Skip to content

fix(alicloud): allow existing ACK cluster tag updates - #158

Merged
maxsxu merged 3 commits into
mainfrom
max/fix-alicloud-ack-cluster-tags
Sep 22, 2026
Merged

maxsxu merged 3 commits into
mainfrom
max/fix-alicloud-ack-cluster-tags

Conversation

@maxsxu

@maxsxu maxsxu commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

Existing ACK clusters cannot add or backfill tags through provisioning because the vendor-access policy omits cs:ModifyClusterTags. This adds the action to the existing ACK allow statement, using its existing Resource: "*" scope. The shared policy updates both streamnative-bootstrap and streamnative-support.

CI now explicitly validates the AliCloud vendor-access module.

Validation:

  • Policy JSON parsing, Terraform formatting, and git diff --check pass.
  • terraform validate passes with the pinned provider v1.248.0.
  • Live ACK tag updates and full provision2 execution are not tested.

Fixes #157

@maxsxu
maxsxu requested a review from a team as a code owner September 18, 2026 10:37
@maxsxu
maxsxu requested a review from tuteng September 18, 2026 11:09
@maxsxu
maxsxu merged commit 286a4ef into main Sep 22, 2026
6 checks passed
@maxsxu
maxsxu deleted the max/fix-alicloud-ack-cluster-tags branch September 22, 2026 04:37
maxsxu pushed a commit that referenced this pull request Sep 22, 2026
🤖 I have created a release *beep* *boop*
---


##
[3.25.2](v3.25.1...v3.25.2)
(2026-09-22)


### Bug Fixes

* **alicloud:** allow existing ACK cluster tag updates
([#158](#158))
([286a4ef](286a4ef)),
closes
[#157](#157)

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[AliCloud] Allow provisioning role to update ACK cluster tags

2 participants