Closed ragnaray closed 5 months ago
@ragnaray drift_detection
should be enabled during initial apply of the Group resource. If you retroactively enable it then the state might still contain entries which will be reconciled on the next plan/apply cycle. Once an apply has run with drift_detection = false
, subsequent plans will ignore any entries outside of your Terraform declarations.
Create a group in IAM using terraform. Create users using HSDP apis outside of terraform and add the users to this group. Modify the terraform script to create any unrelated resource and run terraform apply. Observe that the script tries to update all users in place too. This inspite of setting drift_detection = false.