Hey! I think the best way is to clone the terraform and make edits. Sounds like you could introduce your cert as a data block and reference it in the load balancer. That would give you the ability to remove (read delete) the resources that do the cert provisioning, ie ACM and R53 via DNS validation.