chore(terraform): preserve live Cloud SQL binlog flag - #709
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem / evidence
A refreshing production Terraform plan proposed removing the live Cloud SQL flag
log_bin_trust_function_creators=on.gcloud sql instances describe newapi-mysqlconfirms the flag is active alongside the declared database settings, and the instance isRUNNABLEwith a 216 GB disk and the expected tier.Scope / design
Declare the existing flag in the Cloud SQL module so Terraform preserves current production behavior instead of removing it during an unrelated apply.
Impact / risks
This is desired-state alignment only: production already has the exact value. No database restart, failover, replacement, or immediate infrastructure apply is required. Removing this flag could break function/trigger creation under binary logging, so preserving it is the conservative choice.
Validation
terraform fmtterraform validate0 destroy, with no Cloud SQL or secret replacementDeployment recommendation