-
Notifications
You must be signed in to change notification settings - Fork 9.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Bug]: SecretsManager secret version does not gracefully remove deleted versions from state #36607
Comments
Community NoteVoting for Prioritization
Volunteering to Work on This Issue
|
I can confirm this error, I struggled to understand the pattern leading to this. It happens across multiple environments on a secret where I perform secret rotation every 4 hours. It did not happen on other secrets which I don't rotate. Hence I believe that the explanation makes sense. |
Warning This issue has been closed, meaning that any additional comments are hard for our team to see. Please assume that the maintainers will not see them. Ongoing conversations amongst community members are welcome, however, the issue will be locked after 30 days. Moving conversations to another venue, such as the AWS Provider forum, is recommended. If you have additional concerns, please open a new issue, referencing this one where needed. |
This functionality has been released in v5.43.0 of the Terraform AWS Provider. Please see the Terraform documentation on provider versioning or reach out if you need any assistance upgrading. For further feature requests or bug reports with this functionality, please create a new GitHub issue following the template. Thank you! |
I'm going to lock this issue because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues. |
Terraform Core Version
1.8.0-rc1
AWS Provider Version
5.42.0
Affected Resource(s)
aws_secretsmanager_secret_version
Expected Behavior
When a secret version is deleted by the automated AWS cleanup process, the provider should remove the resource from state
Actual Behavior
The provider throws an error:
Relevant Error/Panic Output Snippet
No response
Terraform Configuration Files
Steps to Reproduce
terraform plan
.Debug Output
No response
Panic Output
No response
Important Factoids
The AWS provider includes logic like the following to catch deleted secrets and remove them from state gracefully. However, there is no handling for deleted secret versions.
terraform-provider-aws/internal/service/secretsmanager/secret_version.go
Line 328 in 3532b9f
Updating this check to a shorter portion of the error message should allow for detection of both secrets and secret versions deleted out of band.
References
Would you like to implement a fix?
None
The text was updated successfully, but these errors were encountered: