6.58.0 (Unreleased)
BREAKING CHANGES:
- resource/aws_db_instance:
character_set_name can no longer be set with replicate_source_db, restore_to_point_in_time, s3_import, or snapshot_identifier (#README.md)
NOTES:
- resource/aws_dms_s3_endpoint: The
kms_key_arn attribute has been deprecated. Use server_side_encryption_kms_key_id instead (#README.md)
FEATURES:
- New Action:
aws_sfn_start_execution (#README.md)
- New Data Source:
aws_s3control_access_points (#README.md)
- New Ephemeral Resource:
aws_sts_web_identity_token (#README.md)
- New Function:
arn_parse (#README.md)
- New Guide:
Tag Policy Compliance (#README.md)
- New List Resource:
aws_db_subnet_group (#README.md)
- New List Resource:
aws_prometheus_anomaly_detector (#49139)
- New Resource:
aws_bedrockagentcore_api_key_credential_provider (#README.md)
- New Resource:
aws_prometheus_anomaly_detector (#49139)
ENHANCEMENTS:
- resource/aws_dx_connection: Add
state attribute (#42150)
- resource/aws_ssm_resource_data_sync: Add
s3_destination.destination_data_sharing argument (#README.md)
BUG FIXES:
- resource/aws_bedrockagentcore_memory_strategy: Fix
Value Conversion Error ... Received null value, however the target type cannot handle null values errors (#49188)
- resource/aws_bedrockagentcore_memory_strategy: Replace resource rather than erroring when
configuration.consolidation, configuration.extraction, or configuration.reflection blocks are removed (#49188)
- resource/aws_glue_catalog_table: Fix
Invalid address to set errors when reading partition_keys.parameters (#README.md)
- resource/aws_glue_catalog_table: Fix
InvalidInputException: StorageDescriptor is not allowed error when creating or updating ATHENA-dialect views (#49156)
- resource/aws_glue_catalog_table: Fix
InvalidInputException error when creating or updating SPARK-dialect views without an explicit storage_descriptor block (#49156)
- resource/aws_glue_catalog_table: Fix perpetual diff on
view_definition.representations fields (validation_connection, view_original_text, view_expanded_text) that AWS Glue does not echo back for validated ATHENA views (#49156)
- resource/aws_ssm_parameter: Correctly imports when passing ARN value. (#49134)
- resource/aws_ssm_parameter: Prevents errors when importing specific version. (#49134)
6.57.1 (July 29, 2026)
NOTES:
- resource/aws_bedrockagentcore_memory_strategy: The
memory_execution_role_arn attribute has been deprecated. Use the memory_execution_role_arn attribute on the aws_bedrockagentcore_memory resource instead (#49140)
- resource/aws_bedrockagentcore_memory_strategy: The
namespaces attribute has been deprecated. All configurations using namespaces should be updated to use the namespace_templates attribute instead (#49140)
FEATURES:
- New Data Source:
aws_eks_access_policies (#49090)
- New List Resource:
aws_bedrock_evaluation_job (#49044)
- New List Resource:
aws_eks_access_entry (#49090)
- New List Resource:
aws_eks_access_policy_association (#49121)
- New List Resource:
aws_eks_node_group (#49073)
- New List Resource:
aws_flow_log (#49086)
- New List Resource:
aws_mailmanager_traffic_policy (#49043)
- New List Resource:
aws_osis_pipeline (#49157)
- New List Resource:
aws_osis_pipeline_endpoint (#44383)
- New List Resource:
aws_osis_resource_policy (#44383)
- New List Resource:
aws_rekognition_collection (#49135)
- New Resource:
aws_bedrock_evaluation_job (#49044)
- New Resource:
aws_cloudwatch_log_storage_tier_policy (#49076)
- New Resource:
aws_mailmanager_traffic_policy (#49043)
- New Resource:
aws_osis_pipeline_endpoint (#44383)
- New Resource:
aws_osis_resource_policy (#44383)
ENHANCEMENTS:
- data-source/aws_launch_template: Add
ena_queue_count attribute to network_interfaces configuration block (#48892)
- data-source/aws_secretsmanager_secret: Add
type attribute (#46414)
- data-source/aws_secretsmanager_secret_rotation: Add
external_secret_rotation_metadata and external_secret_rotation_role_arn attributes (#46414)
- data-source/aws_vpc: Adds support for
ipv6_cidr_block_associations. (#46918)
- data-source/aws_vpc: Deprecates
ipv6_association_id and ipv6_cidr_block. (#46918)
- resource/aws_autoscaling_group: Add
reservations-then-balanced valid value for availability_zone_distribution.capacity_distribution_strategy (#48934)
- resource/aws_bedrockagentcore_memory: Add
timeouts.update with a default value of 30m (#49140)
- resource/aws_bedrockagentcore_memory_strategy: Add
configuration.reflection configuration block for EPISODIC_OVERRIDE strategy type (#49140)
- resource/aws_bedrockagentcore_memory_strategy: Add
namespace_templates argument (#49140)
- resource/aws_bedrockagentcore_memory_strategy: Add
reflection_configuration configuration block for EPISODIC strategy type (#49140)
- resource/aws_bedrockagentcore_memory_strategy: Increase default
timeouts values to 45m (#49140)
- resource/aws_codepipeline: Add
stage.action.commands and stage.action.output_artifacts_for_compute_action arguments to support Compute action types (#42507)
- resource/aws_codepipeline:
stage.action.output_artifacts_for_compute_action and stage.action.output_artifacts now conflict (#42507)
- resource/aws_eks_pod_identity_association: Add
policy argument to support inline session policies (#48869)
- resource/aws_fis_experiment_template: Support
MultiRegionClusters as a value for action.target.key (#48781)
- resource/aws_flow_log: Add resource identity support (#49086)
- resource/aws_launch_template: Add
ena_queue_count argument to network_interfaces configuration block (#48892)
- resource/aws_rekognition_collection: Add Resource Identity support (#49022)
- resource/aws_rekognition_project: Add Resource Identity support (#49022)
- resource/aws_rekognition_stream_processor: Add Resource Identity support (#49022)
- resource/aws_secretsmanager_secret: Add
type argument in support of managed external secrets (#46414)
- resource/aws_secretsmanager_secret_rotation: Add
external_secret_rotation_metadata and external_secret_rotation_role_arn arguments in support of managed external secrets (#46414)
BUG FIXES:
- provider: Fixes api error UnknownError: UnknownError introduced in release 6.57.0 (#49175)
- resource/aws_dynamodb_table: No longer replace resource when decreasing
warm_throughput values (#49032)
6.57.0 (July 29, 2026)
Important
Release v6.57.0 had a significant bug and has been removed from GitHub and the Terraform Registry. However, if you successfully used v6.57.0 and then downgraded to v6.56.0, your state may refer to features that are not available in the downgraded version. This will cause errors. In that scenario, it is important to upgrade to v6.57.1.
6.56.0 (July 22, 2026)
FEATURES:
- New Action:
aws_elasticache_apply_service_update (#48963)
- New Data Source:
aws_elasticache_service_update_actions (#48958)
- New Data Source:
aws_s3_buckets (#48965)
- New List Resource:
aws_eks_addon (#49067)
- New List Resource:
aws_s3_bucket_notification (#48974)
- New List Resource:
aws_secretsmanager_secret_policy (#49058)
ENHANCEMENTS:
- data-source/aws_eks_node_group: Add
warm_pool_config attribute (#48977)
- data-source/aws_msk_bootstrap_brokers: Add
bootstrap_brokers_ipv6, bootstrap_brokers_sasl_iam_ipv6, bootstrap_brokers_sasl_scram_ipv6, and bootstrap_brokers_tls_ipv6 attributes to expose IPv6 bootstrap broker URLs (#48975)
- data-source/aws_opensearchserverless_security_config: Add
iam_federation_options block (#48495)
- data-source/aws_opensearchserverless_security_config: Add
iam_identity_center_options block (#48495)
- provider: Web identity tokens can be configured via the
TF_AWS_WEB_IDENTITY_TOKEN environment variable. Any value configured via assume_role_with_web_identity.web_identity_token takes precedence (#48736)
- resource/aws_autoscaling_group: Add
instance_lifecycle_policy configuration block (#48973)
- resource/aws_bedrockagent_data_source: Add
data_source_configuration.managed_knowledge_base_connector_configuration block (#48904)
- resource/aws_bedrockagent_data_source: Add
timeouts.update with a default value of 30m (#48904)
- resource/aws_bedrockagent_knowledge_base: Add
vector_knowledge_base_configuration.bedrock_embedding_model_configuration.audio and vector_knowledge_base_configuration.bedrock_embedding_model_configuration.video configuration blocks (#48538)
- resource/aws_bedrockagent_knowledge_base: Add support for Managed Knowledge Base type (
type = "MANAGED") with managed_knowledge_base_configuration block (#48904)
- resource/aws_cloudwatch_log_subscription_filter: Add
@source.log as a valid value for emit_system_fields (#48956)
- resource/aws_eks_node_group: Add
warm_pool_config configuration block (#48977)
- resource/aws_flow_log: Add
tag_field_specification configuration block (#48913)
- resource/aws_guardduty_detector_feature: Support
AI_PROTECTION and AI_ANALYST feature names (#48972)
- resource/aws_guardduty_organization_configuration_feature: Support
AI_PROTECTION and AI_ANALYST feature names (#48972)
- resource/aws_msk_cluster: Add
bootstrap_brokers_ipv6, bootstrap_brokers_sasl_iam_ipv6, bootstrap_brokers_sasl_scram_ipv6, and bootstrap_brokers_tls_ipv6 attributes to expose IPv6 bootstrap broker URLs (#48975)
- resource/aws_opensearch_package_association: Add import support (#46690)
- resource/aws_opensearchserverless_security_config: Add
iam_federation_options configuration block (#48495)
- resource/aws_opensearchserverless_security_config: Add
iam_identity_center_options configuration block (#48495)
- resource/aws_s3tables_table: Add
metadata.iceberg.properties argument (#48635)
BUG FIXES:
- provider: Fix "one of
assume_role_with_web_identity.0.web_identity_token,assume_role_with_web_identity.0.web_identity_token_file must be specified" errors, allowing any AWS_WEB_IDENTITY_TOKEN_FILE environment variable value to be used (#48736)
- resource/aws_bedrockagent_data_source: Short-circuit waiting for creation if the resource reaches a
FAILED state (#48904)
- resource/aws_datazone_domain: Fixed
AccessDeniedException error when deleting (#48516)
- resource/aws_fsx_lustre_file_system: Fix perpetual diff in
data_read_cache_configuration.size when sizing_mode is PROPORTIONAL_TO_THROUGHPUT_CAPACITY and size is not specified (#49023)
- resource/aws_mq_broker: Fix perpetual
shared_resources diffs for ActiveMQ brokers (#48962)
- resource/aws_mq_configuration: Retry
ConflictException: Configuration ID [...] is in use errors on delete (#48962)
- resource/aws_sagemaker_endpoint: Prevents
Cannot create already existing endpoint error when retrying creation. (#48966)
- resource/aws_subnet: Wait for IPAM to release its CIDR on delete (#46523)
