Update Terraform aws to v6 - #7
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
|
🚀 env0 had composed a PR Plan for environment ACME Financial Services / Demos / Autoupgrade / Renovate Terraform : |
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
2 times, most recently
from
July 13, 2025 16:15
45940fb to
b6541e7
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
July 27, 2025 11:55
b6541e7 to
5538df9
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
2 times, most recently
from
August 8, 2025 07:04
0b3e022 to
b59adb0
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
August 14, 2025 23:57
b59adb0 to
6663daf
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
August 23, 2025 07:10
6663daf to
f63fe98
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
2 times, most recently
from
September 5, 2025 15:10
6637a8d to
6044457
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
2 times, most recently
from
September 19, 2025 06:53
5b8060a to
203a06a
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
September 23, 2025 03:59
203a06a to
693b0ca
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
October 3, 2025 00:04
693b0ca to
a6929fb
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
October 10, 2025 07:01
a6929fb to
a49c675
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
October 18, 2025 10:58
a49c675 to
0359786
Compare
There was a problem hiding this comment.
This PR is being reviewed by Cursor Bugbot
Details
Your team is on the Bugbot Free tier. On this plan, Bugbot will review limited PRs each billing cycle for each member of your team.
To receive Bugbot reviews on all of your PRs, visit the Cursor dashboard to activate Pro and start your 14-day free trial.
| aws = { | ||
| source = "hashicorp/aws" | ||
| version = "5.42.0" | ||
| version = "6.17.0" |
There was a problem hiding this comment.
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
October 25, 2025 11:57
0359786 to
5e417f3
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
2 times, most recently
from
November 8, 2025 03:54
1162319 to
fb65248
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
2 times, most recently
from
November 21, 2025 23:58
4f41dda to
f2cc916
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
November 26, 2025 23:42
f2cc916 to
2d69363
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
2 times, most recently
from
December 5, 2025 15:54
9c939ac to
90f6bf3
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
2 times, most recently
from
December 18, 2025 07:35
80f248a to
28241c8
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
January 9, 2026 03:52
28241c8 to
c4d8c88
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
2 times, most recently
from
January 29, 2026 11:13
471384e to
f3d5d15
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
February 5, 2026 11:59
f3d5d15 to
d58eeca
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
3 times, most recently
from
February 19, 2026 00:15
7acd4d1 to
5d256d4
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
March 1, 2026 10:10
5d256d4 to
402e29f
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
2 times, most recently
from
March 14, 2026 22:43
a6b7f3b to
52ffc2a
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
March 31, 2026 09:33
52ffc2a to
2de605d
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
2 times, most recently
from
April 19, 2026 05:59
f11a909 to
68e6d60
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
April 30, 2026 08:11
68e6d60 to
634ee03
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
2 times, most recently
from
May 14, 2026 10:59
d9d9b72 to
c418251
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
2 times, most recently
from
May 28, 2026 00:13
7782ecc to
0def888
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
June 5, 2026 07:56
0def888 to
48af181
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
June 12, 2026 16:02
48af181 to
e1375cd
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
2 times, most recently
from
June 27, 2026 03:56
376f608 to
4dd50d5
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
