Skip to content

azurerm_api_management[_custom_domain] - fix certificate update behaviour#31534

Merged
sreallymatt merged 3 commits intomainfrom
mp/apim-certificates
Jan 21, 2026
Merged

azurerm_api_management[_custom_domain] - fix certificate update behaviour#31534
sreallymatt merged 3 commits intomainfrom
mp/apim-certificates

Conversation

@sreallymatt
Copy link
Collaborator

@sreallymatt sreallymatt commented Jan 19, 2026

Community Note

  • Please vote on this PR by adding a 👍 reaction to the original PR to help the community and maintainers prioritize for review
  • Please do not leave comments along the lines of "+1", "me too" or "any updates", they generate extra noise for PR followers and do not help prioritize for review

Description

Cause of this issue was due to the behaviour of O+C properties. Terraform returns the old state value for key_vault_id, which would then overwrite the new value of key_vault_certificate_id preventing cert updates when using this field.

  • fixes update functionality for *.key_vault_certificate_id in both resources by using RawConfig to determine whether key_vault_id was set.
  • adds additional tests as this regression was previously not caught

PR Checklist

  • I have followed the guidelines in our Contributing Documentation.
  • I have checked to ensure there aren't other open Pull Requests for the same update/change.
  • I have checked if my changes close any open issues. If so please include appropriate closing keywords below.
  • I have updated/added Documentation as required written in a helpful and kind way to assist users that may be unfamiliar with the resource / data source.
  • I have used a meaningful PR title to help maintainers and other users understand this change and help prevent duplicate work.
    For example: “resource_name_here - description of change e.g. adding property new_property_name_here

Changes to existing Resource / Data Source

  • I have added an explanation of what my changes do and why I'd like you to include them (This may be covered by linking to an issue above, but may benefit from additional explanation).
  • I have written new tests for my resource or datasource changes & updated any relevant documentation.
  • I have successfully run tests with my changes locally. If not, please provide details on testing challenges that prevented you running the tests.
  • (For changes that include a state migration only). I have manually tested the migration path between relevant versions of the provider.

Testing

  • My submission includes Test coverage as described in the Contribution Guide and the tests pass. (if this is not possible for any reason, please include details of why you did or could not add test coverage)

4.0 tests:
single new failure was due to hitting a SKU quota limit
image

5.0 tests:
image

Change Log

Below please provide what should go into the changelog (if anything) conforming to the Changelog Format documented here.

  • azurerm_resource - support for the thing1 property [GH-00000]

This is a (please select all that apply):

  • Bug Fix
  • New Feature (ie adding a service, resource, or data source)
  • Enhancement
  • Breaking Change

Related Issue(s)

Fixes #31450

AI Assistance Disclosure

  • AI Assisted - This contribution was made by, or with the assistance of, AI/LLMs

Rollback Plan

If a change needs to be reverted, we will publish an updated version of the provider.

Changes to Security Controls

Are there any changes to security controls (access controls, encryption, logging) in this pull request? If so, explain.

Note

If this PR changes meaningfully during the course of review please update the title and description as required.

@sreallymatt sreallymatt changed the title azurerm_api_management[_custom_domain - fix certificate update behaviour azurerm_api_management[_custom_domain] - fix certificate update behaviour Jan 19, 2026
@teowa
Copy link
Collaborator

teowa commented Jan 19, 2026

Hi @sreallymatt , thanks for the PR, this fixes #31450

@github-actions github-actions bot added the bug label Jan 20, 2026
@sreallymatt sreallymatt marked this pull request as ready for review January 20, 2026 19:17
@sreallymatt sreallymatt requested review from a team, WodansSon and magodo as code owners January 20, 2026 19:17
Copy link
Member

@mbfrahry mbfrahry left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@sreallymatt sreallymatt merged commit 5c57424 into main Jan 21, 2026
49 checks passed
@sreallymatt sreallymatt deleted the mp/apim-certificates branch January 21, 2026 16:13
@github-actions github-actions bot added this to the v4.58.0 milestone Jan 21, 2026
@github-actions
Copy link
Contributor

I'm going to lock this pull request because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active contributions.
If you have found a problem that seems related to this change, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Feb 21, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

APIM Custom Domain Certificate Not Refreshing from Key Vault via Terraform

3 participants