From 2fb3dc0bec98d65fcec9f541f439fe43741b7a74 Mon Sep 17 00:00:00 2001 From: Cristian Magherusan-Stanciu Date: Tue, 26 May 2026 02:16:06 +0200 Subject: [PATCH] refactor(iac/aws-lambda): preserve Function URL across count removal via moved block The prior commit dropped `count` from aws_lambda_function_url.main. Without a `moved` block, terraform sees this as destroy + create, which generates a new Function URL host and breaks the dashboard (CORS origins, DASHBOARD_URL, frontend bundles all reference the old host). The `moved` block makes terraform treat it as a state-index update in-place instead. aws_lambda_permission.function_url retains its count expression (now `var.function_url_auth_type == "NONE" ? 1 : 0`), so its state address stays indexed and needs no moved block. --- terraform/modules/compute/aws/lambda/main.tf | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/terraform/modules/compute/aws/lambda/main.tf b/terraform/modules/compute/aws/lambda/main.tf index 21ab88770..5d0e44768 100644 --- a/terraform/modules/compute/aws/lambda/main.tf +++ b/terraform/modules/compute/aws/lambda/main.tf @@ -114,6 +114,18 @@ resource "aws_lambda_function" "main" { # Lambda Function URL (for HTTP access) # ============================================== +# moved: aws_lambda_function_url.main lost its `count` in PR #574 (drop +# of dead-knob lambda_enable_function_url). The existing deployment's +# state holds the resource at index [0]; this block tells terraform +# to update the state index in-place instead of destroying the +# existing Function URL and creating a fresh one with a different +# host (which would break the dashboard until origins/DASHBOARD_URL +# are re-propagated everywhere). +moved { + from = aws_lambda_function_url.main[0] + to = aws_lambda_function_url.main +} + resource "aws_lambda_function_url" "main" { function_name = aws_lambda_function.main.function_name authorization_type = var.function_url_auth_type