Can not change AWS WAF association once created #4782
Labels
awaiting/core
Blocked on a missing bug or feature in pulumi/pulumi (except codegen)
blocked
The issue cannot be resolved without 3rd party action.
kind/bug
Some behavior is incorrect or out of spec
Describe what happened
I have a WAF Web ACL and an association for that ACL that associates it with an application load balancer. The initial deploy of this worked great. However, once I changed the name of the association from
webAclAssociation
toopsWebAclAssociationLB
, the delete and create options seem to step on each others toes. It creates the new association correctly as I can see it in the browser after the state of that action hits "created" in the pulumi up output, but once the deletion finishes it gets rid of the newly created association.In the AWS UI, I noticed the following :
I almost wonder if the same thing is happening with the pulumi create/delete steps here. The new resource association is created which AWS likely approves and auto deletes the previous association. Then, pulumi gets to the delete step on the old association resource, which actually deletes the newly created association?
I was able to solve the problem by commenting out the resource, deploying, and then redeploying after uncommenting again.
Sample program
Log output
The following final log output appears in an order which would almost make you believe the delete happens first -- but the order of live output is definitely creation then deletion
Affected Resource(s)
No response
Output of
pulumi about
@pulumi/aws NPM package is version 6.49.0. Will have to modify ci runner to output the full about if necessary.
Additional context
No response
Contributing
Vote on this issue by adding a 👍 reaction.
To contribute a fix for this issue, leave a comment (and link to your pull request, if you've opened one already).
The text was updated successfully, but these errors were encountered: