fix(enterprise_organization): prevent taint when PAT not yet authorized#3025
Closed
ericpardee wants to merge 1 commit intointegrations:mainfrom
Closed
fix(enterprise_organization): prevent taint when PAT not yet authorized#3025ericpardee wants to merge 1 commit intointegrations:mainfrom
ericpardee wants to merge 1 commit intointegrations:mainfrom
Conversation
When a github_enterprise_organization is created in an EMU environment, subsequent resources may fail because the PAT hasn't been authorized for the new org yet. When the user then authorizes the PAT and re-runs apply, the Read operation was incorrectly removing the org from state (because GraphQL returned "Could not resolve to a node"), causing Terraform to mark it as tainted and destroy+recreate it. This fix verifies via REST API whether the org actually exists before removing it from state. If the org exists but GraphQL can't access it, we now return a helpful error instead of silently removing from state. Fixes integrations#1914
|
👋 Hi! Thank you for this contribution! Just to let you know, our GitHub SDK team does a round of issue and PR reviews twice a week, every Monday and Friday! We have a process in place for prioritizing and responding to your input. Because you are a part of this community please feel free to comment, add to, or pick up any issues/PRs that are labeled with |
Contributor
Author
|
Tested manually in EMU environment:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolves #1914
Before the change?
When creating a
github_enterprise_organizationin an EMU environment, REST API calls fail with SAML enforcement errors until the PAT is authorized for the new org. This affects settingdescription/display_nameduring create (and any subsequent updates). The error caused Terraform to taint the resource, leading to destroy+recreate on the next apply.After the change?
SAML enforcement errors during create/update are now caught and handled gracefully:
description/display_namefrom state so it reflects realityNext plan will show drift and retry after PAT authorization.
Pull request checklist
Does this introduce a breaking change?