From fcc10a99f7a0720ba663911df6e983643bdfdeae Mon Sep 17 00:00:00 2001 From: Claude Date: Mon, 5 Oct 2026 15:48:46 +0000 Subject: [PATCH] Remove one-time state cleanup for clare@ from deploy PR #211 added a TEMP block to the deploy workflow that exported the prod Pulumi state, dropped the gws-user-clare User and gws-pwd-clare RandomPassword entries (and their URNs from other resources' dependencies), and re-imported it before `make up`, so Pulumi would stop managing clare@'s Workspace user once she was marked existingGWSUser. Deploy #291 ran that step without error, so the state surgery has done its job. This drops the block and returns the deploy step to its normal shape. Clare's existingGWSUser flag in src/config/users.ts is unchanged. Co-Authored-By: Claude Fable 5.1 Claude-Session: https://claude.ai/code/session_01SyDWqMwnKtkynCQNahMKxf --- .github/workflows/deploy.yml | 37 ------------------------------------ 1 file changed, 37 deletions(-) diff --git a/.github/workflows/deploy.yml b/.github/workflows/deploy.yml index c29b730..667fee0 100644 --- a/.github/workflows/deploy.yml +++ b/.github/workflows/deploy.yml @@ -78,41 +78,4 @@ jobs: if [ -n "$CLOUDFLARE_ROLE_MANAGEMENT_TOKEN" ]; then pulumi config set cloudflare:roleManagementToken "$CLOUDFLARE_ROLE_MANAGEMENT_TOKEN" --secret --stack prod fi - # TEMP: one-time state surgery so Pulumi stops managing clare@'s Workspace - # user (existingGWSUser in src/config/users.ts). Deploy runs #289 and #290 - # (2026-10-05) fail in the refresh pass of `make up` because Google returns - # 400 on users.get for the stored gws-user-clare resource although the - # account is active. With the flag set, the program no longer declares - # gws-user-clare or its gws-pwd-clare RandomPassword, so both MUST leave - # state before `make up`, or Pulumi plans a real users.delete. - # `pulumi state delete` is not usable here: clare's GroupMember records list - # the User in their dependencies, so it refuses without --target-dependents - # (which would also drop the memberships from state). Instead: export the - # state, remove both entries, strip their URNs from every remaining - # resource's dependencies, and re-import. Deliberately NOT `|| true`-guarded: - # a failed surgery must fail the deploy loudly rather than let `make up` - # delete the real account. Idempotent: if neither entry is in state, the - # import is skipped. Remove this block after the next green deploy. - STALE_URNS='[ - "urn:pulumi:prod::mcp-access::googleworkspace:index/user:User::gws-user-clare", - "urn:pulumi:prod::mcp-access::random:index/randomPassword:RandomPassword::gws-pwd-clare" - ]' - pulumi stack export --stack prod --file /tmp/state.json - jq --argjson urns "$STALE_URNS" ' - def drop_stale: map(select(. as $d | ($urns | index($d)) | not)); - .deployment.resources |= ( - map(select(.urn as $u | ($urns | index($u)) | not)) - | map( - (if .dependencies then .dependencies |= drop_stale else . end) - | (if .propertyDependencies then .propertyDependencies |= map_values(drop_stale) else . end) - ) - )' /tmp/state.json > /tmp/state-repaired.json - before=$(jq '.deployment.resources | length' /tmp/state.json) - after=$(jq '.deployment.resources | length' /tmp/state-repaired.json) - echo "State surgery: removing $((before - after)) stale gws-user-clare/gws-pwd-clare entries" - if [ "$before" -eq "$after" ]; then - echo "No matching entries in state (already removed); skipping import" - else - pulumi stack import --stack prod --file /tmp/state-repaired.json - fi make up