BREAKING CHANGES:
most_recent is true and owner and image ID filter criteria has been increased to an error. Existing configurations which were previously receiving a warning diagnostic will now fail to apply. To prevent this error, set the owner argument or include a filter block with an image-id or owner-id name/value pair. To continue using unsafe filter values with most_recent set to true, set the new allow_unsafe_filter argument to true. This is not recommended. (#42114)inference_accelerator attribute. Amazon Elastic Inference reached end of life on April, 2024. (#42137)inference_accelerator_overrides attribute. Amazon Elastic Inference reached end of life on April, 2024. (#42137)action.authenticate_cognito, action.authenticate_oidc, action.fixed_response, action.forward, action.forward.stickiness, action.redirect, condition.host_header, condition.http_header, condition.http_request_method, condition.path_pattern, condition.query_string, and condition.source_ip attributes are now list nested blocks instead of single nested blocks (#42283)filter has been removed (#42325)elastic_inference_accelerator attribute. Amazon Elastic Inference reached end of life on April, 2024. (#42137)elastic_gpu_specifications has been removed (#42312)kibana_endpoint has been removed (#42268)saml_options is now a list nested block instead of a single nested block (#42270)tags_all attribute (#42136)aws_opsworks_application resource has been removed (#41948)aws_opsworks_custom_layer resource has been removed (#41948)aws_opsworks_ecs_cluster_layer resource has been removed (#41948)aws_opsworks_ganglia_layer resource has been removed (#41948)aws_opsworks_haproxy_layer resource has been removed (#41948)aws_opsworks_instance resource has been removed (#41948)aws_opsworks_java_app_layer resource has been removed (#41948)aws_opsworks_memcached_layer resource has been removed (#41948)aws_opsworks_mysql_layer resource has been removed (#41948)aws_opsworks_nodejs_app_layer resource has been removed (#41948)aws_opsworks_permission resource has been removed (#41948)aws_opsworks_php_app_layer resource has been removed (#41948)aws_opsworks_rails_app_layer resource has been removed (#41948)aws_opsworks_rds_db_instance resource has been removed (#41948)aws_opsworks_stack resource has been removed (#41948)aws_opsworks_static_web_layer resource has been removed (#41948)aws_opsworks_user_profile resource has been removed (#41948)aws_simpledb_domain resource has been removed. Add a constraint to v5 of the Terraform AWS Provider for continued use of this resource (#41775)aws_worklink_fleet resource has been removed (#42059)aws_worklink_website_certificate_authority_association resource has been removed (#42059)aws_redshift_service_account resource has been removed. AWS recommends that a service principal name should be used instead of an AWS account ID in any relevant IAM policy (#41941)endpoints.opsworks configuration argument has been removed (#41948)endpoints.simpledb and endpoints.sdb configuration arguments have been removed (#41775)endpoints.worklink configuration argument has been removed (#42059)filter.exists now only accepts one of "" (empty string), true, or false (#42434)preserve_client_ip now only accepts one of "" (empty string), true, or false (#42434)reset_on_delete argument has been removed (#42226)canary_settings, execution_arn, invoke_url, stage_description, and stage_name arguments. Instead, use the aws_api_gateway_stage resource to manage stages. (#42249)compute_environment_name to name
resource/aws_batch_compute_environment: Rename compute_environment_name_prefix to name_prefix (#38050)compute_environment_name to name (#38050)compute_environments in place of compute_environment_order (#40751)logging_config, logging_config.cloudwatch_config, logging_config.cloudwatch_config.large_data_delivery_s3_config, and logging_config.s3_config are now list nested blocks instead of single nested blocks (#42307)id is now set to remote object's Id instead of name (#42230)etag argument is now computed only (#38448)suspend now only accepts one of "" (empty string), true, or false (#42434)id attribute is now a comma-delimited string concatenating the user_pool_id, group_name, and username arguments (#34082)character_set_name now cannot be set with replicate_source_db, restore_to_point_in_time, s3_import, or snapshot_identifier. (#42348)s3_settings attribute. Use aws_dms_s3_endpoint instead (#42379)vpn_gateway_id has been removed (#42323)terminate_instances_on_delete now only accepts one of "" (empty string), true, or false (#42434)block_duration_minutes attribute (#42060)inference_accelerator attribute. Amazon Elastic Inference reached end of life on April, 2024. (#42137)vpc has been removed. Use domain instead. (#42340)resolve_conflicts has been removed. Use resolve_conflicts_on_create and resolve_conflicts_on_update instead. (#42318)auto_minor_version_upgrade now only accepts one of "" (empty string), true, or false (#42434)at_rest_encryption_enabled and auto_minor_version_upgrade now only accept one of "" (empty string), true, or false (#42434)auth_token_update_strategy no longer has a default value. If auth_token is set, auth_token_update_strategy must also be explicitly configured. (#42336)variations.value.bool_value now only accepts one of "" (empty string), true, or false (#42434)log_group_name has been removed. Use log_destination instead. (#42333)id attribute is now computed only (#42097)datasources. Use aws_guardduty_detector_feature resources instead. (#42436)auto_enable attribute has been removed (#42251)filter has been removed (#42325)instance_configuration.block_device_mapping.ebs.delete_on_termination and instance_configuration.block_device_mapping.ebs.encrypted now only accept one of "" (empty string), true, or false (#42434)block_device_mapping.ebs.delete_on_termination and block_device_mapping.ebs.encrypted now only accept one of "" (empty string), true, or false (#42434)cpu_core_count and cpu_threads_per_core. Instead, use cpu_options. (#42280)user_data now displays cleartext instead of a hash. Base64 encoded content should use user_data_base64 instead. (#42078)block_device_mappings.ebs.delete_on_termination, block_device_mappings.ebs.encrypted, ebs_optimized, network_interfaces.associate_carrier_ip_address, network_interfaces.associate_public_ip_address, network_interfaces.delete_on_termination, and network_interfaces.primary_ipv6 now only accept one of "" (empty string), true, or false (#42434)elastic_inference_accelerator attribute. Amazon Elastic Inference reached end of life on April, 2024. (#42137)elastic_gpu_specifications has been removed (#42312)mutual_authentication attributes advertise_trust_store_ca_names, ignore_client_certificate_expiry, and trust_store_arn are only valid if mode is verify (#42326)preserve_client_ip now only accepts one of "" (empty string), true, or false (#42434)logs.audit now only accepts one of "" (empty string), true, or false (#42434)base_policy_region argument has been removed. Use base_policy_regions instead. (#38398)kibana_endpoint has been removed (#42268)saml_options is now a list nested block instead of a single nested block (#42270)key_attributes and key_attributes.key_modes_of_use are now list nested blocks instead of single nested blocks. (#42264)tags_all has been removed (#42260)cluster_public_key, cluster_revision_number, and endpoint are now read only and should not be set (#42119)logging attribute has been removed (#42013)publicly_accessible attribute now defaults to false (#41978)snapshot_copy attribute has been removed (#41995)regions_of_interest.bounding_box is now a list nested block instead of a single nested block (#41380)policy, policy.az, policy.hardware, policy.software, and policy.region are now list nested blocks instead of single nested blocks (#42297)accelerator_types from your configuration—it no longer exists. Instead, use instance_type to use Inferentia. (#42099)instance_id argument (#42224)definition is now a list nested block instead of a single nested block (#42305)rule.statement.managed_rule_group_statement.managed_rule_group_configs.aws_managed_rules_bot_control_rule_set.enable_machine_learning now defaults to false (#39858)NOTES:
name attribute has been deprecated. All configurations using name should be updated to use the region attribute instead (#42131)bucket_region attribute. Use of the bucket_region attribute instead of the region attribute is encouraged (#42014)region attribute has been deprecated. All configurations using region should be updated to use the aws_region attribute instead (#42131)region attribute has been deprecated. All configurations using region should be updated to use the regions attribute instead (#42014)region attribute has been deprecated. All configurations using region should be updated to use the service_region attribute instead (#42014)region attribute has been deprecated. All configurations using region should be updated to use the requester_region attribute instead (#42014)s3_us_east_1_regional_endpoint argument. The ability to use the global S3 endpoint will be removed in v7.0.0. (#42375)region attribute has been deprecated. All configurations using region should be updated to use the stack_set_instance_region attribute instead (#42014)id in favor of arn (#42232)region attribute has been deprecated. All configurations using region should be updated to use the authorized_aws_region attribute instead (#42014)region attribute has been deprecated. All configurations using region should be updated to use the connection_region attribute instead (#42014)engine value is deprecated (#42419)engine value is deprecated (#42419)engine value is deprecated (#42419)datasources now returns a deprecation warning (#42251)aws_kinesisanalyticsv2_application resource instead (#42102)bucket_region attribute. Use of the bucket_region attribute instead of the region attribute is encouraged (#42014)health_check_custom_config.failure_threshold is deprecated. The argument is no longer supported by AWS and is always set to 1 (#40777)region attribute has been deprecated. All configurations using region should be updated to use the aws_region attribute instead (#42131)region attribute has been deprecated. All configurations using region should be updated to use the regions attribute instead (#42014)ENHANCEMENTS:
allow_unsafe_filter argument (#42114)group_long_name attribute (#42014)region as Optional, allowing a value to be configured (#42014)roles.role_arn and roles.role_type (#42131)control_mapping_sources.source_frequency, control_mapping_sources.source_set_up_option, and control_mapping_sources.source_type (#42131)finding_publishing_frequency. (#42436)mutual_authentication attribute trust_store_arn is required if mode is verify (#42326)policy_arn (#42131)access_type source.aws_log_source_resource.source_name, and subscriber_identity.external_id (#42131)BUG FIXES:
Provider produced inconsistent result after apply errors (#42131)regions_of_interest.bounding_box and regions_of_interest.polygon argument validation (#41380)access_type to ForceNew (#42131)Fetched April 8, 2026