Problem
The audit log input describes s3_object_lock as off by default, but its optional attribute default is true. When audit logs are enabled and this field is omitted, the typed input therefore enables Object Lock despite the documented expectation.
Verified in src/variables.tf on main at 2bb7c755692674ad619ffc46a0a17a781f019106. This is a source-level default mismatch; no bucket was created to reproduce it.
Impact
Callers and configuration UIs can unintentionally select GOVERNANCE-mode retention when relying on the description. The description itself notes that this behavior is not cleanly reversible.
Acceptance criteria
Related: #16 (original audit/activity logs feature, closed). The Configurator will expose the effective setting explicitly rather than relying on the contradictory description.
Problem
The audit log input describes
s3_object_lockas off by default, but its optional attribute default istrue. When audit logs are enabled and this field is omitted, the typed input therefore enables Object Lock despite the documented expectation.Verified in src/variables.tf on
mainat2bb7c755692674ad619ffc46a0a17a781f019106. This is a source-level default mismatch; no bucket was created to reproduce it.Impact
Callers and configuration UIs can unintentionally select GOVERNANCE-mode retention when relying on the description. The description itself notes that this behavior is not cleanly reversible.
Acceptance criteria
Related: #16 (original audit/activity logs feature, closed). The Configurator will expose the effective setting explicitly rather than relying on the contradictory description.