Update Terraform - #555
Conversation
|
Caution [High Risk] Replacing the core-api instance will break the current transaction-feed backend on The Reassociating the Elastic IP SignalsRoutine → Multiple compute and infrastructure resources showing unusual infrequent routine changes at 1-3 events/week for the last 2-5 months, with several resources at 1 event/week for the last 5 months and 1 event/week for the last 2 months, which is infrequent compared to typical patterns. Additional Change Details: |
0ca79d2 to
2e1b402
Compare
895ca34 to
1c80533
Compare
1c80533 to
4781cfb
Compare
This PR contains the following updates:
< 6.55→< 6.606.54.0→6.59.06.37.0→6.59.07.39.0→7.44.07.5.0→7.6.0Release Notes
hashicorp/terraform-provider-aws (aws)
v6.59.0Compare Source
FEATURES:
aws_rds_snapshots(#49259)aws_resiliencehubv2_policy(#48324)aws_resiliencehubv2_service(#48326)aws_resiliencehubv2_system(#48325)aws_vpclattice_service_network_service_associations(#42680)aws_backup_plan(#49329)aws_backup_selection(#49283)aws_backup_vault(#49423)aws_bedrockagentcore_gateway_rule(#48804)aws_mailmanager_ingress_point(#49322)aws_neptunegraph_private_graph_endpoint(#45929)aws_networkfirewall_container_association(#49321)aws_pinpointsmsvoicev2_resource_policy(#48771)aws_pinpointsmsvoicev2_sender_id(#46472)aws_resiliencehubv2_service(#48323)aws_resiliencehubv2_system(#48322)aws_ssm_patch_baseline(#49332)aws_bedrockagentcore_gateway_rule(#48804)aws_mailmanager_ingress_point(#49322)aws_neptunegraph_private_graph_endpoint(#45929)aws_networkfirewall_container_association(#49321)aws_pinpointsmsvoicev2_resource_policy(#48771)aws_pinpointsmsvoicev2_sender_id(#46472)aws_resiliencehubv2_service(#48323)aws_resiliencehubv2_system(#48322)ENHANCEMENTS:
kube_api_server_config,kube_controller_manager_config, andkube_scheduler_configattributes (#49420)control_plane_component_configandcontrol_plane_scaling_tiersattributes (#49421)step.aurora_provisioned_scaling_config,step.aurora_serverless_scaling_config,step.neptune_global_database_config, andstep.lambda_event_source_mapping_configarguments (#48392)report_configurationandreport_configuration.report_output.s3_configurationto a single block each (#46758)target_configuration.mcp.mcp_server.mcp_tool_schemaconfiguration block andtarget_configuration.mcp.mcp_server.resource_priorityargument (#48703)memory_actual(#49383)memory.disabled(#49334)memory.managed_memory_configuration(#49285)policy_details.parameters.exclude_data_volume_tagsargument (#45113)transit_gateway_attachment_idattribute (#49274)target_vpc_subnet_idto Optional (#49274)timeoutsvalues to30m(#49274)kube_api_server_config,kube_controller_manager_config, andkube_scheduler_configarguments (#49412)exporterconfiguration block with OpenSearch exporter support (#49346)pre_parse_text_transformationargument tobyte_match_statement,regex_match_statement,regex_pattern_set_reference_statement,size_constraint_statement,sqli_match_statement, andxss_match_statementrule statements (#49381)pre_parse_text_transformationargument tobyte_match_statement,regex_match_statement,regex_pattern_set_reference_statement,size_constraint_statement,sqli_match_statement, andxss_match_statementrule statements (#49381)BUG FIXES:
reading MQ Broker (...) shared resourceserrors when reading RabbitMQ brokers in partitions wheremq:DescribeSharedResourcesis unavailable, such as AWS GovCloud (US) (#49340)metadata_configurationrequest and response headers (#49374)CREATE_PENDING_AUTHandUPDATE_PENDING_AUTHstatuses as successful terminal states (#48703)reading MQ Broker (...) shared resourceserrors when reading RabbitMQ brokers in partitions wheremq:DescribeSharedResourcesis unavailable, such as AWS GovCloud (US) (#49340)InvalidParameterCombinationerror whenengine_versionis updated externally (#49396)UpdateDomainContactPrivacybeing incorrectly triggered whenbilling_contactchanges (#49314)namewith a leading slash and no other slashes was stripping the leading slash. (#49339)v6.58.0Compare Source
FEATURES:
aws_mailmanager_rule_set(#49257)aws_prometheus_anomaly_detector(#49139)aws_prometheus_scraper(#47466)aws_prometheus_scraper_logging_configuration(#47466)aws_resiliencehubv2_policy(#48321)aws_mailmanager_rule_set(#49257)aws_prometheus_anomaly_detector(#49139)aws_prometheus_scraper_logging_configuration(#47466)aws_resiliencehubv2_policy(#48321)ENHANCEMENTS:
stateattribute (#42150)RESERVEDas a valid value formanaged_instances_provider.instance_launch_template.capacity_option_type(#48816)local_storage_configurationattribute tomanaged_instances_provider.instance_launch_template(#47513)managed_instances_provider.instance_launch_template.capacity_reservationsargument (#48816)configuration.compaction_configurationargument (#43868)destination.cloudwatchconfiguration block for CloudWatch Metrics destination support (#49088)BUG FIXES:
BadRequestException: There is already an update in progresserrors (#49205)embed_host_domainsnot being sent to the AWS API on update, which caused a permanent plan diff when the argument was added or changed on an existing stack (#49015)bedrock_data_automation_configurationwhenparsing_strategy = "BEDROCK_DATA_AUTOMATION", a regression introduced in v6.56.0 (#49111):(colon) in thematch_value_stringandmatch_value_string_listattributes ofauthorizer_configuration.custom_jwt_authorizer.custom_claim.authorizing_claim_match_value.claim_match_value(#48437)Value Conversion Error ... Received null value, however the target type cannot handle null valueserrors (#49188)too many results: wanted 1, got 2error when creating or updating a strategy on a memory that already has another strategy of a different type (#49250)configuration.consolidation,configuration.extraction, orconfiguration.reflectionblocks are removed (#49188)sigint_rollbackfalsely rolling back healthy deployments duringwait_for_steady_state(#49077)apply_immediately = false) (#48246)InvalidInputException: StorageDescriptor is not allowederror when creating or updating ATHENA-dialect views (#49156)InvalidInputExceptionerror when creating or updating SPARK-dialect views without an explicitstorage_descriptorblock (#49156)view_definition.representationsfields (validation_connection,view_original_text,view_expanded_text) that AWS Glue does not echo back for validated ATHENA views (#49156)v6.57.1Compare Source
NOTES:
memory_execution_role_arnattribute has been deprecated. This attribute should be removed from configurations (#49140)namespacesattribute has been deprecated. All configurations usingnamespacesshould be updated to use thenamespace_templatesattribute instead (#49140)FEATURES:
aws_eks_access_policies(#49090)aws_bedrock_evaluation_job(#49044)aws_eks_access_entry(#49090)aws_eks_access_policy_association(#49121)aws_eks_node_group(#49073)aws_flow_log(#49086)aws_mailmanager_traffic_policy(#49043)aws_osis_pipeline(#49157)aws_osis_pipeline_endpoint(#44383)aws_osis_resource_policy(#44383)aws_rekognition_collection(#49135)aws_bedrock_evaluation_job(#49044)aws_cloudwatch_log_storage_tier_policy(#49076)aws_mailmanager_traffic_policy(#49043)aws_osis_pipeline_endpoint(#44383)aws_osis_resource_policy(#44383)ENHANCEMENTS:
ena_queue_countattribute tonetwork_interfacesconfiguration block (#48892)typeattribute (#46414)external_secret_rotation_metadataandexternal_secret_rotation_role_arnattributes (#46414)ipv6_cidr_block_associations. (#46918)ipv6_association_idandipv6_cidr_block. (#46918)reservations-then-balancedvalid value foravailability_zone_distribution.capacity_distribution_strategy(#48934)timeouts.updatewith a default value of30m(#49140)configuration.reflectionconfiguration block forEPISODIC_OVERRIDEstrategy type (#49140)namespace_templatesargument (#49140)reflection_configurationconfiguration block forEPISODICstrategy type (#49140)timeoutsvalues to45m(#49140)stage.action.commandsandstage.action.output_artifacts_for_compute_actionarguments to support Compute action types (#42507)stage.action.output_artifacts_for_compute_actionandstage.action.output_artifactsnow conflict (#42507)policyargument to support inline session policies (#48869)MultiRegionClustersas a value foraction.target.key(#48781)ena_queue_countargument tonetwork_interfacesconfiguration block (#48892)typeargument in support of managed external secrets (#46414)external_secret_rotation_metadataandexternal_secret_rotation_role_arnarguments in support of managed external secrets (#46414)BUG FIXES:
warm_throughputvalues (#49032)v6.56.0Compare Source
FEATURES:
aws_elasticache_apply_service_update(#48963)aws_elasticache_service_update_actions(#48958)aws_s3_buckets(#48965)aws_eks_addon(#49067)aws_s3_bucket_notification(#48974)aws_secretsmanager_secret_policy(#49058)ENHANCEMENTS:
warm_pool_configattribute (#48977)bootstrap_brokers_ipv6,bootstrap_brokers_sasl_iam_ipv6,bootstrap_brokers_sasl_scram_ipv6, andbootstrap_brokers_tls_ipv6attributes to expose IPv6 bootstrap broker URLs (#48975)iam_federation_optionsblock (#48495)iam_identity_center_optionsblock (#48495)TF_AWS_WEB_IDENTITY_TOKENenvironment variable. Any value configured viaassume_role_with_web_identity.web_identity_tokentakes precedence (#48736)instance_lifecycle_policyconfiguration block (#48973)data_source_configuration.managed_knowledge_base_connector_configurationblock (#48904)timeouts.updatewith a default value of30m(#48904)vector_knowledge_base_configuration.bedrock_embedding_model_configuration.audioandvector_knowledge_base_configuration.bedrock_embedding_model_configuration.videoconfiguration blocks (#48538)type = "MANAGED") withmanaged_knowledge_base_configurationblock (#48904)@source.logas a valid value foremit_system_fields(#48956)warm_pool_configconfiguration block (#48977)tag_field_specificationconfiguration block (#48913)AI_PROTECTIONandAI_ANALYSTfeature names (#48972)AI_PROTECTIONandAI_ANALYSTfeature names (#48972)bootstrap_brokers_ipv6,bootstrap_brokers_sasl_iam_ipv6,bootstrap_brokers_sasl_scram_ipv6, andbootstrap_brokers_tls_ipv6attributes to expose IPv6 bootstrap broker URLs (#48975)iam_federation_optionsconfiguration block (#48495)iam_identity_center_optionsconfiguration block (#48495)metadata.iceberg.propertiesargument (#48635)BUG FIXES:
assume_role_with_web_identity.0.web_identity_token,assume_role_with_web_identity.0.web_identity_token_filemust be specified" errors, allowing anyAWS_WEB_IDENTITY_TOKEN_FILEenvironment variable value to be used (#48736)FAILEDstate (#48904)AccessDeniedExceptionerror when deleting (#48516)data_read_cache_configuration.sizewhensizing_modeisPROPORTIONAL_TO_THROUGHPUT_CAPACITYandsizeis not specified (#49023)shared_resourcesdiffs for ActiveMQ brokers (#48962)ConflictException: Configuration ID [...] is in useerrors on delete (#48962)Cannot create already existing endpointerror when retrying creation. (#48966)v6.55.0Compare Source
6.55.0 (July 15, 2026)
FEATURES:
aws_elasticache_service_updates(#44608)aws_autoscaling_group(#48928)aws_cloudwatch_log_stream(#48878)aws_kinesis_firehose_delivery_stream(#48946)aws_network_interface(#48887)aws_rds_cluster(#48948)aws_sfn_state_machine(#48840)ENHANCEMENTS:
updated_atattribute (#48881)allowed_workload_configuration,private_endpoint, andprivate_endpoint_overridesconfiguration blocks toauthorizer_configuration.custom_jwt_authorizer, and the read-onlyrequire_service_s3_endpointattribute tonetwork_configuration.network_mode_config(#48654)allowed_workload_configuration,private_endpoint, andprivate_endpoint_overridesconfiguration blocks toauthorizer_configuration.custom_jwt_authorizer(#48654)allowed_workload_configuration,private_endpoint, andprivate_endpoint_overridesconfiguration blocks toauthorizer_configuration.custom_jwt_authorizer(#48654)require_service_s3_endpointargument tonetwork_configuration.network_mode_config(#48654)allowed_workload_configuration,private_endpoint, andprivate_endpoint_overridesconfiguration blocks toauthorizer_configuration.custom_jwt_authorizer(#48654)consumer_group_offset_sync_modeattribute toconsumer_group_replicationblock (#47670)BUG FIXES:
Unsupported Typeerrors when nomemoryis configured (#48654)interface conversion: interface {} is nil, not *configservice.DescribeOrganizationConfigRuleStatusesOutputpanics on delete (#48845)v6.54.0Compare Source
NOTES:
capacity_reservation_config, it is best effort and we ask for community help in testing (#45926)FEATURES:
aws_route53profiles_profile(#48780)aws_bedrockagentcore_browser_profile(#46862)aws_codepipeline(#48808)aws_lambda_function_scaling_config(#48229)aws_scheduler_schedule(#48828)aws_ssoadmin_region(#48126)aws_workspaces_pool(#42678)aws_bedrockagentcore_browser_profile(#46862)aws_lambda_function_scaling_config(#48229)aws_ssoadmin_region(#48126)aws_workspaces_pool(#42678)ENHANCEMENTS:
host_kernel_overrideargument (#48777)resource_share_arnsandshared_resourcesattributes (#48729)tagsandtags_allattributes (#48458)host_kernelargument to theenvironmentconfiguration block (#48777)use_resource_timeout_for_propagationargument (#46405)10mforcreateandupdate,5mfordelete. (#46405)use_resource_timeout_for_propagationargument (#46405)5mforcreate,read, anddelete. (#46405)resource_share_arnsargument andshared_resourcesattribute (#48729)out_of_order_time_window_in_secondsandrule_query_offset_in_secondsarguments (#48659)auto_minor_version_upgradeargument (#42472)production_variants.capacity_reservation_configandshadow_production_variants.capacity_reservation_configconfiguration blocks (#45926)BUG FIXES:
content_policy_configblock. (#48772)topic_policy_configblock. (#48772)content_policy_config.filters_config.input_modalitiesvalues. (#48772)content_policy_config.filters_config.output_modalitiesvalues. (#48772)etagon Import. (#48782)etagwhen onlytagsupdated. (#48782)UnsupportedOperationExceptionerror when readingenable_directory_data_accessin regions where Directory Service Data is not available (e.g. GovCloud) (#47660)v6.53.0Compare Source
BREAKING CHANGES:
opt_out_list_nameandtwo_way_channel_enabledin favor of AWS server-side defaults (Defaultandfalserespectively). Configurations that omit these attributes will now show(known after apply)on first plan instead of the previous static value; the post-apply state is unchanged. This change mitigates persistent drift when the phone number is managed by anaws_pinpointsmsvoicev2_pool. (#48414)NOTES:
bedrock-agentcorenamespace to theagent-registrynamespace. Theaws_bedrockagentcore_browserresource will continue to work until September 17, 2026 (#48693)bedrock-agentcorenamespace to theagent-registrynamespace. Theaws_bedrockagentcore_browserresource will continue to work until September 17, 2026 (#48693)aws_ecs_cluster_capacity_providers, add areplace_triggered_bylifecycle rule to the association so the old capacity provider is detached before it is deleted (#48156)FEATURES:
aws_bedrock_foundation_model_agreement_offers(#47665)aws_bedrock_use_case_for_model_access(#47665)aws_ec2_capacity_block_reservation(#48185)aws_pinpointsmsvoicev2_pool(#48414)aws_bedrock_foundation_model_agreement(#47665)aws_bedrock_use_case_for_model_access(#47665)aws_pinpointsmsvoicev2_pool(#48414)ENHANCEMENTS:
security_policyandendpoint_access_modeattributes (#47973)customer_action_statusattribute (#48536)security_policyandendpoint_access_modearguments (#47973)browser_signing,certificate, andenterprise_policyconfiguration blocks (#47816)certificateargument (#47817)rule_definition(#48679)rule_stateto Optional and Computed (#48679)resource_arnandtemplate_name(#48679)customer_action_statusattribute (#48536)force_disassociateargument (#48414)idin favor ofarn(#48636)idin favor ofarn(#48636)idin favor ofarn(#48636)BUG FIXES:
authorization_tokenas sensitive (#48577)resource_arn,tagsandtemplate_nameasForceNew(#48679)importblock orterraform import(#47590)InvalidActionerrors in partitions where access key cleanup operations are not supported (#48473)instance_market_options.market_typeis set tocapacity-block(#48701)secret_access_keyas sensitive (#48577)private_keyas sensitive (#48577)typeattribute to no longer force resource replacement on change (#47105)[
v6.52.0](https://redirect.github.com/hashicorp/terraform-Configuration
📅 Schedule: (in timezone Europe/London)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.