How do I avoid hitting a rate limit with Terraform refresh/apply, causing the operation to fail?

Viewed 376

Terraform offers providers for a great number of diffent Cloud Providers (both IaaS, PaaS and SaaS). Some of these providers have very low rate limits, which you will quickly hit once your infrastructure reaches a certain scale where you have hundreds of resources in the same terraform state. I've encountered issues with this with several providers, most recently Azure Resource Manager (azurerm), whose DNS rate limit is (currently) 500 GET requests per 5 minutes.

One common and sensible way to deal with rate limiting issues in Terraform is to split your state up into smaller logically cohesive states. However, you eventually reach a limit where it no longer makes semantic sense to split the state up any further. I don't want to wind up in the situation where I have to create separate states which semantically should be the same, but which I for rate limiting reasons must arbitrarily separate.

Another approach to solve this is to pass the -parallelism=1 flag to the respective terraform CLI command, to avoid any parallel requests to the provider, thereby minimising the requests performed per minute.

I have now exhausted both of these approaches to the rate limiting issue I'm currently experiencing with one of my states, but the issue persists. Parallelism is disabled, and it doesn't make sense to break down the state further. I am still hitting the rate limit, and as such, all terraform refresh and terraform apply operations fail for this state.

Independent of the specific provider in question, is there any way to tell Terraform to perform the requests toward the provider more slowly (or at a certain max rate) to avoid hitting a rate limit? I have not found any flag for this in the relevant Terraform CLI commands.

0 Answers
Related