From bbbe3598582d49c59fcc403572130cff8aa21451 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Fri, 18 Sep 2026 20:53:13 +0000 Subject: [PATCH] fix(iam): ignore default tags on hcptf roles (PLAT-210) (#196) * fix(iam): ignore default tags on hcptf roles (PLAT-210) The apply role cannot iam:TagRole on itself. Provider default_tags from the env split 403'd the prod apply on hcptf-meal-order-manager and -plan. * fix(iam): ignore tags_all on hcptf roles (PLAT-210) ignore_changes on tags does not cover provider default_tags. The prod speculative plan still wanted Environment on tags_all and would TagRole. --- terraform/hcp_iam.tf | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/terraform/hcp_iam.tf b/terraform/hcp_iam.tf index 5ca7ae0..a5fc6eb 100644 --- a/terraform/hcp_iam.tf +++ b/terraform/hcp_iam.tf @@ -719,6 +719,12 @@ resource "aws_iam_role" "hcptf_apply" { Owner = "adam@seahavenind.com" ManagedBy = "terraform" } + + # Apply role cannot iam:TagRole on itself. Provider default_tags + # merge into tags_all, so ignoring tags alone still 403s mid-apply. + lifecycle { + ignore_changes = [tags, tags_all] + } } # Empty exclusive set keeps seahaven-hcptf-iam-management detached. @@ -737,6 +743,11 @@ resource "aws_iam_role" "hcptf_plan" { Owner = "adam@seahavenind.com" ManagedBy = "terraform" } + + # Same self-tag restriction as hcptf_apply. + lifecycle { + ignore_changes = [tags, tags_all] + } } resource "aws_iam_role_policy_attachment" "hcptf_plan_viewonly" {