Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.87.0
->5.90.0
1.10.5
->1.11.1
Release Notes
hashicorp/terraform-provider-aws (aws)
v5.90.0
Compare Source
BREAKING CHANGES:
rule.noncurrent_version_expiration.noncurrent_days
andrule.noncurrent_version_transition.noncurrent_days
are Required (#40796)NOTES:
elastic_gpu_specifications
andelastic_inference_accelerator
are deprecated. AWS no longer supports Elastic Graphics or Elastic Inference. (#41677)X25519Kyber768Draft00
. Previously, in environments using AWS Network Firewall, the Provider would hang due to a handshake issue between Go 1.23 and Network Firewall, which supported Suricata 6.0.9. We had disabled the post-quantum key exchange to resolve the issue. Since November 2024, AWS Network Firewall has upgraded to Suricata 7.0, which no longer has this issue. However, if you use AWS Network Firewall, we’d appreciate your help in identifying any remaining issues related to this change. (#41655)overrides.inference_accelerator_overrides
is deprecated. AWS no longer provides the Elastic Inference service. (#41676)elastic_gpu_specifications
andelastic_inference_accelerator
are deprecated. AWS no longer supports Elastic Graphics or Elastic Inference. (#41677)accelerator_types
is deprecated and will be removed in a future version. Useinstance_type
instead. (#41673)FEATURES:
aws_dataexchange_event_action
(#40552)aws_lakeformation_opt_in
(#41611)ENHANCEMENTS:
arn
attribute (#41660)arn
attribute (#41660)arn
attribute (#41660)arn
attribute (#41660)arn
attribute (#41660)state
attribute (#41575)cluster_config.node_options
attribute (#40181)arn
attribute (#41660)arn
attribute (#41660)arn
attribute (#41660)arn
attribute (#41660)arn
attribute (#41660)arn
attribute (#41660)arn
attribute (#41660)arn
attribute (#41660)disconnect_on_session_timeout
attribute (#41621)max_webservers
andmin_webservers
arguments from2
to1
in support of Amazon MWAA micro environments (#40244)cluster_config.node_options
configuration block in support of dedicated coordinator nodes (#40181)vpc_options.vpc_endpoint_management
argument (#38001)arn
attribute (#41645)tags
argument andtags_all
attribute (#41645)arn
attribute (#41660)arn
attribute (#41660)rule.filter
(#41662)rule.noncurrent_version_expiration.noncurrent_days
andrule.noncurrent_version_transition.noncurrent_days
are Required. Technically this is a breaking change, but failure to configure this attribute would have led toInvalidArgument
orMalformedXML
errors (#40796)arn
attribute (#41660)arn
attribute (#41660)BUG FIXES:
exclude_characters
fromBool
toString
(#41546)vpc_lattice_configurations
blocks (#41594)rule
configuration fromfilter.prefix
tofilter.and.prefix
(#41662)rule
configuration fromprefix
tofilter.prefix
orfilter.and.prefix
(#41662)ConflictException
errors on delete (#41594)v5.89.0
Compare Source
FEATURES:
aws_macie2_organization_configuration
(#41475)aws_neptunegraph_graph
(#41216)aws_quicksight_role_membership
(#41589)aws_rds_shard_group
(#41254)aws_xray_resource_policy
(#41517)ENHANCEMENTS:
configuration
argument (#41524)cluster_scalability_type
attribute (#41254)database_insights_mode
attribute (#41254)application/yaml
to the list ofContent-Type
s that return a body (#41443)application/yaml
to the list ofContent-Type
s that return a body (#41443)checksum_crc64nvme
attribute (#41015)target_tracking_configuration.customized_metric_specification.period
argument to support high-resolution metrics (#41385)RequiredWith
validationpassword_wo
andpassword_wo_version
. RemovePreferWriteOnlyAttribute
validation (#41562)RequiredWith
validationmaster_password_wo
andmaster_password_wo_version
. RemovePreferWriteOnlyAttribute
validation (#41562)25Gbps
and400Gbps
as supportedbandwidth
values (#41547)25Gbps
as a supportedbandwidth
value (#41547)400Gbps
as a supportedconnections_bandwidth
value (#41547)network_interfaces.ena_srd_specification
configuration block (#41367)enable_zonal_shift
support for Application Load Balancers (#41335)tags
to be updated in-place (#41266)tags
to be updated in-place (#41266)tags
to be updated in-place (#41266)tags
to be updated in-place (#41266)secondary_private_ip_address_count
tosecondary_private_ip_addresses
for private NAT Gateways (#41403)RequiredWith
validationmaster_password_wo
andmaster_password_wo_version
. RemovePreferWriteOnlyAttribute
validation (#41562)cluster_scalability_type
argument (#41254)database_insights_mode
argument (#41254)""
as a valid value forengine_mode
(#41254)iam-db-auth-error
as a valid value forenabled_cloudwatch_logs_exports
(#41408)RequiredWith
validationmaster_password_wo
andmaster_password_wo_version
. RemovePreferWriteOnlyAttribute
validation (#41562)RequiredWith
validationadmin_user_password_wo
andadmin_user_password_wo_version
. RemovePreferWriteOnlyAttribute
validation (#41562)data_redundancy
isSingleLocalZone
iflocation.type
isLocalZone
(#40944)checksum_crc64nvme
attribute (#41015)checksum_crc64nvme
attribute (#41015)RequiredWith
validationsecret_string_wo
andsecret_string_wo_version
. RemovePreferWriteOnlyAttribute
validation (#41562)PreferWriteOnlyAttribute
validation (#41562)BUG FIXES:
s3_delivery_configuration.suffix_path
(#41497)spot_options.max_total_price
,spot_options.min_target_capacity
,spot_options.single_instance_type
, andspot_options.single_availability_zone
arguments (#41272)routing_http_response_server_enabled
,routing_http_response_strict_transport_security_header_value
,routing_http_response_access_control_allow_origin_header_value
,routing_http_response_access_control_allow_methods_header_value
,routing_http_response_access_control_allow_headers_header_value
,routing_http_response_access_control_allow_credentials_header_value
,routing_http_response_access_control_expose_headers_header_value
,routing_http_response_access_control_max_age_header_value
,routing_http_response_content_security_policy_header_value
,routing_http_response_x_content_type_options_header_value
,routing_http_response_x_frame_options_header_value
,routing_http_request_x_amzn_mtls_clientcert_serial_number_header_name
,routing_http_request_x_amzn_mtls_clientcert_issuer_header_name
,routing_http_request_x_amzn_mtls_clientcert_subject_header_name
,routing_http_request_x_amzn_mtls_clientcert_validity_header_name
,routing_http_request_x_amzn_mtls_clientcert_leaf_header_name
,routing_http_request_x_amzn_mtls_clientcert_header_name
,routing_http_request_x_amzn_tls_version_header_name
, androuting_http_request_x_amzn_tls_cipher_suite_header_name
are updated iftcp_idle_timeout_seconds
does not change (#41299)status
andtags
can be updated in-place (#41266)secondary_allocation_ids
to be updated in-place (#41403)master_username
validation (#41556)InvalidRequest
error whenrule.and.object_size_less_than
not set. (#41542)v5.88.0
Compare Source
NOTES:
rule.expiration.expired_object_delete_marker
is set with eitherrule.expiration.date
orrule.expiration.days
. While historically the provider allowed this invalid configuration, the migration of this resource to the Terraform Plugin Framework inv5.86.0
resulted in this misconfiguration surfacing as a hardinconsistent result after apply
error. This diagnostic aims to direct users how to resolve the issue at plan time. See this issue comment for additional context. (#41462)FEATURES:
aws_cloudwatch_contributor_managed_insight_rules
(#41472)aws_cloudwatch_contributor_managed_insight_rule
(#41449)aws_qbusiness_application
(#35249)ENHANCEMENTS:
video_data_delivery_enabled
argument (#41317)password_wo
write-only attribute (#41366)master_password_wo
write-only attribute (#41413)storage_descriptor.additional_locations
argument (#41434)master_password_wo
write-only attribute (#41411)admin_user_password_wo
write-only attribute (#41412)secret_string_wo
write-only attribute (#41371)BUG FIXES:
scaling_configuration
is not empty. (#41377)sub_domain
(#36961)embedding_data_delivery_enabled
,image_data_delivery_enabled
, andtext_data_delivery_enabled
arguments as optional with default value oftrue
(#41317)hashicorp/terraform (hashicorp/terraform)
v1.11.1
Compare Source
1.11.1 (March 5, 2025)
BUG FIXES:
Temporarily revert updated Windows symlink handling until we can account for known existing configurations using non-symlink junctions. (#36575)
terraform test
: Fix crash when a run block attempts to cleanup after a non-applyable plan. (#36582)Updated dependency golang.org/x/oauth2 from v0.23.0 => v0.27.0 to integrate latest changes (fix for CVE-2025-22868) (#36584)
lang/funcs/transpose: Avoid crash due to map with null values (#36611)
Combining ephemeral and sensitive marks could fail when serializing planned changes (#36619)
v1.11.0
Compare Source
1.11.0 (February 27, 2025)
NEW FEATURES:
Add write-only attributes to resources. Providers can specify that certain attributes are write-only. They are not persisted in state. You can use ephemeral values in write-only attributes. (#36031)
terraform test
: The-junit-xml
option for the terraform test command is now generally available. This option allows the command to create a test report in JUnit XML format. Feedback during the experimental phase helped map terraform test concepts to the JUnit XML format, and new additons may happen in future releases. (#36324)S3 native state locking is now generally available. The
use_lockfile
argument enables users to adopt the S3-native mechanism for state locking. As part of this change, we've deprecated the DynamoDB-related arguments in favor of this new locking mechanism. While you can still use DynamoDB alongside S3-native state locking for migration purposes, we encourage migrating to the new state locking mechanism. (#36338)ENHANCEMENTS:
init
: Provider installation will utilise credentials configured in a.netrc
file for the download and shasum URLs returned by provider registries. (#35843)terraform test
: Test runs now support using mocked or overridden values during unit test runs (e.g., with command = "plan"). Setoverride_during = plan
in the test configuration to use the overridden values during the plan phase. The default value isoverride_during = apply
. (#36227)terraform test
: Add newstate_key
attribute forrun
blocks, allowing test authors control over which internal state file should be used for the current test run. (#36185)Updates the azure backend authentication to match the terraform-provider-azurermprovider authentication, in several ways:
(#36258)
Include
ca-certificates
package in our official Docker image to help with certificate handling by downstream (#36486)BUG FIXES:
ephemeral values: correct error message when ephemeral values are included in provisioner output (#36427)
Attempting to override a variable during
apply
viaTF_VAR_
environment variable will now yield warning instead of misleading error. (#36435)backends: Fix crash when interrupting during interactive prompt for values (#36448)
Fixes hanging behavior seen when applying a saved plan with -auto-approve using the cloud backend (#36453)
Previous Releases
For information on prior major and minor releases, refer to their changelogs:
Configuration
📅 Schedule: Branch creation - "* 0-3 1 * *" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.