Undo the fs abbreviation in civic-tech-jobs - #236
Merged
Merged
Conversation
Contributor
|
Terraform plan in terraform Plan: 10 to add, 1 to change, 10 to destroy.Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
!~ update in-place
-/+ destroy and then create replacement
+/- create replacement and then destroy
Terraform will perform the following actions:
# module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_cloudwatch_log_group.this must be replaced
-/+ resource "aws_cloudwatch_log_group" "this" {
!~ arn = "arn:aws:logs:us-west-2:035866691871:log-group:/ecs/civic-tech-jobs-fs-stage" -> (known after apply)
!~ deletion_protection_enabled = false -> (known after apply)
!~ id = "*****************************" -> (known after apply)
!~ log_group_class = "STANDARD" -> (known after apply)
!~ name = "/ecs/civic-tech-jobs-fs-stage" -> "/ecs/civic-tech-jobs-fullstack-stage" # forces replacement
+ name_prefix = (known after apply)
tags = {
"project" = "civic-tech-jobs"
}
# (5 unchanged attributes hidden)
}
# module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_ecs_service.fargate[0] must be replaced
-/+ resource "aws_ecs_service" "fargate" {
!~ arn = "arn:aws:ecs:us-west-2:035866691871:service/incubator-prod/civic-tech-jobs-fs-stage" -> (known after apply)
!~ availability_zone_rebalancing = "ENABLED" -> (known after apply)
- health_check_grace_period_seconds = 0 -> null
!~ iam_role = "/aws-service-role/ecs.amazonaws.com/AWSServiceRoleForECS" -> (known after apply)
!~ id = "**********************************************************************************" -> (known after apply)
!~ name = "civic-tech-jobs-fs-stage" -> "civic-tech-jobs-fullstack-stage" # forces replacement
+ platform_version = (known after apply)
tags = {
"project" = "civic-tech-jobs"
}
!~ task_definition = "arn:aws:ecs:us-west-2:035866691871:task-definition/civic-tech-jobs-fs-stage:9" -> (known after apply)
!~ triggers = {} -> (known after apply)
# (12 unchanged attributes hidden)
- deployment_circuit_breaker {
- enable = false -> null
- rollback = false -> null
}
!~ deployment_configuration (known after apply)
- deployment_configuration {
- bake_time_in_minutes = "0" -> null
- strategy = "ROLLING" -> null
}
- deployment_controller {
- type = "ECS" -> null
}
- load_balancer {
- container_name = "civic-tech-jobs-fs-stage" -> null
- container_port = 8000 -> null
- target_group_arn = "arn:aws:elasticloadbalancing:us-west-2:035866691871:targetgroup/civic-tech-jobs-fs-stage-145/56a29f2b04cb1961" -> null
# (1 unchanged attribute hidden)
}
+ load_balancer {
+ container_name = "civic-tech-jobs-fullstack-stage"
+ container_port = 8000
+ target_group_arn = (known after apply)
# (1 unchanged attribute hidden)
}
!~ network_configuration {
!~ security_groups = [
- "sg-0d384beaea3ec08be",
] -> (known after apply)
# (2 unchanged attributes hidden)
}
# (2 unchanged blocks hidden)
}
# module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_ecs_task_definition.task must be replaced
-/+ resource "aws_ecs_task_definition" "task" {
!~ arn = "arn:aws:ecs:us-west-2:035866691871:task-definition/civic-tech-jobs-fs-stage:9" -> (known after apply)
!~ arn_without_revision = "arn:aws:ecs:us-west-2:035866691871:task-definition/civic-tech-jobs-fs-stage" -> (known after apply)
!~ container_definitions = (sensitive value) # forces replacement
!~ enable_fault_injection = false -> (known after apply)
!~ family = "civic-tech-jobs-fs-stage" -> "civic-tech-jobs-fullstack-stage" # forces replacement
!~ id = "************************" -> (known after apply)
!~ revision = 9 -> (known after apply)
tags = {
"project" = "civic-tech-jobs"
}
!~ task_role_arn = "arn:aws:iam::035866691871:role/ecs-container-civic-tech-jobs-fs-stage" -> (known after apply) # forces replacement
# (11 unchanged attributes hidden)
}
# module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_iam_policy.container_policy must be replaced
-/+ resource "aws_iam_policy" "container_policy" {
!~ arn = "arn:aws:iam::035866691871:policy/civic-tech-jobs-fs-stage-task-policy" -> (known after apply)
!~ attachment_count = 1 -> (known after apply)
!~ id = "*********************************************************************" -> (known after apply)
