Repository navigation
Commit ad8e58a
feat!: remove module provider "aws" block — caller owns credentials (v5.0.1)
BREAKING (operational, not API): the module no longer declares its own
provider "aws". As a child module, a self-declared provider block takes
precedence for the modules resources and IGNORES the callers provider,
stripping the wrapper control over credentials (assume_role / profile /
region) and default_tags — the deprecated pattern, and the root cause of the
STSaaS-account 403 workaround in atlantis.yaml (the module credential-less
provider ran as ambient atlantis-sa instead of the assumed STSaaS role).
The module keeps its provider *requirement* (versions.tf required_providers).
Now every module.comet resource inherits the CALLERs provider.
Wrapper migration required when bumping to v5.0.1:
* ensure the wrapper provider "aws" carries region + assume_role/profile
(stsaasuat already does, via var.provider_assume_role_arn)
* move default_tags (Terraform / Environment / common_tags) onto the wrapper
provider — the module no longer sets them
* the atlantis.yaml assume-role-and-export-creds shell hack for the stsaas
workflow can then be replaced with a normal provider-level assume_role
No aliased/region-specific providers exist in the module (checked: no
configuration_aliases, no provider = aws.*), so single-provider inheritance is
safe. terraform init + validate pass.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>1 parent a906fb3 commit ad8e58a
1 file changed
Lines changed: 14 additions & 13 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
2 | | - | |
3 | | - | |
4 | | - | |
5 | | - | |
6 | | - | |
7 | | - | |
8 | | - | |
9 | | - | |
10 | | - | |
11 | | - | |
12 | | - | |
13 | | - | |
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
0 commit comments