I have been experimenting with terraform with the following basic configuration file for creating a resource group...
resource "azurerm_resource_group" "myrg" {
name = "MyResourceGroup"
location = "westeurope"
}
output resource_group_details {
value = azurerm_resource_group.myrg
}
- First
terraform plan- 1 resource will be created - First
terraform apply- 1 resource created - Second
terraform plan(with no changes made to the configuration file) -Objects have changed outside of Terraform(See below) - Second
terraform apply-Objects have changed outside of Terraform, 0 added/changed/detroyed - Third
terraform plan(with no changes made to the configuration file) -No changes. Your infrastructure matches the configuration.
Note: Objects have changed outside of Terraform
Terraform detected the following changes made outside of Terraform since the last "terraform apply" which may have
affected this plan:
# azurerm_resource_group.myrg has changed
~ resource "azurerm_resource_group" "myrg" {
id = "/subscriptions/176f2ee3-d0a2-476d-9106-43cad1f63f16/resourceGroups/MyResourceGroup"
name = "MyResourceGroup"
+ tags = {}
# (1 unchanged attribute hidden)
}
Based on what I've tried to find about this online, it looks like this warning is because Azure adds an empty tag array to a resource group during creation. Then when terraform compares the now existing resource with the configuration file and state, it's now warning you there is a difference. I'm not quite sure how terraform reconciles this on the third terraform plan though....
What should be the workflow here? Particularly when thinking about CI?
It appears to just be noise to be informed of the existence of an empty, optional attribute that I haven't defined.
I've looked at -refresh=false but it looks like this could suppress a genuine change that has occurred on your infrastructure that you may want to be notified about. When using -refresh-only on the second terraform plan and apply it just outputs the same noise as above.