Repository navigation
stackit_resourcemanager_project - Provider error when removing labels that are auto-populated by the API #1381
Description
Activity
Hi @LukeDearden,
thank you for reporting this issue. We will have a look at this.any updates on this so far? Labels on projects and resource manager folders are basically broken at the moment
is there already a rough timeline or update for this? Labels are important for us since they are used as feature flags/for setting NVAs
is there already a rough timeline or update for this?
We hit what looks like the same bug from the other direction, still present on
0.112.0. Here the
configuration never manages labels at all, so there is nothing to remove.labelsisOptionaland notComputed, so a configuration that omits it planslabels -> null.
STACKIT does not clear the labels in response to that update, so after apply the provider sees a
non-empty map where it plannednull, and it fails.toUpdatePayloadsends
Labels: &labelsfromutils.LabelsToPayload(ctx, model.Labels)on every update, including when the
model value is null.The consequence is that an existing project carrying any labels cannot be adopted into Terraform by a
module that does not itself manage labels. Every retry produces the same plan and the same error, so the
resource never converges.To reproduce, create a project outside Terraform with labels:
stackit project create --name example-project --parent-id <parent-id> \ --label project=develop --label workspace=example-workspace
then import it into this configuration and apply:
resource "stackit_resourcemanager_project" "project" { name = "example-project" parent_container_id = "<parent-id>" owner_email = "<owner-email>" # labels deliberately not managed }
Error: Provider produced inconsistent result after apply When applying changes to stackit_resourcemanager_project.project, provider "provider[\"registry.opentofu.org/stackitcloud/stackit\"]" produced an unexpected new value: .labels: was null, but now cty.MapVal(map[string]cty.Value{"project":cty.StringVal("develop"), "workspace":cty.StringVal("example-workspace")}). This is a bug in the provider, which should be reported in the provider's own issue tracker.A module that passes
labels = length(var.labels) > 0 ? var.labels : nullwith an empty input map
produces the same null value and the same failure.For a protected label this has no workaround at all, because the label cannot be removed to make the
apply pass.billingReference— STACKIT's Billing Reference project setting, editable in the Portal —
is stored as a protected label, and the labels endpoint refuses to delete it even for an organization
owner:DELETE https://resource-manager.api.stackit.cloud/v2/projects/<id>/labels?keys=billingReference → 409 {"message":"The label [billingReference] is protected and can't be changed or deleted", ...}Such a project is permanently unusable by a module that does not manage labels.
One API observation while investigating, which may be a separate bug on the API side: a
PATCHon the
project with an explicit null value does remove a protected label, contradicting the409above.
stackit project update --labelcan only add labels, and aPATCHwithlabels: {}is a merge that
keeps everything.curl -X PATCH -H "Authorization: Bearer $(stackit auth get-access-token)" \ -H 'Content-Type: application/json' -d '{"labels":{"billingReference":null}}' \ "https://resource-manager.api.stackit.cloud/v2/projects/<id>"
Environment: Linux (Manjaro, kernel 7.1.6), OpenTofu
1.11.0and1.12.5both affected, STACKIT
provider0.112.0.
Description
When attempting to remove a label from a stackit_resourcemanager_project resource, the apply fails with a provider inconsistency error because the STACKIT API automatically re-adds the label after the update.
Steps to reproduce
Actual behavior
Expected behavior
The label is removed and Terraform state reflects the updated labels.
Environment
Ubuntu 24.04
Provider version: 0.90.0
Terraform version: 1.14.8
Resource: stackit_resourcemanager_project