- resource/aws_vpc_ipam_pool: Fix "Error: reading EC2 VPC" when creating an IPAM VPC resource planning pool for a VPC in another account. (#46483)
6.55.0 (July 15, 2026)
FEATURES:
- New Data Source:
aws_elasticache_service_updates (#44608)
- New List Resource:
aws_autoscaling_group (#48928)
- New List Resource:
aws_cloudwatch_log_stream (#48878)
- New List Resource:
aws_kinesis_firehose_delivery_stream (#48946)
- New List Resource:
aws_network_interface (#48887)
- New List Resource:
aws_rds_cluster (#48948)
- New List Resource:
aws_sfn_state_machine (#48840)
ENHANCEMENTS:
- resource/aws_bedrock_guardrail: Add
updated_at attribute (#48881)
- resource/aws_bedrockagentcore_agent_runtime: Add
allowed_workload_configuration, private_endpoint, and private_endpoint_overrides configuration blocks to authorizer_configuration.custom_jwt_authorizer, and the read-only require_service_s3_endpoint attribute to network_configuration.network_mode_config (#48654)
- resource/aws_bedrockagentcore_gateway: Add
allowed_workload_configuration, private_endpoint, and private_endpoint_overrides configuration blocks to authorizer_configuration.custom_jwt_authorizer (#48654)
- resource/aws_bedrockagentcore_harness: Add
allowed_workload_configuration, private_endpoint, and private_endpoint_overrides configuration blocks to authorizer_configuration.custom_jwt_authorizer (#48654)
- resource/aws_bedrockagentcore_harness: Add
require_service_s3_endpoint argument to network_configuration.network_mode_config (#48654)
- resource/aws_bedrockagentcore_registry: Add
allowed_workload_configuration, private_endpoint, and private_endpoint_overrides configuration blocks to authorizer_configuration.custom_jwt_authorizer (#48654)
- resource/aws_msk_replicator: Add
consumer_group_offset_sync_mode attribute to consumer_group_replication block (#47670)
- resource/aws_network_interface: Add resource identity support (#48887)
- resource/aws_rds_cluster: Add resource identity support (#48948)
BUG FIXES:
- resource/aws_bedrockagentcore_harness: Fix
Unsupported Type errors when no memory is configured (#48654)
- resource/aws_config_organization_managed_rule: Fix
interface conversion: interface {} is nil, not *configservice.DescribeOrganizationConfigRuleStatusesOutput panics on delete (#48845)
6.54.0 (July 8, 2026)
NOTES:
- resource/aws_sagemaker_endpoint_configuration: Because we cannot easily test the behavior of
capacity_reservation_config, it is best effort and we ask for community help in testing (#45926)
- resource/aws_ssoadmin_region: Because we cannot easily test this functionality, it is best effort and we ask for community help in testing (#48126)
FEATURES:
- New Data Source:
aws_route53profiles_profile (#48780)
- New List Resource:
aws_bedrockagentcore_browser_profile (#46862)
- New List Resource:
aws_codepipeline (#48808)
- New List Resource:
aws_lambda_function_scaling_config (#48229)
- New List Resource:
aws_scheduler_schedule (#48828)
- New List Resource:
aws_ssoadmin_region (#48126)
- New List Resource:
aws_workspaces_pool (#42678)
- New Resource:
aws_bedrockagentcore_browser_profile (#46862)
- New Resource:
aws_lambda_function_scaling_config (#48229)
- New Resource:
aws_ssoadmin_region (#48126)
- New Resource:
aws_workspaces_pool (#42678)
ENHANCEMENTS:
- action/aws_codebuild_start_build: Add
host_kernel_override argument (#48777)
- data-source/aws_mq_broker: Add
resource_share_arns and shared_resources attributes (#48729)
- resource/aws_cloudfront_key_value_store: Add
tags and tags_all attributes (#48458)
- resource/aws_cloudwatch_event_api_destination: Add Resource Identity support (#48819)
- resource/aws_cloudwatch_event_archive: Add Resource Identity support (#48819)
- resource/aws_cloudwatch_event_bus: Add Resource Identity support (#48819)
- resource/aws_cloudwatch_event_bus_policy: Add Resource Identity support (#48819)
- resource/aws_cloudwatch_event_connection: Add Resource Identity support (#48819)
