From 01438bd1fd79a656da6ab207533474ca3da97024 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 29 May 2026 17:18:15 -0400 Subject: [PATCH] Fix file-share DLM policy duplicate-tag error (audit C-8) The SnapshotPolicy schedule set both copyTags:true and tagsToAdd file-share-backup=true. Since that tag is already on the data volume, copyTags propagates it to each snapshot and the explicit tagsToAdd of the same key triggers DLM's duplicate-tag error, leaving the policy in ERROR state -- nightly snapshots of the 500 GB NAS volume were silently failing. Dropping the redundant tagsToAdd (copyTags still tags the snapshots) lets the policy run. The live policy was already corrected out-of-band to stop the failing backups; this commit codifies that change so the next clean deploy shows no drift on the policy. --- lib/file-share-stack.ts | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/lib/file-share-stack.ts b/lib/file-share-stack.ts index 1d955a8..7b85d7c 100644 --- a/lib/file-share-stack.ts +++ b/lib/file-share-stack.ts @@ -193,8 +193,10 @@ export class FileShareStack extends cdk.Stack { name: "file-share-nightly", createRule: { interval: 24, intervalUnit: "HOURS", times: ["06:00"] }, retainRule: { count: 30 }, + // copyTags already propagates file-share-backup=true from the volume to each + // snapshot; an explicit tagsToAdd of the same key triggers DLM's duplicate-tag + // error ("Tag file-share-backup is already defined") and puts the policy in ERROR. copyTags: true, - tagsToAdd: [{ key: "file-share-backup", value: "true" }], }], }, });