diff --git a/terraform/hcp_iam.tf b/terraform/hcp_iam.tf index 5ca7ae0..a5fc6eb 100644 --- a/terraform/hcp_iam.tf +++ b/terraform/hcp_iam.tf @@ -719,6 +719,12 @@ resource "aws_iam_role" "hcptf_apply" { Owner = "adam@seahavenind.com" ManagedBy = "terraform" } + + # Apply role cannot iam:TagRole on itself. Provider default_tags + # merge into tags_all, so ignoring tags alone still 403s mid-apply. + lifecycle { + ignore_changes = [tags, tags_all] + } } # Empty exclusive set keeps seahaven-hcptf-iam-management detached. @@ -737,6 +743,11 @@ resource "aws_iam_role" "hcptf_plan" { Owner = "adam@seahavenind.com" ManagedBy = "terraform" } + + # Same self-tag restriction as hcptf_apply. + lifecycle { + ignore_changes = [tags, tags_all] + } } resource "aws_iam_role_policy_attachment" "hcptf_plan_viewonly" {