!~ name = "civic-tech-jobs-fs-stage-task-policy" -> "civic-tech-jobs-fullstack-stage-task-policy" # forces replacement
+ name_prefix = (known after apply)
!~ policy_id = "*********************" -> (known after apply)
- tags = {} -> null
# (4 unchanged attributes hidden)
}
# module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_iam_role.instance must be replaced
-/+ resource "aws_iam_role" "instance" {
!~ arn = "arn:aws:iam::035866691871:role/ecs-container-civic-tech-jobs-fs-stage" -> (known after apply)
!~ create_date = "2025-03-13T06:34:58Z" -> (known after apply)
!~ id = "**************************************" -> (known after apply)
!~ managed_policy_arns = [
- "arn:aws:iam::035866691871:policy/civic-tech-jobs-fs-stage-task-policy",
] -> (known after apply)
!~ name = "ecs-container-civic-tech-jobs-fs-stage" -> "ecs-container-civic-tech-jobs-fullstack-stage" # forces replacement
+ name_prefix = (known after apply)
tags = {
"tag-key" = "*********"
}
!~ unique_id = "*********************" -> (known after apply)
# (7 unchanged attributes hidden)
!~ inline_policy (known after apply)
}
# module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_iam_role_policy_attachment.task_policy must be replaced
-/+ resource "aws_iam_role_policy_attachment" "task_policy" {
!~ id = "*****************************************************************" -> (known after apply)
!~ policy_arn = "arn:aws:iam::035866691871:policy/civic-tech-jobs-fs-stage-task-policy" -> (known after apply) # forces replacement
!~ role = "ecs-container-civic-tech-jobs-fs-stage" -> "ecs-container-civic-tech-jobs-fullstack-stage" # forces replacement
}
# module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_lb_listener_rule.static will be updated in-place
!~ resource "aws_lb_listener_rule" "static" {
id = "arn:aws:elasticloadbalancing:us-west-2:035866691871:listener-rule/app/incubator-prod-lb/7451adf77133ef36/390a225766a4daf3/8b944647d0d45e1e"
tags = {}
# (5 unchanged attributes hidden)
!~ action {
!~ target_group_arn = "arn:aws:elasticloadbalancing:us-west-2:035866691871:targetgroup/civic-tech-jobs-fs-stage-145/56a29f2b04cb1961" -> (known after apply)
# (2 unchanged attributes hidden)
}
# (2 unchanged blocks hidden)
}
# module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_lb_target_group.this must be replaced
+/- resource "aws_lb_target_group" "this" {
!~ arn = "arn:aws:elasticloadbalancing:us-west-2:035866691871:targetgroup/civic-tech-jobs-fs-stage-145/56a29f2b04cb1961" -> (known after apply)
!~ arn_suffix = "targetgroup/civic-tech-jobs-fs-stage-145/56a29f2b04cb1961" -> (known after apply)
+ connection_termination = (known after apply)
!~ id = "*************************************************************************************************************" -> (known after apply)
!~ ip_address_type = "ipv4" -> (known after apply)
!~ load_balancer_arns = [
- "arn:aws:elasticloadbalancing:us-west-2:035866691871:loadbalancer/app/incubator-prod-lb/7451adf77133ef36",
] -> (known after apply)
!~ load_balancing_algorithm_type = "round_robin" -> (known after apply)
!~ load_balancing_anomaly_mitigation = "off" -> (known after apply)
!~ load_balancing_cross_zone_enabled = "use_load_balancer_configuration" -> (known after apply)
!~ name = "civic-tech-jobs-fs-stage-145" -> "ctj-fs-stage-145" # forces replacement
+ name_prefix = (known after apply)
+ preserve_client_ip = (known after apply)
!~ protocol_version = "HTTP1" -> (known after apply)
- tags = {} -> null
- target_control_port = 0 -> null
# (10 unchanged attributes hidden)
!~ health_check {
!~ timeout = 5 -> (known after apply)
# (8 unchanged attributes hidden)
}
!~ stickiness (known after apply)
- stickiness {
- cookie_duration = 86400 -> null
- enabled = false -> null
- type = "lb_cookie" -> null
# (1 unchanged attribute hidden)
}
!~ target_failover (known after apply)
- target_failover {}
!~ target_group_health (known after apply)
- target_group_health {
- dns_failover {
- minimum_healthy_targets_count = "1" -> null
- minimum_healthy_targets_percentage = "off" -> null
}
- unhealthy_state_routing {
- minimum_healthy_targets_count = 1 -> null
- minimum_healthy_targets_percentage = "off" -> null
}
}
