r/aws_kms_replica_key: Add configurable create timeout - #49917
Open
shashankvarma499 wants to merge 2 commits into
Open
r/aws_kms_replica_key: Add configurable create timeout#49917shashankvarma499 wants to merge 2 commits into
shashankvarma499 wants to merge 2 commits into
Conversation
The create path waited for the replica key to leave Creating and reach Enabled using a hardcoded 2 minute timeout. Multi-Region key replication routinely takes longer than that, so add a timeouts block with a configurable create timeout (default 20 minutes) and wire it into the wait. Signed-off-by: Shashank Varma <324153016+shashankvarma499@users.noreply.github.com>
Signed-off-by: Shashank Varma <324153016+shashankvarma499@users.noreply.github.com>
Contributor
Community GuidelinesThis comment is added to every new Pull Request to provide quick reference to how the Terraform AWS Provider is maintained. Please review the information below, and thank you for contributing to the community that keeps the provider thriving! 🚀 Voting for Prioritization
Pull Request Authors
|
Contributor
|
✅ Thank you for correcting the previously detected issues! The maintainers appreciate your efforts to make the review process as smooth as possible. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Closes #49915.
The
aws_kms_replica_keycreate path waits for the replica key to leaveCreatingand reachEnabledusing a hardcoded 2 minute timeout (waitReplicaKeyCreated). Multi-Region key replication routinely takes longer than that, roughly 10 minutes forus-east-1toeu-central-1in the reported case, so the create reliably fails even though AWS goes on to finish creating the replica successfully.This change adds a
timeoutsblock with a configurablecreatetimeout, defaulting to 20 minutes, and wires it intowaitReplicaKeyCreated. Users replicating across slower regions can now raise the timeout instead of the create failing every time.Relations
This addresses the hardcoded 2 minute wait described in #49915. The other two symptoms reported there, the tainted-resource
ReplicateKeyAlreadyExistsExceptionpath andupdateKeyEnablednot retryingKMSInvalidStateException, are left for separate follow-ups so this change stays focused.References