Skip to content

chore(misc): update terraform (major) - #1015

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-terraform
Open

chore(misc): update terraform (major)#1015
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-terraform

Conversation

@renovate

@renovate renovate Bot commented Jun 22, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
aws (source) required_provider major ~> 5.100.0~> 6.63.0
cloudflare (source) required_provider major ~> 4.52.0~> 5.24.0
grafana (source) required_provider major ~> 3.25.9~> 4.45.0

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

hashicorp/terraform-provider-aws (aws)

v6.63.0

Compare Source

FEATURES:

  • New List Resource: aws_accountaccess_application (#​49551)
  • New List Resource: aws_key_pair (#​49712)
  • New List Resource: aws_lambdamicrovms_image (#​49724)
  • New List Resource: aws_lambdamicrovms_microvm (#​48984)
  • New List Resource: aws_mailmanager_archive (#​49580)
  • New List Resource: aws_opensearchserverless_access_policy (#​49717)
  • New List Resource: aws_opensearchserverless_lifecycle_policy (#​49718)
  • New List Resource: aws_opensearchserverless_security_config (#​49769)
  • New List Resource: aws_opensearchserverless_security_policy (#​49770)
  • New List Resource: aws_opensearchserverless_vpc_endpoint (#​49774)
  • New Resource: aws_accountaccess_application (#​49551)
  • New Resource: aws_datazone_policy_grant (#​47050)
  • New Resource: aws_lambdamicrovms_microvm (#​48984)
  • New Resource: aws_mailmanager_archive (#​49580)

ENHANCEMENTS:

  • data-source/aws_dx_connection: Add prefix_pool_size_ipv4, prefix_pool_size_ipv6, prefix_pool_unallocated_count_ipv4, and prefix_pool_unallocated_count_ipv6 attributes (#​49711)
  • data-source/aws_dx_connection: Add rate_limiter_status attribute (#​48910)
  • data-source/aws_eks_cluster: Add pod_gc_controller_config attribute to the kube_controller_manager_config configuration block (#​49728)
  • data-source/aws_eks_cluster_versions: Add pod_gc_controller_config attribute to the control_plane_component_config.kube_controller_manager_config configuration block (#​49730)
  • resource/aws_bedrockagentcore_gateway_target: Add Resource Identity support (#​48706)
  • resource/aws_bedrockagentcore_gateway_target: Add target_configuration.http.agentcore_runtime.schema and target_configuration.http.passthrough configuration blocks (#​48704)
  • resource/aws_bedrockagentcore_gateway_target: Add target_configuration.inference configuration block (#​48705)
  • resource/aws_bedrockagentcore_gateway_target: Add target_configuration.mcp.connector configuration block (#​48706)
  • resource/aws_dx_connection: Add prefix_pool_size_ipv4, prefix_pool_size_ipv6, prefix_pool_unallocated_count_ipv4, and prefix_pool_unallocated_count_ipv6 attributes (#​49711)
  • resource/aws_dx_connection: Add rate_limiter_status attribute (#​48910)
  • resource/aws_dx_hosted_private_virtual_interface: Add prefix_pool_allocated_count_ipv4 and prefix_pool_allocated_count_ipv6 attributes (#​49711)
  • resource/aws_dx_hosted_private_virtual_interface: Add rate_limit argument (#​48910)
  • resource/aws_dx_hosted_private_virtual_interface_accepter: Add prefix_pool_allocated_count_ipv4 and prefix_pool_allocated_count_ipv6 arguments (#​49711)
  • resource/aws_dx_hosted_public_virtual_interface: Add rate_limit argument (#​48910)
  • resource/aws_dx_hosted_transit_virtual_interface: Add prefix_pool_allocated_count_ipv4 and prefix_pool_allocated_count_ipv6 attributes (#​49711)
  • resource/aws_dx_hosted_transit_virtual_interface: Add rate_limit argument (#​48910)
  • resource/aws_dx_hosted_transit_virtual_interface_accepter: Add prefix_pool_allocated_count_ipv4 and prefix_pool_allocated_count_ipv6 arguments (#​49711)
  • resource/aws_dx_lag: Add rate_limiter_status attribute (#​48910)
  • resource/aws_dx_private_virtual_interface: Add prefix_pool_allocated_count_ipv4 and prefix_pool_allocated_count_ipv6 arguments (#​49711)
  • resource/aws_dx_private_virtual_interface: Add rate_limit argument (#​48910)
  • resource/aws_dx_public_virtual_interface: Add rate_limit argument (#​48910)
  • resource/aws_dx_transit_virtual_interface: Add prefix_pool_allocated_count_ipv4 and prefix_pool_allocated_count_ipv6 arguments (#​49711)
  • resource/aws_dx_transit_virtual_interface: Add rate_limit argument (#​48910)
  • resource/aws_eks_cluster: Add pod_gc_controller_config argument to the kube_controller_manager_config configuration block (#​49725)
  • resource/aws_key_pair: Add resource identity support (#​49712)
  • resource/aws_synthetics_canary: Add kms_key_arn argument (#​49406)

BUG FIXES:

  • provider: Fix assume_role_with_web_identity.web_identity_token being rejected when AWS_WEB_IDENTITY_TOKEN_FILE is set (#​49671)
  • resource/aws_db_parameter_group: Fix name_prefix length validation to allow the correct maximum of 229 characters (#​49197)
  • resource/aws_docdb_cluster_parameter_group: Fix name_prefix length validation to allow the correct maximum of 229 characters (#​49197)
  • resource/aws_observabilityadmin_telemetry_rule_for_organization: Fix updates when all_regions is enabled (#​49743)
  • resource/aws_rds_cluster_parameter_group: Fix name_prefix length validation to allow the correct maximum of 229 characters (#​49197)
  • resource/aws_redshift_namespace_registration: Fixes errors when Importing by ID (#​49690)
  • resource/aws_redshift_namespace_registration: Fixes errors when Importing by Identity (#​49690)
  • resource/aws_s3_bucket: Setting object_lock_configuration.object_lock_enabled to Enabled no longer forces a replacement (#​36530)
  • resource/aws_s3_bucket: Setting object_lock_enabled to true no longer forces a replacement (#​36530)

v6.62.0

Compare Source

NOTES:

  • resource/aws_db_instance: When manage_master_user_password is enabled, the managed secret's automatic rotation can now be disabled using aws_secretsmanager_secret_rotation with rotation_enabled = false (#​49659)
  • resource/aws_rds_cluster: When manage_master_user_password is enabled, the managed secret's automatic rotation can now be disabled using aws_secretsmanager_secret_rotation with rotation_enabled = false (#​49659)
  • resource/aws_savingsplans_savings_plan: Because we cannot easily test this functionality, it is best effort and we ask for community help in testing (#​49264)

FEATURES:

  • New List Resource: aws_db_instance (#​49602)
  • New List Resource: aws_dsql_cluster (#​49657)
  • New List Resource: aws_dsql_cluster_policy (#​49676)
  • New List Resource: aws_ecr_lifecycle_policy (#​49696)
  • New List Resource: aws_ecs_cluster (#​49682)
  • New List Resource: aws_pinpointsmsvoicev2_keyword (#​48967)
  • New Resource: aws_pinpointsmsvoicev2_keyword (#​48967)
  • New Resource: aws_sesv2_multi_region_endpoint (#​49660)

ENHANCEMENTS:

  • data-source/aws_resiliencehubv2_service: Add associated_system.user_journey_ids attribute (#​49603)
  • resource/aws_bedrockagentcore_browser: Add plan-time validation of name (#​48766)
  • resource/aws_bedrockagentcore_memory: Add Resource Identity support (#​48766)
  • resource/aws_bedrockagentcore_memory: Allow adding indexed_key entries in place instead of forcing a new resource (#​48877)
  • resource/aws_bedrockagentcore_memory: Change indexed_key from List to Set to ignore ordering (#​48877)
  • resource/aws_bedrockagentcore_memory_strategy: Add Resource Identity support (#​48766)
  • resource/aws_bedrockagentcore_memory_strategy: Add configuration.self_managed_configuration argument in support of self-managed strategies (#​48766)
  • resource/aws_bedrockagentcore_memory_strategy: Add memory_record_schema argument (#​48765)
  • resource/aws_bedrockagentcore_memory_strategy: Add plan-time validation of description (#​48766)
  • resource/aws_bedrockagentcore_memory_strategy: Change description to Optional and Computed (#​48766)
  • resource/aws_cloudfront_function: Validate name, code, and comment against CloudFront's documented constraints during plan instead of failing at apply time (#​49395)
  • resource/aws_db_instance: Add resource identity support (#​49602)
  • resource/aws_dsql_cluster: Add resource identity support (#​49657)
  • resource/aws_dx_private_virtual_interface: Add bgp_asn_long argument (#​49587)
  • resource/aws_dx_transit_virtual_interface: Add bgp_asn_long argument (#​49588)
  • resource/aws_ecs_cluster: Add resource identity support (#​49682)
  • resource/aws_elasticache_replication_group: Add auth_token_wo and auth_token_wo_version write-only arguments (#​49268)
  • resource/aws_observabilityadmin_centralization_rule_for_organization: Add tag_propagation_configuration configuration block to rule.destination.destination_logs_configuration, and tag_propagation_status and tag_propagation_failure_reason attributes (#​49656)
  • resource/aws_resiliencehubv2_service: Add user_journey_ids argument to the associated_system configuration block (#​49603)
  • resource/aws_secretsmanager_secret_rotation: rotation_enabled is now configurable (previously read-only) and can be set to false to disable rotation for a secret. This is particularly useful for secrets whose rotation is otherwise managed by AWS, such as an RDS master user password secret created with manage_master_user_password (#​49659)
  • resource/aws_secretsmanager_secret_rotation: rotation_rules is now optional, and must be omitted when rotation_enabled is false (#​49659)
  • resource/aws_workspaces_directory: Add workspace_access_properties.access_endpoint_config argument (#​49668)

BUG FIXES:

  • resource/aws_bedrockagentcore_harness: Correct plan-time validation of name (#​48766)
  • resource/aws_bedrockagentcore_memory_strategy: Force resource replacement when name is modified (#​48766)
  • resource/aws_bedrockagentcore_registry: Correct plan-time validation of name (#​48766)
  • resource/aws_cloudwatch_log_resource_policy: Fixes error when importing by identity when using resource-scope (#​49614)
  • resource/aws_elasticache_cluster: Add plan-time validation to reject transit_encryption_enabled for Redis and Valkey engines, which are only supported on aws_elasticache_replication_group (#​49114)
  • resource/aws_resiliencehubv2_input_source: Change resource_configuration.resource_tag from List to Set to ignore ordering (#​49585)
  • resource/aws_s3_account_public_access_block: Fixes eventual consistency issue on creation (#​49687)
  • resource/aws_savingsplan_savings_plan: Because we cannot easily test this functionality, it is best effort and we ask for community help in testing (#​49678)
  • resource/aws_savingsplan_savings_plan: Because we cannot easily test this functionality, it is best effort and we ask for community help in testing (#​49679)
  • resource/aws_savingsplan_savings_plan: Mark purchase_time as Optional and Computed (#​49679)
  • resource/aws_savingsplan_savings_plan: Treat queued as a target state during creation (#​49678)
  • resource/aws_savingsplans_savings_plan: Mark upfront_payment_amount as Computed to fix a Provider produced inconsistent result after apply error for No Upfront savings plans (#​49264)

v6.61.0

Compare Source

FEATURES:

  • New Data Source: aws_odb_iam_role_association (#​46794)
  • New List Resource: aws_ec2_ami_launch_permission (#​49461)
  • New List Resource: aws_iam_instance_profile (#​49576)
  • New List Resource: aws_lambdacore_network_connector (#​49387)
  • New List Resource: aws_mailmanager_relay (#​49394)
  • New List Resource: aws_resiliencehubv2_assertion (#​48329)
  • New List Resource: aws_resiliencehubv2_service_function (#​48328)
  • New List Resource: aws_resiliencehubv2_user_journey (#​48330)
  • New Resource: aws_dsql_cluster_policy (#​47748)
  • New Resource: aws_lambdacore_network_connector (#​49387)
  • New Resource: aws_lambdamicrovms_image (#​48950)
  • New Resource: aws_mailmanager_relay (#​49394)
  • New Resource: aws_odb_iam_role_association (#​46794)
  • New Resource: aws_resiliencehubv2_assertion (#​48329)
  • New Resource: aws_resiliencehubv2_service_function (#​48328)
  • New Resource: aws_resiliencehubv2_user_journey (#​48330)
  • New Resource: aws_securityhub_feature_v2 (#​49503)

ENHANCEMENTS:

  • data-source/aws_fsx_ontap_file_system: Add network_type attribute (#​49512)
  • data-source/aws_fsx_windows_file_system: Add network_type attribute (#​49514)
  • data-source/aws_lb_listener_rule: Add condition.source_ip.ip_address_type attribute (#​49476)
  • data-source/aws_resiliencehubv2_service: Add associated_system attribute (#​49498)
  • data-source/aws_vpclattice_service: Add idle_timeout_seconds attribute (#​49540)
  • resource/aws_bedrockagentcore_harness: Adds attribute environment_actual (#​48815)
  • resource/aws_ec2_ami_launch_permission: Add resource identity support (#​49461)
  • resource/aws_fsx_ontap_file_system: Add network_type argument (#​49512)
  • resource/aws_fsx_openzfs_file_system: Add network_type argument (#​49513)
  • resource/aws_fsx_windows_file_system: Add network_type argument (#​49514)
  • resource/aws_lb_listener_rule: Add condition.source_ip.ip_address_type argument (#​49476)
  • resource/aws_lb_listener_rule: Change condition.source_ip.values to Optional (#​49476)
  • resource/aws_medialive_channel: Add resource identity (#​49532)
  • resource/aws_medialive_input: Add resource identity support (#​49534)
  • resource/aws_medialive_input_security_group: Add resource identity support (#​49537)
  • resource/aws_medialive_multiplex: Add resource identity support (#​49557)
  • resource/aws_medialive_multiplex_program: Add resource identity (#​49561)
  • resource/aws_observabilityadmin_centralization_rule_for_organization: Add encryption_scope argument to the logs_encryption_configuration configuration block (#​49563)
  • resource/aws_pinpointsmsvoicev2_phone_number: Add status attribute (#​49485)
  • resource/aws_pinpointsmsvoicev2_phone_number: Add wait_for_active argument to allow create and update to return without waiting for the phone number to reach ACTIVE status. Number types gated on carrier or registration approval (for example TEN_DLC, TOLL_FREE, or any number submitted with registration_id) can remain PENDING for days to weeks, which previously caused terraform apply to time out (#​49485)
  • resource/aws_resiliencehubv2_service: Add associated_system configuration block (#​49498)
  • resource/aws_vpclattice_service: Add idle_timeout_seconds argument (#​49540)

BUG FIXES:

  • list-resource/aws_bedrockagentcore_harness: Prevents error when remote resource disappears during List (#​49446)
  • list-resource/aws_bedrockagentcore_online_evaluation_config: Prevents error when remote resource disappears during List (#​49479)
  • list-resource/aws_bedrockagentcore_policy_engine: Prevents error when remote resource disappears during List (#​49478)
  • list-resource/aws_bedrockagentcore_registry: Prevents error when remote resource disappears during List (#​49480)
  • list-resource/aws_bedrockagentcore_resource_policy: Prevents error when remote resource disappears during List (#​49481)
  • resource/aws_bedrockagentcore_harness: Fix Provider produced inconsistent result after apply error for environment (#​48815)
  • resource/aws_bedrockagentcore_online_evaluation_config: Retries additional IAM propagation errors on creation (#​49479)
  • resource/aws_mailmanager_ingress_point: Include FAILED as a pending state while an ingress point is deleting (#​49502)
  • resource/aws_nat_gateway: Allow updating secondary_private_ip_address_count in-place for private NAT gateways (#​47477)
  • resource/aws_observabilityadmin_telemetry_enrichment: Prevent couldn't find resource (21 retries) errors on delete if enrichment has never been started in the Region (#​49502)
  • resource/aws_observabilityadmin_telemetry_evaluation: Include NOT_STARTED as a target state while the resource is deleting (#​49502)

v6.60.0

Compare Source

FEATURES:

  • New List Resource: aws_db_parameter_group (#​49418)
  • New List Resource: aws_resiliencehubv2_input_source (#​48327)
  • New Resource: aws_resiliencehubv2_input_source (#​48327)

ENHANCEMENTS:

  • resource/aws_db_parameter_group: Add Resource Identity support (#​49418)

BUG FIXES:

  • resource/aws_bedrockagentcore_gateway_target: Prevent state inconsistencies caused by the service-managed policy session header (#​49447)
  • resource/aws_network_acl_rule: Fix Missing Resource Identity After Read errors. This fixes a regression introduced in v6.59.0 (#​49470)

v6.59.0

Compare Source

FEATURES:

  • New Data Source: aws_rds_snapshots (#​49259)
  • New Data Source: aws_resiliencehubv2_policy (#​48324)
  • New Data Source: aws_resiliencehubv2_service (#​48326)
  • New Data Source: aws_resiliencehubv2_system (#​48325)
  • New Data Source: aws_vpclattice_service_network_service_associations (#​42680)
  • New List Resource: aws_backup_plan (#​49329)
  • New List Resource: aws_backup_selection (#​49283)
  • New List Resource: aws_backup_vault (#​49423)
  • New List Resource: aws_bedrockagentcore_gateway_rule (#​48804)
  • New List Resource: aws_mailmanager_ingress_point (#​49322)
  • New List Resource: aws_neptunegraph_private_graph_endpoint (#​45929)
  • New List Resource: aws_networkfirewall_container_association (#​49321)
  • New List Resource: aws_pinpointsmsvoicev2_resource_policy (#​48771)
  • New List Resource: aws_pinpointsmsvoicev2_sender_id (#​46472)
  • New List Resource: aws_resiliencehubv2_service (#​48323)
  • New List Resource: aws_resiliencehubv2_system (#​48322)
  • New List Resource: aws_ssm_patch_baseline (#​49332)
  • New Resource: aws_bedrockagentcore_gateway_rule (#​48804)
  • New Resource: aws_mailmanager_ingress_point (#​49322)
  • New Resource: aws_neptunegraph_private_graph_endpoint (#​45929)
  • New Resource: aws_networkfirewall_container_association (#​49321)
  • New Resource: aws_pinpointsmsvoicev2_resource_policy (#​48771)
  • New Resource: aws_pinpointsmsvoicev2_sender_id (#​46472)
  • New Resource: aws_resiliencehubv2_service (#​48323)
  • New Resource: aws_resiliencehubv2_system (#​48322)

ENHANCEMENTS:

  • data-source/aws_eks_cluster: Add kube_api_server_config, kube_controller_manager_config, and kube_scheduler_config attributes (#​49420)
  • data-source/aws_eks_cluster_versions: Add control_plane_component_config and control_plane_scaling_tiers attributes (#​49421)
  • resource/aws_arcregionswitch_plan: Add step.aurora_provisioned_scaling_config, step.aurora_serverless_scaling_config, step.neptune_global_database_config, and step.lambda_event_source_mapping_config arguments (#​48392)
  • resource/aws_arcregionswitch_plan: Add provider-side validation restricting report_configuration and report_configuration.report_output.s3_configuration to a single block each (#​46758)
  • resource/aws_backup_plan: Add resource identity support (#​49329)
  • resource/aws_backup_selection: Add resource identity support (#​49283)
  • resource/aws_backup_vault: Add resource identity support (#​49423)
  • resource/aws_bedrockagentcore_gateway_target: Add target_configuration.mcp.mcp_server.mcp_tool_schema configuration block and target_configuration.mcp.mcp_server.resource_priority argument (#​48703)
  • resource/aws_bedrockagentcore_harness: Adds computed attribute memory_actual (#​49383)
  • resource/aws_bedrockagentcore_harness: Adds support for memory.disabled (#​49334)
  • resource/aws_bedrockagentcore_harness: Adds support for memory.managed_memory_configuration (#​49285)
  • resource/aws_dlm_lifecycle_policy: Add policy_details.parameters.exclude_data_volume_tags argument (#​45113)
  • resource/aws_ec2_client_vpn_route: Add transit_gateway_attachment_id attribute (#​49274)
  • resource/aws_ec2_client_vpn_route: Change target_vpc_subnet_id to Optional (#​49274)
  • resource/aws_ec2_client_vpn_route: Increase default timeouts values to 30m (#​49274)
  • resource/aws_eks_cluster: Add kube_api_server_config, kube_controller_manager_config, and kube_scheduler_config arguments (#​49412)
  • resource/aws_prometheus_scraper: Add exporter configuration block with OpenSearch exporter support (#​49346)
  • resource/aws_wafv2_rule_group: Add pre_parse_text_transformation argument to byte_match_statement, regex_match_statement, regex_pattern_set_reference_statement, size_constraint_statement, sqli_match_statement, and xss_match_statement rule statements (#​49381)
  • resource/aws_wafv2_web_acl: Add pre_parse_text_transformation argument to byte_match_statement, regex_match_statement, regex_pattern_set_reference_statement, size_constraint_statement, sqli_match_statement, and xss_match_statement rule statements (#​49381)

BUG FIXES:

  • data-source/aws_lakeformation_permissions: Fix failure to read cross-account IAM principals (#​49398)
  • data-source/aws_mq_broker: Fix reading MQ Broker (...) shared resources errors when reading RabbitMQ brokers in partitions where mq:DescribeSharedResources is unavailable, such as AWS GovCloud (US) (#​49340)
  • resource/aws_bedrockagentcore_gateway_target: Remove client-side count validation for metadata_configuration request and response headers (#​49374)
  • resource/aws_bedrockagentcore_gateway_target: Treat OAuth CREATE_PENDING_AUTH and UPDATE_PENDING_AUTH statuses as successful terminal states (#​48703)
  • resource/aws_lakeformation_permissions: Fix failure to read cross-account IAM principals (#​49398)
  • resource/aws_mq_broker: Fix reading MQ Broker (...) shared resources errors when reading RabbitMQ brokers in partitions where mq:DescribeSharedResources is unavailable, such as AWS GovCloud (US) (#​49340)
  • resource/aws_rds_cluster: Fix InvalidParameterCombination error when engine_version is updated externally (#​49396)
  • resource/aws_route53domains_registered_domain: Fix UpdateDomainContactPrivacy being incorrectly triggered when billing_contact changes (#​49314)
  • resource/aws_ssm_parameter: Fixes error where name with a leading slash and no other slashes was stripping the leading slash. (#​49339)

v6.58.0

Compare Source

FEATURES:

  • New List Resource: aws_mailmanager_rule_set (#​49257)
  • New List Resource: aws_prometheus_anomaly_detector (#​49139)
  • New List Resource: aws_prometheus_scraper (#​47466)
  • New List Resource: aws_prometheus_scraper_logging_configuration (#​47466)
  • New List Resource: aws_resiliencehubv2_policy (#​48321)
  • New Resource: aws_mailmanager_rule_set (#​49257)
  • New Resource: aws_prometheus_anomaly_detector (#​49139)
  • New Resource: aws_prometheus_scraper_logging_configuration (#​47466)
  • New Resource: aws_resiliencehubv2_policy (#​48321)

ENHANCEMENTS:

  • resource/aws_api_gateway_rest_api: Add configurable resource timeouts. (#​49205)
  • resource/aws_dx_connection: Add state attribute (#​42150)
  • resource/aws_ecs_capacity_provider: Add RESERVED as a valid value for managed_instances_provider.instance_launch_template.capacity_option_type (#​48816)
  • resource/aws_ecs_capacity_provider: Add local_storage_configuration attribute to managed_instances_provider.instance_launch_template (#​47513)
  • resource/aws_ecs_capacity_provider: Add managed_instances_provider.instance_launch_template.capacity_reservations argument (#​48816)
  • resource/aws_glue_catalog_table_optimizer: Add configuration.compaction_configuration argument (#​43868)
  • resource/aws_prometheus_scraper: Add Resource Identity support (#​47466)
  • resource/aws_prometheus_scraper: Add destination.cloudwatch configuration block for CloudWatch Metrics destination support (#​49088)

BUG FIXES:

  • resource/aws_api_gateway_rest_api: Wait for the REST API to reach an available state on create and update, and to be fully deleted on delete, preventing intermittent BadRequestException: There is already an update in progress errors (#​49205)
  • resource/aws_appstream_stack: Fix embed_host_domains not being sent to the AWS API on update, which caused a permanent plan diff when the argument was added or changed on an existing stack (#​49015)
  • resource/aws_bedrockagent_data_source: Fix validator incorrectly requiring bedrock_data_automation_configuration when parsing_strategy = "BEDROCK_DATA_AUTOMATION", a regression introduced in v6.56.0 (#​49111)
  • resource/aws_bedrockagentcore_agent_runtime: Allow : (colon) in the match_value_string and match_value_string_list attributes of authorizer_configuration.custom_jwt_authorizer.custom_claim.authorizing_claim_match_value.claim_match_value (#​48437)
  • resource/aws_bedrockagentcore_memory_strategy: Fix Value Conversion Error ... Received null value, however the target type cannot handle null values errors (#​49188)
  • resource/aws_bedrockagentcore_memory_strategy: Fix too many results: wanted 1, got 2 error when creating or updating a strategy on a memory that already has another strategy of a different type (#​49250)
  • resource/aws_bedrockagentcore_memory_strategy: Replace resource rather than erroring when configuration.consolidation, configuration.extraction, or configuration.reflection blocks are removed (#​49188)
  • resource/aws_ecs_service: Fix sigint_rollback falsely rolling back healthy deployments during wait_for_steady_state (#​49077)
  • resource/aws_ecs_service: Prevent non-EBS deployment volume configurations from being written to state (#​48947)
  • resource/aws_elasticache_replication_group: Fix perpetual diff when changes are pending for the next maintenance window (apply_immediately = false) (#​48246)
  • resource/aws_glue_catalog_table: Fix InvalidInputException: StorageDescriptor is not allowed error when creating or updating ATHENA-dialect views (#​49156)
  • resource/aws_glue_catalog_table: Fix InvalidInputException error when creating or updating SPARK-dialect views without an explicit storage_descriptor block (#​49156)
  • resource/aws_glue_catalog_table: Fix perpetual diff on view_definition.representations fields (validation_connection, view_original_text, view_expanded_text) that AWS Glue does not echo back for validated ATHENA views (#​49156)
  • resource/aws_iam_user: Retry destroying users when there are conflicts, and ignore non-errors during destroy (#​49260)
  • resource/aws_route53recoverycontrolconfig_safety_rule: Fix crash when the create operation returns an error (#​49155)
  • resource/aws_ssm_parameter: Correctly imports when passing ARN value. (#​49134)
  • resource/aws_ssm_parameter: Prevents errors when importing specific version. (#​49134)

v6.57.1

Compare Source

NOTES:

  • resource/aws_bedrockagentcore_memory_strategy: The memory_execution_role_arn attribute has been deprecated. This attribute should be removed from configurations (#​49140)
  • resource/aws_bedrockagentcore_memory_strategy: The namespaces attribute has been deprecated. All configurations using namespaces should be updated to use the namespace_templates attribute instead (#​49140)

FEATURES:

  • New Data Source: aws_eks_access_policies (#​49090)
  • New List Resource: aws_bedrock_evaluation_job (#​49044)
  • New List Resource: aws_eks_access_entry (#​49090)
  • New List Resource: aws_eks_access_policy_association (#​49121)
  • New List Resource: aws_eks_node_group (#​49073)
  • New List Resource: aws_flow_log (#​49086)
  • New List Resource: aws_mailmanager_traffic_policy (#​49043)
  • New List Resource: aws_osis_pipeline (#​49157)
  • New List Resource: aws_osis_pipeline_endpoint (#​44383)
  • New List Resource: aws_osis_resource_policy (#​44383)
  • New List Resource: aws_rekognition_collection (#​49135)
  • New Resource: aws_bedrock_evaluation_job (#​49044)
  • New Resource: aws_cloudwatch_log_storage_tier_policy (#​49076)
  • New Resource: aws_mailmanager_traffic_policy (#​49043)
  • New Resource: aws_osis_pipeline_endpoint (#​44383)
  • New Resource: aws_osis_resource_policy (#​44383)

ENHANCEMENTS:

  • data-source/aws_launch_template: Add ena_queue_count attribute to network_interfaces configuration block (#​48892)
  • data-source/aws_secretsmanager_secret: Add type attribute (#​46414)
  • data-source/aws_secretsmanager_secret_rotation: Add external_secret_rotation_metadata and external_secret_rotation_role_arn attributes (#​46414)
  • data-source/aws_vpc: Adds support for ipv6_cidr_block_associations. (#​46918)
  • data-source/aws_vpc: Deprecates ipv6_association_id and ipv6_cidr_block. (#​46918)
  • resource/aws_autoscaling_group: Add reservations-then-balanced valid value for availability_zone_distribution.capacity_distribution_strategy (#​48934)
  • resource/aws_bedrockagentcore_memory: Add timeouts.update with a default value of 30m (#​49140)
  • resource/aws_bedrockagentcore_memory_strategy: Add configuration.reflection configuration block for EPISODIC_OVERRIDE strategy type (#​49140)
  • resource/aws_bedrockagentcore_memory_strategy: Add namespace_templates argument (#​49140)
  • resource/aws_bedrockagentcore_memory_strategy: Add reflection_configuration configuration block for EPISODIC strategy type (#​49140)
  • resource/aws_bedrockagentcore_memory_strategy: Increase default timeouts values to 45m (#​49140)
  • resource/aws_codepipeline: Add stage.action.commands and stage.action.output_artifacts_for_compute_action arguments to support Compute action types (#​42507)
  • resource/aws_codepipeline: stage.action.output_artifacts_for_compute_action and stage.action.output_artifacts now conflict (#​42507)
  • resource/aws_eks_pod_identity_association: Add policy argument to support inline session policies (#​48869)
  • resource/aws_fis_experiment_template: Support MultiRegionClusters as a value for action.target.key (#​48781)
  • resource/aws_flow_log: Add resource identity support (#​49086)
  • resource/aws_launch_template: Add ena_queue_count argument to network_interfaces configuration block (#​48892)
  • resource/aws_rekognition_collection: Add Resource Identity support (#​49022)
  • resource/aws_rekognition_project: Add Resource Identity support (#​49022)
  • resource/aws_rekognition_stream_processor: Add Resource Identity support (#​49022)
  • resource/aws_secretsmanager_secret: Add type argument in support of managed external secrets (#​46414)
  • resource/aws_secretsmanager_secret_rotation: Add external_secret_rotation_metadata and external_secret_rotation_role_arn arguments in support of managed external secrets (#​46414)

BUG FIXES:

  • provider: Fixes api error UnknownError: UnknownError introduced in release 6.57.0 (#​49175)
  • resource/aws_dynamodb_table: No longer replace resource when decreasing warm_throughput values (#​49032)

v6.56.0

Compare Source

FEATURES:

  • **New Ac

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Asia/Taipei)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added area/misc Non-core, uncatagorized changes type/chore Version bumps or boring things labels Jun 22, 2026
@renovate
renovate Bot force-pushed the renovate/major-terraform branch 4 times, most recently from db535b3 to d85f763 Compare June 24, 2026 20:38
@renovate
renovate Bot force-pushed the renovate/major-terraform branch 3 times, most recently from d0231d4 to 71aff28 Compare July 2, 2026 17:46
@renovate
renovate Bot force-pushed the renovate/major-terraform branch 4 times, most recently from 4629207 to 23c7d7f Compare July 12, 2026 10:44
@renovate
renovate Bot force-pushed the renovate/major-terraform branch 2 times, most recently from ccd42e4 to d441c1e Compare July 17, 2026 13:26
@renovate
renovate Bot force-pushed the renovate/major-terraform branch 2 times, most recently from 9fc0db7 to f3629b8 Compare July 28, 2026 20:51
@renovate
renovate Bot force-pushed the renovate/major-terraform branch 3 times, most recently from 4e507a1 to 6ca160d Compare August 6, 2026 13:58
@renovate
renovate Bot force-pushed the renovate/major-terraform branch 2 times, most recently from c9a37b3 to 22ec6cb Compare August 16, 2026 08:17
@github-actions

Copy link
Copy Markdown
--- kubernetes/flux-system Kustomization: flux-system/0-flux-system HelmRelease: flux-system/flux2

+++ kubernetes/flux-system Kustomization: flux-system/0-flux-system HelmRelease: flux-system/flux2

@@ -11,13 +11,13 @@

   chart:
     spec:
       chart: flux2
       sourceRef:
         kind: HelmRepository
         name: fluxcd-community
-      version: 2.16.4
+      version: 2.15.0
   install:
     crds: CreateReplace
   interval: 1h
   maxHistory: 1
   timeout: 1m0s
   upgrade:

@github-actions

Copy link
Copy Markdown
--- HelmRelease: flux-system/flux2 Deployment: flux-system/helm-controller

+++ HelmRelease: flux-system/flux2 Deployment: flux-system/helm-controller

@@ -32,13 +32,13 @@

         - --enable-leader-election
         env:
         - name: RUNTIME_NAMESPACE
           valueFrom:
             fieldRef:
               fieldPath: metadata.namespace
-        image: ghcr.io/fluxcd/helm-controller:v1.3.0
+        image: ghcr.io/fluxcd/helm-controller:v1.2.0
         imagePullPolicy: IfNotPresent
         livenessProbe:
           httpGet:
             path: /healthz
             port: healthz
         name: manager
--- HelmRelease: flux-system/flux2 Deployment: flux-system/image-automation-controller

+++ HelmRelease: flux-system/flux2 Deployment: flux-system/image-automation-controller

@@ -32,13 +32,13 @@

         - --enable-leader-election
         env:
         - name: RUNTIME_NAMESPACE
           valueFrom:
             fieldRef:
               fieldPath: metadata.namespace
-        image: ghcr.io/fluxcd/image-automation-controller:v0.41.2
+        image: ghcr.io/fluxcd/image-automation-controller:v0.40.0
         imagePullPolicy: IfNotPresent
         livenessProbe:
           httpGet:
             path: /healthz
             port: healthz
         name: manager
--- HelmRelease: flux-system/flux2 Deployment: flux-system/image-reflector-controller

+++ HelmRelease: flux-system/flux2 Deployment: flux-system/image-reflector-controller

@@ -32,13 +32,13 @@

         - --enable-leader-election
         env:
         - name: RUNTIME_NAMESPACE
           valueFrom:
             fieldRef:
               fieldPath: metadata.namespace
-        image: ghcr.io/fluxcd/image-reflector-controller:v0.35.2
+        image: ghcr.io/fluxcd/image-reflector-controller:v0.34.0
         imagePullPolicy: IfNotPresent
         livenessProbe:
           httpGet:
             path: /healthz
             port: healthz
         name: manager
--- HelmRelease: flux-system/flux2 Deployment: flux-system/kustomize-controller

+++ HelmRelease: flux-system/flux2 Deployment: flux-system/kustomize-controller

@@ -32,13 +32,13 @@

         - --enable-leader-election
         env:
         - name: RUNTIME_NAMESPACE
           valueFrom:
             fieldRef:
               fieldPath: metadata.namespace
-        image: ghcr.io/fluxcd/kustomize-controller:v1.6.1
+        image: ghcr.io/fluxcd/kustomize-controller:v1.5.1
         imagePullPolicy: IfNotPresent
         livenessProbe:
           httpGet:
             path: /healthz
             port: healthz
         name: manager
--- HelmRelease: flux-system/flux2 Deployment: flux-system/notification-controller

+++ HelmRelease: flux-system/flux2 Deployment: flux-system/notification-controller

@@ -31,13 +31,13 @@

         - --enable-leader-election
         env:
         - name: RUNTIME_NAMESPACE
           valueFrom:
             fieldRef:
               fieldPath: metadata.namespace
-        image: ghcr.io/fluxcd/notification-controller:v1.6.0
+        image: ghcr.io/fluxcd/notification-controller:v1.5.0
         imagePullPolicy: IfNotPresent
         livenessProbe:
           httpGet:
             path: /healthz
             port: healthz
         name: manager
--- HelmRelease: flux-system/flux2 Deployment: flux-system/source-controller

+++ HelmRelease: flux-system/flux2 Deployment: flux-system/source-controller

@@ -36,13 +36,13 @@

         - --storage-adv-addr=source-controller.$(RUNTIME_NAMESPACE).svc.cluster.local.
         env:
         - name: RUNTIME_NAMESPACE
           valueFrom:
             fieldRef:
               fieldPath: metadata.namespace
-        image: ghcr.io/fluxcd/source-controller:v1.6.2
+        image: ghcr.io/fluxcd/source-controller:v1.5.0
         imagePullPolicy: IfNotPresent
         livenessProbe:
           httpGet:
             path: /healthz
             port: healthz
         name: manager
--- HelmRelease: flux-system/flux2 Job: flux-system/flux2-flux-check

+++ HelmRelease: flux-system/flux2 Job: flux-system/flux2-flux-check

@@ -23,13 +23,13 @@

     spec:
       restartPolicy: Never
       serviceAccountName: flux2-flux-check
       automountServiceAccountToken: true
       containers:
       - name: flux-cli
-        image: ghcr.io/fluxcd/flux-cli:v2.6.4
+        image: ghcr.io/fluxcd/flux-cli:v2.5.1
         command:
         - /usr/local/bin/flux
         - check
         - --pre
         - --namespace
         - flux-system

@renovate
renovate Bot force-pushed the renovate/major-terraform branch 2 times, most recently from 7f28f8d to a651afc Compare August 20, 2026 01:55
@renovate
renovate Bot force-pushed the renovate/major-terraform branch 2 times, most recently from f0b48dc to 6a0ede2 Compare August 26, 2026 21:53
@renovate
renovate Bot force-pushed the renovate/major-terraform branch 2 times, most recently from 56f2f3f to 1431b2f Compare September 3, 2026 11:09
@renovate
renovate Bot force-pushed the renovate/major-terraform branch from 1431b2f to f2e5801 Compare September 3, 2026 22:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/misc Non-core, uncatagorized changes type/chore Version bumps or boring things

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants