Open Fodsuk opened 3 months ago
Does the same thing happen if you only include the custom role in the initial apply, then add in the azuread_directory_role_eligibility_schedule_request
afterwards?
I am now getting a few other issues with the same configuration on every single apply (so initial and adding afterwards):
azuread_directory_role_eligibility_schedule_request
using a azuread_custom_directory_role
will always force replace the current eligibility assignment. Looks like the role_definition_id keeps changing when using template_id or object_id. azuread_directory_role_assignment
using a azuread_directory_role
is always wanting to create a new resource even if it has been imported. When running apply it will error stating a resource already exists.Working:
azuread_directory_role_assignment
using a azuread_custom_directory_role
- working as expected and using template_id. azuread_directory_role_eligibility_schedule_request
using a azuread_directory_role
- working as expected.azurerm has some similar issues as well.
azurerm_pim_eligible_role_assignment
using a azurerm_role_definition
against a azurerm_subscriptions
is always wanting to create a new resource even if it has been imported. When running apply it will error stating a resource already exists. azurerm_pim_eligible_role_assignment
using a azurerm_role_definition
against a azurerm_management_group
I have imported with the same resource names, no change.
Community Note
Terraform (and AzureAD Provider) Version
Affected Resource(s)
azuread_directory_role_eligibility_schedule_request
Terraform Configuration Files
Debug Output
Panic Output
Expected Behavior
The eligibility role assignment is created
Actual Behavior
The custom role isn't found and the following error fails
Steps to Reproduce
terraform apply
Important Factoids
I have tried adding a wait provisioner to the custom directory role creation
References
0000