Skip to content

Conversation

@asri-badlah
Copy link
Collaborator

what

This PR updates the data.aws_iam_policy_document.default block in the OpenSearch module to ensure consistent ordering of principals and resources when generating the policy JSON.

why

Terraform was detecting in-place updates for aws_opensearch_domain_policy due to differences in array ordering between what AWS returns and what Terraform generates. This drift is harmless but causes unnecessary terraform plan changes and confusion.

@matteomallus matteomallus force-pushed the canonicalize-openSearch-IAM-policy branch from 22055e1 to 3036720 Compare December 1, 2025 14:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants