From b01b9d6c0427c5d9590900a929a2ca1300ca5418 Mon Sep 17 00:00:00 2001 From: Cristian Magherusan-Stanciu Date: Mon, 27 Jul 2026 12:06:10 +0200 Subject: [PATCH] fix(iac/aws): create_before_destroy on OIDC signing key (follow-up to #1480) #1480 migrated aws_kms_key.signing from RSA_2048 to ECC_NIST_P256, which forces a KMS key replacement. Terraform's default destroy-before-create schedules the live signing key for deletion (immediately unusable for kms:Sign) before the new EC key exists, briefly breaking OIDC client-assertion JWT minting on deploy. Add lifecycle { create_before_destroy = true } so the new key is created and the alias cut over before the old key is scheduled for deletion. GCP crypto keys are versioned (no gap) and Azure Key Vault soft-delete keeps the old key recoverable, so only the AWS KMS key needs this. --- terraform/modules/compute/aws/lambda/signing-key.tf | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/terraform/modules/compute/aws/lambda/signing-key.tf b/terraform/modules/compute/aws/lambda/signing-key.tf index 8e5d7dec7..a8e309924 100644 --- a/terraform/modules/compute/aws/lambda/signing-key.tf +++ b/terraform/modules/compute/aws/lambda/signing-key.tf @@ -15,6 +15,16 @@ resource "aws_kms_key" "signing" { tags = merge(var.tags, { Name = "${var.stack_name}-oidc-signing" }) + + # Any change that forces a new CMK (e.g. the RSA_2048 -> ECC_NIST_P256 + # migration in #1480) must create the replacement key and cut the alias + # over to it BEFORE scheduling the old key for deletion. Without this, + # Terraform's default destroy-before-create would schedule the live OIDC + # signing key for deletion (immediately unusable for kms:Sign) before the + # new key exists, briefly breaking client-assertion JWT minting. + lifecycle { + create_before_destroy = true + } } resource "aws_kms_alias" "signing" {