- resource/aws_cloudwatch_event_endpoint: Add Resource Identity support (#48819)
- resource/aws_cloudwatch_event_permission: Add Resource Identity support (#48819)
- resource/aws_codebuild_project: Add
host_kernel argument to the environment configuration block (#48777)
- resource/aws_codepipeline: Add resource identity support (#48808)
- resource/aws_iam_policy_attachment: Add resource identity support (#48639)
- resource/aws_lambda_event_source_mapping: Add
use_resource_timeout_for_propagation argument (#46405)
- resource/aws_lambda_event_source_mapping: Add configurable resource timeouts. Defaults to
10m for create and update, 5m for delete. (#46405)
- resource/aws_lambda_function: Add
use_resource_timeout_for_propagation argument (#46405)
- resource/aws_lambda_permission: Add configurable resource timeouts. Defaults to
5m for create, read, and delete. (#46405)
- resource/aws_lambda_permission: Hard-coded timeouts to account for eventual consistency have been replaced with configurable resource timeouts (#46405)
- resource/aws_mq_broker: Add
resource_share_arns argument and shared_resources attribute (#48729)
- resource/aws_prometheus_workspace_configuration: Add
out_of_order_time_window_in_seconds and rule_query_offset_in_seconds arguments (#48659)
- resource/aws_rds_cluster: Add support for
auto_minor_version_upgrade argument (#42472)
- resource/aws_sagemaker_endpoint_configuration: Add Resource Identity support (#45926)
- resource/aws_sagemaker_endpoint_configuration: Add
production_variants.capacity_reservation_config and shadow_production_variants.capacity_reservation_config configuration blocks (#45926)
- resource/aws_scheduler_schedule: Add resource identity support (#48828)
BUG FIXES:
- resource/aws_bedrock_guardrail: Prevents "inconsistent result" error when adding
content_policy_config block. (#48772)
- resource/aws_bedrock_guardrail: Prevents "inconsistent result" error when adding
topic_policy_config block. (#48772)
- resource/aws_bedrock_guardrail: Prevents "inconsistent result" error with multiple
content_policy_config.filters_config.input_modalities values. (#48772)
- resource/aws_bedrock_guardrail: Prevents "inconsistent result" error with multiple
content_policy_config.filters_config.output_modalities values. (#48772)
- resource/aws_cloudfront_multitenant_distribution: Correctly handles default tags. (#48783)
- resource/aws_cloudfront_multitenant_distribution: Correctly taints resource if Create fails. (#48782)
- resource/aws_cloudfront_multitenant_distribution: Sets
etag on Import. (#48782)
- resource/aws_cloudfront_multitenant_distribution: Updates
etag when only tags updated. (#48782)
- resource/aws_cloudfront_multitenant_distribution: Waits for deployment on Update. (#48782)
- resource/aws_directory_service_directory: Fix
UnsupportedOperationException error when reading enable_directory_data_access in regions where Directory Service Data is not available (e.g. GovCloud) (#47660)
6.53.0 (July 1, 2026)
BREAKING CHANGES:
- resource/aws_pinpointsmsvoicev2_phone_number: Remove provider-side defaults for
opt_out_list_name and two_way_channel_enabled in favor of AWS server-side defaults (Default and false respectively). Configurations that omit these attributes will now show (known after apply) on first plan instead of the previous static value; the post-apply state is unchanged. This change mitigates persistent drift when the phone number is managed by an aws_pinpointsmsvoicev2_pool. (#48414)
NOTES:
- list-resource/aws_bedrockagentcore_registry: This resource is deprecated. AWS Agent Registry is currently available in public preview. On August 6, 2026 this functionality will move from the
bedrock-agentcore namespace to the agent-registry namespace. The aws_bedrockagentcore_browser resource will continue to work until September 17, 2026 (#48693)
- resource/aws_bedrockagentcore_registry: This resource is deprecated. AWS Agent Registry is currently available in public preview. On August 6, 2026 this functionality will move from the
bedrock-agentcore namespace to the agent-registry namespace. The aws_bedrockagentcore_browser resource will continue to work until September 17, 2026 (#48693)
- resource/aws_ecs_capacity_provider: When a change forces replacement of a capacity provider that is associated with a cluster via
aws_ecs_cluster_capacity_providers, add a replace_triggered_by lifecycle rule to the association so the old capacity provider is detached before it is deleted (#48156)
FEATURES:
- New Data Source:
aws_bedrock_foundation_model_agreement_offers (#47665)
- New Data Source:
aws_bedrock_use_case_for_model_access (#47665)
- New Data Source:
aws_ec2_capacity_block_reservation (#48185)
- New List Resource:
aws_pinpointsmsvoicev2_pool (#48414)
- New Resource:
aws_bedrock_foundation_model_agreement (#47665)
- New Resource:
aws_bedrock_use_case_for_model_access (#47665)
- New Resource:
aws_pinpointsmsvoicev2_pool (#48414)
ENHANCEMENTS:
- data-source/aws_api_gateway_rest_api: Add
security_policy and endpoint_access_mode attributes (#47973)
- data-source/aws_msk_cluster: Add
customer_action_status attribute (#48536)
- resource/aws_api_gateway_rest_api: Add
security_policy and endpoint_access_mode arguments (#47973)
- resource/aws_bedrockagentcore_browser: Add
browser_signing, certificate, and enterprise_policy configuration blocks (#47816)
- resource/aws_bedrockagentcore_code_interpreter: Add
certificate argument (#47817)
- resource/aws_cloudwatch_composite_alarm: Add Resource Identity support (#48679)
- resource/aws_cloudwatch_contributor_insight_rule: Add Resource Identity support (#48679)
- resource/aws_cloudwatch_contributor_insight_rule: Add plan-time validation of
rule_definition (#48679)
- resource/aws_cloudwatch_contributor_insight_rule: Change
rule_state to Optional and Computed (#48679)
- resource/aws_cloudwatch_contributor_managed_insight_rule: Add Resource Identity support (#48679)
- resource/aws_cloudwatch_contributor_managed_insight_rule: Add plan-time validation of
resource_arn and template_name (#48679)
- resource/aws_cloudwatch_dashboard: Add Resource Identity support (#48679)
- resource/aws_cloudwatch_metric_stream: Add Resource Identity support (#48679)
- resource/aws_default_vpc: Add resource identity support (#47590)
- resource/aws_msk_cluster: Add
customer_action_status attribute (#48536)
- resource/aws_pinpointsmsvoicev2_phone_number: Add
force_disassociate argument (#48414)
- resource/aws_securityhub_automation_rule: Deprecates
id in favor of arn (#48636)
- resource/aws_ssmcontacts_rotation: Deprecates
id in favor of arn (#48636)
- resource/aws_ssoadmin_trusted_token_issuer: Deprecates
id in favor of arn (#48636)
BUG FIXES:
- data-source/aws_codeartifact_authorization_token: Mark
authorization_token as sensitive (#48577)
- resource/aws_cloudwatch_contributor_managed_insight_rule: Mark
resource_arn, tags and template_name as ForceNew (#48679)
- resource/aws_default_vpc: Fix provider panic (nil pointer dereference) when importing via an
import block or terraform import (#47590)
- resource/aws_ecs_capacity_provider: Return the underlying error immediately instead of timing out after 20 minutes when deleting a capacity provider that is still associated with a cluster (#48156)
- resource/aws_iam_user: Handle
InvalidAction errors in partitions where access key cleanup operations are not supported (#48473)
- resource/aws_instance: Fix perpetual diff when
instance_market_options.market_type is set to capacity-block (#48701)
- resource/aws_lightsail_bucket_access_key: Mark
secret_access_key as sensitive (#48577)
- resource/aws_lightsail_key_pair: Mark
private_key as sensitive (#48577)
- resource/aws_route53_record: Fix the
type attribute to no longer force resource replacement on change (#47105)
- resource/aws_sqs_queue: Reduce the wait time for queue deletion. This fixes a regression introduced in v6.34.0. (#48722)