chore(misc): update terraform (major) - #1015
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/major-terraform
branch
4 times, most recently
from
June 24, 2026 20:38
db535b3 to
d85f763
Compare
renovate
Bot
force-pushed
the
renovate/major-terraform
branch
3 times, most recently
from
July 2, 2026 17:46
d0231d4 to
71aff28
Compare
renovate
Bot
force-pushed
the
renovate/major-terraform
branch
4 times, most recently
from
July 12, 2026 10:44
4629207 to
23c7d7f
Compare
renovate
Bot
force-pushed
the
renovate/major-terraform
branch
2 times, most recently
from
July 17, 2026 13:26
ccd42e4 to
d441c1e
Compare
renovate
Bot
force-pushed
the
renovate/major-terraform
branch
2 times, most recently
from
July 28, 2026 20:51
9fc0db7 to
f3629b8
Compare
renovate
Bot
force-pushed
the
renovate/major-terraform
branch
3 times, most recently
from
August 6, 2026 13:58
4e507a1 to
6ca160d
Compare
renovate
Bot
force-pushed
the
renovate/major-terraform
branch
2 times, most recently
from
August 16, 2026 08:17
c9a37b3 to
22ec6cb
Compare
--- kubernetes/flux-system Kustomization: flux-system/0-flux-system HelmRelease: flux-system/flux2
+++ kubernetes/flux-system Kustomization: flux-system/0-flux-system HelmRelease: flux-system/flux2
@@ -11,13 +11,13 @@
chart:
spec:
chart: flux2
sourceRef:
kind: HelmRepository
name: fluxcd-community
- version: 2.16.4
+ version: 2.15.0
install:
crds: CreateReplace
interval: 1h
maxHistory: 1
timeout: 1m0s
upgrade: |
--- HelmRelease: flux-system/flux2 Deployment: flux-system/helm-controller
+++ HelmRelease: flux-system/flux2 Deployment: flux-system/helm-controller
@@ -32,13 +32,13 @@
- --enable-leader-election
env:
- name: RUNTIME_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- image: ghcr.io/fluxcd/helm-controller:v1.3.0
+ image: ghcr.io/fluxcd/helm-controller:v1.2.0
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
path: /healthz
port: healthz
name: manager
--- HelmRelease: flux-system/flux2 Deployment: flux-system/image-automation-controller
+++ HelmRelease: flux-system/flux2 Deployment: flux-system/image-automation-controller
@@ -32,13 +32,13 @@
- --enable-leader-election
env:
- name: RUNTIME_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- image: ghcr.io/fluxcd/image-automation-controller:v0.41.2
+ image: ghcr.io/fluxcd/image-automation-controller:v0.40.0
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
path: /healthz
port: healthz
name: manager
--- HelmRelease: flux-system/flux2 Deployment: flux-system/image-reflector-controller
+++ HelmRelease: flux-system/flux2 Deployment: flux-system/image-reflector-controller
@@ -32,13 +32,13 @@
- --enable-leader-election
env:
- name: RUNTIME_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- image: ghcr.io/fluxcd/image-reflector-controller:v0.35.2
+ image: ghcr.io/fluxcd/image-reflector-controller:v0.34.0
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
path: /healthz
port: healthz
name: manager
--- HelmRelease: flux-system/flux2 Deployment: flux-system/kustomize-controller
+++ HelmRelease: flux-system/flux2 Deployment: flux-system/kustomize-controller
@@ -32,13 +32,13 @@
- --enable-leader-election
env:
- name: RUNTIME_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- image: ghcr.io/fluxcd/kustomize-controller:v1.6.1
+ image: ghcr.io/fluxcd/kustomize-controller:v1.5.1
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
path: /healthz
port: healthz
name: manager
--- HelmRelease: flux-system/flux2 Deployment: flux-system/notification-controller
+++ HelmRelease: flux-system/flux2 Deployment: flux-system/notification-controller
@@ -31,13 +31,13 @@
- --enable-leader-election
env:
- name: RUNTIME_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- image: ghcr.io/fluxcd/notification-controller:v1.6.0
+ image: ghcr.io/fluxcd/notification-controller:v1.5.0
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
path: /healthz
port: healthz
name: manager
--- HelmRelease: flux-system/flux2 Deployment: flux-system/source-controller
+++ HelmRelease: flux-system/flux2 Deployment: flux-system/source-controller
@@ -36,13 +36,13 @@
- --storage-adv-addr=source-controller.$(RUNTIME_NAMESPACE).svc.cluster.local.
env:
- name: RUNTIME_NAMESPACE
valueFrom:
fieldRef:
fieldPath: metadata.namespace
- image: ghcr.io/fluxcd/source-controller:v1.6.2
+ image: ghcr.io/fluxcd/source-controller:v1.5.0
imagePullPolicy: IfNotPresent
livenessProbe:
httpGet:
path: /healthz
port: healthz
name: manager
--- HelmRelease: flux-system/flux2 Job: flux-system/flux2-flux-check
+++ HelmRelease: flux-system/flux2 Job: flux-system/flux2-flux-check
@@ -23,13 +23,13 @@
spec:
restartPolicy: Never
serviceAccountName: flux2-flux-check
automountServiceAccountToken: true
containers:
- name: flux-cli
- image: ghcr.io/fluxcd/flux-cli:v2.6.4
+ image: ghcr.io/fluxcd/flux-cli:v2.5.1
command:
- /usr/local/bin/flux
- check
- --pre
- --namespace
- flux-system |
renovate
Bot
force-pushed
the
renovate/major-terraform
branch
2 times, most recently
from
August 20, 2026 01:55
7f28f8d to
a651afc
Compare
renovate
Bot
force-pushed
the
renovate/major-terraform
branch
2 times, most recently
from
August 26, 2026 21:53
f0b48dc to
6a0ede2
Compare
renovate
Bot
force-pushed
the
renovate/major-terraform
branch
2 times, most recently
from
September 3, 2026 11:09
56f2f3f to
1431b2f
Compare
renovate
Bot
force-pushed
the
renovate/major-terraform
branch
from
September 3, 2026 22:42
1431b2f to
f2e5801
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
~> 5.100.0→~> 6.63.0~> 4.52.0→~> 5.24.0~> 3.25.9→~> 4.45.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
hashicorp/terraform-provider-aws (aws)
v6.63.0Compare Source
FEATURES:
aws_accountaccess_application(#49551)aws_key_pair(#49712)aws_lambdamicrovms_image(#49724)aws_lambdamicrovms_microvm(#48984)aws_mailmanager_archive(#49580)aws_opensearchserverless_access_policy(#49717)aws_opensearchserverless_lifecycle_policy(#49718)aws_opensearchserverless_security_config(#49769)aws_opensearchserverless_security_policy(#49770)aws_opensearchserverless_vpc_endpoint(#49774)aws_accountaccess_application(#49551)aws_datazone_policy_grant(#47050)aws_lambdamicrovms_microvm(#48984)aws_mailmanager_archive(#49580)ENHANCEMENTS:
prefix_pool_size_ipv4,prefix_pool_size_ipv6,prefix_pool_unallocated_count_ipv4, andprefix_pool_unallocated_count_ipv6attributes (#49711)rate_limiter_statusattribute (#48910)pod_gc_controller_configattribute to thekube_controller_manager_configconfiguration block (#49728)pod_gc_controller_configattribute to thecontrol_plane_component_config.kube_controller_manager_configconfiguration block (#49730)target_configuration.http.agentcore_runtime.schemaandtarget_configuration.http.passthroughconfiguration blocks (#48704)target_configuration.inferenceconfiguration block (#48705)target_configuration.mcp.connectorconfiguration block (#48706)prefix_pool_size_ipv4,prefix_pool_size_ipv6,prefix_pool_unallocated_count_ipv4, andprefix_pool_unallocated_count_ipv6attributes (#49711)rate_limiter_statusattribute (#48910)prefix_pool_allocated_count_ipv4andprefix_pool_allocated_count_ipv6attributes (#49711)rate_limitargument (#48910)prefix_pool_allocated_count_ipv4andprefix_pool_allocated_count_ipv6arguments (#49711)rate_limitargument (#48910)prefix_pool_allocated_count_ipv4andprefix_pool_allocated_count_ipv6attributes (#49711)rate_limitargument (#48910)prefix_pool_allocated_count_ipv4andprefix_pool_allocated_count_ipv6arguments (#49711)rate_limiter_statusattribute (#48910)prefix_pool_allocated_count_ipv4andprefix_pool_allocated_count_ipv6arguments (#49711)rate_limitargument (#48910)rate_limitargument (#48910)prefix_pool_allocated_count_ipv4andprefix_pool_allocated_count_ipv6arguments (#49711)rate_limitargument (#48910)pod_gc_controller_configargument to thekube_controller_manager_configconfiguration block (#49725)kms_key_arnargument (#49406)BUG FIXES:
assume_role_with_web_identity.web_identity_tokenbeing rejected whenAWS_WEB_IDENTITY_TOKEN_FILEis set (#49671)name_prefixlength validation to allow the correct maximum of 229 characters (#49197)name_prefixlength validation to allow the correct maximum of 229 characters (#49197)all_regionsis enabled (#49743)name_prefixlength validation to allow the correct maximum of 229 characters (#49197)object_lock_configuration.object_lock_enabledtoEnabledno longer forces a replacement (#36530)object_lock_enabledtotrueno longer forces a replacement (#36530)v6.62.0Compare Source
NOTES:
manage_master_user_passwordis enabled, the managed secret's automatic rotation can now be disabled usingaws_secretsmanager_secret_rotationwithrotation_enabled = false(#49659)manage_master_user_passwordis enabled, the managed secret's automatic rotation can now be disabled usingaws_secretsmanager_secret_rotationwithrotation_enabled = false(#49659)FEATURES:
aws_db_instance(#49602)aws_dsql_cluster(#49657)aws_dsql_cluster_policy(#49676)aws_ecr_lifecycle_policy(#49696)aws_ecs_cluster(#49682)aws_pinpointsmsvoicev2_keyword(#48967)aws_pinpointsmsvoicev2_keyword(#48967)aws_sesv2_multi_region_endpoint(#49660)ENHANCEMENTS:
associated_system.user_journey_idsattribute (#49603)name(#48766)indexed_keyentries in place instead of forcing a new resource (#48877)indexed_keyfromListtoSetto ignore ordering (#48877)configuration.self_managed_configurationargument in support of self-managed strategies (#48766)memory_record_schemaargument (#48765)description(#48766)descriptionto Optional and Computed (#48766)name,code, andcommentagainst CloudFront's documented constraints during plan instead of failing at apply time (#49395)bgp_asn_longargument (#49587)bgp_asn_longargument (#49588)auth_token_woandauth_token_wo_versionwrite-only arguments (#49268)tag_propagation_configurationconfiguration block torule.destination.destination_logs_configuration, andtag_propagation_statusandtag_propagation_failure_reasonattributes (#49656)user_journey_idsargument to theassociated_systemconfiguration block (#49603)rotation_enabledis now configurable (previously read-only) and can be set tofalseto disable rotation for a secret. This is particularly useful for secrets whose rotation is otherwise managed by AWS, such as an RDS master user password secret created withmanage_master_user_password(#49659)rotation_rulesis now optional, and must be omitted whenrotation_enabledisfalse(#49659)workspace_access_properties.access_endpoint_configargument (#49668)BUG FIXES:
name(#48766)nameis modified (#48766)name(#48766)resource_configuration.resource_tagfromListtoSetto ignore ordering (#49585)purchase_timeasOptionalandComputed(#49679)queuedas a target state during creation (#49678)upfront_payment_amountasComputedto fix aProvider produced inconsistent result after applyerror forNo Upfrontsavings plans (#49264)v6.61.0Compare Source
FEATURES:
aws_odb_iam_role_association(#46794)aws_ec2_ami_launch_permission(#49461)aws_iam_instance_profile(#49576)aws_lambdacore_network_connector(#49387)aws_mailmanager_relay(#49394)aws_resiliencehubv2_assertion(#48329)aws_resiliencehubv2_service_function(#48328)aws_resiliencehubv2_user_journey(#48330)aws_dsql_cluster_policy(#47748)aws_lambdacore_network_connector(#49387)aws_lambdamicrovms_image(#48950)aws_mailmanager_relay(#49394)aws_odb_iam_role_association(#46794)aws_resiliencehubv2_assertion(#48329)aws_resiliencehubv2_service_function(#48328)aws_resiliencehubv2_user_journey(#48330)aws_securityhub_feature_v2(#49503)ENHANCEMENTS:
network_typeattribute (#49512)network_typeattribute (#49514)condition.source_ip.ip_address_typeattribute (#49476)associated_systemattribute (#49498)idle_timeout_secondsattribute (#49540)environment_actual(#48815)network_typeargument (#49512)network_typeargument (#49513)network_typeargument (#49514)condition.source_ip.ip_address_typeargument (#49476)condition.source_ip.valuesto Optional (#49476)encryption_scopeargument to thelogs_encryption_configurationconfiguration block (#49563)statusattribute (#49485)wait_for_activeargument to allowcreateandupdateto return without waiting for the phone number to reachACTIVEstatus. Number types gated on carrier or registration approval (for exampleTEN_DLC,TOLL_FREE, or any number submitted withregistration_id) can remainPENDINGfor days to weeks, which previously causedterraform applyto time out (#49485)associated_systemconfiguration block (#49498)idle_timeout_secondsargument (#49540)BUG FIXES:
Provider produced inconsistent result after applyerror forenvironment(#48815)FAILEDas a pending state while an ingress point is deleting (#49502)secondary_private_ip_address_countin-place for private NAT gateways (#47477)couldn't find resource (21 retries)errors on delete if enrichment has never been started in the Region (#49502)NOT_STARTEDas a target state while the resource is deleting (#49502)v6.60.0Compare Source
FEATURES:
aws_db_parameter_group(#49418)aws_resiliencehubv2_input_source(#48327)aws_resiliencehubv2_input_source(#48327)ENHANCEMENTS:
BUG FIXES:
Missing Resource Identity After Readerrors. This fixes a regression introduced in v6.59.0 (#49470)v6.59.0Compare Source
FEATURES:
aws_rds_snapshots(#49259)aws_resiliencehubv2_policy(#48324)aws_resiliencehubv2_service(#48326)aws_resiliencehubv2_system(#48325)aws_vpclattice_service_network_service_associations(#42680)aws_backup_plan(#49329)aws_backup_selection(#49283)aws_backup_vault(#49423)aws_bedrockagentcore_gateway_rule(#48804)aws_mailmanager_ingress_point(#49322)aws_neptunegraph_private_graph_endpoint(#45929)aws_networkfirewall_container_association(#49321)aws_pinpointsmsvoicev2_resource_policy(#48771)aws_pinpointsmsvoicev2_sender_id(#46472)aws_resiliencehubv2_service(#48323)aws_resiliencehubv2_system(#48322)aws_ssm_patch_baseline(#49332)aws_bedrockagentcore_gateway_rule(#48804)aws_mailmanager_ingress_point(#49322)aws_neptunegraph_private_graph_endpoint(#45929)aws_networkfirewall_container_association(#49321)aws_pinpointsmsvoicev2_resource_policy(#48771)aws_pinpointsmsvoicev2_sender_id(#46472)aws_resiliencehubv2_service(#48323)aws_resiliencehubv2_system(#48322)ENHANCEMENTS:
kube_api_server_config,kube_controller_manager_config, andkube_scheduler_configattributes (#49420)control_plane_component_configandcontrol_plane_scaling_tiersattributes (#49421)step.aurora_provisioned_scaling_config,step.aurora_serverless_scaling_config,step.neptune_global_database_config, andstep.lambda_event_source_mapping_configarguments (#48392)report_configurationandreport_configuration.report_output.s3_configurationto a single block each (#46758)target_configuration.mcp.mcp_server.mcp_tool_schemaconfiguration block andtarget_configuration.mcp.mcp_server.resource_priorityargument (#48703)memory_actual(#49383)memory.disabled(#49334)memory.managed_memory_configuration(#49285)policy_details.parameters.exclude_data_volume_tagsargument (#45113)transit_gateway_attachment_idattribute (#49274)target_vpc_subnet_idto Optional (#49274)timeoutsvalues to30m(#49274)kube_api_server_config,kube_controller_manager_config, andkube_scheduler_configarguments (#49412)exporterconfiguration block with OpenSearch exporter support (#49346)pre_parse_text_transformationargument tobyte_match_statement,regex_match_statement,regex_pattern_set_reference_statement,size_constraint_statement,sqli_match_statement, andxss_match_statementrule statements (#49381)pre_parse_text_transformationargument tobyte_match_statement,regex_match_statement,regex_pattern_set_reference_statement,size_constraint_statement,sqli_match_statement, andxss_match_statementrule statements (#49381)BUG FIXES:
reading MQ Broker (...) shared resourceserrors when reading RabbitMQ brokers in partitions wheremq:DescribeSharedResourcesis unavailable, such as AWS GovCloud (US) (#49340)metadata_configurationrequest and response headers (#49374)CREATE_PENDING_AUTHandUPDATE_PENDING_AUTHstatuses as successful terminal states (#48703)reading MQ Broker (...) shared resourceserrors when reading RabbitMQ brokers in partitions wheremq:DescribeSharedResourcesis unavailable, such as AWS GovCloud (US) (#49340)InvalidParameterCombinationerror whenengine_versionis updated externally (#49396)UpdateDomainContactPrivacybeing incorrectly triggered whenbilling_contactchanges (#49314)namewith a leading slash and no other slashes was stripping the leading slash. (#49339)v6.58.0Compare Source
FEATURES:
aws_mailmanager_rule_set(#49257)aws_prometheus_anomaly_detector(#49139)aws_prometheus_scraper(#47466)aws_prometheus_scraper_logging_configuration(#47466)aws_resiliencehubv2_policy(#48321)aws_mailmanager_rule_set(#49257)aws_prometheus_anomaly_detector(#49139)aws_prometheus_scraper_logging_configuration(#47466)aws_resiliencehubv2_policy(#48321)ENHANCEMENTS:
stateattribute (#42150)RESERVEDas a valid value formanaged_instances_provider.instance_launch_template.capacity_option_type(#48816)local_storage_configurationattribute tomanaged_instances_provider.instance_launch_template(#47513)managed_instances_provider.instance_launch_template.capacity_reservationsargument (#48816)configuration.compaction_configurationargument (#43868)destination.cloudwatchconfiguration block for CloudWatch Metrics destination support (#49088)BUG FIXES:
BadRequestException: There is already an update in progresserrors (#49205)embed_host_domainsnot being sent to the AWS API on update, which caused a permanent plan diff when the argument was added or changed on an existing stack (#49015)bedrock_data_automation_configurationwhenparsing_strategy = "BEDROCK_DATA_AUTOMATION", a regression introduced in v6.56.0 (#49111):(colon) in thematch_value_stringandmatch_value_string_listattributes ofauthorizer_configuration.custom_jwt_authorizer.custom_claim.authorizing_claim_match_value.claim_match_value(#48437)Value Conversion Error ... Received null value, however the target type cannot handle null valueserrors (#49188)too many results: wanted 1, got 2error when creating or updating a strategy on a memory that already has another strategy of a different type (#49250)configuration.consolidation,configuration.extraction, orconfiguration.reflectionblocks are removed (#49188)sigint_rollbackfalsely rolling back healthy deployments duringwait_for_steady_state(#49077)apply_immediately = false) (#48246)InvalidInputException: StorageDescriptor is not allowederror when creating or updating ATHENA-dialect views (#49156)InvalidInputExceptionerror when creating or updating SPARK-dialect views without an explicitstorage_descriptorblock (#49156)view_definition.representationsfields (validation_connection,view_original_text,view_expanded_text) that AWS Glue does not echo back for validated ATHENA views (#49156)v6.57.1Compare Source
NOTES:
memory_execution_role_arnattribute has been deprecated. This attribute should be removed from configurations (#49140)namespacesattribute has been deprecated. All configurations usingnamespacesshould be updated to use thenamespace_templatesattribute instead (#49140)FEATURES:
aws_eks_access_policies(#49090)aws_bedrock_evaluation_job(#49044)aws_eks_access_entry(#49090)aws_eks_access_policy_association(#49121)aws_eks_node_group(#49073)aws_flow_log(#49086)aws_mailmanager_traffic_policy(#49043)aws_osis_pipeline(#49157)aws_osis_pipeline_endpoint(#44383)aws_osis_resource_policy(#44383)aws_rekognition_collection(#49135)aws_bedrock_evaluation_job(#49044)aws_cloudwatch_log_storage_tier_policy(#49076)aws_mailmanager_traffic_policy(#49043)aws_osis_pipeline_endpoint(#44383)aws_osis_resource_policy(#44383)ENHANCEMENTS:
ena_queue_countattribute tonetwork_interfacesconfiguration block (#48892)typeattribute (#46414)external_secret_rotation_metadataandexternal_secret_rotation_role_arnattributes (#46414)ipv6_cidr_block_associations. (#46918)ipv6_association_idandipv6_cidr_block. (#46918)reservations-then-balancedvalid value foravailability_zone_distribution.capacity_distribution_strategy(#48934)timeouts.updatewith a default value of30m(#49140)configuration.reflectionconfiguration block forEPISODIC_OVERRIDEstrategy type (#49140)namespace_templatesargument (#49140)reflection_configurationconfiguration block forEPISODICstrategy type (#49140)timeoutsvalues to45m(#49140)stage.action.commandsandstage.action.output_artifacts_for_compute_actionarguments to support Compute action types (#42507)stage.action.output_artifacts_for_compute_actionandstage.action.output_artifactsnow conflict (#42507)policyargument to support inline session policies (#48869)MultiRegionClustersas a value foraction.target.key(#48781)ena_queue_countargument tonetwork_interfacesconfiguration block (#48892)typeargument in support of managed external secrets (#46414)external_secret_rotation_metadataandexternal_secret_rotation_role_arnarguments in support of managed external secrets (#46414)BUG FIXES:
warm_throughputvalues (#49032)v6.56.0Compare Source
FEATURES:
Configuration
📅 Schedule: (in timezone Asia/Taipei)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.