Skip to content

chore(deps): update terraform cloudposse/s3-log-storage/aws to v2.1.0 (main) - #165

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/main-cloudposse-s3-log-storage-aws-2.x
Open

chore(deps): update terraform cloudposse/s3-log-storage/aws to v2.1.0 (main)#165
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/main-cloudposse-s3-log-storage-aws-2.x

Conversation

@renovate

@renovate renovate Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
cloudposse/s3-log-storage/aws (source) module minor 2.0.02.1.0

Release Notes

cloudposse/terraform-aws-s3-log-storage (cloudposse/s3-log-storage/aws)

v2.1.0

Compare Source

✨ Features

feat: add object_lock_enabled passthrough @​Benbentwo (#​141)

what

  • Bump cloudposse/s3-bucket/aws from 4.10.0 to 4.15.0.
  • Expose that module's object_lock_enabled input as a variable on this module.
  • Raise the AWS provider floor from >= 4.9.0 to >= 6.37.0, which s3-bucket 4.15.0 requires.

why

object_lock_configuration is the only Object Lock knob this module exposes, and it is a bucket-wide default retention
rule
— mode plus days or years, both required. There is no way to ask for "Object Lock enabled, nothing locked by
default", which is what you want when objects are protected individually with a retention period or a legal hold.

That matters for log buckets specifically. A default retention rule interacts badly with lifecycle expiration: S3 cannot
delete an object still under retention, so a retention period longer than the expiration deadlocks the lifecycle rule.
Callers who want the WORM capability without that coupling currently have no option.

cloudposse/terraform-aws-s3-bucket already solved this in
v4.15.0 by adding a bare
object_lock_enabled bool alongside object_lock_configuration. This PR just carries that input up one layer. The
variable description is copied verbatim from the child module so the two stay consistent.

references

note on the provider floor

The provider bump is the part worth a second look — it comes along with s3-bucket 4.15.0 rather than from this change
itself, and it is a large jump for consumers still on provider v4 or v5. Happy to split it out or gate it differently if
you would rather land the passthrough separately.

🤖 Automatic Updates

chore(deps): bump github.com/ulikunitz/xz from 0.5.10 to 0.5.14 in /test/src @​[dependabot[bot]](https://redirect.github.com/apps/dependabot) (#​131) Bumps [github.com/ulikunitz/xz](https://redirect.github.com/ulikunitz/xz) from 0.5.10 to 0.5.14.
Commits

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the auto-update This PR was automatically generated label Sep 8, 2026
@renovate
renovate Bot requested review from a team as code owners September 8, 2026 23:35
@mergify

mergify Bot commented Sep 8, 2026

Copy link
Copy Markdown

/terratest

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto-update This PR was automatically generated

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants