Update Terraform aws to v6 #56
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.60.0→6.28.0Release Notes
hashicorp/terraform-provider-aws (aws)
v6.28.0Compare Source
NOTES:
FEATURES:
aws_cloudfront_connection_group(#44885)aws_cloudfront_distribution_tenant(#45088)aws_kms_alias(#45700)aws_sqs_queue(#45691)aws_cloudfront_connection_function(#45664)aws_cloudfront_connection_group(#44885)aws_cloudfront_distribution_tenant(#45088)aws_cloudfront_multitenant_distribution(#45535)aws_dynamodb_global_secondary_index(#44999)aws_ecr_pull_time_update_exclusion(#45765)aws_organizations_tag(#45730)aws_redshift_idc_application(#37345)aws_secretsmanager_tag(#45825)aws_sesv2_tenant(#45706)ENHANCEMENTS:
endpoint_access_modeattribute (#45741)endpoint_network_typeandtarget_connection_network_typeattributes (#45634)tagsattribute (#45766)rule.action.target_storage_classandrule.selection.storage_classarguments, and new valid values forrule.action.typeandrule.selection.count_typearguments (#45752)saml_provider_uuidattribute (#45707)response_streaming_invoke_arnattribute (#45652)code_signing_config_arnin AWS GovCloud (US) Regions (#45652)dns_threat_protection,confidence_threshold,firewall_threat_protection_id,firewall_domain_redirection_action, andq_typeattributes (#45711)target_ipsattribute (#45492)dns_options.private_dns_preferenceanddns_options.private_dns_specified_domainsattributes (#45679)service_regionandvpc_endpoint_typefrom attributes to arguments for filtering (#45679)elasticloadbalancing:loadbalancertag type (#45671)elasticloadbalancing:listenertag type (#45671)elasticloadbalancing:listener-ruletag type (#45671)elasticloadbalancing:targetgrouptag type (#45671)endpoint_access_modeargument and configurable timeout for create and update (#45741)customer_content_encryption_configurationargument (#45744)enable_minimum_encryption_configurationargument (#45744)monitoring_configurationargument (#45744)connection_function_associationandviewer_mtls_configarguments (#45847)owner_account_idargument tovpc_origin_configfor cross-account VPC origin support (#45011)apply_on_transformed_logsargument (#45826)emit_system_fieldsargument (#45760)endpoint_network_typeandtarget_connection_network_typearguments (#45634)rds:dbtag type (#45671)rds:global-clustertag type (#45671)tagsargument andtags_allattribute. This functionality requires thedirectconnect:TagResourceanddirectconnect:UntagResourceIAM permissions (#45766)CREATE_ON_PUSHas a valid value forapplied_for(#45720)managed_instances_provider.instance_launch_template.capacity_option_typeargument (#45667)fsx:file-systemtag type (#45671)fsx:file-systemtag type (#45671)fsx:file-systemtag type (#45671)fsx:snapshottag type (#45671)fsx:volumetag type (#45671)fsx:file-systemtag type (#45671)finding_criteria.criterion.matchesandfinding_criteria.criterion.not_matchesarguments (#45758)delay_after_policy_creation_in_msargument. This functionality requires theiam:SetDefaultPolicyVersionIAM permission (#42054)saml_provider_uuidattribute (#45707)serial_numberattribute (#45751)logging_configurationargument (#45749)logging_configurationargument (#45749)resource_group_arn(#45688)rules_package_arnsandtarget_arn(#45688)provisioned_poller_config.poller_group_nameargument (#45313)kafka://topic-name) fordestination_config.on_failure.destination_arnargument (#45802)response_streaming_invoke_arnattribute (#45652)code_signing_config_arnin AWS GovCloud (US) Regions (#45652)lambda:InvokeFunctionpermission, with theInvokedViaFunctionUrlflag set totrue, to the function on creation whenauthorization_typeisNONE(#44858)invoked_via_function_urlargument (#44858)quic_server_idargument (#45666)target_group_arn(#45666)rds:clustertag type (#45671)rds:dbtag type (#45671)rds:global-clustertag type (#45671)routing_policy_labelargument. This functionality requires thenetworkmanager: PutAttachmentRoutingPolicyLabelandnetworkmanager: RemoveAttachmentRoutingPolicyLabelIAM permissions (#45728)pipeline_role_arnargument to support specifying a IAM role at the pipeline level (#45806)rds:clustertag type (#45671)consumer_region(#45688)dns_threat_protection,confidence_threshold, andfirewall_threat_protection_idarguments to support DNS Firewall Advanced rules (#45711)endpoint_details.vpcconfiguration block to support VPC hosted Transfer Family web app (#45745)dns_options.private_dns_preferenceanddns_options.private_dns_specified_domainsarguments (#45679)private_dns_enabledargument (#45673)tunnel*_inside_cidrandtunnel*_inside_ipv6_cidrarguments (#45781)BUG FIXES:
proxy_endpointwhenregistry_idis specified (#45754)account-id, notaccount, as a valid value forattachment_policies.conditions.type. This fixes a regression introduced in v6.27.0 (#45788)service_regionattribute (#45679)user_agentvalues where the product name contains a forward slash (#45715)node_propertieshasNodeRangeProperties.ecsPropertiesset (#45676)PutSubscriptionFilter: RetryValidationException: Make sure you have given CloudWatch Logs permission to assume the provided role(#43762)reading EC2 VPC (...) default Security Group: empty resultandreading EC2 VPC (...) main Route Table: empty resulterrors when importing RAM-shared VPCs. This fixes a regression introduced in v6.17.0 (#45780)private_dns_enabledargument is now marked asForceNew(#45679)v6.27.0Compare Source
FEATURES:
aws_organizations_account(#45543)user_agent(#45464)aws_kms_key(#45514)aws_cloudfront_trust_store(#45534)ENHANCEMENTS:
root_domain_unit_idattribute (#44964)routing_policiesandattachment_routing_policy_rulesarguments (#45246)rni_enhanced_metrics_enabledattribute (#45630)target_name_server_metrics_enabledattribute (#45630)user_agentargument (#45464)provider_metablock is now supported. Theuser_agentargument enables module authors to include additional product information in theUser-Agentheader sent during all AWS API requests made during Create, Read, Update, and Delete operations. (#45464)knowledge_base_configuration.kendra_knowledge_base_configurationargument (#44388)knowledge_base_configuration.sql_knowledge_base_configurationandstorage_configuration.neptune_analytics_configurationarguments (#45465)storage_configuration.mongo_db_atlas_configurationargument (#37220)storage_configuration.opensearch_managed_cluster_configurationargument (#44060)storage_configuration.s3_vectors_configurationblock (#45468)knowledge_base_configuration.vector_knowledge_base_configurationand ``storage_configuration` optional (#44388)cache.cache_namespaceargument (#45584)root_domain_unit_idargument (#44964)code_sha256is now optional and computed (#45618)routing_policy_labelargument (#45246)bgp_options.peer_asn(#45246)configuration.bgp_configurations.peer_asn(#45639)routing_policy_labelargument (#45246)routing_policy_labelargument (#45246)routing_policy_labelargument (#45246)routing_policy_labelargument (#45246)rni_enhanced_metrics_enabledargument (#45630)target_name_server_metrics_enabledargument (#45630)private_dns_enabledanddns_optionsarguments (#45619)BUG FIXES:
attachment_policies.conditions.typeto allowaccountinstead ofaccount-id(#45246)knowledge_base_configuration.vector_knowledge_base_configuration.embedding_model_configurationandknowledge_base_configuration.vector_knowledge_base_configuration.supplemental_data_storage_configurationasForceNew(#45465)global_secondary_indexwhen usingignore_changeslifecycle meta-argument (#41113)NoSuchEntityerrors whennameandtagsarguments are both updated (#45608)excluded_column_namesordering causing "Provider produced inconsistent result after apply" errors (#45453)bgp_optionsandbgp_options.peer_asnto Optional, Computed and ForceNew (#45639)endpoint rule error, AccountId must only contain a-z, A-Z, 0-9 and `-`errors when the provider is configured withskip_requesting_account_id = true. This fixes a regression introduced in v6.23.0 (#45576)v6.26.0Compare Source
FEATURES:
aws_batch_job_definition(#45401)aws_codebuild_project(#45400)aws_lambda_capacity_provider(#45467)aws_ssm_parameter(#45512)aws_iam_outbound_web_identity_federation(#45217)ENHANCEMENTS:
upgrade_rollout_orderattribute (#45527)update_configblock includingupdate_strategyattribute (#41487)upgrade_rollout_orderattribute (#45527)session_summary_configuration.max_recent_sessionsargument (#45449)upgrade_rollout_orderattribute (#45527)update_config.update_strategyattribute (#41487)application_configuration.application_encryption_configurationargument (#45356)FLINK-1_20as a valid value forruntime_environment(#45356)odb_network_arnfor resource sharing model. (#45509)upgrade_rollout_orderattribute (#45527)encryption_configurationblock (#45470)metadata_configurationblock (#45470)BUG FIXES:
encryption_support. This addresses a regression introduced in v6.25.0. (#45462)timeout_millisecondsvalidation to allow up to 900,000 ms whenresponse_transfer_modeisSTREAM(#45482)logging_config.s3_config.bucket_name,logging_config.cloudwatch_config.log_group_name,logging_config.cloudwatch_config.role_arn, andlogging_config.cloudwatch_config.large_data_delivery_s3_config.bucket_nameas Required (#45469)encryption_support. This addresses a regression introduced in v6.25.0. (#45462)image_confighasnullvalues set in config (#45511)event_patternargument is not specified in config (#45524)vpc_config.security_group_idsandvpc_config.subnetsasForceNew(#45491)v6.25.0Compare Source
FEATURES:
aws_cloudwatch_log_transformer(#44300)aws_eks_capability(#45326)ENHANCEMENTS:
rule.scan_actionandscan_settingattributes (#45392)deletion_protection_enabledattribute (#45298)encryption_supportattribute (#45317)durable_configattribute (#45359)health_check_logsattribute (#45269)target_control_portattribute (#45270)enable_accelerated_recoveryattribute (#45302)egress_configattribute to expose VPC Lattice connectivity configuration (#45314)tenancyattribute (#43134)integration_targetargument (#45311)response_transfer_modeargument (#45329)configuration.managed_query_results_configurationblock (#44273)rule.scan_actionandscan_settingconfiguration blocks (#45392)interceptor_configurationargument (#45344)deletion_protection_enabledargument (#45298)encryption_supportargument (#45317)regional_nat_gateway_idargument (#45380)plaintext_woandplaintext_wo_versionarguments to support write-only input (#43592)durable_configargument (#45359)health_check_logsconfiguration block (#45269)target_control_portargument to support the ALB Target Optimizer (#45270)accept_role_session_nameargument (#45391)managed_policy_arnsandrole_arns(#45391)enable_accelerated_recoveryargument (#45302)calendar_namesargument (#45363)egress_configargument to support VPC Lattice connectivity for SFTP connectors (#45314)urlargument optional to support VPC Lattice connectors (#45314)tenancyargument (#43134)v6.24.0Compare Source
FEATURES:
aws_lambda_capacity_provider(#45342)aws_s3tables_table_bucket_replication(#45360)aws_s3tables_table_replication(#45360)aws_s3vectors_index(#43393)aws_s3vectors_vector_bucket(#43393)aws_s3vectors_vector_bucket_policy(#43393)ENHANCEMENTS:
capacity_provider_configattribute (#45342)auto_provision_zones,auto_scaling_ips,availability_mode,availability_zone_address,regional_nat_gateway_address, androute_table_idattributes (#45240)target_logically_air_gapped_backup_vault_arnargument toruleblock (#45321)capacity_provider_configandpublish_toarguments (#45342)id. Usearninstead. (#45345)id. Usearninstead. (#45345)subnet_idargument optional to support regional NAT Gateways (#45420)availability_mode,availability_zone_address, andvpc_idarguments, andauto_provision_zones,auto_scaling_ips,regional_nat_gateway_address, androute_table_idattributes. This functionality requires theec2:DescribeAvailabilityZonesIAM permission (#45240)bgp_log_enabled,bgp_log_group_arn, andbgp_log_stream_arnarguments totunnel1_log_options.cloudwatch_log_optionsandtunnel2_log_options.cloudwatch_log_optionsblocks (#45271)v6.23.0Compare Source
NOTES:
TagResource,UntagResource, andListTagsForResourcefor read and update operations. The calling principal must have the correspondings3:TagResource,s3:UntagResource, ands3:ListTagsForResourceIAM permissions. If the principal lacks the appropriate permissions, the provider will fall back to tagging after creation and using the S3 tagging APIsPutBucketTagging,DeleteBucketTagging, andGetBucketTagginginstead. With ABAC enabled, tag modifications may fail with the fall back behavior. See the AWS documentation for additional details on enabling ABAC in general purpose buckets. (#45251)FEATURES:
aws_ecs_express_gateway_service(#45235)aws_s3_bucket_abac(#45251)aws_vpc_encryption_control(#45263)aws_vpn_concentrator(#45175)ENHANCEMENTS:
tenant_idargument (#45170)control_plane_scaling_configattribute (#45258)tenancy_configattribute (#45170)tenant_idargument (#45170)vpn_concentrator_idattribute (#45175)managed_instances_provider.infrastructure_optimizationargument (#45142)network_typeargument (#45140)supported_network_typesattribute (#45140)control_plane_scaling_configconfiguration block to support EKS Provisioned Control Plane (#45258)tenancy_configargument (#45170)tenant_idargument (#45170)s3:TagResourcepermission is present (#45251)s3:TagResource,s3:UntagResource, ands3:ListTagsForResourcepermissions are present (#45251)vpn_concentrator_idargument to support Site-to-Site VPN Concentrator (#45175)v6.22.1Compare Source
ENHANCEMENTS:
INTELLIGENT_TIERINGstorage type and addread_cache_configurationargument (#45159)rebalancingconfiguration block to support intelligent rebalancing for Express broker clusters (#45073)BUG FIXES:
interface conversion: interface {} is nil, not map[string]interface {}panics whenconfiguration.unused_access.analysis_rule.exclusion.resource_tagscontainsnullvalues (#45202)v6.22.0Compare Source
NOTES:
blocked_encryption_typesargument to manage this behavior for specific buckets. (#45105)FEATURES:
aws_ecr_authorization_token(#44949)Tag Policy Compliance(#45143)aws_billing_view(#45097)aws_vpclattice_domain_verification(#45085)ENHANCEMENTS:
default_action.jwt_validationattribute (#45089)action.jwt_validationattribute (#45089)tagsonly or byvpc_idonly (#39671)tag_policy_complianceprovider argument, or theTF_AWS_TAG_POLICY_COMPLIANCEenvironment variable. When enabled, the principal executing Terraform must have thetags:ListRequiredTagsIAM permission. (#45143)encryption_key_arnargument (#45020)input_action,input_enabled,input_modalities,output_action,output_enabled, andoutput_modalitiesarguments to thecontent_policy_config.filters_configblock (#45104)storage_configuration.rds_configuration.field_mapping.custom_metadata_fieldargument (#45075)agent_runtime_artifact.code_configurationblock (#45091)agent_runtime_artifact.container_configurationblock optional (#45091)global_table_witnessargument (#43908)scaling_strategyandutilization_performance_indexarguments (#45132)log_configuration.cloudwatch_logs_configuration.log_group_arn(#35941)Functionstoaction.*.target(#41209)jwt-validationas a validdefault_action.typeand adddefault_action.jwt_validationconfiguration block (#45089)jwt-validationas a validaction.typeand addaction.jwt_validationconfiguration block (#45089)SECURITYHUB_POLICYas a valid value forenabled_policy_typesargument (#45135)destination.cloudwatch_logs.log_group_arn(#35941)logging_configuration.log_group_arn(#35941)rule.blocked_encryption_typesargument (#45105)container.additional_model_data_sourceandprimary_container.additional_model_data_sourcearguments (#44407)logging_configuration.log_destination(#35941)engine_typeattribute (#44899)timestream-influxdb:GetDbParameterGroupIAM permission (#44899)custom_domain_nameanddomain_verification_idarguments anddomain_verification_arnanddomain_verification_statusattributes to support custom domain names for resource configurations ([#45085](https://redirect.github.Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.