modernisation-platform icon indicating copy to clipboard operation
modernisation-platform copied to clipboard

Fix issue with baselines module throwing an error if default VPC resources don't exist

Open jakemulley opened this issue 4 years ago • 7 comments

The ministryofjustice/modernisation-platform-terraform-baselines module attempts to tag default VPC resources when it is run.

If an account no longer has default VPC resources, it throws an error:

Error: InvalidGroup.NotFound: The security group 'sg-123' does not exist
	status code: 400, request id: 123

In the future, we'd like to delete these during the account bootstrap step so users don't get confused with our core network strategy and the VPCs configured as part of that; though Terraform doesn't currently support the full lifecycle of these resources, so for now, we should check if a default resource exists, and then tag it, or ignore it if not.

jakemulley avatar Feb 09 '21 13:02 jakemulley

It is not possible to (easily) check if a default VPC exists. We have this issue with the analytical platform account as they have deleted their default VPC, so we are skipping the baseline for this account for now. Once the aws provider supports deleting default vpcs we will delete for all accounts and remove from the baselines.

davidkelliott avatar Jun 24 '21 10:06 davidkelliott

Support for full lifecycle management in terraform of default vpcs is coming in Version 4.0 of the AWS Provider

davidkelliott avatar Jan 13 '22 16:01 davidkelliott

https://registry.terraform.io/providers/hashicorp/aws/latest/docs/guides/version-4-upgrade#full-resource-lifecycle-of-default-resources

dms1981 avatar May 17 '22 10:05 dms1981

All of our customers are now using AWS Provider V4 so this can be progressed

dms1981 avatar May 23 '22 08:05 dms1981

Removed this one from the sprint as @davidkelliott is working on this as time allows, and as it is not tied to any specific sprint goal.

dms1981 avatar Jul 01 '22 08:07 dms1981

The delete code has been created, still need to deal with regions and how to not manage in terraform once deleted

davidkelliott avatar Jul 28 '22 15:07 davidkelliott

This issue is stale because it has been open 90 days with no activity.

github-actions[bot] avatar Mar 16 '23 01:03 github-actions[bot]

Currently not an issue - as we have implemented a workaround

SimonPPledger avatar Oct 31 '23 10:10 SimonPPledger