Skip to content

Restart instance to update secgroup - #351

Open
bddvlpr wants to merge 1 commit into
apache:mainfrom
bddvlpr:fix/instance-sg-recreate
Open

bddvlpr wants to merge 1 commit into
apache:mainfrom
bddvlpr:fix/instance-sg-recreate

Conversation

@bddvlpr

@bddvlpr bddvlpr commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

This addition makes it so security_group_ids and security_group_names attributes passed to instances do not require recreation of the resource. Instead it will (per official support) temporarily shut down the instance, apply these changes, and restart it after.
It will attempt to restart the instance regardless on if the state change was successful or not. Previously stopped instances will not be restarted.

Copilot AI lite review requested due to automatic review settings September 17, 2026 06:55

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Acceptance coverage is missing for the new update and lifecycle behavior.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

This pull request enables in-place instance security-group updates while preserving stopped-state behavior.

Changes:

  • Removes ForceNew from security-group attributes.
  • Adds stop, update, and restart lifecycle handling.
  • Updates instance documentation.
File summaries
File Summary Review note
website/docs/r/instance.html.markdown Documents the updated behavior. None
cloudstack/resource_cloudstack_instance.go Implements in-place security-group updates and lifecycle handling. Moderate: add acceptance coverage for security-group updates and restart-state behavior (3 votes).
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 1
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +859 to +864
// Update security groups once, even when switching between names and IDs.
if d.HasChange("security_group_ids") || d.HasChange("security_group_names") {
p := cs.VirtualMachine.NewUpdateVirtualMachineParams(d.Id())
ids := d.Get("security_group_ids").(*schema.Set)
names := d.Get("security_group_names").(*schema.Set)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants