From 10c86f2de6a49c8503e893406af54421dced447e Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Mon, 10 Aug 2026 17:48:05 -0400 Subject: [PATCH] fix(apigateway): drop orphaned authorizer invoke role from state (#137) Apply destroyed the inline policy then failed deleting the role on iam:ListInstanceProfilesForRole; the role was removed out of band. --- terraform/apigateway.tf | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/terraform/apigateway.tf b/terraform/apigateway.tf index c58ade3..c182974 100644 --- a/terraform/apigateway.tf +++ b/terraform/apigateway.tf @@ -123,3 +123,13 @@ resource "aws_lambda_permission" "admin_authorizer" { principal = "apigateway.amazonaws.com" source_arn = "${aws_apigatewayv2_api.order_api.execution_arn}/authorizers/${aws_apigatewayv2_authorizer.admin_google.id}" } + +# PLAT-102 follow-up: role already deleted in AWS after apply failed on +# iam:ListInstanceProfilesForRole. Drop from state without a destroy call. +removed { + from = aws_iam_role.admin_authorizer_invoke + + lifecycle { + destroy = false + } +}