Skip to content

Migrate vulnerability_alerts off deprecated repo argument - #6

Merged
nickvigilante merged 1 commit into
mainfrom
refactor-vulnerability-alerts
May 11, 2026
Merged

Migrate vulnerability_alerts off deprecated repo argument#6
nickvigilante merged 1 commit into
mainfrom
refactor-vulnerability-alerts

Conversation

@nickvigilante

Copy link
Copy Markdown
Owner

Summary

Provider deprecated github_repository.vulnerability_alerts in favor of the dedicated github_repository_vulnerability_alerts resource. Every plan was emitting one warning per managed repo — 17 in total — drowning out real signal.

Changes:

  • Drop the vulnerability_alerts = each.value.vulnerability_alerts line from github_repository.managed.
  • Add lifecycle.ignore_changes = [vulnerability_alerts] so removing the field doesn't cause Tofu to call the disable API on the existing state.
  • Add github_repository_vulnerability_alerts.alerts for each repo where the resolved config wants alerts on. The provider's create function calls GitHub's enable endpoint, which is idempotent against already-enabled repos — so no behavioral change.

Applied locally so cluster (well, GitHub) state matches before merge:

Plan: 10 to add, 0 to change, 0 to destroy.
Apply complete! Resources: 10 added, 0 changed, 0 destroyed.

After this lands, the 17 vulnerability_alerts warnings collapse to 1 — that last one comes from referencing the deprecated attribute name inside ignore_changes, which is unavoidable until the provider drops the attribute entirely.

Test plan

  • tofu plan shows 10 adds, 0 changes, 0 destroys
  • No github_repository.managed[*] resources show a vulnerability_alerts: true -> false diff (the dangerous case)
  • tofu apply succeeds
  • Re-running tofu plan after apply is a no-op (idempotent)
  • Warning count drops from 17 → 1 for this deprecation

The `vulnerability_alerts` attribute on `github_repository` is deprecated
in favor of the dedicated `github_repository_vulnerability_alerts`
resource. Until now every plan emitted one warning per managed repo
(17 total).

Migration approach:

- Drop the `vulnerability_alerts` assignment from `github_repository.managed`.
- Add `lifecycle.ignore_changes = [vulnerability_alerts]` so removing the
  field doesn't cause Tofu to call the disable API on the existing state.
- Add `github_repository_vulnerability_alerts.alerts` for each repo where
  the resolved config wants alerts on. Provider's create is idempotent
  against the GitHub enable endpoint, so no behavioral change.

Applied locally: 10 to add, 0 to change, 0 to destroy. The 17 warnings
collapse to 1 (the unavoidable reference inside `ignore_changes`).
@github-actions

