diff --git a/terraform/hcp_iam.tf b/terraform/hcp_iam.tf index 5ca7ae0..e891e94 100644 --- a/terraform/hcp_iam.tf +++ b/terraform/hcp_iam.tf @@ -719,6 +719,12 @@ resource "aws_iam_role" "hcptf_apply" { Owner = "adam@seahavenind.com" ManagedBy = "terraform" } + + # Apply role cannot iam:TagRole on itself. Provider default_tags + # (Environment/Workspace) would otherwise 403 mid-apply. + lifecycle { + ignore_changes = [tags] + } } # Empty exclusive set keeps seahaven-hcptf-iam-management detached. @@ -737,6 +743,11 @@ resource "aws_iam_role" "hcptf_plan" { Owner = "adam@seahavenind.com" ManagedBy = "terraform" } + + # Same self-tag restriction as hcptf_apply. + lifecycle { + ignore_changes = [tags] + } } resource "aws_iam_role_policy_attachment" "hcptf_plan_viewonly" {