Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Deprecation: inline rules for SecurityGroup and NetworkAcl resources #3729

Merged
merged 2 commits into from
Mar 26, 2024

Conversation

EronWright
Copy link
Contributor

@EronWright EronWright commented Mar 25, 2024

Marks the ingress and egress properties of ec2.SecurityGroup as deprecated, and emits a warning at deployment time. Same for ec2.NetworkAcl. It is recommended that the standalone "rule" resources be used instead.

The output resembles:

Diagnostics:
  aws:ec2:SecurityGroup (clusterSecurityGroup):
    warning: Use of inline rules is discouraged as they cannot be used in conjunction with any Security Group Rule resources. Doing so will cause a conflict and may overwrite rules.

Closes pulumi/pulumi-eks#1031

@EronWright EronWright requested a review from a team March 25, 2024 22:42
Copy link

Does the PR have any schema changes?

Does the PR have any schema changes?

Looking good! No breaking changes found.
No new resources/functions.

Maintainer note: consult the runbook for dealing with any breaking changes.

@EronWright EronWright marked this pull request as ready for review March 25, 2024 23:12
@t0yv0 t0yv0 requested review from t0yv0 and corymhall March 26, 2024 00:03
@t0yv0 t0yv0 merged commit 8fc4907 into master Mar 26, 2024
23 checks passed
@t0yv0 t0yv0 deleted the eronwright/issue-1031 branch March 26, 2024 16:59
lumiere-bot bot referenced this pull request in coolguy1771/home-ops Apr 3, 2024
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [@pulumi/aws](https://pulumi.io)
([source](https://togithub.com/pulumi/pulumi-aws)) | dependencies |
minor | [`6.27.0` ->
`6.28.2`](https://renovatebot.com/diffs/npm/@pulumi%2faws/6.27.0/6.28.2)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>pulumi/pulumi-aws (@&#8203;pulumi/aws)</summary>

###
[`v6.28.2`](https://togithub.com/pulumi/pulumi-aws/releases/tag/v6.28.2)

[Compare
Source](https://togithub.com/pulumi/pulumi-aws/compare/v6.28.1...v6.28.2)

##### Changelog

- [`60ee1d9`](https://togithub.com/pulumi/pulumi-aws/commit/60ee1d9972)
Correctly set the alt type for `aws_cloudwatch_log_resource_policy`
([#&#8203;3743](https://togithub.com/pulumi/pulumi-aws/issues/3743))
- [`2ee8434`](https://togithub.com/pulumi/pulumi-aws/commit/2ee84343ef)
Update the interface for ECS Container PortMapping with current options
([#&#8203;3043](https://togithub.com/pulumi/pulumi-aws/issues/3043))
- [`bcceea1`](https://togithub.com/pulumi/pulumi-aws/commit/bcceea1a68)
Upgrade pulumi-terraform-bridge to v3.79.0
([#&#8203;3758](https://togithub.com/pulumi/pulumi-aws/issues/3758))
- [`1ee3194`](https://togithub.com/pulumi/pulumi-aws/commit/1ee31944f4)
fix: rds.dataSourceEngineVersionRead panic
([#&#8203;3757](https://togithub.com/pulumi/pulumi-aws/issues/3757))

###
[`v6.28.1`](https://togithub.com/pulumi/pulumi-aws/releases/tag/v6.28.1)

[Compare
Source](https://togithub.com/pulumi/pulumi-aws/compare/v6.27.0...v6.28.1)

##### Changelog

##### What's Changed

- Upstream v5.42.0 by [@&#8203;t0yv0](https://togithub.com/t0yv0) in
[https://github.com/pulumi/pulumi-aws/pull/3728](https://togithub.com/pulumi/pulumi-aws/pull/3728)
- Add support for C7a instance types by
[@&#8203;t0yv0](https://togithub.com/t0yv0) in
[https://github.com/pulumi/pulumi-aws/pull/3734](https://togithub.com/pulumi/pulumi-aws/pull/3734)
- Remove patch for CloudWatch Logging entry in Lambda description by
[@&#8203;guineveresaenger](https://togithub.com/guineveresaenger) in
[https://github.com/pulumi/pulumi-aws/pull/3654](https://togithub.com/pulumi/pulumi-aws/pull/3654)
- Fix rds.ParameterGroup diff not clear
[#&#8203;2442](https://togithub.com/pulumi/pulumi-aws/issues/2442) by
[@&#8203;t0yv0](https://togithub.com/t0yv0) in
[https://github.com/pulumi/pulumi-aws/pull/3638](https://togithub.com/pulumi/pulumi-aws/pull/3638)
- Remove stale doc for acm.CertificateValidation by
[@&#8203;guineveresaenger](https://togithub.com/guineveresaenger) in
[https://github.com/pulumi/pulumi-aws/pull/3656](https://togithub.com/pulumi/pulumi-aws/pull/3656)
- Cleanup: Update import overwrite for Network Firewall Resource Policy
by [@&#8203;guineveresaenger](https://togithub.com/guineveresaenger) in
[https://github.com/pulumi/pulumi-aws/pull/3676](https://togithub.com/pulumi/pulumi-aws/pull/3676)
- Fix updating tags on aws_launch_template by
[@&#8203;t0yv0](https://togithub.com/t0yv0) in
[https://github.com/pulumi/pulumi-aws/pull/3687](https://togithub.com/pulumi/pulumi-aws/pull/3687)
- Update auto-generated AWS managed IAM policies by
[@&#8203;iwahbe](https://togithub.com/iwahbe) in
[https://github.com/pulumi/pulumi-aws/pull/3701](https://togithub.com/pulumi/pulumi-aws/pull/3701)
- Deprecation: inline rules for SecurityGroup and NetworkAcl resources
by [@&#8203;EronWright](https://togithub.com/EronWright) in
[https://github.com/pulumi/pulumi-aws/pull/3729](https://togithub.com/pulumi/pulumi-aws/pull/3729)
- Add EKS service principal for Node.js SDK by
[@&#8203;auvred](https://togithub.com/auvred) in
[https://github.com/pulumi/pulumi-aws/pull/3651](https://togithub.com/pulumi/pulumi-aws/pull/3651)

##### Dependencies

- Upgrade pulumi-terraform-bridge to v3.78.0 by
[@&#8203;pulumi-bot](https://togithub.com/pulumi-bot) in
[https://github.com/pulumi/pulumi-aws/pull/3673](https://togithub.com/pulumi/pulumi-aws/pull/3673)

##### New Contributors

- [@&#8203;EronWright](https://togithub.com/EronWright) made their first
contribution in
[https://github.com/pulumi/pulumi-aws/pull/3729](https://togithub.com/pulumi/pulumi-aws/pull/3729)
- [@&#8203;auvred](https://togithub.com/auvred) made their first
contribution in
[https://github.com/pulumi/pulumi-aws/pull/3651](https://togithub.com/pulumi/pulumi-aws/pull/3651)

**Full Changelog**:
pulumi/pulumi-aws@v6.27.0...v6.28.1

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update
again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://togithub.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4yNzMuMCIsInVwZGF0ZWRJblZlciI6IjM3LjI3Ni4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiJ9-->

Co-authored-by: lumiere-bot[bot] <98047013+lumiere-bot[bot]@users.noreply.github.com>
lumiere-bot bot referenced this pull request in coolguy1771/home-ops Apr 3, 2024
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [@pulumi/aws](https://pulumi.io)
([source](https://togithub.com/pulumi/pulumi-aws)) | dependencies |
minor | [`6.27.0` ->
`6.28.2`](https://renovatebot.com/diffs/npm/@pulumi%2faws/6.27.0/6.28.2)
|

---

> [!WARNING]
> Some dependencies could not be looked up. Check the Dependency
Dashboard for more information.

---

### Release Notes

<details>
<summary>pulumi/pulumi-aws (@&#8203;pulumi/aws)</summary>

###
[`v6.28.2`](https://togithub.com/pulumi/pulumi-aws/releases/tag/v6.28.2)

[Compare
Source](https://togithub.com/pulumi/pulumi-aws/compare/v6.28.1...v6.28.2)

##### Changelog

- [`60ee1d9`](https://togithub.com/pulumi/pulumi-aws/commit/60ee1d9972)
Correctly set the alt type for `aws_cloudwatch_log_resource_policy`
([#&#8203;3743](https://togithub.com/pulumi/pulumi-aws/issues/3743))
- [`2ee8434`](https://togithub.com/pulumi/pulumi-aws/commit/2ee84343ef)
Update the interface for ECS Container PortMapping with current options
([#&#8203;3043](https://togithub.com/pulumi/pulumi-aws/issues/3043))
- [`bcceea1`](https://togithub.com/pulumi/pulumi-aws/commit/bcceea1a68)
Upgrade pulumi-terraform-bridge to v3.79.0
([#&#8203;3758](https://togithub.com/pulumi/pulumi-aws/issues/3758))
- [`1ee3194`](https://togithub.com/pulumi/pulumi-aws/commit/1ee31944f4)
fix: rds.dataSourceEngineVersionRead panic
([#&#8203;3757](https://togithub.com/pulumi/pulumi-aws/issues/3757))

