Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
~> 5.0->~> 6.0Release Notes
hashicorp/terraform-provider-aws (aws)
v6.7.0Compare Source
FEATURES:
aws_quicksight_ip_restriction(#43596)aws_quicksight_key_registration(#43587)ENHANCEMENTS:
instance_typeattribute incompute_configurationblock (#43449)volume_initialization_rateattribute (#43565)load_balancerattribute (#43582)tagsattribute. This functionality requires thes3:ListTagsForResourceIAM permission (#43630)deletion_protectionattribute (#43452)configuration.identity_center_configurationargument (#38717)analytics_engineargument (#43614)instance_typeargument incompute_configurationblock to support custom instance types (#43449)volume_initialization_rateargument (#43565)tagsargument andtags_allattribute. This functionality requires thes3:ListTagsForResource,s3:TagResource, ands3:UntagResourceIAM permissions (#43630)deletion_protectionargument (#43452)BUG FIXES:
missing required field, CreateFlowInput.Definition.Nodes[0].Configuration[prompt].SourceConfiguration[resource].PromptArnerrors on Create (#43595)NoSuchTagSetErrorresponses from S3-compatible services (#43589)NoSuchTagSetErrorresponses from S3-compatible services (#43589)Provider produced inconsistent final planerrors when changing from usingvalueto usingvalue_wo(#42877)versionnot being updated whendescriptionchanges (#42595)v6.6.0Compare Source
FEATURES:
aws_connect_phone_number_contact_flow_association(#43557)aws_nat_gateway_eip_association(#42591)ENHANCEMENTS:
log_configattribute (#43453)available_security_updates_compliance_statusargument (#43560)cross_region_config,content_policy_config.tier_config, andtopic_policy_config.tier_configarguments (#43517)workgroupargument (#36628)compute_resources.ec2_configuration.image_kubernetes_versionargument (#43454)log_configargument (#43453)nameto be updated in-place (#41702)nameto be updated in-place (#42639)secondary_allocation_idsto Optional and Computed (#42591)available_security_updates_compliance_statusargument (#43560)/ssm/prefix) forsetting_id(#43562)BUG FIXES:
test_listener_ruleincorrectly being set as empty string inload_balancer.advanced_configurationblock (#43558)v6.5.0Compare Source
NOTES:
FEATURES:
aws_ecr_images(#42577)aws_cognito_log_delivery_configuration(#43396)aws_networkfirewall_firewall_transit_gateway_attachment_accepter(#43430)aws_s3_bucket_metadata_configuration(#41364)ENHANCEMENTS:
postgres_settings.authentication_methodandpostgres_settings.service_access_role_arnattributes (#43440)availability_zone_change_protection,availability_zone_mapping,firewall_status.sync_states.attachment.status_message,firewall_status.transit_gateway_attachment_sync_states,transit_gateway_id, andtransit_gateway_owner_account_idattributes (#43430)oracle_settingsconfiguration block for authentication method (#43125)postgres_settings.authentication_methodandpostgres_settings.service_access_role_arnarguments (#43440)postgres_settings.database_mode,postgres_settings.map_long_varchar_as, andpostgres_settings.plugin_namearguments (#43440)dns_name_serversattribute andkerberos_authentication_settingsconfiguration block for Kerberos authentication settings (#43125)transit_gateway_attachment_idattribute. This functionality requires theec2:DescribeTransitGatewayAttachmentsIAM permission (#43436)CODE_REPOSITORYas a valid value forresource_types(#43525)auto_enable.code_repositoryargument (#43525)availability_zone_change_protection,availability_zone_mapping, andtransit_gateway_idarguments andfirewall_status.transit_gateway_attachment_sync_statesandtransit_gateway_owner_account_idattributes (#43430)subnet_mappingandvpc_idas Optional (#43430)aws_account_idargument. (#43501)rules_jsonargument (#43397)statement.rate_based_statement.custom_key.asnargument (#43506)BUG FIXES:
forces replacementonregionfor numerous resource types when upgrading from a pre-v6.0.0 provider version and-refresh=falseis in effect (#43516)pathwhenpath_partis updated (#43215)definition.connectionanddefinition.nodelist length limits (#43471)ipv6_addresseswhenipv6_address_countis updated (#43158)v6.4.0Compare Source
FEATURES:
aws_s3_access_point(#43391)aws_bedrockagent_flow(#42201)aws_fsx_s3_access_point_attachment(#43391)ENHANCEMENTS:
typeargument (#43150)hybrid_access_enabled,with_federationandwith_privileged_accessattributes (#43377)options.exportargument to issue an exportable certificate (#43207)apply_on_transformed_logsargument (#43381)agent_arnsoptional (#43400)deployment_configurationargument (#43434)load_balancer.advanced_configurationargument (#43434)service.client_alias.test_traffic_rulesargument (#43434)deployment_controller.typechanges no longer force a replacement (#43434)with_privileged_accessargument (#43377)skip_destroyargument (#43415)BUG FIXES:
parent_action_group_signatureon Read (#43355)Inappropriate value for attribute "regional_parameters"errors during planning. This fixes a regression introduced in v6.0.0 (#43382)transit_gateway_attachment_idas ForceNew if the value is known not to change (#43405)waiting for Lambda Function (...) version publish: unexpected state '', wanted target 'Successful'errors on Update. This fixes a regression introduced in v6.2.0 (#43416)sub_slot_setting.slot_specification.value_elicitation_setting.prompt_specification.prompt_attempts_specificationandvalue_elicitation_setting.prompt_specification.prompt_attempts_specificationhave default values (#43358)meta_store_role_arnto be updated in-place (#36874)v6.3.0Compare Source
FEATURES:
aws_prometheus_query_logging_configuration(#43222)ENHANCEMENTS:
anycast_ip_list_idattribute (#43196)core_network_configuration.dns_supportandcore_network_configuration.security_group_referencing_supportarguments (#43277)anycast_ip_list_idargument (#43196)replica.consistency_modeargument in support of multi-Region strong consistency for Amazon DynamoDB global tables (#43236)BUG FIXES:
runtime error: invalid memory address or nil pointer dereferencepanics for numerous resource types when modifyingtags(#43324)operation can't be performed on Agent when it is in Preparing state.errors during agent action group base creation, update, and deletion. (#43232)operation can't be performed on Agent when it is in Preparing state.errors during agent knowledge base creation and disassociation (#43232)managed_login_versionfor custom Cognito domains (#43252)InvalidDBInstanceStateerrors on delete (#43303)interface conversion: interface {} is nil, not map[string]interface {}panics when configuration blocks are empty (#43308)InvalidDBClusterStateFaulterrors on delete (#43303)availability_zone_relocation_enabled(#43270)resource_propertiesto Computed to enablevpc_endpointassociations (#42562)arnwhen refreshing state. (#43273)v6.2.0Compare Source
NOTES:
idattribute has changed fromkeytobucket/key. All configurations usingidshould be updated to use thekeyattribute instead (#43119)idattribute has changed fromkeytobucket/key. All configurations usingidshould be updated to use thekeyattribute instead (#43119)ENHANCEMENTS:
tagsattribute. This functionality requires thekinesis:ListTagsForResourceIAM permission (#43173)firewall_policy.stateful_rule_group_reference.deep_threat_inspectionattribute (#43137)configuration.internal_accessargument (#43138)job_configargument (#43136)enable_skew_protectionargument (#43218)errorCode,eventType,sessionCredentialFromConsole, andvpcEndpointIdas valid values foradvanced_event_selector.field_selector.field(#43091)errorCode,eventType,sessionCredentialFromConsole, andvpcEndpointIdas valid values foradvanced_event_selector.field_selector.field(#43091)kms_key_identifierargument (#43139)DELIVERYas a valid value forlog_group_class(#42658)environment.docker_serverconfiguration block (#42982)disable_session_tagsandtarget_role_arnarguments andexternal_idattribute (#42979)os_release_labelargument (#43018)resource_tag_logical_operatorargument (#43031)job_modeargument (#42607)tagsargument andtags_allattribute. This functionality requires thekinesis:ListTagsForResource,kinesis:TagResource, andkinesis:UntagResourceIAM permissions (#43173)HMAC_224,HMAC_384,HMAC_512,ML_DSA_44,ML_DSA_65, andML_DSA_87as valid values forcustomer_master_key_spec(#43128)-1is now a valid value forport_info.from_portandport_info.to_port(#37703)firewall_policy.stateful_rule_group_reference.deep_threat_inspectionargument (#43137)exclude_resource_tagsargument (#43189)tagsargument andtags_allattribute. This functionality requires thes3express:ListTagsForResource,s3express:TagResource, ands3express:UntagResourceIAM permissions (#43256)metadataargument (#43112)aws_managed_rules_anti_ddos_rule_settomanaged_rule_group_configsconfiguration block in support of L7 DDoS protection (#43149)BUG FIXES:
Unexpected Identity Changeerrors for numerous resource types when refreshing resources created or refreshed by Terraform AWS Provider v6.0.0 (#43221)Exceeded the number of retries on OptLock failure. Too many concurrent requests.errors during update (#43179)Prepare operation can't be performed on Agent when it is in Preparing state.errors during prepare (#43179)Update operation can't be performed on Agent when it is in Preparing state.errors during update (#43179)operation can't be performed on Agent when it is in Preparing state.errors during agent collaborator update and disassociation (#43179)log_group_names(#43183)"") value fors3_prefix. This fixes a regression introduced in v6.0.0 (#43159)log_publishing_optionsremoved on Update. This prevents a perpetual diff (#43033)ValidationException: The Resource Access Policy specified for the CloudWatch Logs log group ... does not grant sufficient permissions for Amazon Elasticsearch Service to create a log streamIAM eventual consistency errors on Create (#43033)logging_configdiffs whenlog_formatis set toJSONandpublish = true(#42660)confirmation_setting.prompt_specification.prompt_attempts_specificationdefaults (#43147)log_publishing_optionsremoved on Update. This prevents a perpetual diff (#43033)ValidationException: The Resource Access Policy specified for the CloudWatch Logs log group ... does not grant sufficient permissions for Amazon Elasticsearch Service to create a log streamIAM eventual consistency errors on Create (#43033)WHOLEis now a valid value fordefinition.sheets.visuals.pie_chart_visual.chart_configuration.donut_options.arc_options.arc_thickness(#37116)WHOLEis now a valid value fordefinition.sheets.visuals.pie_chart_visual.chart_configuration.donut_options.arc_options.arc_thickness(#37116)WHOLEis now a valid value fordefinition.sheets.visuals.pie_chart_visual.chart_configuration.donut_options.arc_options.arc_thickness(#37116)email(#43014)Value Conversion Errorerrors when upgrading existing resources to Terraform AWS Provider v6.0.0 (#43116)v6.0.0Compare Source
BREAKING CHANGES:
most_recentistrueand owner and image ID filter criteria has been increased to an error. Existing configurations which were previously receiving a warning diagnostic will now fail to apply. To prevent this error, set theownerargument or include afilterblock with animage-idorowner-idname/value pair. To continue using unsafe filter values withmost_recentset totrue, set the newallow_unsafe_filterargument totrue. This is not recommended. (#42114)inference_acceleratorattribute. Amazon Elastic Inference reached end of life on April, 2024. (#42137)inference_accelerator_overridesattribute. Amazon Elastic Inference reached end of life on April, 2024. (#42137)action.authenticate_cognito,action.authenticate_oidc,action.fixed_response,action.forward,action.forward.stickiness,action.redirect,condition.host_header,condition.http_header,condition.http_request_method,condition.path_pattern,condition.query_string, andcondition.source_ipattributes are now list nested blocks instead of single nested blocks (#42283)filterhas been removed (#42325)elastic_inference_acceleratorattribute. Amazon Elastic Inference reached end of life on April, 2024. (#42137)elastic_gpu_specificationshas been removed (#42312)kibana_endpointhas been removed (#42268)saml_optionsis now a list nested block instead of a single nested block (#42270)tags_allattribute (#42136)aws_opsworks_applicationresource has been removed (#41948)aws_opsworks_custom_layerresource has been removed (#41948)aws_opsworks_ecs_cluster_layerresource has been removed (#41948)aws_opsworks_ganglia_layerresource has been removed (#41948)aws_opsworks_haproxy_layerresource has been removed (#41948)aws_opsworks_instanceresource has been removed (#41948)aws_opsworks_java_app_layerresource has been removed (#41948)aws_opsworks_memcached_layerresource has been removed (#41948)aws_opsworks_mysql_layerresource has been removed (#41948)aws_opsworks_nodejs_app_layerresource has been removed (#41948)aws_opsworks_permissionresource has been removed (#41948)aws_opsworks_php_app_layerresource has been removed (#41948)aws_opsworks_rails_app_layerresource has been removed (#41948)aws_opsworks_rds_db_instanceresource has been removed (#41948)aws_opsworks_stackresource has been removed (#41948)aws_opsworks_static_web_layerresource has been removed (#41948)aws_opsworks_user_profileresource has been removed (#41948)aws_simpledb_domainresource has been removed. Add a constraint to v5 of the Terraform AWS Provider for continued use of this resource (#41775)aws_worklink_fleetresource has been removed (#42059)aws_worklink_website_certificate_authority_associationresource has been removed (#42059)aws_redshift_service_accountresource has been removed. AWS recommends that a service principal name should be used instead of an AWS account ID in any relevant IAM policy (#41941)endpoints.iotanalyticsandendpoints.ioteventsconfiguration arguments have been removed (#42703)endpoints.opsworksconfiguration argument has been removed (#41948)endpoints.simpledbandendpoints.sdbconfiguration arguments have been removed (#41775)endpoints.worklinkconfiguration argument has been removed (#42059)filter.existsnow only accepts one of""(empty string),true, orfalse(#42434)preserve_client_ipnow only accepts one of""(empty string),true, orfalse(#42434)reset_on_deleteargument has been removed (#42226)canary_settings,execution_arn,invoke_url,stage_description, andstage_namearguments. Instead, use theaws_api_gateway_stageresource to manage stages. (#42249)compute_environment_nametonameresource/aws_batch_compute_environment: Rename
compute_environment_name_prefixtoname_prefix(#38050)compute_environment_nametoname(#38050)compute_environmentsin place ofcompute_environment_order(#40751)logging_config,logging_config.cloudwatch_config,logging_config.cloudwatch_config.large_data_delivery_s3_config, andlogging_config.s3_configare now list nested blocks instead of single nested blocks (#42307)idis now set to remote object'sIdinstead ofname(#42230)etagargument is now computed only (#38448)suspendnow only accepts one of""(empty string),true, orfalse(#42434)idattribute is now a comma-delimited string concatenating theuser_pool_id,group_name, andusernamearguments (#34082)s3_prefixargument is now required (#38446)character_set_namenow cannot be set withreplicate_source_db,restore_to_point_in_time,s3_import, orsnapshot_identifier. (#42348)s3_settingsattribute. Useaws_dms_s3_endpointinstead (#42379)vpn_gateway_idhas been removed (#42323)terminate_instances_on_deletenow only accepts one of""(empty string),true, orfalse(#42434)block_duration_minutesattribute (#42060)inference_acceleratorattribute. Amazon Elastic Inference reached end of life on April, 2024. (#42137)vpchas been removed. Usedomaininstead. (#42340)resolve_conflictshas been removed. Useresolve_conflicts_on_createandresolve_conflicts_on_updateinstead. (#42318)auto_minor_version_upgradenow only accepts one of""(empty string),true, orfalse(#42434)at_rest_encryption_enabledandauto_minor_version_upgradenow only accept one of""(empty string),true, orfalse(#42434)auth_token_update_strategyno longer has a default value. Ifauth_tokenis set,auth_token_update_strategymust also be explicitly configured. (#42336)variations.value.bool_valuenow only accepts one of""(empty string),true, orfalse(#42434)log_group_namehas been removed. Uselog_destinationinstead. (#42333)idattribute is now computed only (#42097)datasources. Useaws_guardduty_detector_featureresources instead. (#42436)auto_enableattribute has been removed (#42251)filterhas been removed (#42325)instance_configuration.block_device_mapping.ebs.delete_on_terminationandinstance_configuration.block_device_mapping.ebs.encryptednow only accept one of""(empty string),true, orfalse(#42434)block_device_mapping.ebs.delete_on_terminationandblock_device_mapping.ebs.encryptednow only accept one of""(empty string),true, orfalse(#42434)cpu_core_countandcpu_threads_per_core. Instead, usecpu_options. (#42280)user_datanow displays cleartext instead of a hash. Base64 encoded content should useuser_data_base64instead. (#42078)block_device_mappings.ebs.delete_on_termination,block_device_mappings.ebs.encrypted,ebs_optimized,network_interfaces.associate_carrier_ip_address,network_interfaces.associate_public_ip_address,network_interfaces.delete_on_termination, andnetwork_interfaces.primary_ipv6now only accept one of""(empty string),true, orfalse(#42434)elastic_inference_acceleratorattribute. Amazon Elastic Inference reached end of life on April, 2024. (#42137)elastic_gpu_specificationshas been removed (#42312)mutual_authenticationConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.