Skip to content

chore(deps): update terraform providers - #502

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/terraform-providers
Open

chore(deps): update terraform providers#502
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/terraform-providers

Conversation

@renovate

@renovate renovate Bot commented Apr 20, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
aws (source) required_provider minor 6.39.06.62.0
cloudflare (source) required_provider minor 5.18.05.24.0
helm (source) required_provider minor 3.1.13.2.0
http (source) required_provider minor 3.5.03.6.1
kubernetes (source) required_provider minor 3.0.13.2.1
oci (source) required_provider minor 8.8.08.29.0
random (source) required_provider minor 3.8.13.9.0
tls (source) required_provider minor 4.1.04.3.0
unifi (source) required_provider minor 1.0.01.1.0
vault (source) required_provider minor 5.10.15.11.0

Release Notes

hashicorp/terraform-provider-aws (aws)

v6.62.0

Compare Source

NOTES:

  • resource/aws_db_instance: When manage_master_user_password is enabled, the managed secret's automatic rotation can now be disabled using aws_secretsmanager_secret_rotation with rotation_enabled = false (#​49659)
  • resource/aws_rds_cluster: When manage_master_user_password is enabled, the managed secret's automatic rotation can now be disabled using aws_secretsmanager_secret_rotation with rotation_enabled = false (#​49659)
  • resource/aws_savingsplans_savings_plan: Because we cannot easily test this functionality, it is best effort and we ask for community help in testing (#​49264)

FEATURES:

  • New List Resource: aws_db_instance (#​49602)
  • New List Resource: aws_dsql_cluster (#​49657)
  • New List Resource: aws_dsql_cluster_policy (#​49676)
  • New List Resource: aws_ecr_lifecycle_policy (#​49696)
  • New List Resource: aws_ecs_cluster (#​49682)
  • New List Resource: aws_pinpointsmsvoicev2_keyword (#​48967)
  • New Resource: aws_pinpointsmsvoicev2_keyword (#​48967)
  • New Resource: aws_sesv2_multi_region_endpoint (#​49660)

ENHANCEMENTS:

  • data-source/aws_resiliencehubv2_service: Add associated_system.user_journey_ids attribute (#​49603)
  • resource/aws_bedrockagentcore_browser: Add plan-time validation of name (#​48766)
  • resource/aws_bedrockagentcore_memory: Add Resource Identity support (#​48766)
  • resource/aws_bedrockagentcore_memory: Allow adding indexed_key entries in place instead of forcing a new resource (#​48877)
  • resource/aws_bedrockagentcore_memory: Change indexed_key from List to Set to ignore ordering (#​48877)
  • resource/aws_bedrockagentcore_memory_strategy: Add Resource Identity support (#​48766)
  • resource/aws_bedrockagentcore_memory_strategy: Add configuration.self_managed_configuration argument in support of self-managed strategies (#​48766)
  • resource/aws_bedrockagentcore_memory_strategy: Add memory_record_schema argument (#​48765)
  • resource/aws_bedrockagentcore_memory_strategy: Add plan-time validation of description (#​48766)
  • resource/aws_bedrockagentcore_memory_strategy: Change description to Optional and Computed (#​48766)
  • resource/aws_cloudfront_function: Validate name, code, and comment against CloudFront's documented constraints during plan instead of failing at apply time (#​49395)
  • resource/aws_db_instance: Add resource identity support (#​49602)
  • resource/aws_dsql_cluster: Add resource identity support (#​49657)
  • resource/aws_dx_private_virtual_interface: Add bgp_asn_long argument (#​49587)
  • resource/aws_dx_transit_virtual_interface: Add bgp_asn_long argument (#​49588)
  • resource/aws_ecs_cluster: Add resource identity support (#​49682)
  • resource/aws_elasticache_replication_group: Add auth_token_wo and auth_token_wo_version write-only arguments (#​49268)
  • resource/aws_observabilityadmin_centralization_rule_for_organization: Add tag_propagation_configuration configuration block to rule.destination.destination_logs_configuration, and tag_propagation_status and tag_propagation_failure_reason attributes (#​49656)
  • resource/aws_resiliencehubv2_service: Add user_journey_ids argument to the associated_system configuration block (#​49603)
  • resource/aws_secretsmanager_secret_rotation: rotation_enabled is now configurable (previously read-only) and can be set to false to disable rotation for a secret. This is particularly useful for secrets whose rotation is otherwise managed by AWS, such as an RDS master user password secret created with manage_master_user_password (#​49659)
  • resource/aws_secretsmanager_secret_rotation: rotation_rules is now optional, and must be omitted when rotation_enabled is false (#​49659)
  • resource/aws_workspaces_directory: Add workspace_access_properties.access_endpoint_config argument (#​49668)

BUG FIXES:

  • resource/aws_bedrockagentcore_harness: Correct plan-time validation of name (#​48766)
  • resource/aws_bedrockagentcore_memory_strategy: Force resource replacement when name is modified (#​48766)
  • resource/aws_bedrockagentcore_registry: Correct plan-time validation of name (#​48766)
  • resource/aws_cloudwatch_log_resource_policy: Fixes error when importing by identity when using resource-scope (#​49614)
  • resource/aws_elasticache_cluster: Add plan-time validation to reject transit_encryption_enabled for Redis and Valkey engines, which are only supported on aws_elasticache_replication_group (#​49114)
  • resource/aws_resiliencehubv2_input_source: Change resource_configuration.resource_tag from List to Set to ignore ordering (#​49585)
  • resource/aws_s3_account_public_access_block: Fixes eventual consistency issue on creation (#​49687)
  • resource/aws_savingsplan_savings_plan: Because we cannot easily test this functionality, it is best effort and we ask for community help in testing (#​49678)
  • resource/aws_savingsplan_savings_plan: Because we cannot easily test this functionality, it is best effort and we ask for community help in testing (#​49679)
  • resource/aws_savingsplan_savings_plan: Mark purchase_time as Optional and Computed (#​49679)
  • resource/aws_savingsplan_savings_plan: Treat queued as a target state during creation (#​49678)
  • resource/aws_savingsplans_savings_plan: Mark upfront_payment_amount as Computed to fix a Provider produced inconsistent result after apply error for No Upfront savings plans (#​49264)

v6.61.0

Compare Source

FEATURES:

  • New Data Source: aws_odb_iam_role_association (#​46794)
  • New List Resource: aws_ec2_ami_launch_permission (#​49461)
  • New List Resource: aws_iam_instance_profile (#​49576)
  • New List Resource: aws_lambdacore_network_connector (#​49387)
  • New List Resource: aws_mailmanager_relay (#​49394)
  • New List Resource: aws_resiliencehubv2_assertion (#​48329)
  • New List Resource: aws_resiliencehubv2_service_function (#​48328)
  • New List Resource: aws_resiliencehubv2_user_journey (#​48330)
  • New Resource: aws_dsql_cluster_policy (#​47748)
  • New Resource: aws_lambdacore_network_connector (#​49387)
  • New Resource: aws_lambdamicrovms_image (#​48950)
  • New Resource: aws_mailmanager_relay (#​49394)
  • New Resource: aws_odb_iam_role_association (#​46794)
  • New Resource: aws_resiliencehubv2_assertion (#​48329)
  • New Resource: aws_resiliencehubv2_service_function (#​48328)
  • New Resource: aws_resiliencehubv2_user_journey (#​48330)
  • New Resource: aws_securityhub_feature_v2 (#​49503)

ENHANCEMENTS:

  • data-source/aws_fsx_ontap_file_system: Add network_type attribute (#​49512)
  • data-source/aws_fsx_windows_file_system: Add network_type attribute (#​49514)
  • data-source/aws_lb_listener_rule: Add condition.source_ip.ip_address_type attribute (#​49476)
  • data-source/aws_resiliencehubv2_service: Add associated_system attribute (#​49498)
  • data-source/aws_vpclattice_service: Add idle_timeout_seconds attribute (#​49540)
  • resource/aws_bedrockagentcore_harness: Adds attribute environment_actual (#​48815)
  • resource/aws_ec2_ami_launch_permission: Add resource identity support (#​49461)
  • resource/aws_fsx_ontap_file_system: Add network_type argument (#​49512)
  • resource/aws_fsx_openzfs_file_system: Add network_type argument (#​49513)
  • resource/aws_fsx_windows_file_system: Add network_type argument (#​49514)
  • resource/aws_lb_listener_rule: Add condition.source_ip.ip_address_type argument (#​49476)
  • resource/aws_lb_listener_rule: Change condition.source_ip.values to Optional (#​49476)
  • resource/aws_medialive_channel: Add resource identity (#​49532)
  • resource/aws_medialive_input: Add resource identity support (#​49534)
  • resource/aws_medialive_input_security_group: Add resource identity support (#​49537)
  • resource/aws_medialive_multiplex: Add resource identity support (#​49557)
  • resource/aws_medialive_multiplex_program: Add resource identity (#​49561)
  • resource/aws_observabilityadmin_centralization_rule_for_organization: Add encryption_scope argument to the logs_encryption_configuration configuration block (#​49563)
  • resource/aws_pinpointsmsvoicev2_phone_number: Add status attribute (#​49485)
  • resource/aws_pinpointsmsvoicev2_phone_number: Add wait_for_active argument to allow create and update to return without waiting for the phone number to reach ACTIVE status. Number types gated on carrier or registration approval (for example TEN_DLC, TOLL_FREE, or any number submitted with registration_id) can remain PENDING for days to weeks, which previously caused terraform apply to time out (#​49485)
  • resource/aws_resiliencehubv2_service: Add associated_system configuration block (#​49498)
  • resource/aws_vpclattice_service: Add idle_timeout_seconds argument (#​49540)

BUG FIXES:

  • list-resource/aws_bedrockagentcore_harness: Prevents error when remote resource disappears during List (#​49446)
  • list-resource/aws_bedrockagentcore_online_evaluation_config: Prevents error when remote resource disappears during List (#​49479)
  • list-resource/aws_bedrockagentcore_policy_engine: Prevents error when remote resource disappears during List (#​49478)
  • list-resource/aws_bedrockagentcore_registry: Prevents error when remote resource disappears during List (#​49480)
  • list-resource/aws_bedrockagentcore_resource_policy: Prevents error when remote resource disappears during List (#​49481)
  • resource/aws_bedrockagentcore_harness: Fix Provider produced inconsistent result after apply error for environment (#​48815)
  • resource/aws_bedrockagentcore_online_evaluation_config: Retries additional IAM propagation errors on creation (#​49479)
  • resource/aws_mailmanager_ingress_point: Include FAILED as a pending state while an ingress point is deleting (#​49502)
  • resource/aws_nat_gateway: Allow updating secondary_private_ip_address_count in-place for private NAT gateways (#​47477)
  • resource/aws_observabilityadmin_telemetry_enrichment: Prevent couldn't find resource (21 retries) errors on delete if enrichment has never been started in the Region (#​49502)
  • resource/aws_observabilityadmin_telemetry_evaluation: Include NOT_STARTED as a target state while the resource is deleting (#​49502)

v6.60.0

Compare Source

FEATURES:

  • New List Resource: aws_db_parameter_group (#​49418)
  • New List Resource: aws_resiliencehubv2_input_source (#​48327)
  • New Resource: aws_resiliencehubv2_input_source (#​48327)

ENHANCEMENTS:

  • resource/aws_db_parameter_group: Add Resource Identity support (#​49418)

BUG FIXES:

  • resource/aws_bedrockagentcore_gateway_target: Prevent state inconsistencies caused by the service-managed policy session header (#​49447)
  • resource/aws_network_acl_rule: Fix Missing Resource Identity After Read errors. This fixes a regression introduced in v6.59.0 (#​49470)

v6.59.0

Compare Source

FEATURES:

  • New Data Source: aws_rds_snapshots (#​49259)
  • New Data Source: aws_resiliencehubv2_policy (#​48324)
  • New Data Source: aws_resiliencehubv2_service (#​48326)
  • New Data Source: aws_resiliencehubv2_system (#​48325)
  • New Data Source: aws_vpclattice_service_network_service_associations (#​42680)
  • New List Resource: aws_backup_plan (#​49329)
  • New List Resource: aws_backup_selection (#​49283)
  • New List Resource: aws_backup_vault (#​49423)
  • New List Resource: aws_bedrockagentcore_gateway_rule (#​48804)
  • New List Resource: aws_mailmanager_ingress_point (#​49322)
  • New List Resource: aws_neptunegraph_private_graph_endpoint (#​45929)
  • New List Resource: aws_networkfirewall_container_association (#​49321)
  • New List Resource: aws_pinpointsmsvoicev2_resource_policy (#​48771)
  • New List Resource: aws_pinpointsmsvoicev2_sender_id (#​46472)
  • New List Resource: aws_resiliencehubv2_service (#​48323)
  • New List Resource: aws_resiliencehubv2_system (#​48322)
  • New List Resource: aws_ssm_patch_baseline (#​49332)
  • New Resource: aws_bedrockagentcore_gateway_rule (#​48804)
  • New Resource: aws_mailmanager_ingress_point (#​49322)
  • New Resource: aws_neptunegraph_private_graph_endpoint (#​45929)
  • New Resource: aws_networkfirewall_container_association (#​49321)
  • New Resource: aws_pinpointsmsvoicev2_resource_policy (#​48771)
  • New Resource: aws_pinpointsmsvoicev2_sender_id (#​46472)
  • New Resource: aws_resiliencehubv2_service (#​48323)
  • New Resource: aws_resiliencehubv2_system (#​48322)

ENHANCEMENTS:

  • data-source/aws_eks_cluster: Add kube_api_server_config, kube_controller_manager_config, and kube_scheduler_config attributes (#​49420)
  • data-source/aws_eks_cluster_versions: Add control_plane_component_config and control_plane_scaling_tiers attributes (#​49421)
  • resource/aws_arcregionswitch_plan: Add step.aurora_provisioned_scaling_config, step.aurora_serverless_scaling_config, step.neptune_global_database_config, and step.lambda_event_source_mapping_config arguments (#​48392)
  • resource/aws_arcregionswitch_plan: Add provider-side validation restricting report_configuration and report_configuration.report_output.s3_configuration to a single block each (#​46758)
  • resource/aws_backup_plan: Add resource identity support (#​49329)
  • resource/aws_backup_selection: Add resource identity support (#​49283)
  • resource/aws_backup_vault: Add resource identity support (#​49423)
  • resource/aws_bedrockagentcore_gateway_target: Add target_configuration.mcp.mcp_server.mcp_tool_schema configuration block and target_configuration.mcp.mcp_server.resource_priority argument (#​48703)
  • resource/aws_bedrockagentcore_harness: Adds computed attribute memory_actual (#​49383)
  • resource/aws_bedrockagentcore_harness: Adds support for memory.disabled (#​49334)
  • resource/aws_bedrockagentcore_harness: Adds support for memory.managed_memory_configuration (#​49285)
  • resource/aws_dlm_lifecycle_policy: Add policy_details.parameters.exclude_data_volume_tags argument (#​45113)
  • resource/aws_ec2_client_vpn_route: Add transit_gateway_attachment_id attribute (#​49274)
  • resource/aws_ec2_client_vpn_route: Change target_vpc_subnet_id to Optional (#​49274)
  • resource/aws_ec2_client_vpn_route: Increase default timeouts values to 30m (#​49274)
  • resource/aws_eks_cluster: Add kube_api_server_config, kube_controller_manager_config, and kube_scheduler_config arguments (#​49412)
  • resource/aws_prometheus_scraper: Add exporter configuration block with OpenSearch exporter support (#​49346)
  • resource/aws_wafv2_rule_group: Add pre_parse_text_transformation argument to byte_match_statement, regex_match_statement, regex_pattern_set_reference_statement, size_constraint_statement, sqli_match_statement, and xss_match_statement rule statements (#​49381)
  • resource/aws_wafv2_web_acl: Add pre_parse_text_transformation argument to byte_match_statement, regex_match_statement, regex_pattern_set_reference_statement, size_constraint_statement, sqli_match_statement, and xss_match_statement rule statements (#​49381)

BUG FIXES:

  • data-source/aws_lakeformation_permissions: Fix failure to read cross-account IAM principals (#​49398)
  • data-source/aws_mq_broker: Fix reading MQ Broker (...) shared resources errors when reading RabbitMQ brokers in partitions where mq:DescribeSharedResources is unavailable, such as AWS GovCloud (US) (#​49340)
  • resource/aws_bedrockagentcore_gateway_target: Remove client-side count validation for metadata_configuration request and response headers (#​49374)
  • resource/aws_bedrockagentcore_gateway_target: Treat OAuth CREATE_PENDING_AUTH and UPDATE_PENDING_AUTH statuses as successful terminal states (#​48703)
  • resource/aws_lakeformation_permissions: Fix failure to read cross-account IAM principals (#​49398)
  • resource/aws_mq_broker: Fix reading MQ Broker (...) shared resources errors when reading RabbitMQ brokers in partitions where mq:DescribeSharedResources is unavailable, such as AWS GovCloud (US) (#​49340)
  • resource/aws_rds_cluster: Fix InvalidParameterCombination error when engine_version is updated externally (#​49396)
  • resource/aws_route53domains_registered_domain: Fix UpdateDomainContactPrivacy being incorrectly triggered when billing_contact changes (#​49314)
  • resource/aws_ssm_parameter: Fixes error where name with a leading slash and no other slashes was stripping the leading slash. (#​49339)

v6.58.0

Compare Source

FEATURES:

  • New List Resource: aws_mailmanager_rule_set (#​49257)
  • New List Resource: aws_prometheus_anomaly_detector (#​49139)
  • New List Resource: aws_prometheus_scraper (#​47466)
  • New List Resource: aws_prometheus_scraper_logging_configuration (#​47466)
  • New List Resource: aws_resiliencehubv2_policy (#​48321)
  • New Resource: aws_mailmanager_rule_set (#​49257)
  • New Resource: aws_prometheus_anomaly_detector (#​49139)
  • New Resource: aws_prometheus_scraper_logging_configuration (#​47466)
  • New Resource: aws_resiliencehubv2_policy (#​48321)

ENHANCEMENTS:

  • resource/aws_api_gateway_rest_api: Add configurable resource timeouts. (#​49205)
  • resource/aws_dx_connection: Add state attribute (#​42150)
  • resource/aws_ecs_capacity_provider: Add RESERVED as a valid value for managed_instances_provider.instance_launch_template.capacity_option_type (#​48816)
  • resource/aws_ecs_capacity_provider: Add local_storage_configuration attribute to managed_instances_provider.instance_launch_template (#​47513)
  • resource/aws_ecs_capacity_provider: Add managed_instances_provider.instance_launch_template.capacity_reservations argument (#​48816)
  • resource/aws_glue_catalog_table_optimizer: Add configuration.compaction_configuration argument (#​43868)
  • resource/aws_prometheus_scraper: Add Resource Identity support (#​47466)
  • resource/aws_prometheus_scraper: Add destination.cloudwatch configuration block for CloudWatch Metrics destination support (#​49088)

BUG FIXES:

  • resource/aws_api_gateway_rest_api: Wait for the REST API to reach an available state on create and update, and to be fully deleted on delete, preventing intermittent BadRequestException: There is already an update in progress errors (#​49205)
  • resource/aws_appstream_stack: Fix embed_host_domains not being sent to the AWS API on update, which caused a permanent plan diff when the argument was added or changed on an existing stack (#​49015)
  • resource/aws_bedrockagent_data_source: Fix validator incorrectly requiring bedrock_data_automation_configuration when parsing_strategy = "BEDROCK_DATA_AUTOMATION", a regression introduced in v6.56.0 (#​49111)
  • resource/aws_bedrockagentcore_agent_runtime: Allow : (colon) in the match_value_string and match_value_string_list attributes of authorizer_configuration.custom_jwt_authorizer.custom_claim.authorizing_claim_match_value.claim_match_value (#​48437)
  • resource/aws_bedrockagentcore_memory_strategy: Fix Value Conversion Error ... Received null value, however the target type cannot handle null values errors (#​49188)
  • resource/aws_bedrockagentcore_memory_strategy: Fix too many results: wanted 1, got 2 error when creating or updating a strategy on a memory that already has another strategy of a different type (#​49250)
  • resource/aws_bedrockagentcore_memory_strategy: Replace resource rather than erroring when configuration.consolidation, configuration.extraction, or configuration.reflection blocks are removed (#​49188)
  • resource/aws_ecs_service: Fix sigint_rollback falsely rolling back healthy deployments during wait_for_steady_state (#​49077)
  • resource/aws_ecs_service: Prevent non-EBS deployment volume configurations from being written to state (#​48947)
  • resource/aws_elasticache_replication_group: Fix perpetual diff when changes are pending for the next maintenance window (apply_immediately = false) (#​48246)
  • resource/aws_glue_catalog_table: Fix InvalidInputException: StorageDescriptor is not allowed error when creating or updating ATHENA-dialect views (#​49156)
  • resource/aws_glue_catalog_table: Fix InvalidInputException error when creating or updating SPARK-dialect views without an explicit storage_descriptor block (#​49156)
  • resource/aws_glue_catalog_table: Fix perpetual diff on view_definition.representations fields (validation_connection, view_original_text, view_expanded_text) that AWS Glue does not echo back for validated ATHENA views (#​49156)
  • resource/aws_iam_user: Retry destroying users when there are conflicts, and ignore non-errors during destroy (#​49260)
  • resource/aws_route53recoverycontrolconfig_safety_rule: Fix crash when the create operation returns an error (#​49155)
  • resource/aws_ssm_parameter: Correctly imports when passing ARN value. (#​49134)
  • resource/aws_ssm_parameter: Prevents errors when importing specific version. (#​49134)

v6.57.1

Compare Source

NOTES:

  • resource/aws_bedrockagentcore_memory_strategy: The memory_execution_role_arn attribute has been deprecated. This attribute should be removed from configurations (#​49140)
  • resource/aws_bedrockagentcore_memory_strategy: The namespaces attribute has been deprecated. All configurations using namespaces should be updated to use the namespace_templates attribute instead (#​49140)

FEATURES:

  • New Data Source: aws_eks_access_policies (#​49090)
  • New List Resource: aws_bedrock_evaluation_job (#​49044)
  • New List Resource: aws_eks_access_entry (#​49090)
  • New List Resource: aws_eks_access_policy_association (#​49121)
  • New List Resource: aws_eks_node_group (#​49073)
  • New List Resource: aws_flow_log (#​49086)
  • New List Resource: aws_mailmanager_traffic_policy (#​49043)
  • New List Resource: aws_osis_pipeline (#​49157)
  • New List Resource: aws_osis_pipeline_endpoint (#​44383)
  • New List Resource: aws_osis_resource_policy (#​44383)
  • New List Resource: aws_rekognition_collection (#​49135)
  • New Resource: aws_bedrock_evaluation_job (#​49044)
  • New Resource: aws_cloudwatch_log_storage_tier_policy (#​49076)
  • New Resource: aws_mailmanager_traffic_policy (#​49043)
  • New Resource: aws_osis_pipeline_endpoint (#​44383)
  • New Resource: aws_osis_resource_policy (#​44383)

ENHANCEMENTS:

  • data-source/aws_launch_template: Add ena_queue_count attribute to network_interfaces configuration block (#​48892)
  • data-source/aws_secretsmanager_secret: Add type attribute (#​46414)
  • data-source/aws_secretsmanager_secret_rotation: Add external_secret_rotation_metadata and external_secret_rotation_role_arn attributes (#​46414)
  • data-source/aws_vpc: Adds support for ipv6_cidr_block_associations. (#​46918)
  • data-source/aws_vpc: Deprecates ipv6_association_id and ipv6_cidr_block. (#​46918)
  • resource/aws_autoscaling_group: Add reservations-then-balanced valid value for availability_zone_distribution.capacity_distribution_strategy (#​48934)
  • resource/aws_bedrockagentcore_memory: Add timeouts.update with a default value of 30m (#​49140)
  • resource/aws_bedrockagentcore_memory_strategy: Add configuration.reflection configuration block for EPISODIC_OVERRIDE strategy type (#​49140)
  • resource/aws_bedrockagentcore_memory_strategy: Add namespace_templates argument (#​49140)
  • resource/aws_bedrockagentcore_memory_strategy: Add reflection_configuration configuration block for EPISODIC strategy type (#​49140)
  • resource/aws_bedrockagentcore_memory_strategy: Increase default timeouts values to 45m (#​49140)
  • resource/aws_codepipeline: Add stage.action.commands and stage.action.output_artifacts_for_compute_action arguments to support Compute action types (#​42507)
  • resource/aws_codepipeline: stage.action.output_artifacts_for_compute_action and stage.action.output_artifacts now conflict (#​42507)
  • resource/aws_eks_pod_identity_association: Add policy argument to support inline session policies (#​48869)
  • resource/aws_fis_experiment_template: Support MultiRegionClusters as a value for action.target.key (#​48781)
  • resource/aws_flow_log: Add resource identity support (#​49086)
  • resource/aws_launch_template: Add ena_queue_count argument to network_interfaces configuration block (#​48892)
  • resource/aws_rekognition_collection: Add Resource Identity support (#​49022)
  • resource/aws_rekognition_project: Add Resource Identity support (#​49022)
  • resource/aws_rekognition_stream_processor: Add Resource Identity support (#​49022)
  • resource/aws_secretsmanager_secret: Add type argument in support of managed external secrets (#​46414)
  • resource/aws_secretsmanager_secret_rotation: Add external_secret_rotation_metadata and external_secret_rotation_role_arn arguments in support of managed external secrets (#​46414)

BUG FIXES:

  • provider: Fixes api error UnknownError: UnknownError introduced in release 6.57.0 (#​49175)
  • resource/aws_dynamodb_table: No longer replace resource when decreasing warm_throughput values (#​49032)

v6.56.0

Compare Source

FEATURES:

  • New Action: aws_elasticache_apply_service_update (#​48963)
  • New Data Source: aws_elasticache_service_update_actions (#​48958)
  • New Data Source: aws_s3_buckets (#​48965)
  • New List Resource: aws_eks_addon (#​49067)
  • New List Resource: aws_s3_bucket_notification (#​48974)
  • New List Resource: aws_secretsmanager_secret_policy (#​49058)

ENHANCEMENTS:

  • data-source/aws_eks_node_group: Add warm_pool_config attribute (#​48977)
  • data-source/aws_msk_bootstrap_brokers: Add bootstrap_brokers_ipv6, bootstrap_brokers_sasl_iam_ipv6, bootstrap_brokers_sasl_scram_ipv6, and bootstrap_brokers_tls_ipv6 attributes to expose IPv6 bootstrap broker URLs (#​48975)
  • data-source/aws_opensearchserverless_security_config: Add iam_federation_options block (#​48495)
  • data-source/aws_opensearchserverless_security_config: Add iam_identity_center_options block (#​48495)
  • provider: Web identity tokens can be configured via the TF_AWS_WEB_IDENTITY_TOKEN environment variable. Any value configured via assume_role_with_web_identity.web_identity_token takes precedence (#​48736)
  • resource/aws_autoscaling_group: Add instance_lifecycle_policy configuration block (#​48973)
  • resource/aws_bedrockagent_data_source: Add data_source_configuration.managed_knowledge_base_connector_configuration block (#​48904)
  • resource/aws_bedrockagent_data_source: Add timeouts.update with a default value of 30m (#​48904)
  • resource/aws_bedrockagent_knowledge_base: Add vector_knowledge_base_configuration.bedrock_embedding_model_configuration.audio and vector_knowledge_base_configuration.bedrock_embedding_model_configuration.video configuration blocks (#​48538)
  • resource/aws_bedrockagent_knowledge_base: Add support for Managed Knowledge Base type (type = "MANAGED") with managed_knowledge_base_configuration block (#​48904)
  • resource/aws_cloudwatch_log_subscription_filter: Add @source.log as a valid value for emit_system_fields (#​48956)
  • resource/aws_eks_node_group: Add warm_pool_config configuration block (#​48977)
  • resource/aws_flow_log: Add tag_field_specification configuration block (#​48913)
  • resource/aws_guardduty_detector_feature: Support AI_PROTECTION and AI_ANALYST feature names (#​48972)
  • resource/aws_guardduty_organization_configuration_feature: Support AI_PROTECTION and AI_ANALYST feature names (#​48972)
  • resource/aws_msk_cluster: Add bootstrap_brokers_ipv6, bootstrap_brokers_sasl_iam_ipv6, bootstrap_brokers_sasl_scram_ipv6, and bootstrap_brokers_tls_ipv6 attributes to expose IPv6 bootstrap broker URLs (#​48975)
  • resource/aws_opensearch_package_association: Add import support (#​46690)
  • resource/aws_opensearchserverless_security_config: Add iam_federation_options configuration block (#​48495)
  • resource/aws_opensearchserverless_security_config: Add iam_identity_center_options configuration block (#​48495)
  • resource/aws_s3tables_table: Add metadata.iceberg.properties argument (#​48635)

BUG FIXES:

  • provider: Fix "one of assume_role_with_web_identity.0.web_identity_token,assume_role_with_web_identity.0.web_identity_token_file must be specified" errors, allowing any AWS_WEB_IDENTITY_TOKEN_FILE environment variable value to be used (#​48736)
  • resource/aws_bedrockagent_data_source: Short-circuit waiting for creation if the resource reaches a FAILED state (#​48904)
  • resource/aws_datazone_domain: Fixed AccessDeniedException error when deleting (#​48516)
  • resource/aws_fsx_lustre_file_system: Fix perpetual diff in data_read_cache_configuration.size when sizing_mode is PROPORTIONAL_TO_THROUGHPUT_CAPACITY and size is not specified (#​49023)
  • resource/aws_mq_broker: Fix perpetual shared_resources diffs for ActiveMQ brokers (#​48962)
  • resource/aws_mq_configuration: Retry ConflictException: Configuration ID [...] is in use errors on delete (#​48962)
  • resource/aws_sagemaker_endpoint: Prevents Cannot create already existing endpoint error when retrying creation. (#​48966)
  • resource/aws_subnet: Wait for IPAM to release its CIDR on delete (#​46523)
  • resource/aws_vpc_ipam_pool: Fix "Error: reading EC2 VPC" when creating an IPAM VPC resource planning pool for a VPC in another account. (#​46483)

v6.55.0

Compare Source

6.55.0 (July 15, 2026)

FEATURES:

  • New Data Source: aws_elasticache_service_updates (#​44608)
  • New List Resource: aws_autoscaling_group (#​48928)
  • New List Resource: aws_cloudwatch_log_stream (#​48878)
  • New List Resource: aws_kinesis_firehose_delivery_stream (#​48946)
  • New List Resource: aws_network_interface (#​48887)
  • New List Resource: aws_rds_cluster (#​48948)
  • New List Resource: aws_sfn_state_machine ([#​48840](https://redirec

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Apr 20, 2026
@github-actions

github-actions Bot commented Apr 20, 2026

Copy link
Copy Markdown
Contributor

Terraform Plan (00-global)

→ No Resource Changes!


Triggered by @renovate[bot], Commit: 68685b18e778eafcf71998af788838c7381c0c48

@github-actions

github-actions Bot commented Apr 20, 2026

Copy link
Copy Markdown
Contributor

Terraform Plan (cloud-edge)

→ No Resource Changes!


Triggered by @renovate[bot], Commit: 68685b18e778eafcf71998af788838c7381c0c48

@github-actions

github-actions Bot commented Apr 20, 2026

Copy link
Copy Markdown
Contributor

Terraform Plan (03-services)

→ No Resource Changes!


Triggered by @renovate[bot], Commit: 68685b18e778eafcf71998af788838c7381c0c48

@renovate
renovate Bot force-pushed the renovate/terraform-providers branch from bbf8e3f to 0d2cb53 Compare April 23, 2026 01:36
@renovate
renovate Bot force-pushed the renovate/terraform-providers branch from 0d2cb53 to d4b39a1 Compare April 23, 2026 21:46
@github-actions

github-actions Bot commented Apr 23, 2026

Copy link
Copy Markdown
Contributor

Terraform Plan (02-infrastructure)

→ Resource Changes: 1 to create, 0 to update, 0 to re-create, 0 to delete, 0 ephemeral, 0 to import.

✨ Create

local_sensitive_file.ansible_ssh_key
+ content              = (sensitive value)
+ content_base64sha256 = (known after apply)
+ content_base64sha512 = (known after apply)
+ content_md5          = (known after apply)
+ content_sha1         = (known after apply)
+ content_sha256       = (known after apply)
+ content_sha512       = (known after apply)
+ directory_permission = "0700"
+ file_permission      = "0600"
+ filename             = "./.ansible/ssh_key"
+ id                   = (known after apply)

Triggered by @renovate[bot], Commit: e245ccf6350b7be4665d9b8bfe67d84f7f3570b6

@renovate
renovate Bot force-pushed the renovate/terraform-providers branch from d4b39a1 to ed32101 Compare April 23, 2026 21:49
@renovate
renovate Bot force-pushed the renovate/terraform-providers branch from ed32101 to c45d00a Compare April 25, 2026 04:56
@github-actions

github-actions Bot commented Apr 25, 2026

Copy link
Copy Markdown
Contributor

Terraform Plan (01-network)

→ Resource Changes: 2 to create, 6 to update, 0 to re-create, 0 to delete, 0 ephemeral, 0 to import.

✨ Create

unifi_device.tf_cgu
+ allow_adoption    = true
+ disabled          = (known after apply)
+ forget_on_destroy = true
+ id                = (known after apply)
+ mac               = "28:70:4e:3e:fb:15"
+ name              = "Vieta"
+ site              = "default"

+ port_override {
+     name            = "tf-Port1"
+     number          = 1
+     port_profile_id = "694523b42cdb653b685898e8"
      # (2 unchanged attributes hidden)
  }
+ port_override {
+     name            = "tf-Port2"
+     number          = 2
+     port_profile_id = "6945245f2cdb653b685898f1"
      # (2 unchanged attributes hidden)
  }
+ port_override {
+     name            = "tf-Port3"
+     number          = 3
+     port_profile_id = "6945245f2cdb653b685898f1"
      # (2 unchanged attributes hidden)
  }
unifi_user.tf_mesh_router
+ allow_existing         = true
+ fixed_ip               = "10.10.1.90"
+ hostname               = (known after apply)
+ id                     = (known after apply)
+ ip                     = (known after apply)
+ local_dns_record       = "mesh-router.athena"
+ mac                    = "bc:24:11:00:00:90"
+ name                   = "tf-Mesh-Router"
+ network_id             = "694487da2cdb653b68588dbe"
+ note                   = "Managed by Terraform - Tailscale subnet router for clustermesh"
+ site                   = (known after apply)
+ skip_forget_on_destroy = false

♻️ Update

unifi_device.usw_ultra
  id                = "69629e562cdb653b685a2127"
  name              = "USW-Ultra"
  # (5 unchanged attributes hidden)

- port_override {
-     aggregate_num_ports = 0 -> null
-     name                = "tf-Port1" -> null
-     number              = 1 -> null
-     port_profile_id     = "6962b52d2cdb653b685a22e0" -> null
      # (2 unchanged attributes hidden)
  }
- port_override {
-     aggregate_num_ports = 0 -> null
-     name                = "tf-Port2" -> null
-     number              = 2 -> null
-     port_profile_id     = "6962b52d2cdb653b685a22e0" -> null
      # (2 unchanged attributes hidden)
  }
- port_override {
-     aggregate_num_ports = 0 -> null
-     name                = "tf-Port3" -> null
-     number              = 3 -> null
-     port_profile_id     = "6962b52d2cdb653b685a22e0" -> null
      # (2 unchanged attributes hidden)
  }
- port_override {
-     aggregate_num_ports = 0 -> null
-     name                = "tf-Port4" -> null
-     number              = 4 -> null
-     poe_mode            = "off" -> null
      # (2 unchanged attributes hidden)
  }
- port_override {
-     aggregate_num_ports = 0 -> null
-     name                = "tf-Port5" -> null
-     number              = 5 -> null
-     port_profile_id     = "6962b52d2cdb653b685a22e0" -> null
      # (2 unchanged attributes hidden)
  }
+ port_override {
+     name            = "tf-Port1"
+     number          = 1
+     port_profile_id = "6962b52d2cdb653b685a22e0"
      # (2 unchanged attributes hidden)
  }
+ port_override {
+     name            = "tf-Port2"
+     number          = 2
+     port_profile_id = "6962b52d2cdb653b685a22e0"
      # (2 unchanged attributes hidden)
  }
+ port_override {
+     name            = "tf-Port3"
+     number          = 3
+     port_profile_id = "6962b52d2cdb653b685a22e0"
      # (2 unchanged attributes hidden)
  }
+ port_override {
+     name            = "tf-Port4"
+     number          = 4
+     port_profile_id = "6962b52d2cdb653b685a22e0"
      # (2 unchanged attributes hidden)
  }
+ port_override {
+     name            = "tf-Port5"
+     number          = 5
+     port_profile_id = "6962b52d2cdb653b685a22e0"
      # (2 unchanged attributes hidden)
  }
unifi_network.tf_vlan_athena
  id                         = "694487da2cdb653b68588dbe"
! igmp_snooping              = false -> true
  name                       = "tf-Athena"
  # (49 unchanged attributes hidden)
unifi_network.tf_vlan_default
  id                         = "694541612cdb653b68589b05"
! igmp_snooping              = false -> true
  name                       = "tf-Default"
  # (49 unchanged attributes hidden)
unifi_user.tf_talos_worker_1
- dev_id_override        = 4133 -> null
  id                     = "69769463ebb51e7e10272f60"
  name                   = "tf-Talos-Worker-1"
  # (12 unchanged attributes hidden)
unifi_user.tf_talos_worker_2
- dev_id_override        = 4133 -> null
  id                     = "697695feebb51e7e10272fa9"
  name                   = "tf-Talos-Worker-2"
  # (12 unchanged attributes hidden)
unifi_user.tf_talos_worker_3
- dev_id_override        = 4133 -> null
  id                     = "6987b83b312cbf652a03562f"
  name                   = "tf-Talos-Worker-3"
  # (12 unchanged attributes hidden)

Triggered by @renovate[bot], Commit: e245ccf6350b7be4665d9b8bfe67d84f7f3570b6

@renovate
renovate Bot force-pushed the renovate/terraform-providers branch from c45d00a to 9a6068d Compare April 26, 2026 16:41
@renovate
renovate Bot force-pushed the renovate/terraform-providers branch from 9a6068d to 98b0631 Compare April 28, 2026 20:27
@renovate
renovate Bot temporarily deployed to Terraform May 1, 2026 14:37 Inactive
@renovate
renovate Bot temporarily deployed to Terraform May 1, 2026 14:37 Inactive
@renovate
renovate Bot force-pushed the renovate/terraform-providers branch from 51cf5c5 to b7551f6 Compare May 7, 2026 01:24
@renovate
renovate Bot temporarily deployed to Terraform May 7, 2026 01:24 Inactive
@renovate
renovate Bot temporarily deployed to Terraform May 7, 2026 01:24 Inactive
@renovate
renovate Bot temporarily deployed to Terraform May 7, 2026 01:24 Inactive
@renovate
renovate Bot temporarily deployed to Terraform May 7, 2026 01:24 Inactive
@renovate
renovate Bot force-pushed the renovate/terraform-providers branch from b7551f6 to 308b619 Compare May 7, 2026 04:59
@renovate
renovate Bot temporarily deployed to Terraform May 7, 2026 05:00 Inactive
@renovate
renovate Bot temporarily deployed to Terraform May 7, 2026 05:00 Inactive
@renovate
renovate Bot temporarily deployed to Terraform May 7, 2026 05:00 Inactive
@renovate
renovate Bot temporarily deployed to Terraform May 7, 2026 05:00 Inactive
@renovate
renovate Bot force-pushed the renovate/terraform-providers branch from 308b619 to 127727a Compare May 13, 2026 12:36
@renovate
renovate Bot force-pushed the renovate/terraform-providers branch from 127727a to 4671091 Compare May 13, 2026 21:42
@renovate
renovate Bot force-pushed the renovate/terraform-providers branch from 4671091 to 9d76fc2 Compare May 14, 2026 20:29
@renovate
renovate Bot force-pushed the renovate/terraform-providers branch from 9d76fc2 to ab2aaae Compare May 15, 2026 12:14
@github-actions

github-actions Bot commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Terraform Plan (tailscale)

→ No Resource Changes!


Triggered by @renovate[bot], Commit: 68685b18e778eafcf71998af788838c7381c0c48

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants