Skip to content

stackit_resourcemanager_project - Provider error when removing labels that are auto-populated by the API #1381

Description

@LukeDearden

Description

When attempting to remove a label from a stackit_resourcemanager_project resource, the apply fails with a provider inconsistency error because the STACKIT API automatically re-adds the label after the update.

Steps to reproduce

resource "stackit_resourcemanager_project" "example" {
  name                = "example"
  owner_email         = "example@sa.stackit.cloud"
  parent_container_id = "xxxx"
  labels = {
    created = "2026-04-14"
  }
}
  1. Create a project with a created label:
  2. Remove the created label from the config
  3. Run terraform apply

Actual behavior

╷
│ Error: Provider produced inconsistent result after apply
│ 
│ When applying changes to stackit_resourcemanager_project.frends-shared, provider "provider[\"registry.terraform.io/stackitcloud/stackit\"]" produced an unexpected new value: .labels:
│ new element "created" has appeared.
│ 
│ This is a bug in the provider, which should be reported in the provider's own issue tracker.
╵

Expected behavior

The label is removed and Terraform state reflects the updated labels.

Environment

Ubuntu 24.04
Provider version: 0.90.0
Terraform version: 1.14.8
Resource: stackit_resourcemanager_project

Activity

  1. Fyusel commented on Apr 17, 2026

    @Fyusel
    Contributor

    Hi @LukeDearden,
    thank you for reporting this issue. We will have a look at this.

  2. mahauber commented on Apr 28, 2026

    @mahauber

    any updates on this so far? Labels on projects and resource manager folders are basically broken at the moment

  3. mahauber commented on May 28, 2026

    @mahauber

    is there already a rough timeline or update for this? Labels are important for us since they are used as feature flags/for setting NVAs

  4. mahauber commented on Jul 24, 2026

    @mahauber

    is there already a rough timeline or update for this?

  5. grubmeshi commented on Aug 20, 2026

    @grubmeshi

    We hit what looks like the same bug from the other direction, still present on 0.112.0. Here the
    configuration never manages labels at all, so there is nothing to remove.

    labels is Optional and not Computed, so a configuration that omits it plans labels -> null.
    STACKIT does not clear the labels in response to that update, so after apply the provider sees a
    non-empty map where it planned null, and it fails. toUpdatePayload sends
    Labels: &labels from utils.LabelsToPayload(ctx, model.Labels) on every update, including when the
    model value is null.

    The consequence is that an existing project carrying any labels cannot be adopted into Terraform by a
    module that does not itself manage labels. Every retry produces the same plan and the same error, so the
    resource never converges.

    To reproduce, create a project outside Terraform with labels:

    stackit project create --name example-project --parent-id <parent-id> \
      --label project=develop --label workspace=example-workspace

    then import it into this configuration and apply:

    resource "stackit_resourcemanager_project" "project" {
      name                = "example-project"
      parent_container_id = "<parent-id>"
      owner_email         = "<owner-email>"
      # labels deliberately not managed
    }
    Error: Provider produced inconsistent result after apply
    
    When applying changes to stackit_resourcemanager_project.project, provider
    "provider[\"registry.opentofu.org/stackitcloud/stackit\"]" produced an
    unexpected new value: .labels: was null, but now
    cty.MapVal(map[string]cty.Value{"project":cty.StringVal("develop"),
    "workspace":cty.StringVal("example-workspace")}).
    
    This is a bug in the provider, which should be reported in the provider's own
    issue tracker.
    

    A module that passes labels = length(var.labels) > 0 ? var.labels : null with an empty input map
    produces the same null value and the same failure.

    For a protected label this has no workaround at all, because the label cannot be removed to make the
    apply pass. billingReference — STACKIT's Billing Reference project setting, editable in the Portal —
    is stored as a protected label, and the labels endpoint refuses to delete it even for an organization
    owner:

    DELETE https://resource-manager.api.stackit.cloud/v2/projects/<id>/labels?keys=billingReference
    → 409 {"message":"The label [billingReference] is protected and can't be changed or deleted", ...}
    

    Such a project is permanently unusable by a module that does not manage labels.

    One API observation while investigating, which may be a separate bug on the API side: a PATCH on the
    project with an explicit null value does remove a protected label, contradicting the 409 above.
    stackit project update --label can only add labels, and a PATCH with labels: {} is a merge that
    keeps everything.

    curl -X PATCH -H "Authorization: Bearer $(stackit auth get-access-token)" \
      -H 'Content-Type: application/json' -d '{"labels":{"billingReference":null}}' \
      "https://resource-manager.api.stackit.cloud/v2/projects/<id>"

    Environment: Linux (Manjaro, kernel 7.1.6), OpenTofu 1.11.0 and 1.12.5 both affected, STACKIT
    provider 0.112.0.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions