Update dependency hashicorp/terraform-provider-aws to v6#257
Open
renovate[bot] wants to merge 1 commit into
Open
Update dependency hashicorp/terraform-provider-aws to v6#257renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
3 times, most recently
from
July 2, 2025 23:33
c9decca to
c515259
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
from
July 10, 2025 21:56
c515259 to
39877a3
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
from
July 17, 2025 23:37
39877a3 to
7cb63e1
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
from
July 25, 2025 00:13
7cb63e1 to
1f45df5
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
August 7, 2025 21:28
7c12994 to
a2cf05c
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
from
August 14, 2025 20:46
a2cf05c to
d1e8ecb
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
August 28, 2025 20:52
a2c304c to
e8ff807
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
from
September 4, 2025 20:37
e8ff807 to
81a9434
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
September 19, 2025 02:30
135d94b to
66d2096
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
from
September 22, 2025 21:12
66d2096 to
d0a700e
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
October 9, 2025 19:01
9c83e76 to
6953548
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
from
October 16, 2025 21:33
6953548 to
b513080
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
from
October 23, 2025 22:54
b513080 to
92e8140
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
November 6, 2025 23:40
ab57a8a to
1e2f68b
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
from
November 13, 2025 20:53
1e2f68b to
de50195
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
3 times, most recently
from
November 26, 2025 20:12
4570e24 to
3c0a9ed
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
December 5, 2025 04:10
5e3ea07 to
6f02b3c
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
from
December 10, 2025 21:25
6f02b3c to
78f5c59
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
from
December 18, 2025 01:05
78f5c59 to
f232a75
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
from
January 8, 2026 18:14
f232a75 to
5ba2d02
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
February 4, 2026 20:31
af6bcfa to
f3ad7ba
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
February 13, 2026 18:24
1c90cdb to
e018e50
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
February 25, 2026 23:02
c1e19ca to
75c5a7b
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
3 times, most recently
from
March 11, 2026 20:33
82aec0e to
0a3e34e
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
from
March 18, 2026 21:52
0a3e34e to
eab92b5
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
April 1, 2026 22:12
fe8eea1 to
a2930ae
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
from
April 9, 2026 00:18
a2930ae to
8b09f4c
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
April 23, 2026 00:45
08a593c to
f270074
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
May 7, 2026 01:32
175af95 to
7b06e1b
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
May 20, 2026 21:34
538e92d to
7504a72
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
June 3, 2026 21:50
16eac86 to
7f33c04
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
June 10, 2026 23:01
5471193 to
466f1d2
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
June 24, 2026 18:46
aa1bc10 to
7203d2e
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
from
July 1, 2026 22:33
7203d2e to
4069c67
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
2 times, most recently
from
July 15, 2026 18:05
d54ac35 to
1dfd7a0
Compare
renovate
Bot
force-pushed
the
renovate/hashicorp-terraform-provider-aws-6.x
branch
from
July 23, 2026 00:59
1dfd7a0 to
d673a2e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.25.0→6.56.0Release Notes
hashicorp/terraform-provider-aws (hashicorp/terraform-provider-aws)
v6.56.0Compare Source
FEATURES:
aws_elasticache_apply_service_update(#48963)aws_elasticache_service_update_actions(#48958)aws_s3_buckets(#48965)aws_eks_addon(#49067)aws_s3_bucket_notification(#48974)aws_secretsmanager_secret_policy(#49058)ENHANCEMENTS:
warm_pool_configattribute (#48977)bootstrap_brokers_ipv6,bootstrap_brokers_sasl_iam_ipv6,bootstrap_brokers_sasl_scram_ipv6, andbootstrap_brokers_tls_ipv6attributes to expose IPv6 bootstrap broker URLs (#48975)iam_federation_optionsblock (#48495)iam_identity_center_optionsblock (#48495)TF_AWS_WEB_IDENTITY_TOKENenvironment variable. Any value configured viaassume_role_with_web_identity.web_identity_tokentakes precedence (#48736)instance_lifecycle_policyconfiguration block (#48973)data_source_configuration.managed_knowledge_base_connector_configurationblock (#48904)timeouts.updatewith a default value of30m(#48904)vector_knowledge_base_configuration.bedrock_embedding_model_configuration.audioandvector_knowledge_base_configuration.bedrock_embedding_model_configuration.videoconfiguration blocks (#48538)type = "MANAGED") withmanaged_knowledge_base_configurationblock (#48904)@source.logas a valid value foremit_system_fields(#48956)warm_pool_configconfiguration block (#48977)tag_field_specificationconfiguration block (#48913)AI_PROTECTIONandAI_ANALYSTfeature names (#48972)AI_PROTECTIONandAI_ANALYSTfeature names (#48972)bootstrap_brokers_ipv6,bootstrap_brokers_sasl_iam_ipv6,bootstrap_brokers_sasl_scram_ipv6, andbootstrap_brokers_tls_ipv6attributes to expose IPv6 bootstrap broker URLs (#48975)iam_federation_optionsconfiguration block (#48495)iam_identity_center_optionsconfiguration block (#48495)metadata.iceberg.propertiesargument (#48635)BUG FIXES:
assume_role_with_web_identity.0.web_identity_token,assume_role_with_web_identity.0.web_identity_token_filemust be specified" errors, allowing anyAWS_WEB_IDENTITY_TOKEN_FILEenvironment variable value to be used (#48736)FAILEDstate (#48904)AccessDeniedExceptionerror when deleting (#48516)data_read_cache_configuration.sizewhensizing_modeisPROPORTIONAL_TO_THROUGHPUT_CAPACITYandsizeis not specified (#49023)shared_resourcesdiffs for ActiveMQ brokers (#48962)ConflictException: Configuration ID [...] is in useerrors on delete (#48962)Cannot create already existing endpointerror when retrying creation. (#48966)v6.55.0Compare Source
FEATURES:
aws_elasticache_service_updates(#44608)aws_autoscaling_group(#48928)aws_cloudwatch_log_stream(#48878)aws_kinesis_firehose_delivery_stream(#48946)aws_network_interface(#48887)aws_rds_cluster(#48948)aws_sfn_state_machine(#48840)ENHANCEMENTS:
updated_atattribute (#48881)allowed_workload_configuration,private_endpoint, andprivate_endpoint_overridesconfiguration blocks toauthorizer_configuration.custom_jwt_authorizer, and the read-onlyrequire_service_s3_endpointattribute tonetwork_configuration.network_mode_config(#48654)allowed_workload_configuration,private_endpoint, andprivate_endpoint_overridesconfiguration blocks toauthorizer_configuration.custom_jwt_authorizer(#48654)allowed_workload_configuration,private_endpoint, andprivate_endpoint_overridesconfiguration blocks toauthorizer_configuration.custom_jwt_authorizer(#48654)require_service_s3_endpointargument tonetwork_configuration.network_mode_config(#48654)allowed_workload_configuration,private_endpoint, andprivate_endpoint_overridesconfiguration blocks toauthorizer_configuration.custom_jwt_authorizer(#48654)consumer_group_offset_sync_modeattribute toconsumer_group_replicationblock (#47670)BUG FIXES:
Unsupported Typeerrors when nomemoryis configured (#48654)interface conversion: interface {} is nil, not *configservice.DescribeOrganizationConfigRuleStatusesOutputpanics on delete (#48845)v6.54.0Compare Source
NOTES:
capacity_reservation_config, it is best effort and we ask for community help in testing (#45926)FEATURES:
aws_route53profiles_profile(#48780)aws_bedrockagentcore_browser_profile(#46862)aws_codepipeline(#48808)aws_lambda_function_scaling_config(#48229)aws_scheduler_schedule(#48828)aws_ssoadmin_region(#48126)aws_workspaces_pool(#42678)aws_bedrockagentcore_browser_profile(#46862)aws_lambda_function_scaling_config(#48229)aws_ssoadmin_region(#48126)aws_workspaces_pool(#42678)ENHANCEMENTS:
host_kernel_overrideargument (#48777)resource_share_arnsandshared_resourcesattributes (#48729)tagsandtags_allattributes (#48458)host_kernelargument to theenvironmentconfiguration block (#48777)use_resource_timeout_for_propagationargument (#46405)10mforcreateandupdate,5mfordelete. (#46405)use_resource_timeout_for_propagationargument (#46405)5mforcreate,read, anddelete. (#46405)resource_share_arnsargument andshared_resourcesattribute (#48729)out_of_order_time_window_in_secondsandrule_query_offset_in_secondsarguments (#48659)auto_minor_version_upgradeargument (#42472)production_variants.capacity_reservation_configandshadow_production_variants.capacity_reservation_configconfiguration blocks (#45926)BUG FIXES:
content_policy_configblock. (#48772)topic_policy_configblock. (#48772)content_policy_config.filters_config.input_modalitiesvalues. (#48772)content_policy_config.filters_config.output_modalitiesvalues. (#48772)etagon Import. (#48782)etagwhen onlytagsupdated. (#48782)UnsupportedOperationExceptionerror when readingenable_directory_data_accessin regions where Directory Service Data is not available (e.g. GovCloud) (#47660)v6.53.0Compare Source
BREAKING CHANGES:
opt_out_list_nameandtwo_way_channel_enabledin favor of AWS server-side defaults (Defaultandfalserespectively). Configurations that omit these attributes will now show(known after apply)on first plan instead of the previous static value; the post-apply state is unchanged. This change mitigates persistent drift when the phone number is managed by anaws_pinpointsmsvoicev2_pool. (#48414)NOTES:
bedrock-agentcorenamespace to theagent-registrynamespace. Theaws_bedrockagentcore_browserresource will continue to work until September 17, 2026 (#48693)bedrock-agentcorenamespace to theagent-registrynamespace. Theaws_bedrockagentcore_browserresource will continue to work until September 17, 2026 (#48693)aws_ecs_cluster_capacity_providers, add areplace_triggered_bylifecycle rule to the association so the old capacity provider is detached before it is deleted (#48156)FEATURES:
aws_bedrock_foundation_model_agreement_offers(#47665)aws_bedrock_use_case_for_model_access(#47665)aws_ec2_capacity_block_reservation(#48185)aws_pinpointsmsvoicev2_pool(#48414)aws_bedrock_foundation_model_agreement(#47665)aws_bedrock_use_case_for_model_access(#47665)aws_pinpointsmsvoicev2_pool(#48414)ENHANCEMENTS:
security_policyandendpoint_access_modeattributes (#47973)customer_action_statusattribute (#48536)security_policyandendpoint_access_modearguments (#47973)browser_signing,certificate, andenterprise_policyconfiguration blocks (#47816)certificateargument (#47817)rule_definition(#48679)rule_stateto Optional and Computed (#48679)resource_arnandtemplate_name(#48679)customer_action_statusattribute (#48536)force_disassociateargument (#48414)idin favor ofarn(#48636)idin favor ofarn(#48636)idin favor ofarn(#48636)BUG FIXES:
authorization_tokenas sensitive (#48577)resource_arn,tagsandtemplate_nameasForceNew(#48679)importblock orterraform import(#47590)InvalidActionerrors in partitions where access key cleanup operations are not supported (#48473)instance_market_options.market_typeis set tocapacity-block(#48701)secret_access_keyas sensitive (#48577)private_keyas sensitive (#48577)typeattribute to no longer force resource replacement on change (#47105)v6.52.0Compare Source
NOTES:
aws_glue_catalog_tableviews (table_type = "VIRTUAL_VIEW") are now preserved when the view'sview_definitionis updated, as the underlying table is updated in place rather than recreated (#48532)****forNoEchoparameters or is missing default-matchingparameterskeys require a one-time manual reconciliation after upgrading. To recover: (1) addlifecycle { ignore_changes = [parameters] }temporarily, (2) pull state withterraform state pull, (3) correct the affectedparametersvalues and incrementserial, (4) push state back withterraform state push, (5) remove theignore_changesblock, and (6) confirm withterraform plan. For non-sensitive parameters you can instead temporarily set the parameter to a non-default value, apply, revert, and apply again (#46748)NoEchoparameter values are now persisted in Terraform state in plaintext rather than as****. This is consistent with how Terraform stores other sensitive inputs (for example,aws_db_instance.password). Ensure your state backend is appropriately secured (#46748)FEATURES:
aws_s3_bucket_notification(#31512)aws_appautoscaling_target(#48449)aws_bedrockagentcore_registry(#48314)aws_dynamodb_table_item(#48520)aws_bedrockagentcore_registry(#48314)ENHANCEMENTS:
control_plane_egress_modeattribute tovpc_configblock (#48497)arnattribute (#48502)control_plane_egress_modeargument tovpc_configblock (#48497)instances.0.endpointsare now returned in a deterministic order based on protocol prefix and port, including the newhttps://...:16001Prometheus metrics endpoint introduced in RabbitMQ 4.2 and later; any unrecognized endpoint types are appended afterward in API order (#47777)capabilitiesfromRequiredtoOptional/Computed. Applications without required capabilities can now omit the argument and the value applied by AWS will be tracked in state (#46748)BUG FIXES:
IdempotentParameterMismatchby generating client-supplied idempotency tokens using a cryptographically strong random generator and extended alphabet (#47995)TF_LOG=DEBUGoutput for resources, data sources, and list resources. Redaction continues to apply to ephemeral resources and actions (#48463)ConflictExceptionerrors (#48158)Provided delivery configuration is invalid for the destination typeerrors whens3_delivery_configurationis unchanged (#46123)automatic_failover_enableddiff by reading the value from the primary member (#47647)automatic_failover_enableddiff on member replication groups of anaws_elasticache_global_replication_group(#47647)Provider returned invalid result object after applyand subsequenttoo many resultswarning that silently removed the resource from state whenidwas not set in configuration (#48462)InvalidParameterCombination: Serverless Cache modifications only support modifying one field per requesterror when changing multiple attributes in a single apply (#47918)user_idproducing inconsistent final plan when using mixed-case values (#47705)user_group_idproducing inconsistent final plan when using mixed-case values (#47705)VIRTUAL_VIEWtable'sview_definitionby passingViewUpdateActionto the GlueUpdateTableAPI (#48532)change set: unexpected state 'FAILED', wanted target 'CREATE_COMPLETE'. last error: No updates are to be performederrors on subsequent applies. Previously,parameterswhose value matched the application's default were pruned from state, andNoEchoparameter values were stored as****, both of which produced false drift (#46748)v6.51.0Compare Source
NOTES:
managed_certificate_request, managed certificate issuance uses a fixed 3-hour timeout regardless of the configured resource timeout. This behavior will be updated in a future major version. (#47839)kms_key_arnattribute has been deprecated. All configurations usingkms_key_arnshould be updated to use theserver_side_encryption_kms_key_idattribute instead. (#48441)outpost_config, the changes are best effort and we ask for community help in testing (#48367)FEATURES:
aws_acm_certificate(#48283)aws_bedrockagentcore_evaluator(#47964)aws_sagemaker_hub_content_reference(#48379)aws_bedrockagentcore_evaluator(#47964)aws_sagemaker_hub_content_reference(#48379)ENHANCEMENTS:
outpost_config.control_plane_placement.spread_level,outpost_config.etcd_instance_type, andoutpost_config.etcd_placementattributes (#48367)origin.custom_origin_config.origin_mtls_configargument (#46421)origin.custom_origin_config.origin_mtls_configargument (#46421)outpost_config.control_plane_placement.spread_level,outpost_config.etcd_instance_type, andoutpost_config.etcd_placementarguments (#48367)outpost_config.control_plane_placement.group_nameto Optional (#48367)durabilityargument (#48254)network_typeargument (#48371)destination_metrics_configurationandsource_metrics_configurationblocks (#48303)vector_options.serverless_vector_accelerationargument (#47018)BUG FIXES:
subject_alternative_namesfor Imported certificates (#48362)kms_key_arnis set but not returned by the API for S3 engine endpoints. (#48441)log_delivery_configurationwithlog_type = "slow-log"while simultaneously upgrading the engine from Redis 5 to Redis 6 or Valkey 7 (#46526)InvalidArgumentExceptionerrors when creating or updatingextended_s3_configurationin AWS partitions that report unsupportedcustom_time_zoneandfile_extensionattributes in a combined error message (#48369)principalblock required (#48416)runtime error: index out of range [0] with length 0panic when importing a replicator with no replication configurations (#48338)v6.50.0Compare Source
NOTES:
private_endpoint, it is best effort and we ask for community help in testing (#47602)FEATURES:
aws_bedrockagentcore_policy(#47971)aws_cloudwatch_log_s3_table_integration_source(#48190)aws_ecs_daemon(#47562)aws_ecs_daemon_task_definition(#47562)aws_bedrockagentcore_policy(#47971)aws_cloudwatch_log_s3_table_integration_source(#48190)aws_ecs_daemon(#47562)aws_ecs_daemon_task_definition(#47562)aws_observabilityadmin_s3_table_integration(#48190)ENHANCEMENTS:
AGUIas a valid value forprotocol_configuration.server_protocol(#47906)policy_engine_configurationconfiguration block (#47818)listing_modeargument to thetarget_configuration.mcp.mcp_serverconfiguration block (#48225)private_endpointargument to support private connectivity to VPC-hosted MCP servers via Amazon VPC Lattice (#47602)indexed_keyandstream_delivery_resourcesarguments (#48240)BUG FIXES:
couldn't find resourceerrors when reading a version immediately after creation (#48318)ValidationException: Make sure you have given CloudWatch Logs permission to assume the provided roleIAM eventual consistency errors on Create and Update (#48255)route.gateway_idwhenroute.odb_network_arnis configured (#48239)network_configuration[0].security_groupswhen usingnetwork_configuration.ec2:DescribeSecurityGroupsIAM permission is newly required. (#47944)Resource Already Existserror when recreating a service after deletion (#48098)InvalidArgumentExceptionerrors when creating or updatingextended_s3_configurationin AWS partitions that do not support thecustom_time_zoneandfile_extensionattributes (#48284)gateway_idwhenodb_network_arnis configured (#48239)route.gateway_idwhenroute.odb_network_arnis configured (#48239)Provider produced inconsistent final planerrors whensecret_stringorsecret_string_wo_versionreferences a resource being created or replaced in the same apply (#48318)version_stagesbeing empty in state (#48318)secret_stringandsecret_string_wo(or vice versa) without changing the secret value (#48318)v6.49.0Compare Source
ENHANCEMENTS:
advanced_security_options.jwt_options.jwks_urlattribute (#48146)generationattribute (#48125)protocol_configuration.mcp.session_configurationblock (#48179)protocol_configuration.mcp.streaming_configurationblock (#48179)tagsandtags_allarguments (#47916)advanced_security_options.jwt_options.jwks_urlargument (#48146)generationargument (#48125)BUG FIXES:
runtime error: slice bounds out of range [1:0]panics when refreshing state. This fixes a regression introduced in v6.48.0 (#48215)v6.48.0Compare Source
NOTES:
FEATURES:
aws_ec2_hosts(#47986)aws_cleanrooms_membership(#48166)aws_pinpointsmsvoicev2_event_destination(#48034)aws_ec2_local_gateway_route_table([#48013](https://redirect.github.com/hashicorp/terraform-providConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.