Terraform Provider AWS
Mon
Wed
Fri
AugSepOctNovDecJanFebMarAprMayJunJul
LessMore
Releases16Avg5/moVersionsv6.43.0 to v6.57.1
Last Checked
3mo ago
Latest
v6.57.1
BREAKING CHANGES:
character_set_name can no longer be set with replicate_source_db, restore_to_point_in_time, s3_import, or snapshot_identifier (#README.md)NOTES:
kms_key_arn attribute has been deprecated. Use server_side_encryption_kms_key_id instead (#README.md)FEATURES:
aws_sfn_start_execution (#README.md)aws_s3control_access_points (#README.md)aws_sts_web_identity_token (#README.md)arn_parse (#README.md)Tag Policy Compliance (#README.md)aws_db_subnet_group (#README.md)aws_prometheus_anomaly_detector (#49139)aws_bedrockagentcore_api_key_credential_provider (#README.md)aws_prometheus_anomaly_detector (#49139)ENHANCEMENTS:
state attribute (#42150)s3_destination.destination_data_sharing argument (#README.md)BUG FIXES:
Value Conversion Error ... Received null value, however the target type cannot handle null values errors (#49188)configuration.consolidation, configuration.extraction, or configuration.reflection blocks are removed (#49188)Invalid address to set errors when reading partition_keys.parameters (#README.md)InvalidInputException: StorageDescriptor is not allowed error when creating or updating ATHENA-dialect views (#49156)InvalidInputException error when creating or updating SPARK-dialect views without an explicit storage_descriptor block (#49156)view_definition.representations fields (validation_connection, view_original_text, view_expanded_text) that AWS Glue does not echo back for validated ATHENA views (#49156)NOTES:
memory_execution_role_arn attribute has been deprecated. Use the memory_execution_role_arn attribute on the aws_bedrockagentcore_memory resource instead (#49140)namespaces attribute has been deprecated. All configurations using namespaces should be updated to use the namespace_templates attribute instead (#49140)FEATURES:
aws_eks_access_policies (#49090)aws_bedrock_evaluation_job (#49044)aws_eks_access_entry (#49090)aws_eks_access_policy_association (#49121)aws_eks_node_group (#49073)aws_flow_log (#49086)aws_mailmanager_traffic_policy (#49043)aws_osis_pipeline (#49157)aws_osis_pipeline_endpoint (#44383)aws_osis_resource_policy (#44383)aws_rekognition_collection (#49135)aws_bedrock_evaluation_job (#49044)aws_cloudwatch_log_storage_tier_policy (#49076)aws_mailmanager_traffic_policy (#49043)aws_osis_pipeline_endpoint (#44383)aws_osis_resource_policy (#44383)ENHANCEMENTS:
ena_queue_count attribute to network_interfaces configuration block (#48892)type attribute (#46414)external_secret_rotation_metadata and external_secret_rotation_role_arn attributes (#46414)ipv6_cidr_block_associations. (#46918)ipv6_association_id and ipv6_cidr_block. (#46918)reservations-then-balanced valid value for availability_zone_distribution.capacity_distribution_strategy (#48934)timeouts.update with a default value of 30m (#49140)configuration.reflection configuration block for EPISODIC_OVERRIDE strategy type (#49140)namespace_templates argument (#49140)reflection_configuration configuration block for EPISODIC strategy type (#49140)timeouts values to 45m (#49140)stage.action.commands and stage.action.output_artifacts_for_compute_action arguments to support Compute action types (#42507)stage.action.output_artifacts_for_compute_action and stage.action.output_artifacts now conflict (#42507)policy argument to support inline session policies (#48869)MultiRegionClusters as a value for action.target.key (#48781)ena_queue_count argument to network_interfaces configuration block (#48892)type argument in support of managed external secrets (#46414)external_secret_rotation_metadata and external_secret_rotation_role_arn arguments in support of managed external secrets (#46414)BUG FIXES:
warm_throughput values (#49032)Important
Release v6.57.0 had a significant bug and has been removed from GitHub and the Terraform Registry. However, if you successfully used v6.57.0 and then downgraded to v6.56.0, your state may refer to features that are not available in the downgraded version. This will cause errors. In that scenario, it is important to upgrade to v6.57.1.
FEATURES:
aws_elasticache_apply_service_update (#48963)aws_elasticache_service_update_actions (#48958)aws_s3_buckets (#48965)aws_eks_addon (#49067)aws_s3_bucket_notification (#48974)aws_secretsmanager_secret_policy (#49058)ENHANCEMENTS:
warm_pool_config attribute (#48977)bootstrap_brokers_ipv6, bootstrap_brokers_sasl_iam_ipv6, bootstrap_brokers_sasl_scram_ipv6, and bootstrap_brokers_tls_ipv6 attributes to expose IPv6 bootstrap broker URLs (#48975)iam_federation_options block (#48495)iam_identity_center_options block (#48495)TF_AWS_WEB_IDENTITY_TOKEN environment variable. Any value configured via assume_role_with_web_identity.web_identity_token takes precedence (#48736)instance_lifecycle_policy configuration block (#48973)data_source_configuration.managed_knowledge_base_connector_configuration block (#48904)timeouts.update with a default value of 30m (#48904)vector_knowledge_base_configuration.bedrock_embedding_model_configuration.audio and vector_knowledge_base_configuration.bedrock_embedding_model_configuration.video configuration blocks (#48538)type = "MANAGED") with managed_knowledge_base_configuration block (#48904)@source.log as a valid value for emit_system_fields (#48956)warm_pool_config configuration block (#48977)tag_field_specification configuration block (#48913)AI_PROTECTION and AI_ANALYST feature names (#48972)AI_PROTECTION and AI_ANALYST feature names (#48972)bootstrap_brokers_ipv6, bootstrap_brokers_sasl_iam_ipv6, bootstrap_brokers_sasl_scram_ipv6, and bootstrap_brokers_tls_ipv6 attributes to expose IPv6 bootstrap broker URLs (#48975)iam_federation_options configuration block (#48495)iam_identity_center_options configuration block (#48495)metadata.iceberg.properties argument (#48635)BUG FIXES:
assume_role_with_web_identity.0.web_identity_token,assume_role_with_web_identity.0.web_identity_token_file must be specified" errors, allowing any AWS_WEB_IDENTITY_TOKEN_FILE environment variable value to be used (#48736)FAILED state (#48904)AccessDeniedException error when deleting (#48516)data_read_cache_configuration.size when sizing_mode is PROPORTIONAL_TO_THROUGHPUT_CAPACITY and size is not specified (#49023)shared_resources diffs for ActiveMQ brokers (#48962)ConflictException: Configuration ID [...] is in use errors on delete (#48962)Cannot create already existing endpoint error when retrying creation. (#48966)FEATURES:
aws_elasticache_service_updates (#44608)aws_autoscaling_group (#48928)aws_cloudwatch_log_stream (#48878)aws_kinesis_firehose_delivery_stream (#48946)aws_network_interface (#48887)aws_rds_cluster (#48948)aws_sfn_state_machine (#48840)ENHANCEMENTS:
updated_at attribute (#48881)allowed_workload_configuration, private_endpoint, and private_endpoint_overrides configuration blocks to authorizer_configuration.custom_jwt_authorizer, and the read-only require_service_s3_endpoint attribute to network_configuration.network_mode_config (#48654)allowed_workload_configuration, private_endpoint, and private_endpoint_overrides configuration blocks to authorizer_configuration.custom_jwt_authorizer (#48654)allowed_workload_configuration, private_endpoint, and private_endpoint_overrides configuration blocks to authorizer_configuration.custom_jwt_authorizer (#48654)require_service_s3_endpoint argument to network_configuration.network_mode_config (#48654)allowed_workload_configuration, private_endpoint, and private_endpoint_overrides configuration blocks to authorizer_configuration.custom_jwt_authorizer (#48654)consumer_group_offset_sync_mode attribute to consumer_group_replication block (#47670)BUG FIXES:
Unsupported Type errors when no memory is configured (#48654)interface conversion: interface {} is nil, not *configservice.DescribeOrganizationConfigRuleStatusesOutput panics on delete (#48845)NOTES:
capacity_reservation_config, it is best effort and we ask for community help in testing (#45926)FEATURES:
aws_route53profiles_profile (#48780)aws_bedrockagentcore_browser_profile (#46862)aws_codepipeline (#48808)aws_lambda_function_scaling_config (#48229)aws_scheduler_schedule (#48828)aws_ssoadmin_region (#48126)aws_workspaces_pool (#42678)aws_bedrockagentcore_browser_profile (#46862)aws_lambda_function_scaling_config (#48229)aws_ssoadmin_region (#48126)aws_workspaces_pool (#42678)ENHANCEMENTS:
host_kernel_override argument (#48777)resource_share_arns and shared_resources attributes (#48729)tags and tags_all attributes (#48458)host_kernel argument to the environment configuration block (#48777)use_resource_timeout_for_propagation argument (#46405)10m for create and update, 5m for delete. (#46405)use_resource_timeout_for_propagation argument (#46405)5m for create, read, and delete. (#46405)resource_share_arns argument and shared_resources attribute (#48729)out_of_order_time_window_in_seconds and rule_query_offset_in_seconds arguments (#48659)auto_minor_version_upgrade argument (#42472)production_variants.capacity_reservation_config and shadow_production_variants.capacity_reservation_config configuration blocks (#45926)BUG FIXES:
content_policy_config block. (#48772)topic_policy_config block. (#48772)content_policy_config.filters_config.input_modalities values. (#48772)content_policy_config.filters_config.output_modalities values. (#48772)etag on Import. (#48782)etag when only tags updated. (#48782)UnsupportedOperationException error when reading enable_directory_data_access in regions where Directory Service Data is not available (e.g. GovCloud) (#47660)BREAKING CHANGES:
opt_out_list_name and two_way_channel_enabled in favor of AWS server-side defaults (Default and false respectively). Configurations that omit these attributes will now show (known after apply) on first plan instead of the previous static value; the post-apply state is unchanged. This change mitigates persistent drift when the phone number is managed by an aws_pinpointsmsvoicev2_pool. (#48414)NOTES:
bedrock-agentcore namespace to the agent-registry namespace. The aws_bedrockagentcore_browser resource will continue to work until September 17, 2026 (#48693)bedrock-agentcore namespace to the agent-registry namespace. The aws_bedrockagentcore_browser resource will continue to work until September 17, 2026 (#48693)aws_ecs_cluster_capacity_providers, add a replace_triggered_by lifecycle rule to the association so the old capacity provider is detached before it is deleted (#48156)FEATURES:
aws_bedrock_foundation_model_agreement_offers (#47665)aws_bedrock_use_case_for_model_access (#47665)aws_ec2_capacity_block_reservation (#48185)aws_pinpointsmsvoicev2_pool (#48414)aws_bedrock_foundation_model_agreement (#47665)aws_bedrock_use_case_for_model_access (#47665)aws_pinpointsmsvoicev2_pool (#48414)ENHANCEMENTS:
security_policy and endpoint_access_mode attributes (#47973)customer_action_status attribute (#48536)security_policy and endpoint_access_mode arguments (#47973)browser_signing, certificate, and enterprise_policy configuration blocks (#47816)certificate argument (#47817)rule_definition (#48679)rule_state to Optional and Computed (#48679)resource_arn and template_name (#48679)customer_action_status attribute (#48536)force_disassociate argument (#48414)id in favor of arn (#48636)id in favor of arn (#48636)id in favor of arn (#48636)BUG FIXES:
authorization_token as sensitive (#48577)resource_arn, tags and template_name as ForceNew (#48679)import block or terraform import (#47590)InvalidAction errors in partitions where access key cleanup operations are not supported (#48473)instance_market_options.market_type is set to capacity-block (#48701)secret_access_key as sensitive (#48577)private_key as sensitive (#48577)type attribute to no longer force resource replacement on change (#47105)