fix(iam): ignore default tags on hcptf roles (PLAT-210) (#196)

* fix(iam): ignore default tags on hcptf roles (PLAT-210)

The apply role cannot iam:TagRole on itself. Provider default_tags from
the env split 403'd the prod apply on hcptf-meal-order-manager and -plan.

* fix(iam): ignore tags_all on hcptf roles (PLAT-210)

ignore_changes on tags does not cover provider default_tags. The prod
speculative plan still wanted Environment on tags_all and would TagRole.
This commit is contained in:
Adam Moussa 2026-09-18 20:53:13 +00:00 • committed by GitHub
parent 44c79fdefd
commit bbbe359858
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -719,6 +719,12 @@ resource "aws_iam_role" "hcptf_apply" {
Owner = "adam@seahavenind.com" Owner = "adam@seahavenind.com"
ManagedBy = "terraform" ManagedBy = "terraform"
} }
# Apply role cannot iam:TagRole on itself. Provider default_tags
# merge into tags_all, so ignoring tags alone still 403s mid-apply.
lifecycle {
ignore_changes = [tags, tags_all]
}
} }
# Empty exclusive set keeps seahaven-hcptf-iam-management detached. # Empty exclusive set keeps seahaven-hcptf-iam-management detached.
@ -737,6 +743,11 @@ resource "aws_iam_role" "hcptf_plan" {
Owner = "adam@seahavenind.com" Owner = "adam@seahavenind.com"
ManagedBy = "terraform" ManagedBy = "terraform"
} }
# Same self-tag restriction as hcptf_apply.
lifecycle {
ignore_changes = [tags, tags_all]
}
} }
resource "aws_iam_role_policy_attachment" "hcptf_plan_viewonly" { resource "aws_iam_role_policy_attachment" "hcptf_plan_viewonly" {