Termination protection is a flag on a stack that makes delete-stack fail and leaves the stack untouched. Set it at creation with create-stack --enable-termination-protection, or later with update-termination-protection; it applies to the root stack and all its nested stacks, and changing it needs the cloudformation:UpdateTerminationProtection permission, which you can keep from most roles:
aws cloudformation update-termination-protection --stack-name booknest-fn \
--enable-termination-protection --output text | cut -d/ -f1-2
aws cloudformation describe-stacks --stack-name booknest-fn \
--query 'Stacks[0].EnableTerminationProtection'
aws cloudformation delete-stack --stack-name booknest-fn
aws cloudformation wait stack-delete-complete --stack-name booknest-fn && echo "stack deleted"arn:aws:cloudformation:us-east-1:000000000000:stack/booknest-fn true stack deleted
On AWS 24 the delete-stack call fails with a ValidationError that names termination protection, and the stack stays as it was until someone with the permission turns the flag off (not run here). LocalStack 4.13.1 63,725 stores and reports the flag, then deletes the stack anyway. Turn it on for every production stack. It does not stop an update from removing resources; stack policies and DeletionPolicy cover that.