Copy link
Copy Markdown

homelab tofu plan

Plan output
tailscale_dns_nameservers.global: Refreshing state... [id=34619e51-87ec-b5df-c078-fd2e3181d9c5]
tailscale_dns_preferences.main: Refreshing state... [id=ad9f64d5-f380-ae42-4811-7604bfdb5bcd]
data.github_user.self: Reading...
github_repository.managed["dotfiles"]: Refreshing state... [id=dotfiles]
github_repository.managed["infrastructure"]: Refreshing state... [id=infrastructure]
github_repository.managed["tools"]: Refreshing state... [id=tools]
github_repository.managed["passgen"]: Refreshing state... [id=passgen]
github_repository.managed["homelab"]: Refreshing state... [id=homelab]
github_repository.managed["puzzles"]: Refreshing state... [id=puzzles]
github_repository.managed["styleguide"]: Refreshing state... [id=styleguide]
github_repository.managed["tuile"]: Refreshing state... [id=tuile]
github_repository.managed["vale-languagetool"]: Refreshing state... [id=vale-languagetool]
github_repository.managed["docs"]: Refreshing state... [id=docs]
data.github_user.self: Read complete after 3s [id=13631471]
github_actions_secret.github_app_id: Refreshing state... [id=infrastructure:TF_GITHUB_APP_ID]
github_actions_secret.tailscale_oauth_client_id: Refreshing state... [id=infrastructure:TAILSCALE_OAUTH_CLIENT_ID]
github_repository_environment.homelab_apply: Refreshing state... [id=infrastructure:homelab-apply]
github_actions_secret.aws_secret_access_key: Refreshing state... [id=infrastructure:AWS_SECRET_ACCESS_KEY]
github_actions_secret.tailscale_oauth_client_secret: Refreshing state... [id=infrastructure:TAILSCALE_OAUTH_CLIENT_SECRET]
github_branch_protection.main["passgen"]: Refreshing state... [id=BPR_kwDOPAgUIM4Ek1Lp]
github_actions_secret.github_app_private_key: Refreshing state... [id=infrastructure:TF_GITHUB_APP_PRIVATE_KEY]
github_branch_protection.main["tuile"]: Refreshing state... [id=BPR_kwDOSB7YJc4Ek1LN]
github_branch_protection.main["docs"]: Refreshing state... [id=BPR_kwDOSFgwGs4Ek1Ll]
github_branch_protection.main["puzzles"]: Refreshing state... [id=BPR_kwDOSMxZ4c4Ek1Lo]
github_branch_protection.main["vale-languagetool"]: Refreshing state... [id=BPR_kwDONCBpAs4Ek1LO]
github_branch_protection.main["dotfiles"]: Refreshing state... [id=BPR_kwDOKUP2984EclBF]
github_branch_protection.main["infrastructure"]: Refreshing state... [id=BPR_kwDOSZwzas4Ek1LQ]
github_branch_protection.main["styleguide"]: Refreshing state... [id=BPR_kwDONEbTDs4Ek1Lj]
github_branch_protection.main["tools"]: Refreshing state... [id=BPR_kwDOCpIRFs4CjUwo]
github_branch_protection.main["homelab"]: Refreshing state... [id=BPR_kwDOSZ4rVc4Ek1bm]
github_repository_vulnerability_alerts.alerts["homelab"]: Refreshing state... [id=1235102549]
github_actions_secret.github_app_installation_id: Refreshing state... [id=infrastructure:TF_GITHUB_APP_INSTALLATION_ID]
github_repository_vulnerability_alerts.alerts["vale-languagetool"]: Refreshing state... [id=874539266]
github_repository_vulnerability_alerts.alerts["docs"]: Refreshing state... [id=1213739034]
github_repository_vulnerability_alerts.alerts["styleguide"]: Refreshing state... [id=877056782]
github_repository_vulnerability_alerts.alerts["infrastructure"]: Refreshing state... [id=1234973546]
github_repository_vulnerability_alerts.alerts["tools"]: Refreshing state... [id=177344790]
github_repository_vulnerability_alerts.alerts["passgen"]: Refreshing state... [id=1007162400]
github_repository_vulnerability_alerts.alerts["puzzles"]: Refreshing state... [id=1221351905]
github_repository_vulnerability_alerts.alerts["tuile"]: Refreshing state... [id=1209980965]
github_repository_vulnerability_alerts.alerts["dotfiles"]: Refreshing state... [id=692319991]
github_actions_secret.aws_access_key_id: Refreshing state... [id=infrastructure:AWS_ACCESS_KEY_ID]

No changes. Your infrastructure matches the configuration.

OpenTofu has compared your real infrastructure against your configuration and
found no differences, so no changes are needed.

Warning: Deprecated attribute

  on github.tf line 32, in resource "github_repository" "managed":
  32:     ignore_changes = [vulnerability_alerts]

The attribute "vulnerability_alerts" is deprecated. Refer to the provider
documentation for details.

Warning: Argument is deprecated

  with github_actions_secret.tailscale_oauth_client_id,
  on github.tf line 85, in resource "github_actions_secret" "tailscale_oauth_client_id":
  85:   plaintext_value = var.tailscale_oauth_client_id

Use value.

(and 6 more similar warnings elsewhere)

@nickvigilante
nickvigilante merged commit 7bbd65a into main May 11, 2026
1 check passed
@nickvigilante
nickvigilante deleted the refactor-vulnerability-alerts branch May 11, 2026 23:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant