From 0c3ca588d244cafba1290c608478fce37732d86b Mon Sep 17 00:00:00 2001 From: Yu Jiang Date: Fri, 29 Mar 2024 11:59:52 -0700 Subject: [PATCH] skip deletion if rolename is not present (#197) Signed-off-by: Yu Jiang Co-authored-by: Yu Jiang --- internal/controllers/iamrole_controller.go | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/internal/controllers/iamrole_controller.go b/internal/controllers/iamrole_controller.go index 4137daf..f6abce4 100644 --- a/internal/controllers/iamrole_controller.go +++ b/internal/controllers/iamrole_controller.go @@ -101,7 +101,10 @@ func (r *IamroleReconciler) Reconcile(ctx context.Context, req ctrl.Request) (ct iamRole.Status.RetryCount = iamRole.Status.RetryCount + 1 } log.Info("Iamrole delete request") - if iamRole.Status.State != iammanagerv1alpha1.PolicyNotAllowed { + + // If PolicyNotAllowed, we should not have any role created. + // If RoleNameNotAvailable, the role should be deleted. + if iamRole.Status.State != iammanagerv1alpha1.PolicyNotAllowed && iamRole.Status.RoleName != "" { //Get the roleName from status roleName := iamRole.Status.RoleName if err := r.IAMClient.DeleteRole(ctx, roleName); err != nil {