chore(deps): update terraform aws to v6.23.0 #141
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
6.18.0->6.23.0Release Notes
hashicorp/terraform-provider-aws (aws)
v6.23.0Compare Source
NOTES:
TagResource,UntagResource, andListTagsForResourcefor read and update operations. The calling principal must have the correspondings3:TagResource,s3:UntagResource, ands3:ListTagsForResourceIAM permissions. If the principal lacks the appropriate permissions, the provider will fall back to tagging after creation and using the S3 tagging APIsPutBucketTagging,DeleteBucketTagging, andGetBucketTagginginstead. With ABAC enabled, tag modifications may fail with the fall back behavior. See the AWS documentation for additional details on enabling ABAC in general purpose buckets. (#45251)FEATURES:
aws_ecs_express_gateway_service(#45235)aws_s3_bucket_abac(#45251)aws_vpc_encryption_control(#45263)aws_vpn_concentrator(#45175)ENHANCEMENTS:
tenant_idargument (#45170)control_plane_scaling_configattribute (#45258)tenancy_configattribute (#45170)tenant_idargument (#45170)vpn_concentrator_idattribute (#45175)managed_instances_provider.infrastructure_optimizationargument (#45142)network_typeargument (#45140)supported_network_typesattribute (#45140)control_plane_scaling_configconfiguration block to support EKS Provisioned Control Plane (#45258)tenancy_configargument (#45170)tenant_idargument (#45170)s3:TagResourcepermission is present (#45251)s3:TagResource,s3:UntagResource, ands3:ListTagsForResourcepermissions are present (#45251)vpn_concentrator_idargument to support Site-to-Site VPN Concentrator (#45175)v6.22.1Compare Source
ENHANCEMENTS:
INTELLIGENT_TIERINGstorage type and addread_cache_configurationargument (#45159)rebalancingconfiguration block to support intelligent rebalancing for Express broker clusters (#45073)BUG FIXES:
interface conversion: interface {} is nil, not map[string]interface {}panics whenconfiguration.unused_access.analysis_rule.exclusion.resource_tagscontainsnullvalues (#45202)v6.22.0Compare Source
NOTES:
blocked_encryption_typesargument to manage this behavior for specific buckets. (#45105)FEATURES:
aws_ecr_authorization_token(#44949)Tag Policy Compliance(#45143)aws_billing_view(#45097)aws_vpclattice_domain_verification(#45085)ENHANCEMENTS:
default_action.jwt_validationattribute (#45089)action.jwt_validationattribute (#45089)tagsonly or byvpc_idonly (#39671)tag_policy_complianceprovider argument, or theTF_AWS_TAG_POLICY_COMPLIANCEenvironment variable. When enabled, the principal executing Terraform must have thetags:ListRequiredTagsIAM permission. (#45143)encryption_key_arnargument (#45020)input_action,input_enabled,input_modalities,output_action,output_enabled, andoutput_modalitiesarguments to thecontent_policy_config.filters_configblock (#45104)storage_configuration.rds_configuration.field_mapping.custom_metadata_fieldargument (#45075)agent_runtime_artifact.code_configurationblock (#45091)agent_runtime_artifact.container_configurationblock optional (#45091)global_table_witnessargument (#43908)scaling_strategyandutilization_performance_indexarguments (#45132)log_configuration.cloudwatch_logs_configuration.log_group_arn(#35941)Functionstoaction.*.target(#41209)jwt-validationas a validdefault_action.typeand adddefault_action.jwt_validationconfiguration block (#45089)jwt-validationas a validaction.typeand addaction.jwt_validationconfiguration block (#45089)SECURITYHUB_POLICYas a valid value forenabled_policy_typesargument (#45135)destination.cloudwatch_logs.log_group_arn(#35941)logging_configuration.log_group_arn(#35941)rule.blocked_encryption_typesargument (#45105)container.additional_model_data_sourceandprimary_container.additional_model_data_sourcearguments (#44407)logging_configuration.log_destination(#35941)engine_typeattribute (#44899)timestream-influxdb:GetDbParameterGroupIAM permission (#44899)custom_domain_nameanddomain_verification_idarguments anddomain_verification_arnanddomain_verification_statusattributes to support custom domain names for resource configurations (#45085)tunnel_bandwidthargument to support higher bandwidth tunnels (#45070)BUG FIXES:
storage-config-upgradeandstorage-initializationstatuses (#41275)ResourceNamefor option settings and preventing duplicate add/remove operations (#45077)regionargument (#45083)AWS resource not found during refreshwarnings causing resource replacement whenReadOnlys3express:SessionModeis enforced (#45086)target_typeargument to required (#45092)allocated_storage,bucket,organization,username, andpasswordoptional to support InfluxDB V3 clusters (#44899)v6.21.0Compare Source
BREAKING CHANGES:
network_configuration.network_mode_configtonetwork_configuration.vpc_config(#44828)FEATURES:
aws_dynamodb_create_backup(#45001)aws_networkflowmonitor_monitor(#44782)aws_networkflowmonitor_scope(#44782)aws_observabilityadmin_centralization_rule_for_organization(#44806)ENHANCEMENTS:
capacity_provider_strategy,created_at,created_by,deployment_configuration,deployment_controller,deployments,enable_ecs_managed_tags,enable_execute_command,events,health_check_grace_period_seconds,iam_role,network_configuration,ordered_placement_strategy,pending_count,placement_constraints,platform_family,platform_version,propagate_tags,running_count,service_connect_configuration,service_registries,status, andtask_setsattributes (#44842)target_configuration.mcp.mcp_serverblock (#44991)credential_provider_configurationblock optional (#44991)delivery_destination_typeanddelivery_destination_configurationoptional to support AWS X-Ray as a destination (#44995)LINEARandCANARYdeployment strategies withdeployment_configuration.linear_configurationanddeployment_configuration.canary_configurationblocks (#44842)java25runtimevalue (#45024)nodejs24.xruntimevalue (#45024)python3.14runtimevalue (#45024)java25compatible_runtimesvalue (#45024)nodejs24.xcompatible_runtimesvalue (#45024)python3.14compatible_runtimesvalue (#45024)execution_role_arnargument and makemodel_nameoptional inproduction_variantsandshadow_production_variantsblocks to support Inference Components (#44977)AuthorizationError ... is not authorized to perform: iam:PassRole on resource ...IAM eventual consistency errors on Create and Update (#45018)BUG FIXES:
regionargument (#45023)regionargument (#45064)ValidationException: Value null at 'jobTemplateData.configurationOverrides.monitoringConfiguration.cloudWatchMonitoringConfiguration.logGroupName' failed to satisfy constraint: Member must not be nullerror (#45029)setting job_template_data: job_template_data.0.configuration_overrides.0.application_configuration.0: '' expected a map, got 'slice'error (#45029)job_template_data.job_driver.configuration_overrides.monitoring_configuration.persistent_app_uiargument as computed (#45029)Provider returned invalid result object after applyerror occurred when updating the resource (#45030)domain_nametodomain_nameandaccountseparated by a comma (#44982)endpoint_config_namewas not correctly updated, causing the endpoint to retain the old configuration (#42843)redacted_fields.single_header.name(#44987)v6.20.0Compare Source
FEATURES:
aws_ec2_allowed_images_settings(#44800)aws_fis_target_account_configuration(#44875)aws_invoicing_invoice_unit(#44892)ENHANCEMENTS:
media_concurrencies.cross_channel_behaviorattribute (#44934)node_group_configurationattribute to expose node group details including availability zones, replica counts, and slot ranges (#44879)max_record_size_in_kibattribute (#44915)identity_center_optionsattribute (#44626)us-isob-west-1as a valid AWS Region (#44944)logging_v1_enabledattribute (#44838)media_concurrencies.cross_channel_behaviorargument (#44934)destination_cidr_block(#44926)ip_address_typeargument (#44616)max_parallel_nodes_repaired_count,max_parallel_nodes_repaired_percentage,max_unhealthy_node_threshold_count,max_unhealthy_node_threshold_percentage, andnode_repair_config_overridesto thenode_repair_configschema (#44894)node_group_configurationblock to support availability zone specification and snapshot restoration for cluster mode enabled replication groups (#44879)timeoutis unconfigured for Ray jobs (#35012)max_record_size_in_kibargument to support for Kinesis 10MiB payloads. This functionality requires thekinesis:UpdateMaxRecordSizeIAM permission (#44915)identity_center_optionsconfiguration block (#44626)TransferSecurityPolicy-AS2Restricted-2025-07security_policy_namevalue (#44865)TransferSecurityPolicy-AS2Restricted-2025-07as a valid value forsecurity_policy_name(#44652)BUG FIXES:
Source type "...cloudfront.stagingDistributionDNSNamesModel" does not implement attr.Valueerror. This fixes a regression introduced in v6.17.0 (#44972)logging_config.bucketargument fromRequiredtoOptional(#44838)logging_config.include_cookiesargument while keeping V1 logging disabled (#44838)Source type "...cloudfront.originSSLProtocolsModel" does not implement attr.Valueandmissing required field, CreateVpcOriginInput.VpcOriginEndpointConfigerrors. This fixes a regression introduced in v6.17.0 (#44861)0) value fortimeoutfor Apache Spark streaming ETL jobs. This allows the job to be configured with no timeout (#44920)catalog_id,database.catalog_id,table.catalog_id, andtable_with_columns.catalog_idarguments (#44890)"") value forblock_device_mappings.ebs.kms_key_id. This fixes a regression introduced in v6.16.0 (#44708)v6.19.0Compare Source
FEATURES:
aws_ecrpublic_images(#44795)aws_lakeformation_identity_center_configuration(#44867)ENHANCEMENTS:
log_typeisTail(#44843)ami_tagsattribute (#44731)regex_valuesattribute tocondition.host_header,condition.http_headerandcondition.path_patternblocks (#44741)transformattribute (#44702)authorizer_configurationandauthorizer_typeconfig (#44826)monitoring_configurationargument (#43317)runtime_configurationargument (#43302)arnattribute. (#44867)ami_tagsargument (#44731)regex_valuesargument tocondition.host_header,condition.http_headerandcondition.path_patternblocks (#44741)transformconfiguration block (#44702)valuesargument incondition.host_header,condition.http_headerandcondition.path_patternis now optional (#44741)physical_table_map.relational_table.namefrom 64 to 256 characters (#44807)notebook-al2023-v1to validplatform_identifiervalues (#44570)account_idandregionfrom Resource Identity schema (#44846)account_idandregionfrom Resource Identity schema (#44846)account_idandregionfrom Resource Identity schema (#44846)account_idandregionfrom Resource Identity schema (#44846)BUG FIXES:
principal. (#44867)authorizer_configurationblock fromRequiredtoOptional(#44812)authorizer_typeargument asForceNew(#44812)principal. (#44867)Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.