Skip to content

fix(ansible): enable SSM instance targeting - #9

Merged
tanayjdev merged 1 commit into
mainfrom
feat/ansible-ssm-fix
Aug 20, 2026
Merged

tanayjdev merged 1 commit into
mainfrom
feat/ansible-ssm-fix

Conversation

@tanayjdev

Copy link
Copy Markdown
Owner

Fix Ansible AWS SSM inventory targeting and complete the SSM connectivity path for private ASG instances.

…H), first idempotent playbook, verified changed=0 on rerun
Copilot AI lite review requested due to automatic review settings August 20, 2026 14:11

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

Copy link
Copy Markdown

Terraform Plan Result

Acquiring state lock. This may take a few moments...
module.rds.random_password.db_password: Refreshing state... [id=none]
data.aws_availability_zones.available: Reading...
data.aws_ami.latest_packer_build: Reading...
data.aws_ami.ubuntu: Reading...
data.aws_region.current: Reading...
module.main_vpc.aws_eip.nat[0]: Refreshing state... [id=eipalloc-03aff10d08bf89133]
module.asg.aws_iam_role.app_instance: Refreshing state... [id=terraform-mastery-app-instance-role]
module.main_vpc.aws_vpc.this: Refreshing state... [id=vpc-016702f0ed6c85506]
data.aws_caller_identity.current_account: Reading...
module.github_oidc.aws_iam_openid_connect_provider.github_actions: Refreshing state... [id=arn:aws:iam::464975960111:oidc-provider/token.actions.githubusercontent.com]
aws_s3_bucket.ansible_ssm_transfer: Refreshing state... [id=tanay-ansible-ssm-transfer-2026]
data.aws_region.current: Read complete after 0s [id=ap-south-1]
module.rds.aws_secretsmanager_secret.rds_credentials: Refreshing state... [id=terraform-mastery-rds-credentials]
data.aws_vpc.default: Reading...
data.aws_caller_identity.current_account: Read complete after 0s [id=464975960111]
data.aws_caller_identity.current: Reading...
aws_security_group.state_demo: Refreshing state... [id=sg-0fbc18b2768ba7191]
data.aws_caller_identity.current: Read complete after 0s [id=464975960111]
data.aws_iam_policy_document.ec2_assume_role: Reading...
data.aws_iam_policy_document.ec2_assume_role: Read complete after 0s [id=2851119427]
module.rds.aws_db_parameter_group.this: Refreshing state... [id=terraform-mastery-pg-params]
data.aws_availability_zones.available: Read complete after 1s [id=ap-south-1]
module.rds.aws_sns_topic.rds_alerts: Refreshing state... [id=arn:aws:sns:ap-south-1:464975960111:terraform-mastery-rds-alerts]
module.github_oidc.aws_iam_role.terraform_apply: Refreshing state... [id=github-actions-terraform-apply]
module.github_oidc.aws_iam_role.terraform_plan: Refreshing state... [id=github-actions-terraform-plan]
data.aws_ami.latest_packer_build: Read complete after 1s [id=ami-010bc4cb24e6f689e]
data.aws_iam_policy_document.web_server_secrets: Reading...
data.aws_iam_policy_document.web_server_secrets: Read complete after 0s [id=2658366634]
module.asg.aws_iam_role_policy_attachment.ssm: Refreshing state... [id=terraform-mastery-app-instance-role-20260818054358583400000002]
module.asg.aws_iam_role_policy_attachment.secrets: Refreshing state... [id=terraform-mastery-app-instance-role-20260818054358763700000003]
module.asg.aws_iam_instance_profile.app_instance: Refreshing state... [id=terraform-mastery-app-instance-profile]
aws_iam_role.web_server_secrets: Refreshing state... [id=terraform-mastery-web-server-secrets-role]
module.github_oidc.aws_iam_role_policy_attachment.apply_admin: Refreshing state... [id=github-actions-terraform-apply-20260818054358828300000004]
module.github_oidc.aws_iam_role_policy_attachment.plan_readonly: Refreshing state... [id=github-actions-terraform-plan-20260818054358848700000005]
module.github_oidc.aws_iam_role_policy.plan_backend: Refreshing state... [id=github-actions-terraform-plan:github-actions-terraform-plan-backend]
data.aws_ami.ubuntu: Read complete after 1s [id=ami-0aa761682283b4cc8]
aws_iam_role_policy.web_server_secrets: Refreshing state... [id=terraform-mastery-web-server-secrets-role:read-rds-credentials]
aws_iam_instance_profile.web_server: Refreshing state... [id=terraform-mastery-web-server-profile]
module.rds.aws_sns_topic_subscription.rds_alerts_email: Refreshing state... [id=arn:aws:sns:ap-south-1:464975960111:terraform-mastery-rds-alerts:0fdcc913-ae5a-4ec1-89b7-0d187903472b]
data.aws_vpc.default: Read complete after 2s [id=vpc-068d3f58004814661]
aws_security_group.imported_sg: Refreshing state... [id=sg-0e61fcd4f3ed8ee96]
aws_security_group.demo_sg: Refreshing state... [id=sg-07c09914d4ce874f3]
module.main_vpc.aws_internet_gateway.this: Refreshing state... [id=igw-00d90a79438efefd4]
module.main_vpc.aws_subnet.public[0]: Refreshing state... [id=subnet-03f83da4c2ede3641]
module.main_vpc.aws_subnet.public[1]: Refreshing state... [id=subnet-0dd762616728a8a65]
module.main_vpc.aws_subnet.private[1]: Refreshing state... [id=subnet-062363b66b590d170]
module.alb.aws_security_group.alb: Refreshing state... [id=sg-04af7251a979c8daf]
module.main_vpc.aws_subnet.private[0]: Refreshing state... [id=subnet-05b0fac0ac4e69049]
module.alb.aws_lb_target_group.this: Refreshing state... [id=arn:aws:elasticloadbalancing:ap-south-1:464975960111:targetgroup/terraform-mastery-tg/dba9042eea8ae2eb]
module.main_vpc.aws_route_table.public: Refreshing state... [id=rtb-00b6e59cce8ec7f45]
module.asg.aws_security_group.app: Refreshing state... [id=sg-0232654fd2da41617]
module.main_vpc.aws_nat_gateway.this[0]: Refreshing state... [id=nat-05439eeea5f6b969d]
module.alb.aws_lb.this: Refreshing state... [id=arn:aws:elasticloadbalancing:ap-south-1:464975960111:loadbalancer/app/terraform-mastery-alb/e07e9c4c675f2492]
module.main_vpc.aws_route_table_association.public[0]: Refreshing state... [id=rtbassoc-0058b1266eaa699cd]
module.main_vpc.aws_route_table_association.public[1]: Refreshing state... [id=rtbassoc-0eb2859d866024808]
module.rds.aws_db_subnet_group.this: Refreshing state... [id=terraform-mastery-db-subnet-group]
module.rds.aws_security_group.rds: Refreshing state... [id=sg-00be19555dfecf3c1]
module.asg.aws_launch_template.this: Refreshing state... [id=lt-0e40dcefae65b6cc4]
module.main_vpc.aws_route_table.private[0]: Refreshing state... [id=rtb-0162c380846527788]
module.main_vpc.aws_route_table_association.private[1]: Refreshing state... [id=rtbassoc-0e9fe3288ca23fd00]
module.main_vpc.aws_route_table_association.private[0]: Refreshing state... [id=rtbassoc-0b78c8e90f14219b8]
aws_s3_bucket_lifecycle_configuration.ansible_ssm_cleanup: Refreshing state... [id=tanay-ansible-ssm-transfer-2026]
module.rds.aws_db_instance.this: Refreshing state... [id=db-FN6O4O3VIJASAHL4YJLOKF3UZU]
module.rds.aws_secretsmanager_secret_version.rds_credentials: Refreshing state... [id=terraform-mastery-rds-credentials|terraform-20260818055545232800000001]
module.rds.aws_cloudwatch_metric_alarm.low_storage: Refreshing state... [id=terraform-mastery-rds-low-storage]
aws_cloudwatch_dashboard.main: Refreshing state... [id=terraform-mastery-overview]
module.alb.aws_lb_listener.http: Refreshing state... [id=arn:aws:elasticloadbalancing:ap-south-1:464975960111:listener/app/terraform-mastery-alb/e07e9c4c675f2492/a3288cd841714f56]
module.asg.aws_autoscaling_group.this: Refreshing state... [id=terraform-mastery-asg]
module.asg.aws_autoscaling_policy.cpu_target_tracking: Refreshing state... [id=terraform-mastery-cpu-tracking]
module.alb.aws_lb_listener_rule.block_admin: Refreshing state... [id=arn:aws:elasticloadbalancing:ap-south-1:464975960111:listener-rule/app/terraform-mastery-alb/e07e9c4c675f2492/a3288cd841714f56/e45cf816b42902c0]

Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
  ~ update in-place

Terraform will perform the following actions:

  # module.rds.aws_db_instance.this will be updated in-place
  ~ resource "aws_db_instance" "this" {
        id                                    = "db-FN6O4O3VIJASAHL4YJLOKF3UZU"
        tags                                  = {
            "Environment" = "dev"
            "ManagedBy"   = "Terraform"
            "Name"        = "terraform-mastery-db"
            "Project"     = "terraform-mastery"
        }
        # (57 unchanged attributes hidden)
    }

  # module.rds.aws_secretsmanager_secret_version.rds_credentials will be updated in-place
  ~ resource "aws_secretsmanager_secret_version" "rds_credentials" {
        id             = "terraform-mastery-rds-credentials|terraform-20260818055545232800000001"
        # (5 unchanged attributes hidden)
    }

  # module.rds.random_password.db_password will be updated in-place
  ~ resource "random_password" "db_password" {
        id               = "none"
        # (13 unchanged attributes hidden)
    }

Plan: 0 to add, 3 to change, 0 to destroy.

─────────────────────────────────────────────────────────────────────────────

Note: You didn't use the -out option to save this plan, so Terraform can't
guarantee to take exactly these actions if you run "terraform apply" now.
Releasing state lock. This may take a few moments...

@tanayjdev
tanayjdev merged commit 3ec3e63 into main Aug 20, 2026
2 checks passed
@tanayjdev
tanayjdev deleted the feat/ansible-ssm-fix branch August 20, 2026 14:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants