chore(deps): update terraform#514
Conversation
|
Warning [Medium Risk] New API access instance exposes an unauthenticated port 9090 service to the entire internal network The change creates a new EC2 instance This weakens segmentation and expands attack surface in production. Any instance or peered network path that can source traffic from SignalsRoutine → Multiple AWS infrastructure resources showing unusual, infrequent change patterns at 1-2 events/week for the last 3 months, with some related resources at 1 event/week for the last 5 weeks, which is rare compared to typical patterns. Additional Change Details: |
ba884cb to
12213ca
Compare
12213ca to
97c66a8
Compare
97c66a8 to
602c793
Compare
602c793 to
0f43049
Compare
0f43049 to
a110d8e
Compare
a110d8e to
23a5eca
Compare
68cb654 to
23ab534
Compare
b2a3f42 to
9b4ae74
Compare
7e23daa to
eee63e9
Compare
eee63e9 to
198048f
Compare

This PR contains the following updates:
2.7.1→2.8.0< 6.38→< 6.476.37.0→6.46.07.25.0→7.33.03.2.4→3.3.03.8.1→3.9.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
hashicorp/terraform-provider-archive (archive)
v2.8.0Compare Source
ENHANCEMENTS:
hashicorp/terraform-provider-aws (aws)
v6.46.0Compare Source
NOTES:
policy_namenow force resource recreation. Technically this is a breaking change but the resource did not function correctly previously; updatingpolicy_namewould leave an orphaned policy with the old name in AWS (#47948)FEATURES:
aws_bedrockagentcore_harness(#47725)aws_iam_access_key(#47966)aws_observabilityadmin_telemetry_rule_for_organization(#47920)aws_route53_vpc_association_authorization(#47905)aws_route53_zone_association(#47950)aws_securityhub_automation_rule_v2(#47677)aws_bedrockagentcore_harness(#47725)aws_observabilityadmin_telemetry_rule_for_organization(#47920)aws_securityhub_automation_rule_v2(#47677)aws_xray_indexing_rule(#47975)aws_xray_trace_segment_destination(#47961)ENHANCEMENTS:
outpost_lag_idandlocal_gateway_virtual_interface_group_idattributes (#47974)jwt_optionsblock to fix "Invalid address to set" error (#47874)idle_session_ttl_in_secondsfrom3600to5400to match the AWS API limit (#47890)filesystem_configurationargument for mounting session storage, Amazon S3 Files access points, or Amazon EFS access points into the agent runtime (#47810)cache_tag_configconfiguration block (#47872)resource_config_dns_resolutionargument (#47879)BUG FIXES:
acceleration_status,acl,cors_rule,grant,lifecycle_rule,logging,object_lock_configuration,policy,replication_configuration,request_payer,server_side_encryption_configuration,versioning,website) when the attribute is not set in configuration, preventing similar fights between the bucket resource and its standalone counterparts (#47962)InvalidRequest: SourceSelectionCriteria cannot be emptyerrors on unrelated updates (e.g.tags) when replication is managed by the dedicatedaws_s3_bucket_replication_configurationresource usingreplica_modifications(#47962)Provider returned invalid result object after applyerrors on Update (#47948)policy_nameas asForceNew(#47948)v6.45.0Compare Source
FEATURES:
aws_observabilityadmin_telemetry_rule(#47857)aws_securityhub_connector_v2(#47678)aws_observabilityadmin_telemetry_evaluation(#47799)aws_observabilityadmin_telemetry_evaluation_for_organization(#47808)aws_observabilityadmin_telemetry_rule(#47857)aws_securityhub_aggregator_v2(#47651)aws_securityhub_connector_v2(#47678)ENHANCEMENTS:
ruby4.0as aruntimevalue (#47841)ruby4.0as acompatible_runtimesvalue (#47841)secret_stringtosecret_string_wowithout re-creating the resource. (#47815)maintenance_scheduleconfiguration block (#47853)BUG FIXES:
engine_versionreturning full patch version instead of minor version for Valkey engine (#46109)engine,engine_version, andparameter_group_namechanges being ignored after disassociating from a global replication group (#46109)network_access_controlregression causingValidationExceptionwhen only one ofvpce_idsorprefix_list_idsis set (#47646)v6.44.0Compare Source
NOTES:
FEATURES:
aws_glue_catalog(#43583)aws_alb_target_group_attachment(#47724)aws_appautoscaling_policy(#47718)aws_arczonalshift_zonal_autoshift_configuration(#46114)aws_dynamodb_global_secondary_index(#47785)aws_dynamodb_table(#47518)aws_ecr_repository_policy(#47763)aws_glue_catalog(#43583)aws_lb_target_group_attachment(#47724)aws_s3_bucket_logging(#47766)aws_securityhub_standards_control(#47702)aws_vpc_endpoint_route_table_association(#47751)aws_arczonalshift_zonal_autoshift_configuration(#46114)aws_glue_catalog(#43583)aws_outposts_capacity_task(#47681)aws_redshift_namespace_registration(#43583)ENHANCEMENTS:
authentication_configurationattribute (#43583)transit_gateway_configurationblock (#47635)file_system_type_version(#47703)self_managed_active_directory.password_woandself_managed_active_directory.password_wo_versionarguments (#47752)authentication_configurationargument (#43583)maintenance_scheduleconfiguration block (#47354)BUG FIXES:
Deleteto use the file system prefix when resetting the synchronization configuration (#47760)waiting for Security Hub Configuration Policy Association (...) success: timeout while waiting for state to become 'SUCCESS' (last state: 'PENDING', timeout: 5m0s)errors on Create. This fixes a regression introduced in v6.34.0 (#47783)db_parameter_group_identifier(#47052)v6.43.0Compare Source
FEATURES:
aws_securityhub_enabled_standards(#43947)aws_securityhub_security_controls(#43947)aws_db_subnet_group(#47637)aws_ec2_network_insights_access_scope(#47582)aws_iam_group_policy_attachment(#47667)aws_lambda_event_source_mapping(#47686)aws_securityhub_insight(#47622)aws_arczonalshift_autoshift_observer_notification_status(#46343)aws_ec2_network_insights_access_scope(#47582)aws_securityhub_account_v2(#47356)ENHANCEMENTS:
EPISODICas a valid value fortype(#47589)current_deployment. (#47694)SELF_MANAGED_SECURITY_HUBas apolicy_idvalue (#47078)arnattribute (#47543)arnattribute (#47543)terraform destroywhen they block subnet deletion (#46953)terraform destroywhen they block VPC deletion (#46953)BUG FIXES:
One of 'metric_name', 'metric_query', or 'evaluation_criteria' must be set for a cloudwatch metric alarmplan-time errors. This fixes a regression introduced in v6.42.0 (#47666)current_deploymentchanges. (#47694)INACTIVEinstead ofDRAINING. (#47568)runtime error: invalid memory address or nil pointer dereferencepanics when removingresourceblocks (#47625)limits.messages_per_secondfrom 50 to 1 to match the AWS API. (#47636)MalformedXMLerrors during tag-on-create andCreateBucketConfigurationoperations (#47530)v6.42.0Compare Source
BREAKING CHANGES:
mq:DeleteConfigurationIAM permission. To restore the previous no-op behavior, setskip_destroytotrue. (#47273)NOTES:
FEATURES:
aws_ec2_service_link_virtual_interface(#47478)aws_ec2_service_link_virtual_interfaces(#47478)aws_apigatewayv2_api(#47472)aws_cloudwatch_log_metric_filter(#47495)aws_config_remediation_configuration(#47514)aws_ebs_volume(#47551)aws_ebs_volume_attachment(#47561)aws_eip(#47557)aws_iam_user_policy_attachment(#47467)aws_internet_gateway(#47529)aws_lambda_layer_version(#47496)aws_launch_template(#47540)aws_route53_zone(#47494)aws_sagemaker_hyper_parameter_tuning_job(#47138)aws_sqs_queue_policy(#47489)aws_cloudwatch_otel_enrichment(#47275)aws_ebs_volume_copy(#47311)aws_sagemaker_hyper_parameter_tuning_job(#47138)ENHANCEMENTS:
user_statusattribute (#47323)user_statusattribute (#47323)ena_srd_specificationattribute (#46669)evaluation_criteriaandevaluation_intervalarguments in support of PromQL queries. Changecomparison_operatorandevaluation_periodsto Optional (#47449)namespace_configargument (#44087)identity_provider_config_nameattribute (#47428)user_statusattribute (#47323)resource_selection.recipe.semantic_version(#47443)skip_destroyargument (#47273)ena_srd_specificationargument to support ENA Express (#46669)routing_policy_labelargument. This functionality requires thenetworkmanager: PutAttachmentRoutingPolicyLabelandnetworkmanager: RemoveAttachmentRoutingPolicyLabelIAM permissions (#47541)integration_identifierattribute (#45632)data_filterandintegration_name(#45632)storage_lens_configuration.expanded_prefixes_data_exportandstorage_lens_configuration.prefix_delimiterarguments (#47205)accept_bucket_warningargument (#47510)peer_network_cidrsargument. (#46207)BUG FIXES:
source_uriregular expression validation (#47498)topic_policy_config.topics_config.definitionfrom 200 to 1000 to support standard tier. (#47574)mute_targets.alarm_namesordering causing "Provider produced inconsistent result after apply" errors (#47507)UnsupportedOperationerrors in isolated regions (#47091)broker_node_group_info.vpc_connectivityconfiguration block. This fixes a regression introduced in v6.40.0 (#47515)runtime error: invalid memory address or nil pointer dereferencepanic instatusManagedService()andstatusNetwork()whenFindOracleDBNetworkResourceByIDreturns a nil result during resource creation (#47159)emailif returned by AWS API and don't recomputeinvitefrommember_status. This prevents drift for organization members (#47106)v6.41.0Compare Source
FEATURES:
aws_api_gateway_integration(#47370)aws_api_gateway_integration_response(#47388)aws_api_gateway_method(#47365)aws_api_gateway_method_response(#47387)aws_api_gateway_resource(#47382)aws_api_gateway_rest_api(#47404)aws_apigatewayv2_route(#47452)aws_cloudfront_distribution(#47459)aws_cloudwatch_alarm_mute_rule(#46750)aws_cloudwatch_log_subscription_filter(#47451)aws_nat_gateway(#47349)aws_sns_topic_policy(#47445)aws_cloudwatch_alarm_mute_rule(#46750)ENHANCEMENTS:
volume.s3files_volume_configurationattribute (#47363)deployment_strategy_optionsblock (#47401)topic_arn(#47381)metricsattribute (#47047)enable_directory_data_accessargument (#44736)volume.s3files_volume_configurationargument (#47363)passwords_woandpasswords_wo_versionwrite-only arguments (#45988)deployment_strategy_optionsconfiguration block (#47401)BUG FIXES:
ComputeAttributesorAssetLocation(#47450)traffic_sourceto Required (#47381)response_completion_timeoutfor Origins, by removing its default value (#46329)function_associationandlambda_function_associationblock ordering producing inconsistent result after apply when multiple associations are configured (#46378)originblock ordering producing inconsistent result after apply when multiple origins are configured (#47199)key_typeis unknown during plan-time. (#47456)range_keyis set to empty string (#47427)MySQLengine types triggered by upstream changes to the API error response text (#47448)MySQLengine types triggered by upstream changes to the API error response text (#47448)v6.40.0Compare Source
FEATURES:
aws_opensearchserverless_collection_group(#46308)aws_opensearchserverless_collection_groups(#46308)aws_s3files_access_point(#47352)aws_s3files_file_system(#47344)aws_s3files_file_systems(#47344)aws_s3files_mount_target(#47347)aws_config_config_rule(#47319)aws_glue_job(#47266)aws_opensearchserverless_collection_group(#46308)aws_s3files_access_point(#47352)aws_s3files_file_system(#47325)aws_s3files_file_system_policy(#47355)aws_s3files_mount_target(#47347)aws_s3files_synchronization_configuration(#47353)aws_ssm_association(#47321)aws_ssm_patch_group(#47329)aws_opensearchserverless_collection_group(#46308)aws_s3files_access_point(#47352)aws_s3files_file_system(#47325)aws_s3files_file_system_policy(#47355)aws_s3files_mount_target(#47347)aws_s3files_synchronization_configuration(#47353)aws_servicequotas_auto_management(#45968)ENHANCEMENTS:
broker_node_group_info.connectivity_info.network_typeattribute (#47279)depends_on_stack_setstoauto_deploymentconfiguration block (#47269)remediation_typesattribute (#46549)FLINK-2_2as a valid value forruntime_environment(#47207)broker_node_group_info.connectivity_info.network_typeargument (#47279)storage_lens_configuration.data_export.storage_lens_table_destinationargument (#47152)BUG FIXES:
export.data_query.table_configurations(#47261)patternlength in UTF-8 characters (#47287)nameas asForceNew(#47286)AccountAlreadyClosedExceptionerror when deleting an account that has already been closed withclose_on_deletionset totrue(#46627)rule.apply_server_side_encryption_by_default.kms_master_key_id,rule.blocked_encryption_types, andrule.bucket_key_enabledto Optional and Computed, preventings diffs once SSE-C is disabled for all new general purpose buckets (#47359)visible_regionsorvisible_servicesis set to an explicit empty set ([]) (#47290)v6.39.0Compare Source
NOTES:
tags_allattribute is deprecated and will be removed in a future major version ([#47Configuration
📅 Schedule: (in timezone Europe/London)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.