!~ target_health_state {
+ enable_unhealthy_connection_termination = false
+ unhealthy_draining_interval = 0
}
}
# module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_security_group.container must be replaced
+/- resource "aws_security_group" "container" {
!~ arn = "arn:aws:ec2:us-west-2:035866691871:security-group/sg-0d384beaea3ec08be" -> (known after apply)
!~ description = "Container civic-tech-jobs-fs-stage" -> "Container civic-tech-jobs-fullstack-stage" # forces replacement
!~ egress = [
- {
- cidr_blocks = [
- "0.0.0.0/0",
]
- from_port = 0
- ipv6_cidr_blocks = []
- prefix_list_ids = []
- protocol = "-1"
- security_groups = []
- self = false
- to_port = 0
# (1 unchanged attribute hidden)
},
] -> (known after apply)
!~ id = "********************" -> (known after apply)
!~ ingress = [
- {
- cidr_blocks = [
- "10.10.0.0/16",
]
- from_port = 8000
- ipv6_cidr_blocks = []
- prefix_list_ids = []
- protocol = "tcp"
- security_groups = []
- self = false
- to_port = 8000
# (1 unchanged attribute hidden)
},
] -> (known after apply)
!~ name = "ecs-container-civic-tech-jobs-fs-stage" -> "ecs-container-civic-tech-jobs-fullstack-stage" # forces replacement
+ name_prefix = (known after apply)
!~ owner_id = "************" -> (known after apply)
!~ tags = {
!~ "Name" = "ecs-container-civic-tech-jobs-fs-stage" -> "ecs-container-civic-tech-jobs-fullstack-stage"
}
!~ tags_all = {
!~ "Name" = "ecs-container-civic-tech-jobs-fs-stage" -> "ecs-container-civic-tech-jobs-fullstack-stage"
# (1 unchanged element hidden)
}
# (3 unchanged attributes hidden)
}
# module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_vpc_security_group_egress_rule.allow_all_traffic must be replaced
+/- resource "aws_vpc_security_group_egress_rule" "allow_all_traffic" {
!~ arn = "arn:aws:ec2:us-west-2:035866691871:security-group-rule/sgr-00d0ac63ba7740037" -> (known after apply)
!~ id = "*********************" -> (known after apply)
!~ security_group_id = "********************" -> (known after apply) # forces replacement
!~ security_group_rule_id = "*********************" -> (known after apply)
# (4 unchanged attributes hidden)
}
# module.civic-tech-jobs.module.civic_tech_jobs_fullstack_stage_service.aws_vpc_security_group_ingress_rule.container_ingress_port must be replaced
+/- resource "aws_vpc_security_group_ingress_rule" "container_ingress_port" {
!~ arn = "arn:aws:ec2:us-west-2:035866691871:security-group-rule/sgr-0397513833cd8b8af" -> (known after apply)
!~ id = "*********************" -> (known after apply)
!~ security_group_id = "********************" -> (known after apply) # forces replacement
!~ security_group_rule_id = "*********************" -> (known after apply)
# (6 unchanged attributes hidden)
}
Plan: 10 to add, 1 to change, 10 to destroy.✅ Plan applied in Terraform apply (OIDC) #88 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #227.
Spells the civic-tech-jobs stage container's application type out as
fullstackagain, reversing1f13c57. Thefsabbreviation existed only to fit the target group's 32-character limit, which the container module now handles itself (#231), so the service, log group, security group and IAM names can match the ECR repository and Postgres roles.This apply has downtime. An ECS service name forces replacement, so
stage.civictechjobs.orggoes down while the service is destroyed and recreated.What the plan should show, and nothing else:
civic-tech-jobs-fs-stage→civic-tech-jobs-fullstack-stagecivic-tech-jobs-fs-stage-145→ctj-fs-stage-145as+/-(create before destroy) — the full name would be 35 characters, so the ladder drops to rung 2; listener rule 200 updated in placemodule.civic_tech_jobs_stage_database— it already usesfullstack, so its roles, passwords and SSM parameters must not appear. If they do, stop.Also updates the container module's header comment (and README) to say civic-tech-jobs now falls to rung 2 alongside civic-tech-index.
The CivicTechJobs deploy workflow names the old service and is fixed in hackforla/CivicTechJobs#755. That only takes effect when their
developis next released tomain, so their next release needs to be coordinated with this apply, or its redeploy step will target a service that does not exist.