Update Terraform aws to v5.87.0 #8
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.59.0->5.87.0Release Notes
hashicorp/terraform-provider-aws (aws)
v5.87.0Compare Source
FEATURES:
aws_cloudwatch_contributor_insight_rule(#41373)ENHANCEMENTS:
export_typeandincremental_export_specificationarguments (#41303)parameters.s3.role_arnargument to allow override an account-wide role for a specific S3 data source (#41284)master_password_wowrite-only attribute (#41314)stream_processor_arnin favor ofarn. (#41271)value_wowrite-only attribute (#40952)service_network_log_typeargument (#41304)BUG FIXES:
on_demand_throughputandglobal_secondary_index.*.on_demand_throughputattributes to resolve read error (#41350)OperationInProgresserrors (#41388)v5.86.1Compare Source
BUG FIXES:
AccessDeniedErrorattempting to list tags (#41295)AccessDeniedErrorattempting to list tags (#41295)sns_topic_nameshows perpectual diff when an ARN of a SNS topic from a different region is specified (#41279)rule[*].prefixis an empty string. (#41296)v5.86.0Compare Source
NOTES:
prefix, the Terraform plan will show the removal ofprefixfrom state. This is expected, and should not occur on subsequent plans. (#41159)ENHANCEMENTS:
monitoring_intervalandmonitoring_role_arnattributes (#41002)us-isof-east-1andus-isof-south-1as valid AWS Regions (#41243)security_service_policy_data.policy_option.network_acl_common_policyargument to allow creation of FMS-managed NACL rules (#41219)monitoring_intervalandmonitoring_role_arnarguments (#41002)timeouts. (#41232)BUG FIXES:
tags_allvalue (#41256)instance_lifecycleisspot(#41206)panic: runtime error: invalid memory address or nil pointer dereferencewhen deleting the resource would otherwise return an error (#41260)transition_default_minimum_object_size(#41159)ruleduring import (#41205)v5.85.0Compare Source
NOTES:
FEATURES:
aws_vpc_ipam(#40459)aws_vpc_ipams(#40459)aws_secretsmanager_random_password(#41106)aws_guardduty_member_detector_feature(#35625)aws_route53domains_domain(#37885)aws_timestreamquery_scheduled_query(#41145)aws_vpclattice_resource_configuration(#41019)aws_vpclattice_service_network_resource_association(#41057)ENHANCEMENTS:
arnattribute (#41086)arnattribute (#41087)arnattribute (#41084)network_interfaces.connection_tracking_specificationattribute (#41184)connector_profile_config.connector_profile_properties.salesforce.use_privatelink_for_metadata_and_authorizationargument (#41175)target_tracking_configuration.customized_metric_specification.metrics.metric_stat.periodargument to support high-resolution metrics (#41066)data_source_configuration.confluence_configuration,data_source_configuration.salesforce_configuration,data_source_configuration.share_point_configuration, anddata_source_configuration.web_configurationarguments (#40711)knowledge_base_configuration.vector_knowledge_base_configuration.embedding_model_configurationandknowledge_base_configuration.vector_knowledge_base_configuration.supplemental_data_storage_configurationarguments (#40737)sns_topic_arnattribute (#41168)suspendargument (#40607)invocation_connectivity_parametersargument (#41144)arnattribute (#41087)arnattribute (#41084)enable_fault_injectionargument (#41078)network_interfaces.connection_tracking_specificationargument (#41184)concurrent_jobsargument (#41012)createtimeout (#40972)orchestration_sending_role_arnargument (#41043)kms_key_identifierargument (#41082)instanceas a valid value forenabled_cloudwatch_logs_exports(#41111)tagsargument andtags_allattribute (#41192)resource_configuration_arnandservice_network_arnarguments to support creating VPC Endpoints of typeResourceandServiceNetwork(#41116)BUG FIXES:
created_dateandlast_modified_dateattributes (#41105)sort_ascendingto sort in ascending order (#40529)role_arnargument (#41072)Provider produced inconsistent result after applyerrors fors3_delivery_configuration.enable_hive_compatible_path(#41122)field_delimiteras Computed (#41122)provider_nameto count UTF-8 characters properly (#41187)nameto count UTF-8 characters properly (#41187)callback_urls,default_redirect_uri,logout_urls, andsupported_identity_providers` to count UTF-8 characters properly (#41187)panic: interface conversion: interface {} is float64, not string(#41096)InvalidParameterCombinationerror during update (#40969)name,name_prefix, andpathwithout forcing new resource (#41186)invitation_idwhen calling theAcceptInvitationAPI (#41163)v5.84.0Compare Source
NOTES:
FEATURES:
aws_eks_cluster_auth(#40660)aws_media_packagev2_channel_group(#38406)ENHANCEMENTS:
uefi_dataattribute (#40210)bandwidth_weightings,boot_modes,default_network_card_index,efa_maximum_interfaces,ena_srd_supported,inference_accelerators.memory_size,media_accelerators,network_cards,neuron_devices,nitro_enclaves_support,nitro_tpm_support,nitro_tpm_supported_versions,phc_support,supported_cpu_features,total_inference_memory,total_media_memory, andtotal_neuron_device_memoryattributes (#40717)mx-central-1AWS Region (#40940)mx-central-1AWS Region (#40940)mx-central-1AWS Region (#40940)mx-central-1as a valid AWS Region (#40940)uefi_dataargument (#40210)uefi_dataattribute (#40210)uefi_dataattribute (#40210)userIdentity.arnto advanced_event_selector.field_selector (#40629)engineis now case insensitive (#40794)engineis now case insensitive (#40794)arnattribute (#40930)arnattribute (#40930)arnattribute (#40930)arnattribute (#40930)routing_http_response_server_enabled,routing_http_response_strict_transport_security_header_value,routing_http_response_access_control_allow_origin_header_value,routing_http_response_access_control_allow_methods_header_value,routing_http_response_access_control_allow_headers_header_value,routing_http_response_access_control_allow_credentials_header_value,routing_http_response_access_control_expose_headers_header_value,routing_http_response_access_control_max_age_header_value,routing_http_response_content_security_policy_header_value,routing_http_response_x_content_type_options_header_value,routing_http_response_x_frame_options_header_value,routing_http_request_x_amzn_mtls_clientcert_serial_number_header_name,routing_http_request_x_amzn_mtls_clientcert_issuer_header_name,routing_http_request_x_amzn_mtls_clientcert_subject_header_name,routing_http_request_x_amzn_mtls_clientcert_validity_header_name,routing_http_request_x_amzn_mtls_clientcert_leaf_header_name,routing_http_request_x_amzn_mtls_clientcert_header_name,routing_http_request_x_amzn_tls_version_header_name, androuting_http_request_x_amzn_tls_cipher_suite_header_namearguments in support of HTTP header modification (#40736)triggersargument to support synchronization with upstream CloudWatch alarm changes (#40918)production_variants.managed_instance_scalingandshadow_production_variants.managed_instance_scalingto0(#40882)BUG FIXES:
ingress_vpc_configuration,name, andservice_arnto ForceNew (#40927)location URI global ID and subdirectory (...) does not match pattern "..."errors on Read whens3_bucket_arnis an S3 on Outposts access point (#40929)volume.configure_at_launchandvolume.docker_volume_configuration(#40853)v5.1.0with aninputthat cannot be marshaled into amap[string]interface{}(#40958)v5.1.0with no configuration changes (#40958)broker_node_group_info.0.storage_info.0.ebs_storage_info.0.provisioned_throughputis unset (#40910)broker_node_group_info.0.storage_info.0.ebs_storage_info.0.provisioned_throughputblock is removed (#40910)v5.83.1Compare Source
BUG FIXES:
fdqnvalue ifnameis a wildcard domain name (the leftmost label is*). This fixes a regression introduced in v5.83.0 (#40868)v5.83.0Compare Source
NOTES:
apigatewayv2client has been updated to more extensively matchConflictExceptionerror responses. This change should be transparent to users, but if any unexpected changes in behavior withapigatewayv2resources occur following an upgrade to this release, please open a bug report. (#40840)idin favor ofarn. (#40626)id. (#40626)idin favor ofbucket. (#40626)FEATURES:
aws_cloudwatch_event_buses(#40662)aws_ecs_clusters(#40638)aws_route53_records(#38186)aws_cognito_identity_openid_token_for_developer_identity(#40763)aws_bedrockagent_agent_collaborator(#40559)aws_cleanrooms_membership(#35165)aws_cloudwatch_log_delivery(#40731)aws_cloudwatch_log_delivery_destination(#40731)aws_cloudwatch_log_delivery_destination_policy(#40731)aws_cloudwatch_log_delivery_source(#40731)aws_cloudwatch_log_index_policy(#40594)aws_vpclattice_resource_gateway(#40821)ENHANCEMENTS:
compute_configurationattribute (#40752)kafka_settings.sasl_mechanismattribute (#36918)ap-southeast-7AWS Region (#40850)ap-southeast-7AWS Region (#40850)default_for_new_launchesattribute (#40536)supports_certificate_rotation_without_restart,supports_integrations, andsupports_local_write_forwardingattributes (#40700)ap-southeast-7AWS Region (#40850)regionattribute (#40795)service_regionsargument (#40795)ap-southeast-7as a valid AWS Region (#40849)data_transfer_apiattribute to destination_flow_config_list.destination_connector_properties.salesforce (#34937)grpc_configargument todefault_cache_behaviorandordered_cache_behaviorconfiguration blocks (#40762)compute_configurationargument (#40752)email_mfa_configurationargument (#40734)sign_in_policyandweb_authn_configurationarguments (#40765)user_pool_tierargument (#40633)kafka_settings.sasl_mechanismargument (#36918)nameandvaluearguments (#40772)instance_idornetwork_interface_id(#40769)node_repair_configconfiguration block (#40698)VALKEYas supported value for 'engine' argument (#40764)VALKEYas supported value for 'engine' argument (#40764)encryption_key_arnargument (#40771)user_invitation_urlattribute (#40775)iam-db-auth-erroras a valid value forenabled_cloudwatch_logs_exports(#40789)data_filterargument (#40816)override_providerconfiguration block, allowing tags inherited from the providerdefault_tagsconfiguration block to be ignored (#40689)BUG FIXES:
description,nameorversionif they are not present in the OpenAPI definitionbody(#40707)ConflictExceptionerror responses (#40840)panic: interface conversion: interface {} is nil, not map[string]interface {}whenparameters_in_cache_key_and_forwarded_to_origin.cookies_config,parameters_in_cache_key_and_forwarded_to_origin.headers_config, orparameters_in_cache_key_and_forwarded_to_origin.query_strings_configare empty (#40815)scaling_configurationto be removed on Update (#40773)file_system_locationsto be removed on Update (#40842)fips_dns_nameto an empty value ("") when no value is returned from the EC2 API. This fixes known-after-apply loops in Regions that don't support FIPS endpoints (#37939)create_table_default_permissionwith a nilprincipalblock (#40761)http_tokenswhenmetadata_optionsis updated (#40727)public_dnsandpublic_ipattributes when changinginstance_type,user_data, oruser_data_base64(#40710)operation error EC2: DetachInternetGateway, ..., api error InvalidInternetGatewayID.NotFound: ...errors on delete for resources deleted out-of-band (#40790)operation error EC2: DetachInternetGateway, ..., api error InvalidInternetGatewayID.NotFound: ...errors on delete for resources deleted out-of-band (#40790)logical_table_map.tag_column_operation.tags.column_description(#40713)manage_master_user_passwordbeing updated in state when update errors (#40538)alias.namecontains characters that the Route 53 API escapes (#40154)namecontains characters that the Route 53 API escapes (#40154)delivery_options.max_delivery_secondswhen not configured (#40670)sqs_managed_sse_enabled=trueandkms_data_key_reuse_period_secondsis configured (#40729)v5.82.2Compare Source
BUG FIXES:
mutual_authentication.advertise_trust_store_ca_namesattribute. This fixes a regression introduced in v5.82.0 causingsetting mutual_authentication: Invalid address to set: []string{"mutual_authentication", "0", "advertise_trust_store_ca_names"}errors (#40658)v5.82.1Compare Source
ENHANCEMENTS:
availability_zone_distributionargument (#40634)BUG FIXES:
statementsid(#40639)v5.82.0Compare Source
NOTES:
idattribute has changed to prevent inconsistent parsing which resulted in provider crashes under certain conditions. The new format is a comma-delimited string combininggroup_arnandresource_arnin their entirety. Configuarations relying on the previous format may need to be updated to continue functioning correctly. (#40579)FEATURES:
aws_servicecatalogappregistry_attribute_group_associations(#38306)aws_api_gateway_domain_name_access_association(#40566)aws_cloudfront_vpc_origin(#40239)aws_memorydb_multi_region_cluster(#40376)aws_networkmanager_dx_gateway_attachment(#40546)aws_rds_cluster_snapshot_copy(#40398)ENHANCEMENTS:
arnattribute (#40546)statementsidis valid, including on alphanumeric characters (#40562)service_regionattribute (#40583)agent_collaborationattribute to configure agent collaboration role (#40543)origin.vpc_origin_configargument (#40239)name_prefixargument (#40622)arnattribute (#40546)efa_enabledargument (#40381)advertise_trust_store_ca_namesattribute to themutual_authenticationconfiguration block (#40550)multi_region_cluster_nameargument (#40376)edge_locationsattribute (#40546)service_regionargument (#40583)BUG FIXES:
AccessDeniedException: ... is not authorized to perform: acm-pca:GetCertificateAuthorityCsr on resource: ...errors for RAM-shared CAs (#39952)setting entitlements: Invalid address to set: []string{"entitlements", "0", "overage"}errors (#40621)certificate_settingswhen updating. (#40589)certificate_settings.typetoCUSTOM. (#40589)ValidationExceptionwhen settingcertificate_settings.typetoAMPLIFY_MANAGED. (#40589)certificate_settingsnot set. (#40589)certificate_settingsis not set during update. (#40589)arnfor private custom domain names (#40566)vpc_configuration.tls_certificateas Optional (#40574)at_rest_encryption_enabledwhenengineisvalkey. (#40514)IAMPrincipalsprincipal group (#38600)permissionsandpermissions_with_grant_optionattributes (#38047)resultattribute when changinginputattribute, for lifecycle scope "CRUD" (#34263)teletext_destination_settings. (#33797)allocated_storage(#40601)force_destroy = truecan now delete objects with non-XML-safe keys (#40537)force_destroy = truecan now delete objects with non-XML-safe keys (#40537)automatically_after_dayswas not being set properly whenschedule_expressionhad been set previously (#34295)InvalidRequestException: A previous rotation isn't complete. That rotation will be reattempted.(#34295)redrive_allow_policydiffs (#40604)v5.81.0Compare Source
FEATURES:
aws_servicecatalogappregistry_attribute_group(#38188)aws_ssm_parameter(#40313)aws_bedrock_inference_profile(#40294)aws_cloudwatch_log_anomaly_detector(#40437)aws_ecr_account_setting(#40219)aws_msk_single_scram_secret_association(#37056)aws_servicecatalogappregistry_attribute_group(#38183)aws_servicecatalogappregistry_attribute_group_association(#38290)ENHANCEMENTS:
policyanddomain_name_idattributes (#40364)tagsattribute (#38243)delivery_options.max_delivery_secondsandtracking_options.https_policyattributes (#40194)domain_name_idargument (#40447)policyargument anddomain_name_idattribute (#40364)PRIVATEas a valid value forendpoint_configuration.typesargument, enabling custom domain name support for private REST API endpoints (#40364)completion_duration_minutesargument (#40336)configuration.retention_configurationandconfiguration.orphan_file_deletion_configurationattributes. (#40199)thumbprint_listoptional (#37255)enable_primary_ipv6argument to add support for enabling primary IPv6 addresses on EC2 instances (#36425)shard_countwould not exceed the AWS account's shard quota when the data stream capacity mode isPROVISIONED, preventing the provider from retrying for 1 hour in the case that the quota is exceeded. This functionality requires thekinesis:DescribeLimitsIAM permission (#40499)kinesis:DescribeLimitsIAM permission (#40499)topic_replication.topic_name_configurationargument (#40101)enable_primary_ipv6argument to add support for enabling primary IPv6 addresses for network interfaces (#36425)stateful_engine_options.flow_timeoutsargument (#39996)serverlessv2_scaling_configuration.seconds_until_auto_pauseargument (#40441)tagsargument andtags_allattribute (#40470)notebook-al2-v3value forplatform_identifier(#40484)tagsargument andtags_allattribute (#38243)delivery_options.max_delivery_secondsandtracking_options.https_policyarguments (#40194)BUG FIXES:
InvalidArgumentException: NextToken and StreamName cannot be provided togethererrors when the data stream has more than 1000 shards (#40499)rulefromTypeSettoTypeListas order is significant (#40521)throughput_capacityvalidation to allow values up to12228(#40468)logging_configuration.log_destination_configs (#40092)InvalidDBClusterStateFaulterrors when deleting clusters that are members of a global cluster (#40333)InvalidParameterValue: Serverless v2 maximum capacity 0.0 isn't valid. The maximum capacity must be at least 1.0.errors when removingserverlessv2_scaling_configurationin an update (#40511)storage_typewhen restoring from S3 (#40471)storage_typewhen restoring from snapshot (#40471)storage_typewhen restoring to a point in time (#40471)database_nameas Computed. This prevents resource recreation when the source cluster specifies adatabase_name(#40469)v5.80.0Compare Source
FEATURES:
aws_codeconnections_connection(#40300)aws_codeconnections_host(#40300)aws_s3tables_namespace(#40420)aws_s3tables_table(#40420)aws_s3tables_table_bucket(#40420)aws_s3tables_table_bucket_policy(#40420)aws_s3tables_table_policy(#40420)ENHANCEMENTS:
instructionmax length for validation to 8000 (#40279)deletion_protection_enabledargument (#35359)serverlessv2_scaling_configuration.max_capacityandserverlessv2_scaling_configuration.min_capacityminimum values to0to support Amazon Aurora Serverless v2 scaling to 0 ACUs (#40230)LocalZoneas a valid value forlocation.type, enabling support for [Amazon S3 Express OneConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Renovate Bot.