<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Terraform on DevOps &amp; Rock&#39;N&#39;Roll</title>
    <link>https://artazar.pages.dev/tags/terraform/</link>
    <description>Recent content in Terraform on DevOps &amp; Rock&#39;N&#39;Roll</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Wed, 19 Aug 2026 15:55:02 +0700</lastBuildDate>
    <atom:link href="https://artazar.pages.dev/tags/terraform/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Terragrunt: deleting the boilerplate you were told to write</title>
      <link>https://artazar.pages.dev/blog/09-terragrunt-less-boilerplate/</link>
      <pubDate>Tue, 19 May 2026 00:08:30 +0000</pubDate>
      <guid>https://artazar.pages.dev/blog/09-terragrunt-less-boilerplate/</guid>
      <description>&lt;p&gt;Terragrunt exists to keep you DRY, and then you open a mature Terragrunt repository and find ninety &lt;code&gt;terragrunt.hcl&lt;/code&gt; files that are eighty percent identical. There&amp;rsquo;s a joke in there somewhere.&lt;/p&gt;&#xA;&lt;p&gt;It isn&amp;rsquo;t Terragrunt&amp;rsquo;s fault. The default onboarding path — copy the folder next door, change the inputs — is the fastest way to a working stack and the slowest way to a maintainable one. Here&amp;rsquo;s what I strip out when I inherit one of these.&lt;/p&gt;</description>
    </item>
    <item>
      <title>EKS Access Entries: one ARN, one cluster, no sharing</title>
      <link>https://artazar.pages.dev/blog/07-eks-access-entries/</link>
      <pubDate>Tue, 21 Apr 2026 00:08:30 +0000</pubDate>
      <guid>https://artazar.pages.dev/blog/07-eks-access-entries/</guid>
      <description>&lt;p&gt;EKS Access Entries replaced the &lt;code&gt;aws-auth&lt;/code&gt; ConfigMap and made cluster authorization a proper AWS API object instead of a YAML blob that you edited with trembling hands, hoping you wouldn&amp;rsquo;t lock yourself out. It&amp;rsquo;s a genuine improvement. But moving auth into the API surface also moves it into Terraform state, and that&amp;rsquo;s where it gets interesting.&lt;/p&gt;&#xA;&lt;p&gt;The error that sent me down this road:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Error: creating EKS Access Entry (test-spain-001:arn:aws:iam::123456789012:role/PlatformAdmin):&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;ResourceInUseException: The specified access entry resource is already in use&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;on this cluster.&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;My first reaction was the wrong one: &lt;em&gt;are access entries global? Did creating one for cluster A break cluster B?&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Fargate profiles and the art of waiting your turn</title>
      <link>https://artazar.pages.dev/blog/06-fargate-profile-deletion/</link>
      <pubDate>Tue, 07 Apr 2026 00:08:30 +0000</pubDate>
      <guid>https://artazar.pages.dev/blog/06-fargate-profile-deletion/</guid>
      <description>&lt;p&gt;There is a special kind of Terraform error that only shows up when you destroy things. Your &lt;code&gt;apply&lt;/code&gt; has been green for months, everyone is happy, and then one day you run a &lt;code&gt;terragrunt destroy&lt;/code&gt; on a test cluster and get this:&lt;/p&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code class=&#34;language-text&#34; data-lang=&#34;text&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Error: deleting EKS Fargate Profile (test-spain-001:test-spain-001-karpenter-2a):&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;operation error EKS: DeleteFargateProfile, https response error StatusCode: 409,&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;ResourceInUseException: Cannot delete Fargate profile&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;test-spain-001-karpenter-2a because cluster test-spain-001 currently has&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Fargate profile test-spain-001-karpenter-2b in status DELETING&#xA;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Run it again — it works. Run it on the next cluster — it fails again. Welcome to the club.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
