Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 4 additions & 3 deletions modules/comet_eks/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,14 +2,15 @@

| Name | Version |
|------|---------|
| <a name="requirement_aws"></a> [aws](#requirement\_aws) | >= 5.0 |
| <a name="requirement_kubernetes"></a> [kubernetes](#requirement\_kubernetes) | >= 2.10 |
| <a name="requirement_aws"></a> [aws](#requirement\_aws) | >= 6.52 |
| <a name="requirement_time"></a> [time](#requirement\_time) | >= 0.9 |

## Providers

| Name | Version |
|------|---------|
| <a name="provider_aws"></a> [aws](#provider\_aws) | >= 5.0 |
| <a name="provider_aws"></a> [aws](#provider\_aws) | >= 6.52 |
| <a name="provider_time"></a> [time](#provider\_time) | >= 0.9 |

## Modules

Expand Down
20 changes: 20 additions & 0 deletions modules/comet_eks/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -1068,6 +1068,26 @@ module "cloudwatch_exporter_irsa_role" {

data "aws_caller_identity" "current" {}

# Region consistency guard.
#
# This module no longer declares its own provider "aws" (the caller owns it), so
# the provider's region comes from the wrapper. Several resources below still key
# off var.region as a string — the Karpenter controller IAM policy scopes EC2 ARNs
# to arn:aws:ec2:${var.region}:... and pins an aws:RequestedRegion == var.region
# condition. If the caller's provider region diverges from var.region, Karpenter's
# grants would target the wrong region and deny actions. Fail fast at plan time
# instead. (.region is the aws provider v6 attribute; .name is deprecated.)
data "aws_region" "current" {}

resource "terraform_data" "region_consistency" {
lifecycle {
precondition {
condition = data.aws_region.current.region == var.region
error_message = "The AWS provider region (${data.aws_region.current.region}) must match var.region (${var.region}). This module inherits the caller's provider — set the wrapper's provider \"aws\" { region = ... } to the same region you pass as region/eks region, or the Karpenter IAM ARNs and aws:RequestedRegion condition will target the wrong region."
}
Comment on lines +1085 to +1087

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

terraform_data.region_consistency references data.aws_region.current.region in both the precondition and error_message, but that attribute isn't exported by hashicorp/aws v6 — the region name lives in data.aws_region.current.id (or .name depending on version) — so Terraform errors with Unsupported attribute at plan time before the fail-fast check can even run. Should we switch both references to the correct exported attribute (e.g. data.aws_region.current.id) and update the error_message accordingly?

Severity web_search

Want Baz to fix this for you? Activate Fixer

Other fix methods

Fix in Cursor

Prompt for AI Agents
Before applying, verify this suggestion against the current code and the installed AWS
provider version. In modules/comet_eks/main.tf around lines 1082-1089, inside the
`terraform_data.region_consistency` `lifecycle { precondition { ... } }` block, the
`condition` and `error_message` reference `data.aws_region.current.region`, which is not
a valid exported attribute on `data "aws_region" "current"` for `hashicorp/aws` v6 (the
region name is exposed as `.id`, or `.name` in some provider versions). Update both the
`condition` comparison against `var.region` and the `error_message` interpolation to use
the correct attribute (`data.aws_region.current.id`), so the region-consistency check
actually runs at plan time instead of failing with an `Unsupported attribute` error.

}
}

# Tag private subnets for Karpenter node discovery
resource "aws_ec2_tag" "karpenter_subnet" {
for_each = var.enable_karpenter ? toset(var.eks_private_subnets) : toset([])
Expand Down
7 changes: 5 additions & 2 deletions modules/comet_eks/versions.tf
Original file line number Diff line number Diff line change
@@ -1,8 +1,11 @@
terraform {
required_providers {
aws = {
source = "hashicorp/aws"
version = ">= 6.0"
source = "hashicorp/aws"
# Floor = terraform-aws-modules/eks ~> 21.24 requires aws >= 6.52. Keep in
# sync with the root module versions.tf. Ceiling/bad-build pins live in the
# wrapper, not here.
version = ">= 6.52"
}
Comment thread
obezpalko marked this conversation as resolved.
time = {
source = "hashicorp/time"
Expand Down
27 changes: 14 additions & 13 deletions providers.tf
Original file line number Diff line number Diff line change
@@ -1,13 +1,14 @@
provider "aws" {
region = var.region

default_tags {
tags = merge(
{
Terraform = "true"
},
var.environment_tag != "" ? { Environment = var.environment_tag } : {},
var.common_tags
)
}
}
# No provider "aws" configuration block here — on purpose.
#
# This module is consumed as a child module (module "comet" { source = "...?ref=" }),
# so it must NOT declare its own provider config. A child module's provider block
# takes precedence for the module's resources and IGNORES the caller's provider,
Comment thread
obezpalko marked this conversation as resolved.
# which strips the wrapper's control over credentials (assume_role / profile /
# region) and default_tags. That is the deprecated pattern.
#
# The module only declares its provider *requirement* (versions.tf →
# required_providers). Credential + region + default_tags configuration is owned
# by the CALLER's `provider "aws"` block, which the module inherits.
#
# Wrappers: put region, the assume_role/profile, and default_tags on YOUR
# provider "aws" — everything in this module runs through it.
Comment thread
obezpalko marked this conversation as resolved.
7 changes: 5 additions & 2 deletions versions.tf
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,11 @@ terraform {

required_providers {
aws = {
source = "hashicorp/aws"
version = "~> 6.0"
source = "hashicorp/aws"
# Floor = the tightest real dependency: terraform-aws-modules/eks ~> 21.24
# requires aws >= 6.52. No upper bound / bad-build exclusion here — that is
# deployment policy (the wrapper pins e.g. "~> 6.50, != 6.57.0").
version = ">= 6.52"
}
random = {
source = "hashicorp/random"
Expand Down