2 times, most recently
from
July 9, 2026 03:55
62ee5a3 to
fcea468
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
July 17, 2026 20:13
fcea468 to
a431e31
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
July 25, 2026 11:53
a431e31 to
546192c
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
August 1, 2026 12:04
546192c to
29e9129
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
August 7, 2026 23:28
29e9129 to
1afd31f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
5.42.0→6.58.0Release Notes
hashicorp/terraform-provider-aws (aws)
v6.58.0Compare Source
FEATURES:
aws_mailmanager_rule_set(#49257)aws_prometheus_anomaly_detector(#49139)aws_prometheus_scraper(#47466)aws_prometheus_scraper_logging_configuration(#47466)aws_resiliencehubv2_policy(#48321)aws_mailmanager_rule_set(#49257)aws_prometheus_anomaly_detector(#49139)aws_prometheus_scraper_logging_configuration(#47466)aws_resiliencehubv2_policy(#48321)ENHANCEMENTS:
stateattribute (#42150)RESERVEDas a valid value formanaged_instances_provider.instance_launch_template.capacity_option_type(#48816)local_storage_configurationattribute tomanaged_instances_provider.instance_launch_template(#47513)managed_instances_provider.instance_launch_template.capacity_reservationsargument (#48816)configuration.compaction_configurationargument (#43868)destination.cloudwatchconfiguration block for CloudWatch Metrics destination support (#49088)BUG FIXES:
BadRequestException: There is already an update in progresserrors (#49205)embed_host_domainsnot being sent to the AWS API on update, which caused a permanent plan diff when the argument was added or changed on an existing stack (#49015)bedrock_data_automation_configurationwhenparsing_strategy = "BEDROCK_DATA_AUTOMATION", a regression introduced in v6.56.0 (#49111):(colon) in thematch_value_stringandmatch_value_string_listattributes ofauthorizer_configuration.custom_jwt_authorizer.custom_claim.authorizing_claim_match_value.claim_match_value(#48437)Value Conversion Error ... Received null value, however the target type cannot handle null valueserrors (#49188)too many results: wanted 1, got 2error when creating or updating a strategy on a memory that already has another strategy of a different type (#49250)configuration.consolidation,configuration.extraction, orconfiguration.reflectionblocks are removed (#49188)sigint_rollbackfalsely rolling back healthy deployments duringwait_for_steady_state(#49077)apply_immediately = false) (#48246)InvalidInputException: StorageDescriptor is not allowederror when creating or updating ATHENA-dialect views (#49156)InvalidInputExceptionerror when creating or updating SPARK-dialect views without an explicitstorage_descriptorblock (#49156)view_definition.representationsfields (validation_connection,view_original_text,view_expanded_text) that AWS Glue does not echo back for validated ATHENA views (#49156)v6.57.1Compare Source
NOTES:
memory_execution_role_arnattribute has been deprecated. This attribute should be removed from configurations (#49140)namespacesattribute has been deprecated. All configurations usingnamespacesshould be updated to use thenamespace_templatesattribute instead (#49140)FEATURES:
aws_eks_access_policies(#49090)aws_bedrock_evaluation_job(#49044)aws_eks_access_entry(#49090)aws_eks_access_policy_association(#49121)aws_eks_node_group(#49073)aws_flow_log(#49086)aws_mailmanager_traffic_policy(#49043)aws_osis_pipeline(#49157)aws_osis_pipeline_endpoint(#44383)aws_osis_resource_policy(#44383)aws_rekognition_collection(#49135)aws_bedrock_evaluation_job(#49044)aws_cloudwatch_log_storage_tier_policy(#49076)aws_mailmanager_traffic_policy(#49043)aws_osis_pipeline_endpoint(#44383)aws_osis_resource_policy(#44383)ENHANCEMENTS:
ena_queue_countattribute tonetwork_interfacesconfiguration block (#48892)typeattribute (#46414)external_secret_rotation_metadataandexternal_secret_rotation_role_arnattributes (#46414)ipv6_cidr_block_associations. (#46918)ipv6_association_idandipv6_cidr_block. (#46918)reservations-then-balancedvalid value foravailability_zone_distribution.capacity_distribution_strategy(#48934)timeouts.updatewith a default value of30m(#49140)configuration.reflectionconfiguration block forEPISODIC_OVERRIDEstrategy type (#49140)namespace_templatesargument (#49140)reflection_configurationconfiguration block forEPISODICstrategy type (#49140)timeoutsvalues to45m(#49140)stage.action.commandsandstage.action.output_artifacts_for_compute_actionarguments to support Compute action types (#42507)stage.action.output_artifacts_for_compute_actionandstage.action.output_artifactsnow conflict (#42507)policyargument to support inline session policies (#48869)MultiRegionClustersas a value foraction.target.key(#48781)ena_queue_countargument tonetwork_interfacesconfiguration block (#48892)typeargument in support of managed external secrets (#46414)external_secret_rotation_metadataandexternal_secret_rotation_role_arnarguments in support of managed external secrets (#46414)BUG FIXES:
warm_throughputvalues (#49032)v6.56.0Compare Source
FEATURES:
aws_elasticache_apply_service_update(#48963)aws_elasticache_service_update_actions(#48958)aws_s3_buckets(#48965)aws_eks_addon(#49067)aws_s3_bucket_notification(#48974)aws_secretsmanager_secret_policy(#49058)ENHANCEMENTS:
warm_pool_configattribute (#48977)bootstrap_brokers_ipv6,bootstrap_brokers_sasl_iam_ipv6,bootstrap_brokers_sasl_scram_ipv6, andbootstrap_brokers_tls_ipv6attributes to expose IPv6 bootstrap broker URLs (#48975)iam_federation_optionsblock (#48495)iam_identity_center_optionsblock (#48495)TF_AWS_WEB_IDENTITY_TOKENenvironment variable. Any value configured viaassume_role_with_web_identity.web_identity_tokentakes precedence (#48736)instance_lifecycle_policyconfiguration block (#48973)data_source_configuration.managed_knowledge_base_connector_configurationblock (#48904)timeouts.updatewith a default value of30m(#48904)vector_knowledge_base_configuration.bedrock_embedding_model_configuration.audioandvector_knowledge_base_configuration.bedrock_embedding_model_configuration.videoconfiguration blocks (#48538)type = "MANAGED") withmanaged_knowledge_base_configurationblock (#48904)@source.logas a valid value foremit_system_fields(#48956)warm_pool_configconfiguration block (#48977)tag_field_specificationconfiguration block (#48913)AI_PROTECTIONandAI_ANALYSTfeature names (#48972)AI_PROTECTIONandAI_ANALYSTfeature names (#48972)bootstrap_brokers_ipv6,bootstrap_brokers_sasl_iam_ipv6,bootstrap_brokers_sasl_scram_ipv6, andbootstrap_brokers_tls_ipv6attributes to expose IPv6 bootstrap broker URLs (#48975)iam_federation_optionsconfiguration block (#48495)iam_identity_center_optionsconfiguration block (#48495)metadata.iceberg.propertiesargument (#48635)BUG FIXES:
assume_role_with_web_identity.0.web_identity_token,assume_role_with_web_identity.0.web_identity_token_filemust be specified" errors, allowing anyAWS_WEB_IDENTITY_TOKEN_FILEenvironment variable value to be used (#48736)FAILEDstate (#48904)AccessDeniedExceptionerror when deleting (#48516)data_read_cache_configuration.sizewhensizing_modeisPROPORTIONAL_TO_THROUGHPUT_CAPACITYandsizeis not specified (#49023)shared_resourcesdiffs for ActiveMQ brokers (#48962)ConflictException: Configuration ID [...] is in useerrors on delete (#48962)Cannot create already existing endpointerror when retrying creation. (#48966)v6.55.0Compare Source
6.55.0 (July 15, 2026)
FEATURES:
aws_elasticache_service_updates(#44608)aws_autoscaling_group(#48928)aws_cloudwatch_log_stream(#48878)aws_kinesis_firehose_delivery_stream(#48946)aws_network_interface(#48887)aws_rds_cluster(#48948)aws_sfn_state_machine(#48840)ENHANCEMENTS:
updated_atattribute (#48881)allowed_workload_configuration,private_endpoint, andprivate_endpoint_overridesconfiguration blocks toauthorizer_configuration.custom_jwt_authorizer, and the read-onlyrequire_service_s3_endpointattribute tonetwork_configuration.network_mode_config(#48654)allowed_workload_configuration,private_endpoint, andprivate_endpoint_overridesconfiguration blocks toauthorizer_configuration.custom_jwt_authorizer(#48654)allowed_workload_configuration,private_endpoint, andprivate_endpoint_overridesconfiguration blocks toauthorizer_configuration.custom_jwt_authorizer(#48654)require_service_s3_endpointargument tonetwork_configuration.network_mode_config(#48654)allowed_workload_configuration,private_endpoint, andprivate_endpoint_overridesconfiguration blocks toauthorizer_configuration.custom_jwt_authorizer(#48654)consumer_group_offset_sync_modeattribute toconsumer_group_replicationblock (#47670)BUG FIXES:
Unsupported Typeerrors when nomemoryis configured (#48654)interface conversion: interface {} is nil, not *configservice.DescribeOrganizationConfigRuleStatusesOutputpanics on delete (#48845)v6.54.0Compare Source
NOTES:
capacity_reservation_config, it is best effort and we ask for community help in testing (#45926)FEATURES:
aws_route53profiles_profile(#48780)aws_bedrockagentcore_browser_profile(#46862)aws_codepipeline(#48808)aws_lambda_function_scaling_config(#48229)aws_scheduler_schedule(#48828)aws_ssoadmin_region(#48126)aws_workspaces_pool(#42678)aws_bedrockagentcore_browser_profile(#46862)aws_lambda_function_scaling_config(#48229)aws_ssoadmin_region(#48126)aws_workspaces_pool(#42678)ENHANCEMENTS:
host_kernel_overrideargument (#48777)resource_share_arnsandshared_resourcesattributes (#48729)tagsandtags_allattributes (#48458)host_kernelargument to theenvironmentconfiguration block (#48777)use_resource_timeout_for_propagationargument (#46405)10mforcreateandupdate,5mfordelete. (#46405)use_resource_timeout_for_propagationargument (#46405)5mforcreate,read, anddelete. (#46405)resource_share_arnsargument andshared_resourcesattribute (#48729)out_of_order_time_window_in_secondsandrule_query_offset_in_secondsarguments (#48659)auto_minor_version_upgradeargument (#42472)production_variants.capacity_reservation_configandshadow_production_variants.capacity_reservation_configconfiguration blocks (#45926)BUG FIXES:
content_policy_configblock. (#48772)topic_policy_configblock. (#48772)content_policy_config.filters_config.input_modalitiesvalues. (#48772)content_policy_config.filters_config.output_modalitiesvalues. (#48772)etagon Import. (#48782)etagwhen onlytagsupdated. (#48782)UnsupportedOperationExceptionerror when readingenable_directory_data_accessin regions where Directory Service Data is not available (e.g. GovCloud) (#47660)v6.53.0Compare Source
BREAKING CHANGES:
opt_out_list_nameandtwo_way_channel_enabledin favor of AWS server-side defaults (Defaultandfalserespectively). Configurations that omit these attributes will now show(known after apply)on first plan instead of the previous static value; the post-apply state is unchanged. This change mitigates persistent drift when the phone number is managed by anaws_pinpointsmsvoicev2_pool. (#48414)NOTES:
bedrock-agentcorenamespace to theagent-registrynamespace. Theaws_bedrockagentcore_browserresource will continue to work until September 17, 2026 (#48693)bedrock-agentcorenamespace to theagent-registrynamespace. Theaws_bedrockagentcore_browserresource will continue to work until September 17, 2026 (#48693)aws_ecs_cluster_capacity_providers, add areplace_triggered_bylifecycle rule to the association so the old capacity provider is detached before it is deleted (#48156)FEATURES:
aws_bedrock_foundation_model_agreement_offers(#47665)aws_bedrock_use_case_for_model_access(#47665)aws_ec2_capacity_block_reservation(#48185)aws_pinpointsmsvoicev2_pool(#48414)aws_bedrock_foundation_model_agreement(#47665)aws_bedrock_use_case_for_model_access(#47665)aws_pinpointsmsvoicev2_pool(#48414)ENHANCEMENTS:
security_policyandendpoint_access_modeattributes (#47973)customer_action_statusattribute (#48536)security_policyandendpoint_access_modearguments (#47973)browser_signing,certificate, andenterprise_policyconfiguration blocks (#47816)certificateargument (#47817)rule_definition(#48679)rule_stateto Optional and Computed (#48679)resource_arnandtemplate_name(#48679)customer_action_statusattribute (#48536)force_disassociateargument (#48414)idin favor ofarn(#48636)idin favor ofarn(#48636)idin favor ofarn(#48636)BUG FIXES:
authorization_tokenas sensitive (#48577)resource_arn,tagsandtemplate_nameasForceNew(#48679)importblock orterraform import(#47590)InvalidActionerrors in partitions where access key cleanup operations are not supported (#48473)instance_market_options.market_typeis set tocapacity-block(#48701)secret_access_keyas sensitive (#48577)private_keyas sensitive (#48577)typeattribute to no longer force resource replacement on change (#47105)v6.52.0Compare Source
NOTES:
aws_glue_catalog_tableviews (table_type = "VIRTUAL_VIEW") are now preserved when the view'sview_definitionis updated, as the underlying table is updated in place rather than recreated (#48532)****forNoEchoparameters or is missing default-matchingparameterskeys require a one-time manual reconciliation after upgrading. To recover: (1) addlifecycle { ignore_changes = [parameters] }temporarily, (2) pull state withterraform state pull, (3) correct the affectedparametersvalues and incrementserial, (4) push state back withterraform state push, (5) remove theignore_changesblock, and (6) confirm withterraform plan. For non-sensitive parameters you can instead temporarily set the parameter to a non-default value, apply, revert, and apply again (#46748)NoEchoparameter values are now persisted in Terraform state in plaintext rather than as****. This is consistent with how Terraform stores other sensitive inputs (for example,aws_db_instance.password). Ensure your state backend is appropriately secured (#46748)FEATURES:
aws_s3_bucket_notification(#31512)aws_appautoscaling_target(#48449)aws_bedrockagentcore_registry(#48314)aws_dynamodb_table_item(#48520)aws_bedrockagentcore_registry(#48314)ENHANCEMENTS:
control_plane_egress_modeattribute tovpc_configblock (#48497)arnattribute (#48502)control_plane_egress_modeargument tovpc_configblock (#48497)instances.0.endpointsare now returned in a deterministic order based on protocol prefix and port, including the newhttps://...:16001Prometheus metrics endpoint introduced in RabbitMQ 4.2 and later; any unrecognized endpoint types are appended afterward in API order (#47777)capabilitiesfromRequiredtoOptional/Computed. Applications without required capabilities can now omit the argument and the value applied by AWS will be tracked in state (#46748)BUG FIXES:
IdempotentParameterMismatchby generating client-supplied idempotency tokens using a cryptographically strong random generator and extended alphabet (#47995)TF_LOG=DEBUGoutput for resources, data sources, and list resources. Redaction continues to apply to ephemeral resources and actions (#48463)ConflictExceptionerrors (#48158)Provided delivery configuration is invalid for the destination typeerrors whens3_delivery_configurationis unchanged (#46123)automatic_failover_enableddiff by reading the value from the primary member (#47647)automatic_failover_enableddiff on member replication groups of anaws_elasticache_global_replication_group(#47647)Provider returned invalid result object after applyand subsequenttoo many resultswarning that silently removed the resource from state whenidwas not set in configuration (#48462)InvalidParameterCombination: Serverless Cache modifications only support modifying one field per requesterror when changing multiple attributes in a single apply (#47918)user_idproducing inconsistent final plan when using mixed-case values (#47705)user_group_idproducing inconsistent final plan when using mixed-case values (#47705)VIRTUAL_VIEWtable'sview_definitionby passingViewUpdateActionto the GlueUpdateTableAPI (#48532)change set: unexpected state 'FAILED', wanted target 'CREATE_COMPLETE'. last error: No updates are to be performederrors on subsequent applies. Previously,parameterswhose value matched the application's default were pruned from state, andNoEchoparameter values were stored as****, both of which produced false drift (#46748)v6.51.0Compare Source
NOTES:
managed_certificate_request, managed certificate issuance uses a fixed 3-hour timeout regardless of the configured resource timeout. This behavior will be updated in a future major version. (#47839)kms_key_arnattribute has been deprecated. All configurations usingkms_key_arnshould be updated to usConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.