Skip to content

Commit a1a0c3c

Browse files
authored
Merge pull request #12 from data-platform-hq/fix_ingore_rotated_key
fix: ignore tde key id on rotation
2 parents fa886d2 + 80b3d4e commit a1a0c3c

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

main.tf

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,11 @@ resource "azurerm_mssql_server_transparent_data_encryption" "this" {
4848
key_vault_key_id = var.key_vault_key_id
4949
auto_rotation_enabled = var.auto_rotation_enabled
5050

51+
# When automated TDE Key rotation is enabled, it is required to ignore new Key id for state consistency.
52+
lifecycle {
53+
ignore_changes = [key_vault_key_id]
54+
}
55+
5156
depends_on = [azurerm_key_vault_access_policy.tde_policy]
5257
}
5358

0 commit comments

Comments
 (0)