Skip to content

Remove IAM user alexe - #215

Merged
ale210 merged 1 commit into
mainfrom
212-remove-iam-user-alexe
Oct 4, 2026
Merged

ale210 merged 1 commit into
mainfrom
212-remove-iam-user-alexe

Conversation

@ale210

@ale210 ale210 commented Oct 4, 2026

Copy link
Copy Markdown
Member

Part of #212 (end-to-end test, step 1 of 2: remove alexe; a follow-up PR recreates the account as ale210, named after the GitHub handle, with a slack_id so the user-bot DMs it a temporary password)

What changes did you make?

  • Removed the iam_user_alexe module block from terraform/aws-users.tf

Why did you make the changes (we will use this info to test)?

  • The account is being recreated under the GitHub handle ale210, as the naming convention expects, and the new user's CreateLoginProfile is the end-to-end test for the user-bot
  • Expected plan: 0 to add, 0 to change, 3 to destroy: the user, its login profile and its ops-leads membership
  • force_destroy also deletes the user's access key and a directly attached IAMUserChangePassword policy that was never in Terraform. Both are intended

@github-actions

github-actions Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

Terraform plan in terraform
With backend config files: terraform/prod.backend.tfvars
With variables: iam_only = false

Plan: 0 to add, 0 to change, 3 to destroy.
Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
-   destroy

Terraform will perform the following actions:

  # module.iam_user_alexe.aws_iam_user.user will be destroyed
  # (because aws_iam_user.user is not in configuration)
-   resource "aws_iam_user" "user" {
-       arn                  = "arn:aws:iam::035866691871:user/alexe" -> null
-       force_destroy        = true -> null
-       id                   = "alexe" -> null
-       name                 = "alexe" -> null
-       path                 = "/" -> null
-       tags                 = {
-           "Access Level" = "1"
-           "Project"      = "devops-security"
        } -> null
-       tags_all             = {
-           "Access Level" = "1"
-           "Project"      = "devops-security"
-           "managed-by"   = "terraform-devops-security"
        } -> null
-       unique_id            = "AIDAQQWOSJEPUDCMYCMNE" -> null
#        (1 unchanged attribute hidden)
    }

  # module.iam_user_alexe.aws_iam_user_group_membership.user_group_membership will be destroyed
  # (because aws_iam_user_group_membership.user_group_membership is not in configuration)
-   resource "aws_iam_user_group_membership" "user_group_membership" {
-       groups = [
-           "ops-leads",
        ] -> null
-       id     = "terraform-20240815021728326500000001" -> null
-       user   = "alexe" -> null
    }

  # module.iam_user_alexe.aws_iam_user_login_profile.user_login will be destroyed
  # (because aws_iam_user_login_profile.user_login is not in configuration)
-   resource "aws_iam_user_login_profile" "user_login" {
-       id                      = "alexe" -> null
-       password                = (sensitive value) -> null
-       password_length         = 20 -> null
-       password_reset_required = false -> null
-       user                    = "alexe" -> null
    }

Plan: 0 to add, 0 to change, 3 to destroy.

✅ Plan applied in Apply Terraform changes on merge #52

@ale210
ale210 merged commit 813c38e into main Oct 4, 2026
2 checks passed
@ale210
ale210 deleted the 212-remove-iam-user-alexe branch October 4, 2026 22:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant