NOTES:
TagResource, UntagResource, and ListTagsForResource for read and update operations. The calling principal must have the corresponding s3:TagResource, s3:UntagResource, and s3:ListTagsForResource IAM permissions. If the principal lacks the appropriate permissions, the provider will fall back to tagging after creation and using the S3 tagging APIs PutBucketTagging, DeleteBucketTagging, and GetBucketTagging instead. With ABAC enabled, tag modifications may fail with the fall back behavior. See the AWS documentation for additional details on enabling ABAC in general purpose buckets. (#45251)FEATURES:
aws_ecs_express_gateway_service (#45235)aws_s3_bucket_abac (#45251)aws_vpc_encryption_control (#45263)aws_vpn_concentrator (#45175)ENHANCEMENTS:
tenant_id argument (#45170)control_plane_scaling_config attribute (#45258)tenancy_config attribute (#45170)tenant_id argument (#45170)vpn_concentrator_id attribute (#45175)managed_instances_provider.infrastructure_optimization argument (#45142)network_type argument (#45140)supported_network_types attribute (#45140)control_plane_scaling_config configuration block to support EKS Provisioned Control Plane (#45258)tenancy_config argument (#45170)tenant_id argument (#45170)s3:TagResource permission is present (#45251)s3:TagResource, s3:UntagResource, and s3:ListTagsForResource permissions are present (#45251)vpn_concentrator_id argument to support Site-to-Site VPN Concentrator (#45175)Fetched April 8, 2026