Kubernetes (envbox) template: Unexpected Identity Change
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 初心者へのやさしさ
- 35/100
- issue の種類
- バグ
- 明瞭さ
- おおむね明確
- 活発さ
- 停滞
- 技術スタック
- kubernetes, terraform
- 領域
- devops, infrastructure
調査の方向性
kubernetes_pod.main リソースが宣言されている modules/kubernetes-workspace/main.tf の 17 行目から始め、Terraform を再度 apply する前に Workspace を再起動または再スケジュールして失敗を再現します。保存されている pod の identity と返された pod の identity を比較し、再スケジュール後に既存の Workspace が正常に reconcile されるために必要な変更を特定します。Terraform apply が Unexpected Identity Change エラーなしで完了することを確認します。
索引モデルが issue の本文から書いたものです。
説明
I am using the Coder Kubernetes (envbox) template to deploy my Coder workspaces. Recently, I encountered the following error when applying Terraform:
Error: Unexpected Identity Change: During the read operation, the Terraform Provider unexpectedly returned a different identity than the previously stored one. This is always a problem with the provider and should be reported to the provider developer. Current Identity: cty.ObjectVal(map[string]cty.Value{"api_version":cty.NullVal(cty.String), "kind":cty.NullVal(cty.String), "name":cty.NullVal(cty.String), "namespace":cty.NullVal(cty.String)}) New Identity: cty.ObjectVal(map[string]cty.Value{"api_version":cty.StringVal("v1"), "kind":cty.StringVal("Pod"), "name":cty.StringVal("coderws-peter-minikube"), "namespace":cty.StringVal("coder-workspace")})
on modules/kubernetes-workspace/main.tf line 17, in resource "kubernetes_pod" "main": 17: resource "kubernetes_pod" "main" {
Steps to Reproduce
- Deploy Coder workspaces using the envbox Kubernetes template via Terraform.
- Trigger a restart of the workspace, or perform a rolling update / move the pod to another node.
- Apply Terraform again.
Observed Behavior
Terraform fails with the Unexpected Identity Change error and cannot recognize the existing pod, preventing the workspace from starting.
Hypothesis
It seems that when a pod is rescheduled to another node or after a rolling update, its metadata changes. Terraform then sees a “new” pod identity and fails to reconcile it with the previously stored state.
Environment
Kubernetes (envbox) template Provider:
- hashicorp/kubernetes Version: 2.38.0
- coder/coder Version: 2.12.0
Kubernetes version: 1.33.2
Coder Version: 2.26.3
Is the following a possible workaround?
Use kubernetes_deployment instead of kubernetes_pod for workspaces. Deployments manage pods automatically, and Terraform tracks the deployment resource rather than the ephemeral pods, which avoids identity change issues.
- 主要言語
- HCL
- スター
- 81
- フォーク
- 168
- 平均マージ
- 3日 2時間
- マージ済み PR(30日)
- 36
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
coder/registry のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
coder/registry#1142 · コメント 2 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 半日 初心者へのやさしさ 68/100
coder/registry#1120 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
OpenShift template対応中かも @Edd88-pixel が 5 日前に担当しました。 オープン
難易度 4/5 3〜5日 初心者へのやさしさ 50/100
coder/registry#1162 · コメント 1 件 · 担当者 1 名 ·
メンテナーはふだん 1 日以内に返信
-
bug: claude-code keeps stale configuration after managed settings or API key helper are disabled対応中かも @Edd88-pixel が 11 日前に担当しました。 オープン
coder/registry#1156 · コメント 1 件 · リアクション 1 件 · 担当者 1 名 ·
メンテナーはふだん 1 日以内に返信
-
chore: ensure that AWS EC2 instances actually use the AWS region module対応中かも @phorcys420 が 10 日前に担当しました。 オープン
coder/registry#1122 · コメント 1 件 · 担当者 1 名 ·
メンテナーはふだん 1 日以内に返信
似ている issue
-
good first issue track:tests
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
Sara-Managed-Projects/space-radar#848 ·
メンテナーはふだん 1 日以内に返信
-
Status: Untriaged
難易度 1/5 1時間未満 初心者へのやさしさ 85/100
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
components-web-app/docs#195 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
zerocracy/judges-action#2733 ·
メンテナーはふだん 8 日以内に返信
-
[Nginx] Warning: duplicate extension "wasm" in nextcloud.conf対応中かも このイシューにリンクされたプルリクエストがオープン中、またはマージ済みです。 オープン
難易度 1/5 1時間未満 初心者へのやさしさ 74/100
YunoHost-Apps/nextcloud_ynh#916 ·
メンテナーはふだん 1 日以内に返信