fix(terraform/aws): make db_bootstrap_sql output idempotent (LIT-3173)

The break-glass `db_bootstrap_sql` output used bare `CREATE USER`, which
would error with "role already exists" on a re-run. Match the idempotent
`DO $$ BEGIN CREATE USER ... EXCEPTION WHEN duplicate_object THEN NULL;
END $$;` form that bootstrap.tf already uses in its local-exec provisioner.
Safe to run multiple times — re-granting rds_iam and schema privileges is
a no-op in Postgres.

Resolves LIT-3173

https://claude.ai/code/session_01N6myMC1QzDj2NtpqfACDPn
This commit is contained in:
Claude 2026-05-23 22:40:02 +00:00
parent 8513d7fc0c
commit 88dd2492d3
No known key found for this signature in database

View file

@ -43,12 +43,17 @@ output "db_master_password_secret_arn" {
value = aws_secretsmanager_secret.db_master_password.arn
}
# Pre-baked SQL to run once as the master user, creating the IAM-authed
# application user that gateway/backend/migration tasks will authenticate as.
# Pre-baked SQL to run as the master user — idempotent, so safe to re-run.
# bootstrap.tf executes this automatically on `terraform apply` via a
# local-exec provisioner; expose it here for break-glass manual re-runs.
output "db_bootstrap_sql" {
description = "Run this once as the master DB user (after the first apply) to create the IAM-authed app user."
description = "Idempotent SQL to run as the Aurora master user to create (or re-create) the IAM-authed app user. bootstrap.tf runs this automatically; use as a break-glass manual re-run."
value = <<-SQL
CREATE USER ${var.db_username};
DO $$
BEGIN
CREATE USER ${var.db_username};
EXCEPTION WHEN duplicate_object THEN NULL;
END $$;
GRANT rds_iam TO ${var.db_username};
GRANT ALL PRIVILEGES ON DATABASE ${var.db_name} TO ${var.db_username};
GRANT ALL ON SCHEMA public TO ${var.db_username};