NOTES:
FEATURES:
aws_cloudfront_connection_group (#44885)aws_cloudfront_distribution_tenant (#45088)aws_kms_alias (#45700)aws_sqs_queue (#45691)aws_cloudfront_connection_function (#45664)aws_cloudfront_connection_group (#44885)aws_cloudfront_distribution_tenant (#45088)aws_cloudfront_multitenant_distribution (#45535)aws_dynamodb_global_secondary_index (#44999)aws_ecr_pull_time_update_exclusion (#45765)aws_organizations_tag (#45730)aws_redshift_idc_application (#37345)aws_secretsmanager_tag (#45825)aws_sesv2_tenant (#45706)ENHANCEMENTS:
endpoint_access_mode attribute (#45741)endpoint_network_type and target_connection_network_type attributes (#45634)tags attribute (#45766)rule.action.target_storage_class and rule.selection.storage_class arguments, and new valid values for rule.action.type and rule.selection.count_type arguments (#45752)saml_provider_uuid attribute (#45707)response_streaming_invoke_arn attribute (#45652)code_signing_config_arn in AWS GovCloud (US) Regions (#45652)dns_threat_protection, confidence_threshold, firewall_threat_protection_id, firewall_domain_redirection_action, and q_type attributes (#45711)target_ips attribute (#45492)dns_options.private_dns_preference and dns_options.private_dns_specified_domains attributes (#45679)service_region and vpc_endpoint_type from attributes to arguments for filtering (#45679)elasticloadbalancing:loadbalancer tag type (#45671)elasticloadbalancing:listener tag type (#45671)elasticloadbalancing:listener-rule tag type (#45671)elasticloadbalancing:targetgroup tag type (#45671)endpoint_access_mode argument and configurable timeout for create and update (#45741)customer_content_encryption_configuration argument (#45744)enable_minimum_encryption_configuration argument (#45744)monitoring_configuration argument (#45744)connection_function_association and viewer_mtls_config arguments (#45847)owner_account_id argument to vpc_origin_config for cross-account VPC origin support (#45011)apply_on_transformed_logs argument (#45826)emit_system_fields argument (#45760)endpoint_network_type and target_connection_network_type arguments (#45634)rds:db tag type (#45671)rds:global-cluster tag type (#45671)tags argument and tags_all attribute. This functionality requires the directconnect:TagResource and directconnect:UntagResource IAM permissions (#45766)CREATE_ON_PUSH as a valid value for applied_for (#45720)managed_instances_provider.instance_launch_template.capacity_option_type argument (#45667)fsx:file-system tag type (#45671)fsx:file-system tag type (#45671)fsx:file-system tag type (#45671)fsx:snapshot tag type (#45671)fsx:volume tag type (#45671)fsx:file-system tag type (#45671)finding_criteria.criterion.matches and finding_criteria.criterion.not_matches arguments (#45758)delay_after_policy_creation_in_ms argument. This functionality requires the iam:SetDefaultPolicyVersion IAM permission (#42054)saml_provider_uuid attribute (#45707)serial_number attribute (#45751)logging_configuration argument (#45749)logging_configuration argument (#45749)resource_group_arn (#45688)rules_package_arns and target_arn (#45688)provisioned_poller_config.poller_group_name argument (#45313)kafka://topic-name) for destination_config.on_failure.destination_arn argument (#45802)response_streaming_invoke_arn attribute (#45652)code_signing_config_arn in AWS GovCloud (US) Regions (#45652)lambda:InvokeFunction permission, with the InvokedViaFunctionUrl flag set to true, to the function on creation when authorization_type is NONE (#44858)invoked_via_function_url argument (#44858)quic_server_id argument (#45666)target_group_arn (#45666)rds:cluster tag type (#45671)rds:db tag type (#45671)rds:global-cluster tag type (#45671)routing_policy_label argument. This functionality requires the networkmanager: PutAttachmentRoutingPolicyLabel and networkmanager: RemoveAttachmentRoutingPolicyLabel IAM permissions (#45728)pipeline_role_arn argument to support specifying a IAM role at the pipeline level (#45806)rds:cluster tag type (#45671)consumer_region (#45688)dns_threat_protection, confidence_threshold, and firewall_threat_protection_id arguments to support DNS Firewall Advanced rules (#45711)endpoint_details.vpc configuration block to support VPC hosted Transfer Family web app (#45745)dns_options.private_dns_preference and dns_options.private_dns_specified_domains arguments (#45679)private_dns_enabled argument (#45673)tunnel*_inside_cidr and tunnel*_inside_ipv6_cidr arguments (#45781)BUG FIXES:
proxy_endpoint when registry_id is specified (#45754)account-id, not account, as a valid value for attachment_policies.conditions.type. This fixes a regression introduced in v6.27.0 (#45788)service_region attribute (#45679)user_agent values where the product name contains a forward slash (#45715)node_properties has NodeRangeProperties.ecsProperties set (#45676)PutSubscriptionFilter: Retry ValidationException: Make sure you have given CloudWatch Logs permission to assume the provided role (#43762)reading EC2 VPC (...) default Security Group: empty result and reading EC2 VPC (...) main Route Table: empty result errors when importing RAM-shared VPCs. This fixes a regression introduced in v6.17.0 (#45780)private_dns_enabled argument is now marked as ForceNew (#45679)Fetched April 8, 2026