Skip to content

Handle stale terraform locks after nixpkgs bumps - #7

Open
kmein wants to merge 3 commits into
mainfrom
update
Open

Handle stale terraform locks after nixpkgs bumps #7
kmein wants to merge 3 commits into
mainfrom
update

Conversation

@kmein

@kmein kmein commented Sep 1, 2026

Copy link
Copy Markdown
Collaborator

I just ran into this after a nixpkgs bump: Terraform locks the used provider version and will refuse to run if the current version differs from the locked one.

The generated required_providers version is pinned to the nixpkgs-packaged
provider, so bumping nixpkgs moves the constraint while
.terraform.lock.hcl under the service state dir still pins the previous
version, and init aborts with "locked provider ... does not match
configured version constraint". Re-selecting is offline: withPlugins' dir
is the only source.
Hosts that ran a revision before `tofu init -upgrade` stay stuck on the
old lock; document dropping it and restarting the reconciler.
Plants a stale .terraform.lock.hcl (recorded version rewritten to 0.0.1)
and restarts the reconciler. Without `tofu init -upgrade` this fails with
"locked provider ... does not match configured version constraint" --
verified by reverting the flag, which fails the test. The VM has no
network, so re-locking here also proves the re-selection stays offline.
@kmein
kmein requested a review from aforemny September 1, 2026 09:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant