Fix file-share DLM policy duplicate-tag error (audit C-8)

The SnapshotPolicy schedule set both copyTags:true and tagsToAdd
file-share-backup=true. Since that tag is already on the data volume,
copyTags propagates it to each snapshot and the explicit tagsToAdd of
the same key triggers DLM's duplicate-tag error, leaving the policy in
ERROR state -- nightly snapshots of the 500 GB NAS volume were silently
failing. Dropping the redundant tagsToAdd (copyTags still tags the
snapshots) lets the policy run.

The live policy was already corrected out-of-band to stop the failing
backups; this commit codifies that change so the next clean deploy shows
no drift on the policy.
This commit is contained in:
Adam Moussa 2026-05-29 17:18:15 -04:00
parent d8b32264c4
commit 01438bd1fd

View file

@ -193,8 +193,10 @@ export class FileShareStack extends cdk.Stack {
name: "file-share-nightly",
createRule: { interval: 24, intervalUnit: "HOURS", times: ["06:00"] },
retainRule: { count: 30 },
// copyTags already propagates file-share-backup=true from the volume to each
// snapshot; an explicit tagsToAdd of the same key triggers DLM's duplicate-tag
// error ("Tag file-share-backup is already defined") and puts the policy in ERROR.
copyTags: true,
tagsToAdd: [{ key: "file-share-backup", value: "true" }],
}],
},
});