From 88dd2492d3214f9a02940e51b934da4395ea2325 Mon Sep 17 00:00:00 2001 From: Claude Date: Sat, 23 May 2026 22:40:02 +0000 Subject: [PATCH] fix(terraform/aws): make db_bootstrap_sql output idempotent (LIT-3173) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The break-glass `db_bootstrap_sql` output used bare `CREATE USER`, which would error with "role already exists" on a re-run. Match the idempotent `DO $$ BEGIN CREATE USER ... EXCEPTION WHEN duplicate_object THEN NULL; END $$;` form that bootstrap.tf already uses in its local-exec provisioner. Safe to run multiple times — re-granting rds_iam and schema privileges is a no-op in Postgres. Resolves LIT-3173 https://claude.ai/code/session_01N6myMC1QzDj2NtpqfACDPn --- terraform/litellm/aws/outputs.tf | 13 +++++++++---- 1 file changed, 9 insertions(+), 4 deletions(-) diff --git a/terraform/litellm/aws/outputs.tf b/terraform/litellm/aws/outputs.tf index 9c36b1a7e0f..3be4a94fd5a 100644 --- a/terraform/litellm/aws/outputs.tf +++ b/terraform/litellm/aws/outputs.tf @@ -43,12 +43,17 @@ output "db_master_password_secret_arn" { value = aws_secretsmanager_secret.db_master_password.arn } -# Pre-baked SQL to run once as the master user, creating the IAM-authed -# application user that gateway/backend/migration tasks will authenticate as. +# Pre-baked SQL to run as the master user — idempotent, so safe to re-run. +# bootstrap.tf executes this automatically on `terraform apply` via a +# local-exec provisioner; expose it here for break-glass manual re-runs. output "db_bootstrap_sql" { - description = "Run this once as the master DB user (after the first apply) to create the IAM-authed app user." + description = "Idempotent SQL to run as the Aurora master user to create (or re-create) the IAM-authed app user. bootstrap.tf runs this automatically; use as a break-glass manual re-run." value = <<-SQL - CREATE USER ${var.db_username}; + DO $$ + BEGIN + CREATE USER ${var.db_username}; + EXCEPTION WHEN duplicate_object THEN NULL; + END $$; GRANT rds_iam TO ${var.db_username}; GRANT ALL PRIVILEGES ON DATABASE ${var.db_name} TO ${var.db_username}; GRANT ALL ON SCHEMA public TO ${var.db_username};