From 2a3e467d0b309d760313936c93937da01d79d787 Mon Sep 17 00:00:00 2001 From: Olamide Date: Wed, 23 Sep 2026 10:55:59 +0100 Subject: [PATCH] fix(network): narrow depends_on to stop plan-time replacements Module-level depends_on on modules with pending changes defers every data source inside the dependent module to apply time. Changing cluster_names (which only retags the VPC and subnets) therefore made the S3 endpoint's aws_region lookup unknown and forced replacement of the VPC endpoint. - s3_endpoint: drop depends_on; route_table_ids already orders it after the route tables - nat_gateway / public_subnet_routes: drop module.public_subnets from depends_on; subnets are already passed by value. Keep the internet gateway dependency, which is still required. Co-Authored-By: Claude Opus 5.5 --- aws/network/main.tf | 6 ++---- 1 file changed, 2 insertions(+), 4 deletions(-) diff --git a/aws/network/main.tf b/aws/network/main.tf index 179ef40..b8515b8 100644 --- a/aws/network/main.tf +++ b/aws/network/main.tf @@ -28,7 +28,7 @@ module "nat_gateway" { public_subnets = module.public_subnets.instances tags = var.tags - depends_on = [aws_internet_gateway.this, module.public_subnets] + depends_on = [aws_internet_gateway.this] } module "private_subnets" { @@ -84,7 +84,7 @@ module "public_subnet_routes" { tags = merge(var.tags, var.public_subnet_tags) vpc = local.vpc - depends_on = [module.public_subnets, aws_internet_gateway.this] + depends_on = [aws_internet_gateway.this] } module "s3_endpoint" { @@ -100,8 +100,6 @@ module "s3_endpoint" { module.private_subnet_routes.route_table_ids, [module.public_subnet_routes.route_table.id], ) - - depends_on = [module.private_subnet_routes, module.public_subnet_routes] } resource "aws_internet_gateway" "this" {