###
[`v6.28.1`](https://togithub.com/pulumi/pulumi-aws/releases/tag/v6.28.1)

[Compare
Source](https://togithub.com/pulumi/pulumi-aws/compare/v6.27.0...v6.28.1)

##### Changelog

##### What's Changed

- Upstream v5.42.0 by [@&#8203;t0yv0](https://togithub.com/t0yv0) in
[https://github.com/pulumi/pulumi-aws/pull/3728](https://togithub.com/pulumi/pulumi-aws/pull/3728)
- Add support for C7a instance types by
[@&#8203;t0yv0](https://togithub.com/t0yv0) in
[https://github.com/pulumi/pulumi-aws/pull/3734](https://togithub.com/pulumi/pulumi-aws/pull/3734)
- Remove patch for CloudWatch Logging entry in Lambda description by
[@&#8203;guineveresaenger](https://togithub.com/guineveresaenger) in
[https://github.com/pulumi/pulumi-aws/pull/3654](https://togithub.com/pulumi/pulumi-aws/pull/3654)
- Fix rds.ParameterGroup diff not clear
[#&#8203;2442](https://togithub.com/pulumi/pulumi-aws/issues/2442) by
[@&#8203;t0yv0](https://togithub.com/t0yv0) in
[https://github.com/pulumi/pulumi-aws/pull/3638](https://togithub.com/pulumi/pulumi-aws/pull/3638)
- Remove stale doc for acm.CertificateValidation by
[@&#8203;guineveresaenger](https://togithub.com/guineveresaenger) in
[https://github.com/pulumi/pulumi-aws/pull/3656](https://togithub.com/pulumi/pulumi-aws/pull/3656)
- Cleanup: Update import overwrite for Network Firewall Resource Policy
by [@&#8203;guineveresaenger](https://togithub.com/guineveresaenger) in
[https://github.com/pulumi/pulumi-aws/pull/3676](https://togithub.com/pulumi/pulumi-aws/pull/3676)
- Fix updating tags on aws_launch_template by
[@&#8203;t0yv0](https://togithub.com/t0yv0) in
[https://github.com/pulumi/pulumi-aws/pull/3687](https://togithub.com/pulumi/pulumi-aws/pull/3687)
- Update auto-generated AWS managed IAM policies by
[@&#8203;iwahbe](https://togithub.com/iwahbe) in
[https://github.com/pulumi/pulumi-aws/pull/3701](https://togithub.com/pulumi/pulumi-aws/pull/3701)
- Deprecation: inline rules for SecurityGroup and NetworkAcl resources
by [@&#8203;EronWright](https://togithub.com/EronWright) in
[https://github.com/pulumi/pulumi-aws/pull/3729](https://togithub.com/pulumi/pulumi-aws/pull/3729)
- Add EKS service principal for Node.js SDK by
[@&#8203;auvred](https://togithub.com/auvred) in
[https://github.com/pulumi/pulumi-aws/pull/3651](https://togithub.com/pulumi/pulumi-aws/pull/3651)

##### Dependencies

- Upgrade pulumi-terraform-bridge to v3.78.0 by
[@&#8203;pulumi-bot](https://togithub.com/pulumi-bot) in
[https://github.com/pulumi/pulumi-aws/pull/3673](https://togithub.com/pulumi/pulumi-aws/pull/3673)

##### New Contributors

- [@&#8203;EronWright](https://togithub.com/EronWright) made their first
contribution in
[https://github.com/pulumi/pulumi-aws/pull/3729](https://togithub.com/pulumi/pulumi-aws/pull/3729)
- [@&#8203;auvred](https://togithub.com/auvred) made their first
contribution in
[https://github.com/pulumi/pulumi-aws/pull/3651](https://togithub.com/pulumi/pulumi-aws/pull/3651)

**Full Changelog**:
pulumi/pulumi-aws@v6.27.0...v6.28.1

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined),
Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the
rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.

---

- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box

---

This PR has been generated by [Renovate
Bot](https://togithub.com/renovatebot/renovate).

<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy4yNzMuMCIsInVwZGF0ZWRJblZlciI6IjM3LjI3Ni4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiJ9-->

Co-authored-by: lumiere-bot[bot] <98047013+lumiere-bot[bot]@users.noreply.github.com>
EronWright added a commit that referenced this pull request Apr 8, 2024
t0yv0 pushed a commit that referenced this pull request Apr 9, 2024
EronWright added a commit that referenced this pull request Apr 9, 2024
…sources" (#3785)

This reverts commit 8fc4907 from
#3729

The warning message is considered too noisy for this sort of issue.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

eksClusterIngressRule stuck in delete-recreate cycle
3 participants