Update Terraform aws to v6 #27
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.64.0->6.21.0Release Notes
hashicorp/terraform-provider-aws (aws)
v6.21.0Compare Source
BREAKING CHANGES:
network_configuration.network_mode_configtonetwork_configuration.vpc_config(#44828)FEATURES:
aws_dynamodb_create_backup(#45001)aws_networkflowmonitor_monitor(#44782)aws_networkflowmonitor_scope(#44782)aws_observabilityadmin_centralization_rule_for_organization(#44806)ENHANCEMENTS:
capacity_provider_strategy,created_at,created_by,deployment_configuration,deployment_controller,deployments,enable_ecs_managed_tags,enable_execute_command,events,health_check_grace_period_seconds,iam_role,network_configuration,ordered_placement_strategy,pending_count,placement_constraints,platform_family,platform_version,propagate_tags,running_count,service_connect_configuration,service_registries,status, andtask_setsattributes (#44842)target_configuration.mcp.mcp_serverblock (#44991)credential_provider_configurationblock optional (#44991)delivery_destination_typeanddelivery_destination_configurationoptional to support AWS X-Ray as a destination (#44995)LINEARandCANARYdeployment strategies withdeployment_configuration.linear_configurationanddeployment_configuration.canary_configurationblocks (#44842)java25runtimevalue (#45024)nodejs24.xruntimevalue (#45024)python3.14runtimevalue (#45024)java25compatible_runtimesvalue (#45024)nodejs24.xcompatible_runtimesvalue (#45024)python3.14compatible_runtimesvalue (#45024)execution_role_arnargument and makemodel_nameoptional inproduction_variantsandshadow_production_variantsblocks to support Inference Components (#44977)AuthorizationError ... is not authorized to perform: iam:PassRole on resource ...IAM eventual consistency errors on Create and Update (#45018)BUG FIXES:
regionargument (#45023)regionargument (#45064)ValidationException: Value null at 'jobTemplateData.configurationOverrides.monitoringConfiguration.cloudWatchMonitoringConfiguration.logGroupName' failed to satisfy constraint: Member must not be nullerror (#45029)setting job_template_data: job_template_data.0.configuration_overrides.0.application_configuration.0: '' expected a map, got 'slice'error (#45029)job_template_data.job_driver.configuration_overrides.monitoring_configuration.persistent_app_uiargument as computed (#45029)Provider returned invalid result object after applyerror occurred when updating the resource (#45030)domain_nametodomain_nameandaccountseparated by a comma (#44982)endpoint_config_namewas not correctly updated, causing the endpoint to retain the old configuration (#42843)redacted_fields.single_header.name(#44987)v6.20.0Compare Source
FEATURES:
aws_ec2_allowed_images_settings(#44800)aws_fis_target_account_configuration(#44875)aws_invoicing_invoice_unit(#44892)ENHANCEMENTS:
media_concurrencies.cross_channel_behaviorattribute (#44934)node_group_configurationattribute to expose node group details including availability zones, replica counts, and slot ranges (#44879)max_record_size_in_kibattribute (#44915)identity_center_optionsattribute (#44626)us-isob-west-1as a valid AWS Region (#44944)logging_v1_enabledattribute (#44838)media_concurrencies.cross_channel_behaviorargument (#44934)destination_cidr_block(#44926)ip_address_typeargument (#44616)max_parallel_nodes_repaired_count,max_parallel_nodes_repaired_percentage,max_unhealthy_node_threshold_count,max_unhealthy_node_threshold_percentage, andnode_repair_config_overridesto thenode_repair_configschema (#44894)node_group_configurationblock to support availability zone specification and snapshot restoration for cluster mode enabled replication groups (#44879)timeoutis unconfigured for Ray jobs (#35012)max_record_size_in_kibargument to support for Kinesis 10MiB payloads. This functionality requires thekinesis:UpdateMaxRecordSizeIAM permission (#44915)identity_center_optionsconfiguration block (#44626)TransferSecurityPolicy-AS2Restricted-2025-07security_policy_namevalue (#44865)TransferSecurityPolicy-AS2Restricted-2025-07as a valid value forsecurity_policy_name(#44652)BUG FIXES:
Source type "...cloudfront.stagingDistributionDNSNamesModel" does not implement attr.Valueerror. This fixes a regression introduced in v6.17.0 (#44972)logging_config.bucketargument fromRequiredtoOptional(#44838)logging_config.include_cookiesargument while keeping V1 logging disabled (#44838)Source type "...cloudfront.originSSLProtocolsModel" does not implement attr.Valueandmissing required field, CreateVpcOriginInput.VpcOriginEndpointConfigerrors. This fixes a regression introduced in v6.17.0 (#44861)0) value fortimeoutfor Apache Spark streaming ETL jobs. This allows the job to be configured with no timeout (#44920)catalog_id,database.catalog_id,table.catalog_id, andtable_with_columns.catalog_idarguments (#44890)"") value forblock_device_mappings.ebs.kms_key_id. This fixes a regression introduced in v6.16.0 (#44708)v6.19.0Compare Source
FEATURES:
aws_ecrpublic_images(#44795)aws_lakeformation_identity_center_configuration(#44867)ENHANCEMENTS:
log_typeisTail(#44843)ami_tagsattribute (#44731)regex_valuesattribute tocondition.host_header,condition.http_headerandcondition.path_patternblocks (#44741)transformattribute (#44702)authorizer_configurationandauthorizer_typeconfig (#44826)monitoring_configurationargument (#43317)runtime_configurationargument (#43302)arnattribute. (#44867)ami_tagsargument (#44731)regex_valuesargument tocondition.host_header,condition.http_headerandcondition.path_patternblocks (#44741)transformconfiguration block (#44702)valuesargument incondition.host_header,condition.http_headerandcondition.path_patternis now optional (#44741)physical_table_map.relational_table.namefrom 64 to 256 characters (#44807)notebook-al2023-v1to validplatform_identifiervalues (#44570)account_idandregionfrom Resource Identity schema (#44846)account_idandregionfrom Resource Identity schema (#44846)account_idandregionfrom Resource Identity schema (#44846)account_idandregionfrom Resource Identity schema (#44846)BUG FIXES:
principal. (#44867)authorizer_configurationblock fromRequiredtoOptional(#44812)authorizer_typeargument asForceNew(#44812)principal. (#44867)v6.18.0Compare Source
NOTES:
accounts.statusandnon_master_accounts.statusattributes are deprecated. Use theaccounts.stateandnon_master_accounts.stateattributes instead. (#44327)accounts.statusattribute is deprecated. Useaccounts.stateinstead. (#44327)accounts.statusattribute is deprecated. Useaccounts.stateinstead. (#44327)statusattribute is deprecated. Usestateinstead. (#44327)accounts.statusandnon_master_accounts.statusattributes are deprecated. Use theaccounts.stateandnon_master_accounts.stateattributes instead. (#44327)FEATURES:
aws_bedrockagentcore_memory(#44306)aws_bedrockagentcore_memory_strategy(#44306)aws_bedrockagentcore_oauth2_credential_provider(#44307)aws_bedrockagentcore_token_vault_cmk(#44606)aws_bedrockagentcore_workload_identity(#44308)ENHANCEMENTS:
path_prefixattribute (#44703)state,joined_method, and 'joined_timestampattributes to theaccountsandnon_master_accounts` blocks (#44327)state,joined_method, and 'joined_timestampattributes to theaccounts` block (#44327)state,joined_method, and 'joined_timestampattributes to theaccounts` block (#44327)certificate_based_auth_propertiesargument (#44679)pathattribute (#44703)delete_associated_resourcesattribute to enable practitioner to delete associated oci resource. (#44754)stateattribute (#44327)state,joined_method, and 'joined_timestampattributes to theaccountsandnon_master_accounts` blocks (#44327)BUG FIXES:
tagsattribute (#44761)additional_configurationblock to ignore ordering (#44627)v6.17.0Compare Source
NOTES:
FEATURES:
aws_rds_global_cluster(#37286)aws_vpn_connection(#44622)aws_bedrockagentcore_agent_runtime(#44301)aws_bedrockagentcore_agent_runtime_endpoint(#44301)aws_bedrockagentcore_api_key_credential_provider(#44302)aws_bedrockagentcore_browser(#44303)aws_bedrockagentcore_code_interpreter(#44304)aws_bedrockagentcore_gateway(#44305)aws_bedrockagentcore_gateway_target(#44305)ENHANCEMENTS:
throughputmaximum validation from 1000 to 2000 MiB/s for gp3 volumes (#44604)throughputmaximum validation from 1000 to 2000 MiB/s for gp3 volumes (#44604)throughputmaximum validation from 1000 to 2000 MiB/s for gp3 volumes (#44604)admin_pro_group,author_pro_group, andreader_pro_grouparguments (#44638)BUG FIXES:
inconsistent final planerrors (#44542)source_code_hash,s3_bucket,s3_key,s3_object_versionandfilename) to their previous values when an update operation fails (#42829)v6.16.0Compare Source
FEATURES:
aws_transcribe_start_transcription_job(#44445)aws_odb_cloud_autonomous_vm_clusters(#44336)aws_odb_cloud_exadata_infrastructures(#44336)aws_odb_cloud_vm_clusters(#44336)aws_odb_network_peering_connections(#44336)aws_odb_networks(#44336)aws_prometheus_resource_policy(#44256)aws_transfer_host_key(#44559)aws_transfer_web_app(#42708)aws_transfer_web_app_customization(#42708)ENHANCEMENTS:
auto_retry_limitargument (#40035)scheduler_configurationblock (#44589)schema_registry_configconfiguration blocks toamazon_managed_kafka_event_source_configandself_managed_kafka_event_source_configblocks (#44540)ipv4_addresses_per_eniargument (#44560)BUG FIXES:
Missing Resource Identity After Updateerrors for non-refreshed and failed updates of Plugin Framework based resources (#44518)Unexpected Identity Changeerrors when fully-null identity values in state are updated to valid values for Plugin Framework based resources (#44518)glossary_terms. (#44491)unknown valueerror when optionalaccount_identifieris not specified. (#44491)unknown valueerror when optionalaccount_regionis not specified. (#44491)unexpected stateerror when deleting. (#44491)blueprint_identifieron creation. (#44491)user_parameterswhen importing. (#44491)user_parametersshould not be updateable. (#44491)LimitExceededException(#44576)maximum_message_rate_per_secondvalidation maximum to100(#44572)kms_key_idvalidation now accepts key ID, alias, and alias ARN in addition to key ARN (#44505)ThrottlingExceptionerrors (#24730)v6.15.0Compare Source
BREAKING CHANGES:
capacity_provider_strategyto avoid ECS service recreation after recent AWS changes (#43533)FEATURES:
aws_codebuild_start_build(#44444)aws_events_put_events(#44487)aws_sfn_start_execution(#44464)aws_appconfig_application(#44168)aws_odb_db_node(#43792)aws_odb_db_nodes(#43792)aws_odb_db_server(#43792)aws_odb_db_servers(#43792)aws_odb_db_system_shapes(#43825)aws_odb_gi_versions(#43825)aws_lakeformation_lf_tag_expression(#43883)ENHANCEMENTS:
mysql_settingsattribute (#44516)locationattribute (#44328)default_auth_schemeattribute (#44309)ip_address_typeargument toorigin.custom_origin_configblock (#44463)mysql_settingsconfiguration block (#44516)force_destroy. (#44406)throughputmaximum validation from 1000 to 2000 MiB/s for gp3 volumes (#44514)clusterandmanaged_instances_providerarguments (#44509)auto_scaling_group_provideroptional (#44509)credential_age_days,service_credential_alias,service_credential_secret,create_date, andexpiration_dateattributes (#44299)enable_monitoring_dashboardargument (#44515)aiml_optionsargument (#44417)two_way_channel_arnargument to acceptconnect.[region].amazonaws.comin addition to ARNs (#44372)default_auth_schemeargument (#44309)authconfiguration block optional (#44309)network_typeargument (#44377)arnargument (#44408)BUG FIXES:
Invalid address to set: []string{"secondary_ips_auto_assigned_per_subnet"}errors (#44485)firewall_policy.stateful_rule_group_referenceattributes (#44482)quota_namewas provided (#44449)AttributeName("arn") still remains in the path: could not find attribute or block "arn" in schemaerrors when upgrading from a pre-v6.0.0 provider version (#44434)configuration_nameis modified (#43996)LimitExceededException(#44489)LimitExceededException(#44522)ipv6_cidr_blockwhen the VPC has multiple associated IPv6 CIDRs (#44362)postgres_settingsare updated (#44389)deletion_protection_enablednot set. (#44406)compute_config,kubernetes_network_config.elastic_load_balancing, andstorage_config.to Optional and Computed, allowing EKS Auto Mode settings to be enabled, disabled, and removed from configuration (#44334)inconsistent final planerror in some cases withsettingelements. (#44461)inconsistent final planerror in some cases withsettingelements. (#44461)provider produced unexpected valueforcache_usage_limitsargument. (#43841)metadata_configurationfirst to allow simultaneous increase ofmetadata_configuration.iopsandstorage_capacity(#44456)interface conversion: interface {} is nil, not map[string]interface {}panics whencapacity_reservation_targetis empty (#44459)application_configuration.run_configurationvalues are respected during update (#43490)database_insights_modewithglobal_cluster_identifier. (#44404)child_health_thresholdto properly accept explicitly specified zero value (#44006)noncurrent_version_expiration.newer_noncurrent_versionsandnoncurrent_version_transition.newer_noncurrent_versions. (#44442)ipv6_cidr_blockwhen the VPC has multiple associated IPv6 CIDRs (#44362)v6.14.1Compare Source
NOTES:
BUG FIXES:
Missing Resource Identity After Updateerrors for non-refreshed and failed updates (#44375)Unexpected Identity Changeerrors when fully-null identity values in state are updated to valid values (#44375)v6.14.0Compare Source
FEATURES:
aws_cloudfront_create_invalidation(#43955)aws_ec2_stop_instance(#43700)aws_lambda_invoke(#43972)aws_ses_send_email(#44214)aws_sns_publish(#44232)aws_billing_views(#44272)aws_odb_cloud_autonomous_vm_cluster(#43809)aws_odb_cloud_exadata_infrastructure(#43650)aws_odb_cloud_vm_cluster(#43790)aws_odb_network(#43715)aws_odb_network_peering_connection(#43757)aws_controltower_baseline(#42397)aws_odb_cloud_autonomous_vm_cluster(#43809)aws_odb_cloud_exadata_infrastructure(#43650)aws_odb_cloud_vm_cluster(#43790)aws_odb_network(#43715)aws_odb_network_peering_connection(#43757)ENHANCEMENTS:
deployment_configuration.lifecycle_hook.hook_detailsargument (#44289)source_db_cluster_identifierandenginearguments (#44252)action_after_completionargument (#44264)BUG FIXES:
InvalidParameterValue: User xxx is not a member of user group xxxerrors during group modification (#43520)async_inference_config.output_config.notification_configblock is specified (#44310)v6.13.0Compare Source
ENHANCEMENTS:
billing_view_arnattribute (#44241)warm_throughputandglobal_secondary_index.warm_throughputattributes (#41308)ap-southeast-5,ap-southeast-7,eu-south-2, andme-central-1AWS Regions (#44132)ap-southeast-6AWS Region (#44132)ap-southeast-6AWS Region (#44132)ap-southeast-6AWS Region (#44132)predictive_scaling_policy_configurationargument (#44211)policy_type(#44211)step_scaling_policy_configuration.adjustment_typeandstep_scaling_policy_configuration.metric_aggregation_type(#44211)input_action,output_action,input_enabled, andoutput_enabledarguments toword_policy_config.managed_word_lists_configandword_policy_config.words_configconfiguration blocks (#44224)billing_view_arnargument (#44241)origin.response_completion_timeoutargument (#44163)pull_request_build_policyconfiguration block (#44201)warm_throughputand `globalConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.