-
Notifications
You must be signed in to change notification settings - Fork 9.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Can't delete IAM role because policies are attached #5417
Comments
I'm pretty sure it's related to aws created policies that have been attached using aws_policy_attachement. All others got deleted from my role without an issue. |
Similar to @jthenne, I have hit this issue when policies are attached with Additionally, if I add a lifecycle block with |
I'm hitting this problem just trying to delete a policy that has been attached using |
TF does not work with AWS IAM correctly. It has not in the past at 3 years. hashicorp/terraform#3749 This is an ongoing issue that has never been addressed/corrected |
…detaching groups, roles, and users (support group, role, and user renames) Reference: #5417 Previously from acceptance testing (before code updates): ``` --- FAIL: TestAccAWSIAMPolicyAttachment_Groups_RenamedGroup (8.82s) testing.go:568: Step 1 error: errors during apply: Error: [WARN] Error updating user, role, or group list from IAM Policy Attachment tf-acc-test-5552018730471644331: – NoSuchEntity: The group with name tf-acc-test-5552018730471644331-1 cannot be found. --- FAIL: TestAccAWSIAMPolicyAttachment_Roles_RenamedRole (10.31s) testing.go:568: Step 1 error: errors during apply: Error: [WARN] Error updating user, role, or group list from IAM Policy Attachment tf-acc-test-4256997168279122998: – NoSuchEntity: The role with name tf-acc-test-4256997168279122998-1 cannot be found. --- FAIL: TestAccAWSIAMPolicyAttachment_Users_RenamedUser (11.64s) testing.go:568: Step 1 error: errors during apply: Error: [WARN] Error updating user, role, or group list from IAM Policy Attachment tf-acc-test-5706224507827321055: – NoSuchEntity: The user with name tf-acc-test-5706224507827321055-1 cannot be found. ``` Output from acceptance testing: ``` --- PASS: TestAccAWSIAMPolicyAttachment_Groups_RenamedGroup (12.29s) --- PASS: TestAccAWSIAMPolicyAttachment_Users_RenamedUser (12.51s) --- PASS: TestAccAWSIAMPolicyAttachment_Roles_RenamedRole (12.92s) --- PASS: TestAccAWSIAMPolicyAttachment_basic (137.55s) --- PASS: TestAccAWSIAMPolicyAttachment_paginatedEntities (216.36s) ```
…rement for modifying name/path with aws_iam_policy_attachment Reference: #5417
…or modifying name/path with aws_iam_policy_attachment Reference: #5417
Hi folks 👋 The Given this behavior, to setup your Terraform configuration properly for this situation where you want to modify the name or path of roles/users, any resource "aws_iam_policy" "example" {
name = "example"
policy = <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Action": "*",
"Effect": "Allow",
"Resource": "*"
}
]
}
EOF
}
resource "aws_iam_user" "example" {
force_destroy = true
name = "example"
}
resource "aws_iam_policy_attachment" "example" {
name = "example"
policy_arn = "${aws_iam_policy.example.arn}"
users = ["${aws_iam_user.example.name}"]
} I have submitted the following pull request, which ensures modifications to group/role/user names or paths (assuming they are properly enabled beforehand with |
The bugfix and documentation updates for this have been merged and will release with version 2.19.0 of the Terraform AWS Provider, likely in the next two days. 👍 |
This has been released in version 2.19.0 of the Terraform AWS provider. Please see the Terraform documentation on provider versioning or reach out if you need any assistance upgrading. For further feature requests or bug reports with this functionality, please create a new GitHub issue following the template for triage. Thanks! |
This doesn't work for me:
I am hitting the error... 2.29 AWS provider version |
I'm going to lock this issue because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues. If you feel this issue should be reopened, we encourage creating a new issue linking back to this one for added context. Thanks! |
This issue was originally opened by @rhettg as hashicorp/terraform#2761. It was migrated here as a result of the provider split. The original body of the issue is below.
I renamed a policy and when attempting to apply it, failure:
I don't think there is anything special about my configuration, but it looks something like:
The error occurred after changing the role name.
The text was updated successfully, but these errors were encountered: