Conversation
264c238 to
eeda900
Compare
eeda900 to
0c3a2ce
Compare
0c3a2ce to
8132c9a
Compare
8132c9a to
9b75dba
Compare
9b75dba to
f7350d1
Compare
f7350d1 to
c4227fe
Compare
6800454 to
104de7e
Compare
104de7e to
0ca6513
Compare
0ca6513 to
59eeca8
Compare
59eeca8 to
851cc89
Compare
851cc89 to
371d73e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.98.0→6.31.0Release Notes
hashicorp/terraform-provider-aws (aws)
v6.31.0Compare Source
NOTES:
expected_bucket_ownerattribute. (#46262)expected_bucket_ownerattribute from Resource Identity. (#46272)expected_bucket_ownerattribute. (#46262)expected_bucket_ownerattribute from Resource Identity. (#46272)expected_bucket_ownerattribute. (#46262)expected_bucket_ownerandaclattribute from Resource Identity. (#46272)expected_bucket_ownerattribute. (#46262)expected_bucket_ownerattribute from Resource Identity. (#46272)expected_bucket_ownerattribute. (#46262)expected_bucket_ownerattribute from Resource Identity. (#46272)expected_bucket_ownerattribute. (#46262)expected_bucket_ownerattribute from Resource Identity. (#46272)expected_bucket_ownerattribute. (#46262)expected_bucket_ownerattribute from Resource Identity. (#46272)expected_bucket_ownerattribute. (#46262)expected_bucket_ownerattribute from Resource Identity. (#46272)expected_bucket_ownerattribute. (#46262)expected_bucket_ownerattribute from Resource Identity. (#46272)expected_bucket_ownerattribute. (#46262)expected_bucket_ownerattribute from Resource Identity. (#46272)expected_bucket_ownerattribute. (#46262)expected_bucket_ownerattribute from Resource Identity. (#46272)expected_bucket_ownerattribute. (#46262)expected_bucket_ownerattribute from Resource Identity. (#46272)FEATURES:
aws_account_regions(#41746)aws_ecrpublic_authorization_token(#45841)aws_cloudwatch_event_rule(#46304)aws_cloudwatch_event_target(#46297)aws_cloudwatch_metric_alarm(#46268)aws_iam_role_policy(#46293)aws_lambda_function(#46295)aws_s3_bucket_acl(#46305)aws_s3_bucket_policy(#46312)aws_s3_bucket_public_access_block(#46309)aws_ssoadmin_customer_managed_policy_attachments_exclusive(#46191)ENHANCEMENTS:
serverless_vector_accelerationtoaiml_options(#45882)BUG FIXES:
auth_token_update_strategyalways requiredauth_token, which caused an error when migrating from AUTH to RBAC. Now,auth_token_update_strategystill requiresauth_tokenexcept whenauth_token_update_strategyisDELETE. (#45518)aws_elasticache_replication_groupwhencluster_mode="enabled"andnum_node_groupsis reduced. Previously, downscaling could fail in certain scenarios; for example, if nodes0001,0002,0003,0004, and0005exist, and a user manually removes0003and0005, then setsnum_node_groups = 2, terraform would attempt to delete0003,0004, and0005. This is now fixed, after this fix terraform will retrieve the current node groups before resizing. (#45893)user_group_idremoval during modification. (#45571)UnauthorizedOperationerror when detaching resource that does not have an attachment (#46211)v6.30.0Compare Source
FEATURES:
aws_ssoadmin_managed_policy_attachments_exclusive(#46176)BUG FIXES:
global_secondary_indexorglobal_secondary_index.key_schemaaredynamic(#46195)v6.29.0Compare Source
NOTES:
return_organization_onlyargument to return only the results of theDescribeOrganizationAPI and avoid API limits (#40884)regionattribute, as the resource is global. (#46185)return_organization_onlyargument to return only the results of theDescribeOrganizationAPI and avoid API limits (#40884)FEATURES:
aws_arcregionswitch_plan(#43781)aws_arcregionswitch_route53_health_checks(#43781)aws_organizations_entity_path(#45890)aws_resourcegroupstaggingapi_required_tags(#45994)aws_s3_bucket_object_lock_configuration(#45990)aws_s3_bucket_replication_configuration(#42662)aws_s3control_access_points(#45949)aws_s3control_multi_region_access_points(#45974)aws_savingsplans_savings_plan(#45834)aws_wafv2_managed_rule_group(#45899)aws_appflow_connector_profile(#45983)aws_appflow_flow(#45980)aws_cleanrooms_collaboration(#45953)aws_cleanrooms_configured_table(#45956)aws_cloudfront_key_value_store(#45957)aws_opensearchserverless_collection(#46001)aws_route53_record(#46059)aws_s3_bucket(#46004)aws_s3_object(#46002)aws_security_group(#46062)aws_apigatewayv2_routing_rule(#42961)aws_arcregionswitch_plan(#43781)aws_cloudfront_anycast_ip_list(#43331)aws_notifications_managed_notification_account_contact_association(#45185)aws_notifications_managed_notification_additional_channel_association(#45186)aws_notifications_organizational_unit_association(#45197)aws_notifications_organizations_access(#45273)aws_opensearch_application(#43822)aws_ram_permission(#44114)aws_ram_resource_associations_exclusive(#45883)aws_sagemaker_labeling_job(#46041)aws_sagemaker_model_card(#45993)aws_sagemaker_model_card_export_job(#46009)aws_savingsplans_savings_plan(#45834)aws_sesv2_tenant_resource_association(#45904)aws_vpc_security_group_rules_exclusive(#45876)ENHANCEMENTS:
routing_modeargument to support dynamic routing via routing rules (#42961)routing_modeargument to support dynamic routing via routing rules (#42961)allow_privilege_escalationattribute toeks_properties.pod_properties.containers.security_context(#45896)global_secondary_index.key_schemaattribute (#46157)segment_actions.routing_policy_namesargument (#45928)body_base64anddownload_bodyattributes. For improved performance, setdownload_body = falseto ensure bodies are never downloaded (#46163)source_resourceattribute (#44705)allow_privilege_escalationattribute toeks_properties.pod_properties.containers.security_context(#45896)vector_ingestion_configuration.parsing_configuration.bedrock_data_automation_configurationblock (#45966)vector_ingestion_configuration.parsing_configuration.bedrock_foundation_model_configuration.parsing_modalityargument (#46056)certificate_rotation_restartargument (#45984)stream_view_typeis set andstream_enabledis eitherfalseor unset. (#45934)BLOB_MOUNTINGaccount setting name withENABLEDandDISABLEDvalues (#46092)domain_join_service_account_secretargument toself_managed_active_directoryconfiguration block (#45852)self_managed_active_directory.passwordto Optional andself_managed_active_directory.usernameto Optional and Computed (#45852)rulesto a single element. (#46185)memory_sizefrom 10240 MB to 32768 MB (#46065)network_performance_optionsargument (#46071)pipeline_configuration_bodymaximum length validation to 2,621,440 bytes to align with AWS API specification. (#44881)monitoring_schedule_config.monitoring_job_definitionargument (#45951)monitoring_schedule_config.monitoring_job_definition_nameargument optional (#45951)source_resourceargument in support of provisioning of VPC Resource Planning Pools (#44705)organizational_unit_exclusionargument (#45890)ipv4_ipam_pool_id,ipv4_netmask_length,ipv6_ipam_pool_id, andipv6_netmask_lengtharguments in support of provisioning of subnets using IPAM (#44705)ipv6_cidr_blockto Optional and Computed (#44705)BUG FIXES:
rule.action.target_storage_classandrule.selection.storage_classto JSON serialization (#45909)catalog_id,data_location.catalog_id,database.catalog_id,lf_tag_policy.catalog_id,table.catalog_id, andtable_with_columns.catalog_idarguments (#43931)attachment_routing_policy_rules.action.associate_routing_policiesis empty (#46160)regiondefined, in AWS European Sovereign Cloud, prevent failing due to region validation requiring region names to start with "[a-z]{2}-" (#45895)configuration.result_configuration.encryption_configurationargument (#46159)Provider produced inconsistent result after applyerror when queryingCARBON_EMISSIONStable withouttable_configurations(#45972)model_sourceis set (#45713)auto_deploymentwithpermission_modelset toSERVICE_MANAGED(#45992)runtime error: invalid memory address or nil pointer dereferencepanic when mistakenly importing a multi-tenant distribution (#45873)origin_groupto use correctidattribute name and fix field mapping to resolvemissing required fielderrors (#45921)InvalidRecordingGroupException: The recording group provided is not validerrors when therecording_group.exclusion_by_resource_typeorrecording_group.recording_strategyargument is removed during update (#46110)warm_throughputin global_secondary_index when not set in configuration. (#46094)nameis known after apply (#45917)kubernetes_network_configargument name in EKS Auto Mode validation error message (#45997)catalog_id,data_location.catalog_id,database.catalog_id,lf_tag_policy.catalog_id,table.catalog_id, andtable_with_columns.catalog_idarguments (#43931)health_check.protocolfromHTTPtoTCPwhenprotocolisTCP(#46036)firewall_policy.stateful_rule_group_reference.resource_arn(#46124)delete_associated_resourcesbeing set when value is unknown (#45636)partition_count(#45042)iam_database_authentication_enabledwhen restored from snapshot (#39461)portnow works. (#45870)ValidationException: Base capacity cannot be updated when PerformanceTarget is Enablederror when updatingprice_performance_targetandbase_capacity(#46137)regionsargument asComputedto fix an unexpectedregionsdiff when it is not specified (#45829)InvalidChangeBatcherrors during ForceNew operations when zone name changes (#45242)Invalid JSON String Valueerror on initial apply andConflictExceptionon subsequent apply when associating Route53 Resolver Query Log Configs (#45958)UnsupportedArgumenterrors during tag-on-create operations (#46122)MethodNotAllowederrors when S3 Control APIs are unavailable (#46122)ipv6_cidr_blockasForceNewwhen the existing IPv6 subnet was created withassign_ipv6_address_on_create = true(#46043)ip_address_type(#45947)v6.28.0Compare Source
NOTES:
FEATURES:
aws_cloudfront_connection_group(#44885)aws_cloudfront_distribution_tenant(#45088)aws_kms_alias(#45700)aws_sqs_queue(#45691)aws_cloudfront_connection_function(#45664)aws_cloudfront_connection_group(#44885)aws_cloudfront_distribution_tenant(#45088)aws_cloudfront_multitenant_distribution(#45535)aws_dynamodb_global_secondary_index(#44999)aws_ecr_pull_time_update_exclusion(#45765)aws_organizations_tag(#45730)aws_redshift_idc_application(#37345)aws_secretsmanager_tag(#45825)aws_sesv2_tenant(#45706)ENHANCEMENTS:
endpoint_access_modeattribute (#45741)endpoint_network_typeandtarget_connection_network_typeattributes (#45634)tagsattribute (#45766)rule.action.target_storage_classandrule.selection.storage_classarguments, and new valid values forrule.action.typeandrule.selection.count_typearguments (#45752)saml_provider_uuidattribute (#45707)response_streaming_invoke_arnattribute (#45652)code_signing_config_arnin AWS GovCloud (US) Regions (#45652)dns_threat_protection,confidence_threshold,firewall_threat_protection_id,firewall_domain_redirection_action, andq_typeattributes (#45711)target_ipsattribute (#45492)dns_options.private_dns_preferenceanddns_options.private_dns_specified_domainsattributes (#45679)service_regionandvpc_endpoint_typefrom attributes to arguments for filtering (#45679)elasticloadbalancing:loadbalancertag type (#45671)elasticloadbalancing:listenertag type (#45671)elasticloadbalancing:listener-ruletag type (#45671)elasticloadbalancing:targetgrouptag type (#45671)endpoint_access_modeargument and configurable timeout for create and update (#45741)customer_content_encryption_configurationargument (#45744)enable_minimum_encryption_configurationargument (#45744)monitoring_configurationargument (#45744)connection_function_associationandviewer_mtls_configarguments (#45847)owner_account_idargument tovpc_origin_configfor cross-account VPC origin support (#45011)apply_on_transformed_logsargument (#45826)emit_system_fieldsargument (#45760)endpoint_network_typeandtarget_connection_network_typearguments (#45634)rds:dbtag type (#45671)rds:global-clustertag type (#45671)tagsargument andtags_allattribute. This functionality requires thedirectconnect:TagResourceanddirectconnect:UntagResourceIAM permissions (#45766)CREATE_ON_PUSHas a valid value forapplied_for(#45720)managed_instances_provider.instance_launch_template.capacity_option_typeargument (#45667)fsx:file-systemtag type (#45671)fsx:file-systemtag type (#45671)fsx:file-systemtag type (#45671)fsx:snapshottag type (#45671)fsx:volumetag type (#45671)fsx:file-systemtag type (#45671)finding_criteria.criterion.matchesandfinding_criteria.criterion.not_matchesarguments (#45758)delay_after_policy_creation_in_msargument. This functionality requires theiam:SetDefaultPolicyVersionIAM permission (#42054)saml_provider_uuidattribute (#45707)serial_numberattribute (#45751)logging_configurationargument (#45749)logging_configurationargument (#45749)resource_group_arn(#45688)rules_package_arnsandtarget_arn(#45688)provisioned_poller_config.poller_group_nameargument (#45313)kafka://topic-name) fordestination_config.on_failure.destination_arnargument (#45802)response_streaming_invoke_arnattribute (#45652)code_signing_config_arnin AWS GovCloud (US) Regions (#45652)lambda:InvokeFunctionpermission, with theInvokedViaFunctionUrlflag set totrue, to the function on creation whenauthorization_typeisNONE(#44858)invoked_via_function_urlargument (#44858)quic_server_idargument (#45666)target_group_arn(#45666)rds:clustertag type (#45671)rds:dbtag type (#45671)rds:global-clustertag type (#45671)routing_policy_labelargument. This functionality requires thenetworkmanager: PutAttachmentRoutingPolicyLabelandnetworkmanager: RemoveAttachmentRoutingPolicyLabelIAM permissions (#45728)pipeline_role_arnargument to support specifying a IAM role at the pipeline level (#45806)rds:clustertag type (#45671)consumer_region(#45688)dns_threat_protection,confidence_threshold, andfirewall_threat_protection_idarguments to support DNS Firewall Advanced rules (#45711)endpoint_details.vpcconfiguration block to support VPC hosted Transfer Family web app (#45745)dns_options.private_dns_preferenceanddns_options.private_dns_specified_domainsarguments (#45679)private_dns_enabledargument (#45673)tunnel*_inside_cidrandtunnel*_inside_ipv6_cidrarguments (#45781)BUG FIXES:
proxy_endpointwhenregistry_idis specified (#45754)account-id, notaccount, as a valid value forattachment_policies.conditions.type. This fixes a regression introduced in v6.27.0 (#45788)service_regionattribute (#45679)user_agentvalues where the product name contains a forward slash (#45715)node_propertieshasNodeRangeProperties.ecsPropertiesset (#45676)PutSubscriptionFilter: RetryValidationException: Make sure you have given CloudWatch Logs permission to assume the provided role(#43762)reading EC2 VPC (...) default Security Group: empty resultandreading EC2 VPC (...) main Route Table: empty resulterrors when importing RAM-shared VPCs. This fixes a regression introduced in v6.17.0 (#45780)private_dns_enabledargument is now marked asForceNew(#45679)v6.27.0Compare Source
FEATURES:
aws_organizations_account(#45543)user_agent(#45464)aws_kms_key(#45514)aws_cloudfront_trust_store(#45534)ENHANCEMENTS:
root_domain_unit_idattribute (#44964)routing_policiesandattachment_routing_policy_rulesarguments (#45246)rni_enhanced_metrics_enabledattribute (#45630)target_name_server_metrics_enabledattribute (#45630)user_agentargument (#45464)provider_metablock is now supported. Theuser_agentargument enables module authors to include additional product information in theUser-Agentheader sent during all AWS API requests made during Create, Read, Update, and Delete operations. (#45464)knowledge_base_configuration.kendra_knowledge_base_configurationargument (#44388)knowledge_base_configuration.sql_knowledge_base_configurationandstorage_configuration.neptune_analytics_configurationarguments (#45465)storage_configuration.mongo_db_atlas_configurationargument (#37220)storage_configuration.opensearch_managed_cluster_configurationargument (#44060)storage_configuration.s3_vectors_configurationblock (#45468)knowledge_base_configuration.vector_knowledge_base_configurationand ``storage_configuration` optional (#44388)cache.cache_namespaceargument (#45584)root_domain_unit_idargument (#44964)code_sha256is now optional and computed (#45618)routing_policy_labelargument ([#45246](https://redirect.github.com/hashicConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.