Skip to content

Commit ad8e58a

Browse files
obezpalkoclaude
andcommitted
feat!: remove module provider "aws" block — caller owns credentials (v5.0.1)
BREAKING (operational, not API): the module no longer declares its own provider "aws". As a child module, a self-declared provider block takes precedence for the modules resources and IGNORES the callers provider, stripping the wrapper control over credentials (assume_role / profile / region) and default_tags — the deprecated pattern, and the root cause of the STSaaS-account 403 workaround in atlantis.yaml (the module credential-less provider ran as ambient atlantis-sa instead of the assumed STSaaS role). The module keeps its provider *requirement* (versions.tf required_providers). Now every module.comet resource inherits the CALLERs provider. Wrapper migration required when bumping to v5.0.1: * ensure the wrapper provider "aws" carries region + assume_role/profile (stsaasuat already does, via var.provider_assume_role_arn) * move default_tags (Terraform / Environment / common_tags) onto the wrapper provider — the module no longer sets them * the atlantis.yaml assume-role-and-export-creds shell hack for the stsaas workflow can then be replaced with a normal provider-level assume_role No aliased/region-specific providers exist in the module (checked: no configuration_aliases, no provider = aws.*), so single-provider inheritance is safe. terraform init + validate pass. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1 parent a906fb3 commit ad8e58a

1 file changed

Lines changed: 14 additions & 13 deletions

File tree

‎providers.tf‎

Lines changed: 14 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,14 @@
1-
provider "aws" {
2-
region = var.region
3-
4-
default_tags {
5-
tags = merge(
6-
{
7-
Terraform = "true"
8-
},
9-
var.environment_tag != "" ? { Environment = var.environment_tag } : {},
10-
var.common_tags
11-
)
12-
}
13-
}
1+
# No provider "aws" configuration block here — on purpose.
2+
#
3+
# This module is consumed as a child module (module "comet" { source = "...?ref=" }),
4+
# so it must NOT declare its own provider config. A child module's provider block
5+
# takes precedence for the module's resources and IGNORES the caller's provider,
6+
# which strips the wrapper's control over credentials (assume_role / profile /
7+
# region) and default_tags. That is the deprecated pattern.
8+
#
9+
# The module only declares its provider *requirement* (versions.tf →
10+
# required_providers). Credential + region + default_tags configuration is owned
11+
# by the CALLER's `provider "aws"` block, which the module inherits.
12+
#
13+
# Wrappers: put region, the assume_role/profile, and default_tags on YOUR
14+
# provider "aws" — everything in this module runs through it.

0 commit comments

Comments
 (0)