Repository navigation
Unblock deploy: mark clare@ as existing Workspace user - #211
Merged
Merged
Conversation
Deploy runs #289 and #290 (2026-10-05) fail in the refresh pass of `make up` (Makefile:23) with: googleworkspace:index:User (gws-user-clare): Error when reading or editing clare@modelcontextprotocol.io: googleapi: Error 400: Request contains an invalid argument. The account is active in the Admin console, so the stored resource is simply no longer refreshable. Follow the repo precedent for Workspace accounts managed outside Pulumi (bcfc49f ajribeiro/ochafik, 63a42f7 nick, ec18773 den): mark the member existingGWSUser so src/google.ts stops declaring gws-user-clare and its gws-pwd-clare RandomPassword, while her GroupMember resources are still created (now without dependsOn). Because the program no longer declares those two resources, they must leave state before `make up` or Pulumi would plan a real users.delete. Add a one-time TEMP block to the deploy workflow, as in e9e9f1b/93edb25 (state delete before `make up`) and 89cb9de (export/jq/import surgery). `pulumi state delete` cannot be used here: clare's GroupMember records depend on the User, so it refuses without --target-dependents, which would also drop the memberships. The block removes both entries, strips their URNs from the remaining resources' dependencies, re-imports, and is unguarded so a failed surgery fails the deploy loudly. Remove it after the next green deploy. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01SyDWqMwnKtkynCQNahMKxf
Pulumi PreviewClick to expand preview output |
localden
marked this pull request as ready for review
October 5, 2026 15:38
localden
approved these changes
Oct 5, 2026
localden
pushed a commit
that referenced
this pull request
Oct 5, 2026
PR #211 added a TEMP block to the deploy workflow that exported the prod Pulumi state, dropped the gws-user-clare User and gws-pwd-clare RandomPassword entries (and their URNs from other resources' dependencies), and re-imported it before `make up`, so Pulumi would stop managing clare@'s Workspace user once she was marked existingGWSUser. Deploy #291 ran that step without error, so the state surgery has done its job. This drops the block and returns the deploy step to its normal shape. Clare's existingGWSUser flag in src/config/users.ts is unchanged. Claude-Session: https://claude.ai/code/session_01SyDWqMwnKtkynCQNahMKxf Co-authored-by: Claude <noreply@anthropic.com>
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Requested by Den Delimarsky · Slack thread
Before: Deploy #289 and #290 (2026-10-05) fail in the refresh pass of
make up(pulumi up --refresh, Makefile:23): Google returns400: Request contains an invalid argumentonusers.getfor the storedgws-user-clareresource (clare@modelcontextprotocol.io). The account is active in the Admin console, so the resource is simply no longer refreshable, and every deploy since is blocked.After: Pulumi stops managing Clare's User resource, like the other
existingGWSUsermembers (ajribeiro, ochafik, nick, den, ...). Hercore-maintainersgroup membership is unchanged (still declared, now withoutdependsOn), and the deploy's refresh pass no longer reads the user.How: Two changes. (1)
src/config/users.ts:existingGWSUser: trueon Clare's entry, sosrc/google.tsskips declaringgws-user-clareand itsgws-pwd-clareRandomPassword. (2).github/workflows/deploy.yml: a one-time TEMP block beforemake upthat removes exactly those two resources from state (export, jq, re-import), following the precedent of e9e9f1b/93edb25 (state delete beforemake up) and 89cb9de (export/jq/import surgery). The state removal must land together with the flag: with the flag alone the program no longer declares the User, so Pulumi would plan a realusers.deleteof the live account. Deviation from the simplerpulumi state delete ... --yes || trueprecedent: that command refuses to deletegws-user-clarebecause Clare's GroupMember records list it in theirdependencies(Pulumi'sDeleteResourcereturnsResourceHasDependenciesErrorunless--target-dependents, which would also drop her memberships), and the|| trueguard would have turned that refusal into a silent no-op followed by a real delete. The jq surgery removes the two entries, strips their URNs from the remaining resources'dependencies/propertyDependenciessopulumi stack importpasses its integrity check, and is deliberately unguarded so a failed surgery fails the deploy beforemake upruns.Preview note: the PR preview WILL show
- googleworkspace:index/user:User gws-user-clare deleteand- random:index/randomPassword:RandomPassword gws-pwd-clare delete. That is expected in preview (the resources are still in state and preview.yml does not run the deploy's state step) and prevented at deploy by the state-surgery block that runs first. preview.yml runspulumi preview --diffwithout--refresh, so it should not hit the 400.Follow-up: remove the one-time TEMP block from
deploy.ymlafter the first green deploy.🤖 Generated with Claude Code
https://claude.ai/code/session_01SyDWqMwnKtkynCQNahMKxf
Generated by Claude Code