method tags.
> -   Anything you created by hand, which carries no Terraform tag at all.
>
>     Verify those by name instead, using [Resource name reference](#resource-name-reference).

## Unlink the account in New Relic [#unlink]

Once your OCI resources are gone:

1.  Go to **[one.newrelic.com](https://one.newrelic.com) > All capabilities > Infrastructure > Oracle Cloud Infrastructure**.
2.  Select your linked account.
3.  Select **Unlink this account**, then confirm.

This disables all OCI monitoring for that account and affects any dashboards, alerts, and tags that depended on it. You can't undo this.

## Resource name reference [#resource-name-reference]

`<id>` is a short random suffix generated at deploy time, so match on the prefix rather than the full name. `<prefix>` defaults to `newrelic`.

| Stack               | Scope      | Tag key                  | Resources                                                                                                                                                                                                                                               |
| ------------------- | ---------- | ------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Policy              | Tenancy    | `newrelic-orm-terraform` | Compartment, KMS vault, KMS key, ingest secret, user secret, dynamic group, and the metrics, logs, and common policies — all named `newrelic_*_ORM_DO_NOT_REMOVE_<id>`                                                                                  |
| Metrics             | Per region | `newrelic-orm-terraform` | Service Connector Hub, `newrelic-<prefix>-<region>-metrics-function-app`, `newrelic-<prefix>-<region>-metrics-function`, `newrelic-<prefix>-<region>-metrics-vcn` plus its NAT gateway, service gateway, `NRMetricsInternetGateway`, and private subnet |
| Logs                | Per region | `newrelic-terraform`     | Service Connector Hub, logging function application, logging function, log group, log, VCN, and gateways                                                                                                                                                |
| Identity federation | Tenancy    | none                     | `newrelic-ida-app-orm`, `newrelic-token-exchange-app-orm`, `newrelic-wif-svc-user-orm`, `newrelic-svc-user-group-orm`, `newrelic-svc-user-policy-orm`, and the identity propagation trust configurations                                                |

## Related articles [#related-articles]

-   [Introduction to the OCI integration](https://docs.newrelic.com/docs/infrastructure/oci/introduction): What the OCI integration does, its capabilities, and how to connect your account.
-   [Troubleshooting](https://docs.newrelic.com/docs/infrastructure/oci/troubleshoot): Fixes for not seeing data and for trust-configuration conflicts during setup.
