Skip to content

Align audit log Object Lock defaults with documentation and test omitted values #81

Description

@lweberru

Problem

The audit log input describes s3_object_lock as off by default, but its optional attribute default is true. When audit logs are enabled and this field is omitted, the typed input therefore enables Object Lock despite the documented expectation.

Verified in src/variables.tf on main at 2bb7c755692674ad619ffc46a0a17a781f019106. This is a source-level default mismatch; no bucket was created to reproduce it.

Impact

Callers and configuration UIs can unintentionally select GOVERNANCE-mode retention when relying on the description. The description itself notes that this behavior is not cleanly reversible.

Acceptance criteria

  • Decide and document the intended default explicitly; assess compatibility before changing existing behavior.
  • Align the typed default, description and generated documentation.
  • Tests distinguish disabled audit logs, omitted Object Lock, explicit false and explicit true.
  • Provide migration guidance if the effective default changes; no automatic changes to existing buckets.

Related: #16 (original audit/activity logs feature, closed). The Configurator will expose the effective setting explicitly rather than relying on the contradictory description.

Activity

  1. added
    area:acceleratorAccelerator Terraform/OpenTofu roots, modules and examples
    priority:p1High impact correctness, security or required product capability; schedule first
    effort:mSeveral components or contract changes; estimate excludes external waiting
    bugSomething isn't working
    on Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:acceleratorAccelerator Terraform/OpenTofu roots, modules and examplesbugSomething isn't workingeffort:mSeveral components or contract changes; estimate excludes external waitingpriority:p1High impact correctness, security or required product capability; schedule first

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions