Skip to content

Releases: hashicorp/terraform-provider-aws

v5.26.0

16 Nov 22:52
4b389cd
Compare
Choose a tag to compare

FEATURES:

  • New Data Source: aws_iot_registration_code (#15098)
  • New Resource: aws_iot_billing_group (#31237)
  • New Resource: aws_iot_ca_certificate (#15098)
  • New Resource: aws_iot_event_configurations (#31237)

ENHANCEMENTS:

  • data-source/aws_autoscaling_group: Add instance_maintenance_policy attribute (#34430)
  • provider: Adds https_proxy and no_proxy parameters. (#34243)
  • resource/aws_autoscaling_group: Add instance_maintenance_policy configuration block (#34430)
  • resource/aws_finspace_kx_cluster: Increase default create and update timeouts to 4 hours to allow for increased startup times with large volumes of cached data (#34398)
  • resource/aws_finspace_kx_environment: Increase default delete timeout to 75 minutes (#34398)
  • resource/aws_iam_group_policy_attachment: Add plan-time validation of policy_arn (#34378)
  • resource/aws_iam_policy_attachment: Add plan-time validation of policy_arn (#34378)
  • resource/aws_iam_role_policy_attachment: Add plan-time validation of policy_arn (#34378)
  • resource/aws_iam_user_policy_attachment: Add plan-time validation of policy_arn (#34378)
  • resource/aws_iot_ca_certificate: Add ca_certificate_id attribute (#15098)
  • resource/aws_iot_policy: Add configurable timeouts (#34329)
  • resource/aws_iot_policy: When updating the resource, delete the oldest non-default version of the policy if creating a new version would exceed the maximum number of versions (5) (#34329)
  • resource/aws_lambda_function: Add support for nodejs20.x and provided.al2023 runtime values (#34401)
  • resource/aws_lambda_layer_version: Add support for nodejs20.x and provided.al2023 compatible_runtimes values (#34401)
  • resource/aws_quicksight_analysis: Add definition.sheets.visuals.kpi_visual.chart_configuration.kpi_options.sparkline attribute (#33931)
  • resource/aws_quicksight_analysis: Add definition.sheets.visuals.kpi_visual.chart_configuration.kpi_options.visual_layout_options attribute (#33931)
  • resource/aws_quicksight_analysis: Add number_display_format_configuration and percentage_display_format_configuration to nested numeric_format_configuration argument (#33931)
  • resource/aws_quicksight_dashboard: Add definition.sheets.visuals.kpi_visual.chart_configuration.kpi_options.sparkline attribute (#33931)
  • resource/aws_quicksight_dashboard: Add definition.sheets.visuals.kpi_visual.chart_configuration.kpi_options.visual_layout_options attribute (#33931)
  • resource/aws_quicksight_dashboard: Add number_display_format_configuration and percentage_display_format_configuration to nested numeric_format_configuration argument (#33931)
  • resource/aws_quicksight_template: Add definition.sheets.visuals.kpi_visual.chart_configuration.kpi_options.sparkline attribute (#33931)
  • resource/aws_quicksight_template: Add definition.sheets.visuals.kpi_visual.chart_configuration.kpi_options.visual_layout_options attribute (#33931)
  • resource/aws_quicksight_template: Add number_display_format_configuration and percentage_display_format_configuration to nested numeric_format_configuration argument (#33931)
  • resource/aws_rds_cluster: Add delete_automated_backups argument (#34309)

BUG FIXES:

  • resource/aws_chime_voice_connector: Fix read error when resource is not created in us-east-1 (#34334)
  • resource/aws_chime_voice_connector_group: Fix read error when resource is not created in us-east-1 (#34334)
  • resource/aws_chime_voice_connector_logging: Fix read error when resource is not created in us-east-1 (#34334)
  • resource/aws_chime_voice_connector_origination: Fix read error when resource is not created in us-east-1 (#34334)
  • resource/aws_chime_voice_connector_termination: Fix read error when resource is not created in us-east-1 (#34334)
  • resource/aws_chime_voice_connector_termination_credentials: Fix read error when resource is not created in us-east-1 (#34334)
  • resource/aws_chimesdkmediapipelines_media_insights_pipeline_configuration: Fix eventual consistency error when resource is not created in us-east-1 (#34334)
  • resource/aws_chimesdkvoice_sip_media_application: Fix eventual consistency errors when not using us-east-1 (#34426)
  • resource/aws_chimesdkvoice_sip_rule: Fix eventual consistency errors when not using us-east-1 (#34426)
  • resource/aws_elasticache_user: Fix UserNotFound: ... is not available for tagging errors on resource Read when there is a concurrent update to the user (#34396)
  • resource/aws_grafana_workspace_api_key: Change key to Sensitive (#34105)
  • resource/aws_iam_group_policy_attachment: Retry ConcurrentModificationException errors on create and delete (#34378)
  • resource/aws_iam_policy_attachment: Retry ConcurrentModificationException errors on create and delete (#34378)
  • resource/aws_iam_role_policy_attachment: Retry ConcurrentModificationException errors on create and delete (#34378)
  • resource/aws_iam_user_policy_attachment: Retry ConcurrentModificationException errors on create and delete (#34378)
  • resource/aws_inspector2_delegated_admin_account: Fix errors: *target must be interface or implement error panic (#34424)
  • resource/aws_inspector2_enabler: Fix interface conversion: interface {} is nil, not map[string]inspector2.AccountResourceStatus panic (#34424)
  • resource/aws_iot_ca_certificate: Change ca_pem and certificate_pem to ForceNew (#15098)
  • resource/aws_iot_policy: Retry DeleteConflictException errors on delete (#34329)
  • resource/aws_quicksight_analysis: Fix handling of the nested number_scale, prefix, and suffix integer arguments (#33931)
  • resource/aws_quicksight_analysis: Fix handling of the nested rolling_date argument (#33931)
  • resource/aws_quicksight_analysis: Fix handling of the nested select_all_options argument (#33931)
  • resource/aws_quicksight_analysis: Fix handling of the nested visual_ids argument (#33931)
  • resource/aws_quicksight_analysis: Fixes to various optional blocks utilizing the shared column schema definition (#33931)
  • resource/aws_quicksight_analysis: Nested column_index and row_index arguments now properly handle zero values (#33931)
  • resource/aws_quic...
Read more

v5.25.0

10 Nov 06:08
Compare
Choose a tag to compare

NOTES:

  • resource/aws_cloudtrail: The resource's import ID has changed from name to arn (#30758)

FEATURES:

  • New Data Source: aws_apigatewayv2_vpc_link (#33974)
  • New Data Source: aws_athena_named_query (#24815)
  • New Data Source: aws_bedrock_foundation_model (#34148)
  • New Data Source: aws_bedrock_foundation_models (#34148)
  • New Resource: aws_athena_prepared_statement (#33417)
  • New Resource: aws_lexv2models_bot_locale (#33949)

ENHANCEMENTS:

  • provider: Adds SSO API endpoint override parameter endpoints.sso (#34302)
  • resource/aws_appflow_connector_profile: Add jwt_token and oauth2_grant_type arguments to the connector_profile_config.connector_profile_credentials.salesforce block. (#34248)
  • resource/aws_autoscaling_group: Add plan-time validation of initial_lifecycle_hook.default_result, initial_lifecycle_hook.heartbeat_timeout, initial_lifecycle_hook.lifecycle_transition, initial_lifecycle_hook.name, initial_lifecycle_hook.notification_target_arn and initial_lifecycle_hook.role_arn (#12145)
  • resource/aws_autoscaling_lifecycle_hook: Add plan-time validation of default_result, heartbeat_timeout, lifecycle_transition, name, notification_target_arn and role_arn (#12145)
  • resource/aws_datasync_task: Add task_report_config argument (#33861)
  • resource/aws_db_instance: Add postgres as a valid engine value for blue/green deployments (#34216)
  • resource/aws_dms_endpoint: Add pause_replication_tasks, which when set to true, pauses associated running replication tasks, regardless if they are managed by Terraform, prior to modifying the endpoint (only tasks paused by the resource will be restarted after the modification completes) (#34316)
  • resource/aws_eks_cluster: Allow vpc_config.security_group_ids and vpc_config.subnet_ids to be updated in-place (#32409)
  • resource/aws_inspector2_organization_configuration: Add lambda_code argument to the auto_enable configuration block (#34261)
  • resource/aws_route53_record: Allow import of records with an empty record name. (#34212)
  • resource/aws_sagemaker_domain: Add default_user_settings.canvas_app_settings.direct_deploy_settings, default_user_settings.canvas_app_settings.identity_provider_oauth_settings and default_user_settings.canvas_app_settings.kendra_settings arguments (#34265)
  • resource/aws_sagemaker_domain: Change default_space_settings.kernel_gateway_app_settings.custom_image, default_user_settings.kernel_gateway_app_settings.custom_image and default_user_settings.r_session_app_settings.custom_image MaxItems from 30 to 200 (#34265)
  • resource/aws_sagemaker_feature_group: Add offline_store_config.s3_storage_config.resolved_output_s3_uri, online_store_config.storage_type and online_store_config.ttl_duration arguments (#34283)
  • resource/aws_sagemaker_feature_group: Allow online_store_config.ttl_duration to be updated in-place (#34283)
  • resource/aws_sagemaker_model: Add container.model_data_source and primary_container.model_data_source configuration blocks (#34158)
  • resource/aws_sagemaker_space: Change space_settings.kernel_gateway_app_settings.custom_image MaxItems from 30 to 200 (#34265)
  • resource/aws_sagemaker_user_profile: Add default_user_settings.canvas_app_settings.direct_deploy_settings, default_user_settings.canvas_app_settings.identity_provider_oauth_settings and default_user_settings.canvas_app_settings.kendra_settings arguments (#34265)
  • resource/aws_sns_topic: Add archive_policy argument and beginning_archive_time attribute to support message archiving (#34252)
  • resource/aws_sns_topic: Add replay_policy argument (#34252)

BUG FIXES:

  • provider: Fix Value Conversion Error panic for certain resources when null tag values are specified (#34319)
  • provider: Fixes parsing error in AWS shared config files with extra whitespace (#34300)
  • provider: Fixes poor performance when parsing AWS shared config files (#34300)
  • resource/aws_autoscaling_group: Change all initial_lifecycle_hook configuration block attributes to ForceNew (#34260)
  • resource/aws_cloudtrail: Change the id attribute from the trail's name to its ARN to support organization trails (#30758)
  • resource/aws_cloudwatch_event_rule: Increase event_pattern max length for validation to 4096 (#34270)
  • resource/aws_sagemaker_domain: Fix updating default_space_settings.r_studio_server_pro_app_settings.access_status from ENABLED to DISABLED (#34265)

v5.24.0

02 Nov 21:01
Compare
Choose a tag to compare

NOTES:

  • resource/aws_detective_organization_admin_account: Because we cannot easily test this functionality, it is best effort and we ask for community help in testing (#25237)
  • resource/aws_detective_organization_configuration: Because we cannot easily test this functionality, it is best effort and we ask for community help in testing (#25237)

FEATURES:

  • New Data Source: aws_opensearchserverless_lifecycle_policy (#34144)
  • New Resource: aws_detective_organization_admin_account (#25237)
  • New Resource: aws_detective_organization_configuration (#25237)
  • New Resource: aws_opensearchserverless_lifecycle_policy (#34144)
  • New Resource: aws_redshift_resource_policy (#34149)
  • New Resource: aws_verifiedaccess_endpoint (#30763)

ENHANCEMENTS:

  • resource/aws_amplify_app: Add custom_headers argument (#31561)
  • resource/aws_batch_job_definition: Add node_properties argument (#34153)
  • resource/aws_finspace_kx_cluster: In-place updates are now supported for the code, database, and initialization_script arguments. The update timeout has been increased to 30 minutes. (#34220)
  • resource/aws_iot_topic_rule: Add kafka.header and error_action.kafka.header arguments (#34191)
  • resource/aws_networkmanager_connect_attachment: Add NO_ENCAP as a valid options.protocol value (#34109)
  • resource/aws_networkmanager_connect_peer: Add subnet_arn argument to support Tunnel-less Connect attachments (#34109)
  • resource/aws_networkmanager_connect_peer: inside_cidr_blocks is Optional (#34109)
  • resource/aws_rds_cluster: Remove the provider default (previously, "1") and use the AWS default for backup_retention_period (also, "1") to allow integration with AWS Backup (#34187)
  • resource/aws_redshift_cluster: Add snapshot_arn argument (#34181)
  • resource/aws_redshift_cluster: Add the manage_master_password and master_password_secret_kms_key_id arguments to support managed admin credentials (#34182)
  • resource/aws_s3_object: Add override_provider configuration block, allowing tags inherited from the provider default_tags configuration block to be ignored (#33262)
  • resource/aws_secretsmanager_secret_rotation: The rotation_lambda_arn argument is now optional to support modifying the rotation schedule of AWS-managed secrets. (#34180)

BUG FIXES:

  • data-source/aws_vpc_ipam_pools: Add id attribute for individual IPAM pools (#32133)
  • resource/aws_alb_listener_rule: Fixed the action.forward.target_group argument minimum item requirement. Previously this was set to 2, but the AWS API allows specifying a single target group. (#33727)
  • resource/aws_amplify_branch: Remove ForceNew from enable_performance_mode (#34141)
  • resource/aws_lb_listener_rule: Fixed the action.forward.target_group argument minimum item requirement. Previously this was set to 2, but the AWS API allows specifying a single target group. (#33727)
  • resource/aws_quicksight_analysis: Fix "expected type to be integer" errors in window_options.bounds.* argument validatation functions (#34230)
  • resource/aws_quicksight_dashboard: Fix "expected type to be integer" errors in window_options.bounds.* argument validatation functions (#34230)
  • resource/aws_quicksight_template: Fix "expected type to be integer" errors in window_options.bounds.* argument validatation functions (#34230)
  • resource/aws_rds_cluster: Avoid an error on delete related to unexpected state 'scaling-compute' (#34187)

v5.23.1

27 Oct 15:13
Compare
Choose a tag to compare

BUG FIXES:

  • data-source/aws_lambda_function: Add vpc_config.ipv6_allowed_for_dual_stack attribute, fixing Invalid address to set: []string{"vpc_config", "0", "ipv6_allowed_for_dual_stack"} errors (#34134)

v5.23.0

26 Oct 23:17
734f2ed
Compare
Choose a tag to compare

NOTES:

  • provider: This release includes an update to the AWS SDK for Go v2 with breaking type changes to several services: finspace, kafka, medialive, rds, s3control, timestreamwrite, and xray. These changes primarily affect how arguments with default values are serialized for outbound requests, changing scalar types to pointers. See this AWS SDK for Go V2 issue for additional context. The corresponding provider changes should make this breakfix transparent to users, but as with any breaking change there is the potential for missed edge cases. If errors are observed in the impacted resources, please link to this dependency update pull request in the bug report. (#34096)

FEATURES:

  • New Resource: aws_iot_domain_configuration (#24765)

ENHANCEMENTS:

  • data-source/aws_imagebuilder_image: Add image_scanning_configuration attribute (#34049)
  • resource/aws_config_config_rule: Add evaluation_mode attribute (#34033)
  • resource/aws_elasticache_replication_group: Add ip_discovery and network_type arguments (#34019)
  • resource/aws_imagebuilder_image: Add image_scanning_configuration configuration block (#34049)
  • resource/aws_kms_key: Add configurable timeouts (#34112)
  • resource/aws_lambda_function: Add vpc_config.ipv6_allowed_for_dual_stack argument (#34045)
  • resource/aws_lb: Add dns_record_client_routing_policy attribute to configure Availability Zonal DNS affinity on Network Load Balancer (NLB) (#33992)
  • resource/aws_lb_target_group: Add target_health_state configuration block (#34070)
  • resource/aws_lb_target_group: Remove default value (false) for connection_termination argument and mark as Computed, to support new default behavior for UDP/TCP_UDP target groups (#34070)
  • resource/aws_neptune_cluster: Add slowquery as a valid enable_cloudwatch_logs_exports value (#34053)

BUG FIXES:

  • provider/tags: Prevent crash when tags_all is null (#34073)
  • resource/aws_autoscaling_group: Fix error when launch_template name is updated. (#34086)
  • resource/aws_dms_s3_endpoint: Don't send the default value of false for add_trailing_padding_character, maintaining compatibility with older (pre-3.4.7) DMS engine versions (#34048)
  • resource/aws_ecs_task_definition: Add 0 as a valid value for volume.efs_volume_configuration.transit_encryption_port, preventing unexpected drift (#34020)
  • resource/aws_identitystore_group: Fix updating description attribute when it is changed (#34037)
  • resource/aws_iot_indexing_configuration: Add thing_indexing_configuration.filter attribute, resolving InvalidRequestException: NamedShadowNames Filter must not be empty for enabling NamedShadowIndexingMode errors (#26859)
  • resource/aws_storagegateway_gateway: Support the value 0 (representing Sunday) for maintenance_start_time.day_of_week (#34015)
  • resource/aws_verifiedaccess_group: Fix InvalidParameterValue: Policy Document cannot be provided when Policy Enabled is false or missing errors when updating policy_document (#34054)

v5.22.0

19 Oct 22:45
Compare
Choose a tag to compare

FEATURES:

  • New Data Source: aws_media_convert_queue (#27075)
  • New Resource: aws_elasticsearch_vpc_endpoint (#33925)
  • New Resource: aws_msk_replicator (#33973)

ENHANCEMENTS:

  • data-source/aws_ec2_client_vpn_endpoint: Add self_service_portal_url attribute (#34007)
  • resource/aws_alb: Support import of name_prefix argument (#33852)
  • resource/aws_alb_target_group: Support import of name_prefix argument (#33852)
  • resource/aws_cloudfront_public_key: Support import of name_prefix argument (#33852)
  • resource/aws_db_option_group: Support import of name_prefix argument (#33852)
  • resource/aws_docdb_cluster: Support import of cluster_identifier_prefix argument (#33852)
  • resource/aws_docdb_cluster_instance: Support import of identifier_prefix argument (#33852)
  • resource/aws_docdb_cluster_parameter_group: Support import of name_prefix argument (#33852)
  • resource/aws_docdb_subnet_group: Support import of name_prefix argument (#33852)
  • resource/aws_ec2_client_vpn_endpoint: Add self_service_portal_url attribute (#34007)
  • resource/aws_elb: Support import of name_prefix argument (#33852)
  • resource/aws_emr_security_configuration: Support import of name_prefix argument (#33852)
  • resource/aws_iam_group_policy: Support import of name_prefix argument (#33852)
  • resource/aws_iam_role_policy: Support import of name_prefix argument (#33852)
  • resource/aws_iam_user_policy: Support import of name_prefix argument (#33852)
  • resource/aws_iot_provisioning_template: Add type attribute (#33950)
  • resource/aws_lb: Support import of name_prefix argument (#33852)
  • resource/aws_lb_target_group: Support import of name_prefix argument (#33852)
  • resource/aws_neptune_cluster: Support import of cluster_identifier_prefix argument (#33852)
  • resource/aws_neptune_cluster_instance: Support import of identifier_prefix argument (#33852)
  • resource/aws_neptune_cluster_parameter_group: Support import of name_prefix argument (#33852)
  • resource/aws_neptune_event_subscription: Support import of name_prefix argument (#33852)
  • resource/aws_pinpoint_app: Support import of name_prefix argument (#33852)
  • resource/aws_rds_cluster: Support import of cluster_identifier_prefix argument (#33852)
  • resource/aws_rds_cluster_instance: Support import of identifier_prefix argument (#33852)
  • resource/aws_signer_signing_profile: Support import of name_prefix argument (#33852)
  • resource/aws_signer_signing_profile_permission: Add signer:SignPayload as a valid action value (#33852)
  • resource/aws_signer_signing_profile_permission: Support import of statement_id_prefix argument (#33852)
  • resource/aws_transfer_server: Change pre_authentication_login_banner and post_authentication_login_banner length limits to 4096 (#33937)
  • resource/aws_wafv2_web_acl: Add ja3_fingerprint to field_to_match configuration blocks (#33933)

BUG FIXES:

  • data-source/aws_dms_certificate: Fix crash when certificate not found (#34012)
  • resource/aws_cloudformation_stack: Fix error when computed values are not set when there is no update (#33969)
  • resource/aws_codecommit_repository: Doesn't force replacement when renaming (#32207)
  • resource/aws_db_instance: Creating resource from snapshot or point-in-time recovery now handles manage_master_user_password and master_user_secret_kms_key_id attributes correctly (#33699)
  • resource/aws_elasticache_replication_group: Fix error when switching engine_version from 6.x to a specific 6.<digit> version number (#33954)
  • resource/aws_iam_role: Fix refreshing permission_boundary when deleted outside of Terraform (#33963)
  • resource/aws_iam_user: Fix refreshing permission_boundary when deleted outside of Terraform (#33963)
  • resource/aws_inspector2_enabler: Fix Value at 'resourceTypes' failed to satisfy constraint errors (#33348)
  • resource/aws_neptune_cluster_instance: Remove ForceNew from engine_version (#33487)
  • resource/aws_neptune_cluster_parameter_group: Fix condition where defined cluster parameters with system default values are seen as updates (#33487)
  • resource/aws_s3_bucket_object_lock_configuration: Fix found resource errors on Delete (#33966)

v5.21.0

12 Oct 21:04
Compare
Choose a tag to compare

FEATURES:

  • New Data Source: aws_servicequotas_templates (#33871)
  • New Resource: aws_ec2_image_block_public_access (#33810)
  • New Resource: aws_guardduty_organization_configuration_feature (#33913)
  • New Resource: aws_servicequotas_template_association (#33725)
  • New Resource: aws_verifiedaccess_group (#33297)
  • New Resource: aws_verifiedaccess_instance_logging_configuration (#33864)

ENHANCEMENTS:

  • data-source/aws_dms_endpoint: Add s3_settings.glue_catalog_generation attribute (#33778)
  • data-source/aws_msk_cluster: Add cluster_uuid attribute (#33805)
  • resource/aws_codedeploy_deployment_group: Add outdated_instances_strategy argument (#33844)
  • resource/aws_dms_endpoint: Add s3_settings.glue_catalog_generation attribute (#33778)
  • resource/aws_dms_s3_endpoint: Add glue_catalog_generation attribute (#33778)
  • resource/aws_docdb_cluster: Add allow_major_version_upgrade argument (#33790)
  • resource/aws_docdb_cluster_instance: Add copy_tags_to_snapshot argument (#31022)
  • resource/aws_dynamodb_table: Add import_table configuration block (#33802)
  • resource/aws_msk_cluster: Add cluster_uuid attribute (#33805)
  • resource/aws_msk_serverless_cluster: Add cluster_uuid attribute (#33805)
  • resource/aws_networkmanager_core_network: Add base_policy_document argument (#33712)
  • resource/aws_redshiftserverless_workgroup: Allow require_ssl and use_fips_ssl config_parameters keys (#33916)
  • resource/aws_s3_bucket: Use configurable timeout for resource Delete (#33845)
  • resource/aws_verifiedaccess_instance: Add fips_enabled argument (#33880)
  • resource/aws_vpclattice_target_group: Add config.lambda_event_structure_version argument (#33804)
  • resource/aws_vpclattice_target_group: Make config.port, config.protocol and config.vpc_identifier optional (#33804)
  • resource/aws_wafv2_web_acl: Add aws_managed_rules_acfp_rule_set to managed_rule_group_configs configuration block (#33915)

BUG FIXES:

  • provider: Respect valid values for the AWS_S3_US_EAST_1_REGIONAL_ENDPOINT environment variable when configuring the S3 API client (#33874)
  • resource/aws_appflow_connector_profile: Fix various crashes (#33856)
  • resource/aws_db_parameter_group: Group names containing periods (.) no longer fail validation (#33704)
  • resource/aws_opensearchserverless_collection: Fix crash when error is returned (#33918)
  • resource/aws_rds_cluster_parameter_group: Group names containing periods (.) no longer fail validation (#33704)

v5.20.1

10 Oct 16:02
1e981db
Compare
Choose a tag to compare

NOTES:

v5.20.0

06 Oct 18:09
Compare
Choose a tag to compare

FEATURES:

  • New Resource: aws_guardduty_detector_feature (#31463)
  • New Resource: aws_servicequotas_template (#33688)
  • New Resource: aws_sesv2_account_vdm_attributes (#33705)
  • New Resource: aws_verifiedaccess_instance_trust_provider_attachment (#33734)

ENHANCEMENTS:

  • data-source/aws_guardduty_detector: Add features attribute (#31463)
  • resource/aws_finspace_kx_cluster: Increase default creation timeout to 45 minutes, default deletion timeout to 60 minutes (#33745)
  • resource/aws_finspace_kx_environment: Increase default deletion timeout to 45 minutes (#33745)
  • resource/aws_guardduty_filter: Add plan-time validation of name (#21030)
  • resource/aws_kinesis_firehose_delivery_stream: Add opensearchserverless_configuration and msk_source_configuration configuration blocks (#33101)
  • resource/aws_kinesis_firehose_delivery_stream: Add opensearchserverless as a valid destination value (#33101)

BUG FIXES:

  • data-source/aws_fsx_ontap_storage_virtual_machine: Fix crash when active_directory_configuration.self_managed_active_directory_configuration.file_system_administrators_group is not configured (#33800)
  • resource/aws_ec2_transit_gateway_route : Fix TGW route search filter to avoid routes being missed when more than 1,000 static routes are in a TGW route table (#33765)
  • resource/aws_fsx_ontap_storage_virtual_machine: Fix crash when active_directory_configuration.self_managed_active_directory_configuration.file_system_administrators_group is not configured (#33800)
  • resource/aws_medialive_channel: Fix VPC settings flatten/expand/docs. (#33558)
  • resource/aws_vpc_endpoint: Set dns_options.dns_record_ip_type to Computed to prevent diffs (#33743)

v5.19.0

29 Sep 00:55
dbf42d7
Compare
Choose a tag to compare

BREAKING CHANGES:

NOTES:

  • data-source/aws_s3_bucket_object: The metadata attribute's keys are now always returned in lowercase. Please modify configurations as necessary (#33660)
  • data-source/aws_s3_object: The metadata attribute's keys are now always returned in lowercase. Please modify configurations as necessary (#33660)
  • resource/aws_iam_*: This release introduces additional validation of IAM policy JSON arguments to detect duplicate keys. Previously, arguments with duplicated keys resulted in all but one of the key values being overwritten. Since this results in unexpected IAM policies being submitted to AWS, we have updated the validation logic to error in these cases. This may cause existing IAM policy arguments to fail validation, however, those policies are likely not what was originally intended. (#33570)

FEATURES:

  • New Resource: aws_cleanrooms_configured_table (#33602)
  • New Resource: aws_dms_replication_config (#32908)
  • New Resource: aws_lexv2models_bot (#33475)
  • New Resource: aws_rds_custom_db_engine_version (#33285)
  • New Resource: aws_vpclattice_service_network (#30482)

ENHANCEMENTS:

  • data-source/aws_opensearch_domain: Add off_peak_window_options attribute (#30965)
  • resource/aws_cloud9_environment_ec2: Add ubuntu-22.04-x86_64 and resolve:ssm:/aws/service/cloud9/amis/ubuntu-22.04-x86_64 as valid values for image_id (#33662)
  • resource/aws_fsx_ontap_volume: Add bypass_snaplock_enterprise_retention argument and snaplock_configuration configuration block to support SnapLock (#32530)
  • resource/aws_fsx_ontap_volume: Add copy_tags_to_backups and snapshot_policy arguments (#32530)
  • resource/aws_fsx_openzfs_volume: Add delete_volume_options argument (#32530)
  • resource/aws_lightsail_bucket: Add force_delete argument (#33586)
  • resource/aws_opensearch_domain: Add off_peak_window_options configuration block (#30965)
  • resource/aws_opensearch_outbound_connection: Add connection_properties, connection_mode and accept_connection arguments (#32990)
  • resource/aws_schemas_schema: Add JSONSchemaDraft4 schema type support (#33442)
  • resource/aws_wafv2_rule_group: Add rate_based_statement.custom_key configuration block (#33594)
  • resource/aws_wafv2_web_acl: Add rate_based_statement.custom_key configuration block (#33594)

BUG FIXES:

  • resource/aws_batch_job_queue: Correctly validates elements of compute_environments as ARNs (#33577)
  • resource/aws_cloudfront_continuous_deployment_policy: Fix IllegalUpdate errors when updating a staging aws_cloudfront_distribution that is part of continuous deployment (#33578)
  • resource/aws_cloudfront_distribution: Fix IllegalUpdate errors when updating a staging distribution associated with an aws_cloudfront_continuous_deployment_policy (#33578)
  • resource/aws_cloudfront_distribution: Fix PreconditionFailed errors when destroying a distribution associated with an aws_cloudfront_continuous_deployment_policy (#33578)
  • resource/aws_cloudfront_distribution: Fix StagingDistributionInUse errors when destroying a distribution associated with an aws_cloudfront_continuous_deployment_policy (#33578)
  • resource/aws_datasync_location_fsx_ontap_file_system: Correct handling of protocol.smb.domain, protocol.smb.user and protocol.smb.password (#33641)
  • resource/aws_glacier_vault_lock: Fail validation if duplicated keys are found in policy (#33570)
  • resource/aws_iam_group_policy: Fail validation if duplicated keys are found in policy (#33570)
  • resource/aws_iam_policy: Fail validation if duplicated keys are found in policy (#33570)
  • resource/aws_iam_role: Fail validation if duplicated keys are found in assume_role_policy (#33570)
  • resource/aws_iam_role_policy: Fail validation if duplicated keys are found in policy (#33570)
  • resource/aws_iam_user_policy: Fail validation if duplicated keys are found in policy (#33570)
  • resource/aws_mediastore_container_policy: Fail validation if duplicated keys are found in policy (#33570)
  • resource/aws_s3_bucket_policy: Fix intermittent couldn't find resource errors on resource Create (#33537)
  • resource/aws_ssoadmin_permission_set_inline_policy: Fail validation if duplicated keys are found in inline_policy (#33570)
  • resource/aws_transfer_access: Fail validation if duplicated keys are found in policy (#33570)
  • resource/aws_transfer_user: Fail validation if duplicated keys are found in policy (#33570)