NOTES:
return_organization_only argument to return only the results of the DescribeOrganization API and avoid API limits (#40884)region attribute, as the resource is global. (#46185)return_organization_only argument to return only the results of the DescribeOrganization API and avoid API limits (#40884)FEATURES:
aws_arcregionswitch_plan (#43781)aws_arcregionswitch_route53_health_checks (#43781)aws_organizations_entity_path (#45890)aws_resourcegroupstaggingapi_required_tags (#45994)aws_s3_bucket_object_lock_configuration (#45990)aws_s3_bucket_replication_configuration (#42662)aws_s3control_access_points (#45949)aws_s3control_multi_region_access_points (#45974)aws_savingsplans_savings_plan (#45834)aws_wafv2_managed_rule_group (#45899)aws_appflow_connector_profile (#45983)aws_appflow_flow (#45980)aws_cleanrooms_collaboration (#45953)aws_cleanrooms_configured_table (#45956)aws_cloudfront_key_value_store (#45957)aws_opensearchserverless_collection (#46001)aws_route53_record (#46059)aws_s3_bucket (#46004)aws_s3_object (#46002)aws_security_group (#46062)aws_apigatewayv2_routing_rule (#42961)aws_arcregionswitch_plan (#43781)aws_cloudfront_anycast_ip_list (#43331)aws_notifications_managed_notification_account_contact_association (#45185)aws_notifications_managed_notification_additional_channel_association (#45186)aws_notifications_organizational_unit_association (#45197)aws_notifications_organizations_access (#45273)aws_opensearch_application (#43822)aws_ram_permission (#44114)aws_ram_resource_associations_exclusive (#45883)aws_sagemaker_labeling_job (#46041)aws_sagemaker_model_card (#45993)aws_sagemaker_model_card_export_job (#46009)aws_savingsplans_savings_plan (#45834)aws_sesv2_tenant_resource_association (#45904)aws_vpc_security_group_rules_exclusive (#45876)ENHANCEMENTS:
routing_mode argument to support dynamic routing via routing rules (#42961)routing_mode argument to support dynamic routing via routing rules (#42961)allow_privilege_escalation attribute to eks_properties.pod_properties.containers.security_context (#45896)global_secondary_index.key_schema attribute (#46157)segment_actions.routing_policy_names argument (#45928)body_base64 and download_body attributes. For improved performance, set download_body = false to ensure bodies are never downloaded (#46163)source_resource attribute (#44705)allow_privilege_escalation attribute to eks_properties.pod_properties.containers.security_context (#45896)vector_ingestion_configuration.parsing_configuration.bedrock_data_automation_configuration block (#45966)vector_ingestion_configuration.parsing_configuration.bedrock_foundation_model_configuration.parsing_modality argument (#46056)certificate_rotation_restart argument (#45984)stream_view_type is set and stream_enabled is either false or unset. (#45934)BLOB_MOUNTING account setting name with ENABLED and DISABLED values (#46092)domain_join_service_account_secret argument to self_managed_active_directory configuration block (#45852)self_managed_active_directory.password to Optional and self_managed_active_directory.username to Optional and Computed (#45852)rules to a single element. (#46185)memory_size from 10240 MB to 32768 MB (#46065)network_performance_options argument (#46071)pipeline_configuration_body maximum length validation to 2,621,440 bytes to align with AWS API specification. (#44881)monitoring_schedule_config.monitoring_job_definition argument (#45951)monitoring_schedule_config.monitoring_job_definition_name argument optional (#45951)source_resource argument in support of provisioning of VPC Resource Planning Pools (#44705)organizational_unit_exclusion argument (#45890)ipv4_ipam_pool_id, ipv4_netmask_length, ipv6_ipam_pool_id, and ipv6_netmask_length arguments in support of provisioning of subnets using IPAM (#44705)ipv6_cidr_block to Optional and Computed (#44705)BUG FIXES:
rule.action.target_storage_class and rule.selection.storage_class to JSON serialization (#45909)catalog_id, data_location.catalog_id, database.catalog_id, lf_tag_policy.catalog_id, table.catalog_id, and table_with_columns.catalog_id arguments (#43931)attachment_routing_policy_rules.action.associate_routing_policies is empty (#46160)region defined, in AWS European Sovereign Cloud, prevent failing due to region validation requiring region names to start with "[a-z]{2}-" (#45895)configuration.result_configuration.encryption_configuration argument (#46159)Provider produced inconsistent result after apply error when querying CARBON_EMISSIONS table without table_configurations (#45972)model_source is set (#45713)auto_deployment with permission_model set to SERVICE_MANAGED (#45992)runtime error: invalid memory address or nil pointer dereference panic when mistakenly importing a multi-tenant distribution (#45873)origin_group to use correct id attribute name and fix field mapping to resolve missing required field errors (#45921)InvalidRecordingGroupException: The recording group provided is not valid errors when the recording_group.exclusion_by_resource_type or recording_group.recording_strategy argument is removed during update (#46110)warm_throughput in global_secondary_index when not set in configuration. (#46094)name is known after apply (#45917)kubernetes_network_config argument name in EKS Auto Mode validation error message (#45997)catalog_id, data_location.catalog_id, database.catalog_id, lf_tag_policy.catalog_id, table.catalog_id, and table_with_columns.catalog_id arguments (#43931)health_check.protocol from HTTP to TCP when protocol is TCP (#46036)firewall_policy.stateful_rule_group_reference.resource_arn (#46124)delete_associated_resources being set when value is unknown (#45636)partition_count (#45042)iam_database_authentication_enabled when restored from snapshot (#39461)port now works. (#45870)ValidationException: Base capacity cannot be updated when PerformanceTarget is Enabled error when updating price_performance_target and base_capacity (#46137)regions argument as Computed to fix an unexpected regions diff when it is not specified (#45829)InvalidChangeBatch errors during ForceNew operations when zone name changes (#45242)Invalid JSON String Value error on initial apply and ConflictException on subsequent apply when associating Route53 Resolver Query Log Configs (#45958)UnsupportedArgument errors during tag-on-create operations (#46122)MethodNotAllowed errors when S3 Control APIs are unavailable (#46122)ipv6_cidr_block as ForceNew when the existing IPv6 subnet was created with assign_ipv6_address_on_create = true (#46043)ip_address_type (#45947)Fetched April 8, 2026