You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
A common minor niggle I run into using Terraform these days is getting SSH host key mismatches when re-provisioning a machine with a static IP or creating a new one in a small subnet in our AWS development environment.
@ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that a host key has just been changed.
The fingerprint for the RSA key sent by the remote host is
SHA256:w4yYen8fzP8mBv/wl1uG+y337dLZFsVLZUCuyLiMax8.
Please contact your system administrator.
Add correct host key in /Users/jack/.ssh/known_hosts to get rid of this message.
Offending RSA key in /Users/jack/.ssh/known_hosts:158
RSA host key for 172.28.131.8 has changed and you have requested strict checking.
Host key verification failed.
It's simple enough to run the command sed -i.bak -e '158d' ~/.ssh/known_hosts, but still slightly tedious, and something I think it might be good for Terraform to be able to do.
I'm interested in adding this functionality myself, but I'm not sure where to start. I think it should be platform agnostic, so able to work with aws_instance, azure_virtual_machine, google_compute_instance etc. but I'm not sure where the best place for an end user to specify it would be. In the provider block? The resource itself?
Any help or feedback on how/where to get started would be greatly appreciated.
The text was updated successfully, but these errors were encountered:
local-exec would work, but seems a little messy to me. We currently use Makefiles in our projects to force a slightly less error prone workflow and I've the functionality there with: @ssh-keygen -R jq -cr '.modules[].resources[] | select(.type | contains("aws_instance")) | .primary.attributes.private_ip' < .terraform/terraform.tfstate`` after an apply, which still isn't ideal imo, but cleaner than a local-exec in every project imo.
A common minor niggle I run into using Terraform these days is getting SSH host key mismatches when re-provisioning a machine with a static IP or creating a new one in a small subnet in our AWS development environment.
It's simple enough to run the command
sed -i.bak -e '158d' ~/.ssh/known_hosts
, but still slightly tedious, and something I think it might be good for Terraform to be able to do.I'm interested in adding this functionality myself, but I'm not sure where to start. I think it should be platform agnostic, so able to work with
aws_instance
,azure_virtual_machine
,google_compute_instance
etc. but I'm not sure where the best place for an end user to specify it would be. In the provider block? The resource itself?Any help or feedback on how/where to get started would be greatly appreciated.
The text was updated successfully, but these errors were encountered: