You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit bde563e
Browse filesBrowse the repository at this point in the historyBrowse files
fix(ci): serialize AWS and GCP Terraform state writers on environment, not branch (#1812)
Both halves of #1801 were fixed for Azure only in #1803 and were still live on
AWS and GCP.
Half 1: the state key is built from the environment but the concurrency group
was keyed on `github.ref`, so two runs on different refs that resolve to the
same environment landed in different groups and applied against one state file.
Workflow-level `concurrency` cannot see `needs`, so each group moves to the job
that writes state, keyed on the same value that builds the state key:
aws-tfstate-<env> github-<env>/terraform.tfstate (S3)
aws-fargate-tfstate-<env> github-fargate-<env>/terraform.tfstate (S3)
gcp-tfstate-<env> github-<env>/default.tfstate (GCS)
Applied to all ten previously ungrouped state-mutating jobs across
deploy-aws-lambda.yml, deploy-aws-fargate.yml, deploy-gcp.yml,
destroy-fargate-dev.yml, cleanup-staging.yml and rollback.yml, so serialization
holds across workflows, not just within one. `cancel-in-progress: false` on
every one: cancelling mid-apply leaves a half-applied stack and a stuck lock.
Half 2: four steps deleted the state lock object with no age check and no check
that the lock was this run's. Two ran unconditionally before `terraform init`,
two on `failure() || cancelled()`. The `cancelled()` half is the decisive one:
those steps run while `terraform apply` is still shutting down, destroying a
lock the dying run may still be using. All four are removed rather than made
conditional, so a real collision fails loudly with "Error acquiring the state
lock". deploy-aws-fargate.yml's operator-gated `clear_stale_lock` step is kept
as the recovery path.
destroy-fargate-dev.yml was not named in the issue but writes
github-fargate-dev/terraform.tfstate and carried both defects.
rollback.yml's rollback-aws-fargate takes the aws-tfstate-* group because its
backend key is the Lambda namespace, not the Fargate one. That pre-existing
mismatch is tracked in #1811.
Closes#1806
0 commit comments