Repository navigation
fix(deploy): Replace the managed certificate before deleting it - #7
Merged
Merged
Conversation
A domain change replaced the certificate in place, and GCP refused to delete it while the SSL proxy still used it. Give each certificate a unique name and create the new one first. Co-Authored-By: David Cramer <david@sentry.io>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit c2e5056. Configure here.
|
|
||
| resource "google_compute_managed_ssl_certificate" "roach" { | ||
| name = "roach" | ||
| name = "roach-${random_id.certificate.hex}" |
There was a problem hiding this comment.
Certificate replaced without domain change
High Severity
A new random_id is interpolated into the certificate name, so the next apply replaces the live roach certificate even when var.domain is unchanged. Terraform then points the SSL proxy at the still-PROVISIONING cert and deletes the active one, taking HTTPS down until Google finishes issuing it.
Reviewed by Cursor Bugbot for commit c2e5056. Configure here.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


When
domainchanges, Terraform has to replace the Google-managed certificate. With the fixed nameroach, it tried to delete the old certificate first, and GCP refused because the SSL proxy still used it (resourceInUseByAnotherResource).Now the certificate name has a random suffix that changes only when the domain changes, and
create_before_destroyis set. Terraform creates the new certificate, moves the SSL proxy to it, and then deletes the old one.The new certificate stays
PROVISIONINGuntil DNS for the new domain points at the load balancer IP.via David Cramer.
--
View Junior Session [Sentry]