FEATURES
- New Resource:
aws_datasync_location_fsx_windows(#12686) - New Resource:
aws_route53_resolver_query_log_config. (#14897) - New Resource:
aws_route53_resolver_query_log_config_association. (#14901)
ENHANCEMENTS
- resource/aws_apigatewayv2_api: Add
disable_execute_api_endpointattribute [GH-15250] - resource/aws_glue_job - add
non_overridable_argumentsargument [GH-14793] - data-source/aws_lb: Add
customer_owned_ipv4_poolandsubnet_mappingoutpost_idattributes [GH-15170] - resource/aws_fsx_lustre_file_system - add support for backup retention [GH-14446]
- resource/aws_fsx_lustre_file_system: Add
kms_key_idargument [GH-15057] - resource/aws_fsx_lustre_file_system: Add
mount_nameargument [GH-14313] - resource/aws_lb: Add
customer_owned_ipv4_poolargument andsubnet_mappingoutpost_idattribute [GH-15170] - resource/aws_rds_cluster: Add
allow_major_version_upgradeargument [GH-14709] - resource/aws_storagegateway_smb_file_share: Add
admin_user_listargument [GH-12196] - resource/aws_transfer_user: Add
home_directory_mappingsconfiguration blocks andhome_directory_typeargument [GH-13591]
BUG FIXES
- resource/aws_dynamodb_table: Ensure changes in
name,range_key,projection_type, ornon_key_attributesof alocal_secondary_indexconfiguration block force resource recreation [GH-12335] - resource/aws_dynamodb_table: Ensure
local_secondary_indexnon_key_attributesare sent through API requests on resource creation [GH-15115] - resource/aws_fsx_lustre_file_system: Change
aws_fsx_lustre_file_system's'snetwork_interface_idstoTypeListto preserve ordering. [GH-14314] - resource/aws_vpn_gateway: Increase VPC detachment timeout to 30 minutes [GH-15201]
- resource/aws_vpn_gateway_attachment: Increase VPC detachment timeout to 30 minutes [GH-15201]
FEATURES
- New Resource:
aws_config_remediation_configuration(#13884)
ENHANCEMENTS
- resource/aws_db_cluster_snapshot: Add plan-time validation for
db_cluster_snapshot_identifierargument (#15132) - resource/aws_kinesis_firehose_delivery_stream: Add
server_side_encryptionkey_arnandkey_typearguments (support KMS Customer Managed Key encryption) (#11954)
BUG FIXES
- data-source/aws_kms_secrets: Prevent
plaintextvalues to appear in CLI output with Terraform 0.13 (#15169) - resource/aws_acm_certificate: Prevent tagging is not permitted on re-import error (#15060)
- resource/aws_cognito_identity_pool: Prevent ordering differences for
openid_connect_provider_arnsargument (#15178)
FEATURES
- New Resource:
aws_db_proxy_default_target_group(#12743)
BUG FIXES
- resource/aws_ec2_client_vpn_authorization_rule: Increase active and revoked timeouts from 1 to 5 minutes (#15037)
FEATURES
- New Data Source:
aws_docdb_orderable_db_instance(#14931) - New Data Source:
aws_lex_slot_type(#8916) - New Data Source:
aws_neptune_orderable_db_instance(#14953) - New Data Source:
aws_rds_orderable_db_instance(#14834) - New Data Source:
aws_vpc_peering_connections(#9491) - New Resource:
aws_codebuild_report_group(#12573) - New Resource:
aws_db_proxy(#12704) - New Resource:
aws_emr_instance_fleet(#14813) - New Resource:
aws_glue_user_defined_function(#12537) - New Resource:
aws_guardduty_filter(#14876) - New Resource:
aws_lex_slot_type(#8916)
ENHANCEMENTS
- data-source/aws_cur_report_definition: Add
refresh_closed_reportsandreport_versioningattributes (#12428) - data-source/aws_outposts_outpost: Add
arnargument (#14967) - data-source/aws_route: Add
local_gateway_idattribute (#14864) - data-source/aws_route_table: Add
routelocal_gateway_idattribute (#14864) - resource/aws_acm_certificate: Provide additional plan-time validation for
subject_alternative_namesargument values (#14782) - resource/aws_ami: Support
io2value forvolume_typeargument plan-time validation (#14906) - resource/aws_autoscaling_group: Support provider-level
ignore_tagsconfiguration (#13868) - resource/aws_cloudtrail: Add
insight_selectorconfiguration block (#12390) - resource/aws_cur_report_definition: Add
refresh_closed_reportsandreport_versioningarguments (#12428) - resource/aws_cur_report_definition: Support
ATHENAvalue inadditional_artifactsargument plan-time validation (#12428) - resource/aws_cur_report_definition: Support
Parquetvalue incompressionandformatargument plan-time validations (#12428) - resource/aws_cur_report_definition: Support
MONTHLYvalue intime_unitargument plan-time validation (#12428) - resource/aws_ebs_volume: Support io2 type (#14894)
- resource/aws_ec2_client_vpn_endpoint: Support
authentication_optionstypeargumentfederated-authenticationvalue and newsaml_provider_arnargument (#14171) - resource/aws_emr_cluster: Add
core_instance_fleetandmaster_instance_fleetconfiguration blocks (#14788) - resource/aws_instance: Support
io2value forvolume_typeargument plan-time validation (#14906) - resource/aws_kinesis_firehose_delivery_stream: Add
elasticsearch_configurationvpc_configconfiguration block (#13269) - resource/aws_kinesis_firehose_delivery_stream: Add
elasticsearch_configurationcluster_endpointargument (#12484) - resource/aws_kinesis_firehose_delivery_stream: Add various plan-time validations for arguments (#12484)
- resource/aws_launch_template: Support
io2value forvolume_typeargument plan-time validation (#14906) - resource/aws_msk_configuration: Support resource in-place updates and deletion (#14826)
- resource/aws_route: Add
local_gateway_idargument (#14864) - resource/aws_route_table: Add
routelocal_gateway_idargument (#14864) - resource/aws_spot_fleet_request: Support
io2value forvolume_typeargument plan-time validation (#14906) - resource/aws_wafv2_rule_group: Add
ip_set_forwarded_ip_configconfiguration block toip_set_reference_statement(#14902) - resource/aws_wafv2_web_acl: Add
ip_set_forwarded_ip_configconfiguration block toip_set_reference_statement(#14902)
BUG FIXES
- resource/aws_autoscaling_group: Prevent unnecessary tag removal and recreation within tag updates (#13868)
- resource/aws_cloudfront_distribution: Prevent panic with missing
ForwardedValues(#14993) - resource/aws_dynamodb_table: Properly update
global_secondary_indexnon_key_attributesvalues (#9988) - resource/aws_emr_cluster: Prevent recreation when
ebs_config.volumes_per_instanceis greater than 1 (#14858) - resource/aws_lambda_function_event_invoke_config: Prevent unexpected format of function resource error (#14851)
- resource/aws_lightsail_instance: Prevent panic with key-only tags (#13868)
- resource/aws_mq_configuration: Prevent additional revision creation with
tagsonly updates (#14850) - resource/aws_opsworks_stack: Suppress equivalent
custom_jsondifferences (#14886) - resource/aws_rds_cluster_endpoint: Increase creation timeout to 30 minutes (#14862)
- resource/aws_route53_resolver_rule: Correct handling for single period (
.) value indomain_nameargument (#15015) - resource/aws_route53_zone_association: Correctly handle zones with over 100 VPC associations (#14885)
- resource/aws_waf_rate_based_rule: Properly update
rate_limitvalue (#14964) - resource/aws_workspaces_workspace: Prevent error when
workspace_propertiesrunning_modeis set toALWAYS_ON(#13976)
FEATURES
- New Data Source:
aws_db_subnet_group(#9525) - New Resource:
aws_emr_managed_scaling_policy(#13965) - New Resource:
aws_guardduty_publishing_destination(#13894) - New Resource:
aws_securityhub_action_target(#10493) - New Resource:
aws_xray_encryption_config(#13600) - New Resource:
aws_xray_group(#13597)
ENHANCEMENTS
- resource/aws_apigatewayv2_integration: Add
integration_subtypeargument (Support AWS service integrations for HTTP APIs) (#14860) - resource/aws_elasticache_replication_group: Add plan-time validation for
notification_topic_arnandsnapshot_arnsarguments (#12974) - resource/aws_globalaccelerator_endpoint_group: Add
client_ip_preservation_enabledargument to theendpoint_configurationconfiguration block (#14486) - resource/aws_storagegateway_cached_iscsi_volume: Add
kms_encryptedandkms_keyarguments (#12066) - resource/aws_storagegateway_gateway: Add
smb_security_strategyargument (#13563) - resource/aws_storagegateway_gateway: Add plan-time validation for
gateway_ip_addressargument (#13563) - resource/aws_storagegateway_gateway: Add
average_download_rate_limit_in_bits_per_secandaverage_upload_rate_limit_in_bits_per_secarguments (#13568) - resource/aws_storagegateway_nfs_file_share: Add
cache_attributesconfiguration block (#14759) - resource/aws_storagegateway_nfs_file_share: Support
S3_INTELLIGENT_TIERINGvalue indefault_storage_classargument plan-time validation (#14759) - resource/aws_storagegateway_smb_file_share: Add
cache_attributesconfiguration block andcase_sensitivityargument (#14790) - resource/aws_storagegateway_smb_file_share: Support
S3_INTELLIGENT_TIERINGvalue indefault_storage_classargument plan-time validation (#14790) - resource/aws_xray_sampling_rule: Add
tagsargument (#14831)
BUG FIXES
- resource/aws_acmpca_certificate_authority: Ensure
DELETEDstatus triggers state removal (#13684) - resource/aws_appmesh_virtual_node: Prevent panics with empty
backendconfiguration blocks (#14074) - resource/aws_cloudfront_distribution: Preview panics during resource import with empty
forwarded_values.query_string(#14844) - resource/aws_elasticache_replication_group: Ensure
tagsare stored in Terraform state and properly updated (#12974) - resource/aws_emr_instance_group: Increase creation and update timeout to 30 minutes (#13077] / [#14106)
- resource/aws_globalaccelerator_accelerator: Increase creation timeout to 10 minutes (#14486)
- resource/aws_globalaccelerator_endpoint_group: Prevent differences with
health_check_pathdefaults (#14486) - resource/aws_glue_crawler: Properly update
schedulevalue (#14792)
ENHANCEMENTS
- data-source/aws_lambda_layer_version: Support
java8.al2andprovided.al2inruntimeargument plan-time validation (#14663) - provider: Support for appending information to User-Agent request headers with the
TF_APPEND_USER_AGENTenvironment variable (#14555) - resource/aws_apigatewayv2_api: Add
bodyargument (#12567) - resource/aws_customer_gateway: Support tag on create (#14501)
- resource/aws_dms_replication_instance: Add
allow_major_version_upgradeargument (#14550) - resource/aws_ec2_client_vpn_network_association: Allow specifying custom security groups (#14146)
- resource/aws_ec2_client_vpn_network_association: Support resource import (#14146)
- resource/aws_egress_only_intrenet_gateway:-Ssupport tag on create (#14501)
- resource/aws_eks_node_group: Support
AL2_ARM_64value forami_typeargument plan-time validation (#14729) - resource/aws_eks_node_group: Add
launch_templateconfiguration block (#14639) - resource/aws_internet_gateway: Support tag on create (#14501)
- resource/aws_lambda_function: Support
java8.al2andprovided.al2inruntimeargument plan-time validation (#14663) - resource/aws_lambda_layer_version: Support
java8.al2andprovided.al2incompatible_runtimesargument plan-time validation (#14663) - resource/aws_launch_template: Support
elastic-gpuandspot-instances-requestintag_specificationsresource_typeargument plan-time validation (#14662) - resource/aws_network_acl: Support tag on create (#14501)
- resource/aws_network_interface: Support tag on create (#14501)
- resource/aws_route_table: Support tag on create (#14501)
- resource/aws_security_group: Support tag on create (#14501)
- resource/aws_spot_instance_request: Support tag on create (#14501)
- resource/aws_storagegatway_smb_file_share: Add
audit_destination_arnandsmb_acl_enabledarguments (#13572) - resource/aws_subnet: Support tag on create (#14501)
- resource/aws_subnet: Add plan-time validation to
ipv6_cidr_blockargument (#12303) - resource/aws_vpc_dhcp_options: Support tag on create (#14501)
- resource/aws_vpc_peering_connection: Support tag on create (#14501)
- resource/aws_vpn_connection: Support tag on create (#14501)
- resource/aws_vpn_gateway: Support tag on create (#14501)
- resource/aws_wafv2_rule_group: Add
forwarded_ip_configconfiguration block togeo_match_statement(#14685) - resource/aws_wafv2_web_acl: Add
forwarded_ip_configconfiguration block torate_based_statementandgeo_match_statement(#14685) - resource/aws_wafv2_web_acl: Support
FORWARDED_IPvalue forrate_based_statementaggregate_key_typeargument plan-time validation (#14685)
BUG FIXES
- resource/aws_api_gateway_vpc_link: Increase create, update, and delete timeouts to 20 minutes (#10407)
- resource/aws_apigatewayv2_stage: Set
execution_arnattribute for HTTP APIs (#14638) - resource/aws_db_parameter_group: Restore ability to update
parameterconfiguration values (#12112) - resource/aws_user_pool_domain: Ensure state removal when deleted outside Terraform (#14732)
- resource/aws_rds_cluster_parameter_group: Restore ability to update
parameterconfiguration values (#12112) - resource/aws_ssm_parameter: Handle retries after creation for asynchronous
data_typevalidation process (#14514) - resource/aws_storagegateway_nfs_file_share: Skip
UpdateSMBFileShareAPI call when onlytagschange and remove extraneousListTagsForResourceAPI call during read (#13590) - resource/aws_subnet: Ensure
ipv6_cidr_blockargument performs removal when removed from configuration (#12303)
ENHANCEMENTS
- data-source/aws_launch_configuration: Add
ebs_block_deviceno_deviceattribute (#14583) - data-source/aws_lb: Add
subnet_mappingprivate_ipv4_addressattribute (#14545) - provider: Upgrade to Terraform Plugin SDK V2. There should be no breaking changes from a practitioner's perspective. Some validation errors should now feature enhanced messaging. (#14432)
- resource/aws_accessanalyzer_analyzer: Support
ORGANIZATIONvalue intypeargument (#14493) - resource/aws_codebuild_project: Support
WINDOWS_SERVER_2019_CONTAINERvalue inenvironmenttypeargument plan-time validation (#14532) - resource/aws_organizations_organization: Support
AISERVICES_OPT_OUT_POLICYvalue inenabled_policy_typesargument plan-time validation (Support AI Opt Out policies) (#14650) - resource/aws_organizations_policy: Support
AISERVICES_OPT_OUT_POLICYvalue intypeargument plan-time validation (Support AI Opt Out policies) (#14528) - resource/aws_route53_health_check: Add
disabledargument (#14614)
BUG FIXES
- data-source/aws_launch_template: Prevent type error with
network_interfacesdelete_on_terminationattribute (#14599) - resource/aws_acm_certificate_validation: Prevent panic with missing
DomainValidationOptionsResourceRecordattribute in API response [#14590] - resource/aws_ecr_repository: Prevent panic with missing
EncryptionConfigurationattribute in API response (#14584) - resource/aws_wafv2_rule_group: Prevent unnecessary resource recreation with
ruleupdates (#14617) - resource/aws_wafv2_web_acl: Prevent unnecessary resource recreation with
ruleupdates (#14616)
NOTES:
- resource/aws_route53_zone_association: The addition of cross-account zone association support required the use of new
ListHostedZonesByVPCAPI call and adding the VPC Region to the resource ID for new resources. Restrictive IAM permissions for Terraform and cross-region imports may require updates. (#14215)
FEATURES
- New Data Source:
aws_ec2_spot_price(#12504) - New Resource:
aws_route53_vpc_association_authorization(#14215)
ENHANCEMENTS
- data-source/aws_ecr_repository: Allow
registry_idas an argument (#14368) - data-source/aws_ecr_repository: Add
image_scanning_configurationandimage_tag_mutabilityattributes (#14368) - data-source/aws_ecr_repository: Add
encryption_configurationattribute (#14520) - resource/aws_api_gateway_method_settings: Plan-time validation added to
settingsunauthorized_cache_control_header_strategyandlogging_levelarguments (#12651) - resource/aws_ecr_repository: Add
encryption_configurationattribute (#14520) - resource/aws_lb: Add
subnet_mappingconfiguration blockprivate_ipv4_addressargument (#11404) - resource/aws_rds_global_cluster: Add
force_destroyandsource_db_cluster_identifierarguments (#14487) - resource/aws_rds_global_cluster: Add
global_cluster_membersattribute (#14487) - resource/aws_route53_zone_association: Cross-account zone associations can now be created in conjunction with the new
aws_route53_vpc_association_authorizationresource (#14215) - resource/aws_ssm_parameter: Add
data_typeargument (supportaws:ec2:imageparameters) (#13326)
BUG FIXES
- data-source/aws_availability_zones: Prevent unexpected plan output every apply with
group_namesattribute (#14412) - data-source/aws_s3_bucket: Ensure provider
s3_force_path_styleconfiguration is passed through for getting S3 Bucket location with non-AWS implementations (#14481) - resource/aws_api_gateway_method_settings: Allow
settingscache_ttl_in_secondsargument to be set to 0 (#12651) - resource/aws_elastictranscoder_preset: Prevent empty configuration block panics (#14092)
- resource/aws_lambda_event_source_mapping: Allow
maximum_retry_attemptsargument to be set to 0 (#12479) - resource/aws_rds_cluster: Add an
InvalidDBClusterStateFaultretryable error condition for clusters part of a global cluster (#14420) - resource/aws_rds_cluster: Increase retry timeout for deletion to 2 minutes (#14420)
- resource/aws_rds_cluster: Prevent error when both
global_cluster_identifierandreplication_source_identifierare configured on creation (#14490) - resource/aws_s3_bucket: Ensure provider
s3_force_path_styleconfiguration is passed through for getting S3 Bucket location with non-AWS implementations (#14481) - resource/aws_secretsmanager_secret: Allow retries for IAM eventual consistency errors (#14459)
- resource/aws_security_group: Ensure
name_prefixargument with hex digitsathroughfis properly imported (#14475) - resource/aws_spot_fleet_request: Allow
target_capacityargument to be updated to 0 (#12759) - resource/aws_spot_fleet_request: Wait for modify operation completion (default timeout of 10 minutes) (#12759)
- resource/aws_vpc_dhcp_options_association: Properly trigger resource recreation when VPC is deleted outside Terraform (#14367)
NOTES:
- provider: This version is built using Go 1.14.5, including security fixes to the crypto/x509 and net/http packages.
BREAKING CHANGES
- provider: New versions of the provider can only be automatically installed on Terraform 0.12 and later (#14143)
- provider: All "removed" attributes are cut, using them would result in a Terraform Core level error (#14001)
- provider: Credential ordering has changed from static, environment, shared credentials, EC2 metadata, default AWS Go SDK (shared configuration, web identity, ECS, EC2 Metadata) to static, environment, shared credentials, default AWS Go SDK (shared configuration, web identity, ECS, EC2 Metadata) (#14077)
- provider: The
AWS_METADATA_TIMEOUTenvironment variable no longer has any effect as we now depend on the default AWS Go SDK EC2 Metadata client timeout of one second with two retries (#14077) - provider: Remove deprecated
kinesis_analyticsandr53custom service endpoint arguments (#14238) - data-source/aws_availability_zones: Remove deprecated
blacklisted_namesandblacklisted_zone_idsarguments (#14134) - data-source/aws_directory_service_directory: Return an error when a single result is not found (#14006)
- data-source/aws_ecr_repository: Return an error when a single result is not found (#10520)
- data-source/aws_efs_file_system: Return an error when a single result is not found (#14005)
- data-source/aws_launch_template: Return an error when a single result is not found (#10521)
- data-source/aws_route53_resolver_rule: Trailing period removed from
domain_nameargument set in data-source (#14220) - data-source/aws_route53_zone: Trailing period removed from
nameargument set in data-source (#14220) - resource/aws_acm_certificate:
certificate_body,certificate_chain, andprivate_keyattributes are no longer stored in the Terraform state with hash values (#9685) - resource/aws_acm_certificate:
domain_validation_optionsattribute changed from list to set (#14199) - resource/aws_acm_certificate: Plan-time validation added to
domain_nameandsubject_alternative_namesarguments to prevent usage of strings with trailing periods (#14220) - resource/aws_api_gateway_method_settings: Remove
Computedproperty fromthrottling_burst_limitandthrottling_rate_limitarguments, enabling drift detection (#14266) - resource/aws_api_gateway_method_settings: Update
throttling_burst_limitandthrottling_rate_limitargument defaults to match API default of-1to keep throttling disabled (#14266) - resource/aws_autoscaling_group:
availability_zonesandvpc_zone_identifierargument conflict now reported at plan-time (#12927) - resource/aws_autoscaling_group: Remove
Computedproperty fromload_balancersandtarget_group_arnsarguments, enabling drift detection (#14064) - resource/aws_cloudfront_distribution:
active_trusted_signersargument renamed totrusted_signersto support accessingitemsin Terraform 0.12 (#14339) - resource/aws_cloudwatch_log_group: Automatically trim
:*suffix fromarnattribute (#14214) - resource/aws_codepipeline: Removes
GITHUB_TOKENenvironment variable (#14175) - resource/aws_cognito_user_pool: Remove deprecated
admin_create_user_configconfiguration blockunused_account_validity_daysargument (#14294) - resource/aws_dx_gateway: Remove automatic
aws_dx_gateway_associationresource import (#14124) - resource/aws_dx_gateway_association: Remove deprecated
vpn_gateway_idargument (#14144) - resource/aws_dx_gateway_association_proposal: Remove deprecated
vpn_gateway_idargument (#14144) - resource/aws_ebs_volume: Return an error when
iopsargument set to a value greater than 0 for volume types other thanio1(#14310) - resource/aws_elastic_transcoder_preset: Remove
videoconfiguration blockmax_frame_rateargument default value (#7141) - resource/aws_emr_cluster: Remove deprecated
instance_groupconfiguration block,core_instance_count,core_instance_type, andmaster_instance_typearguments (#14137) - resource/aws_glue_job: Remove deprecated
allocated_capacityargument (#14296) - resource/aws_iam_access_key: Remove deprecated
ses_smtp_passwordattribute (#14299) - resource/aws_iam_instance_profile: Remove deprecated
rolesargument (#14303) - resource/aws_iam_server_certificate: Remove state hashing from
certificate_body,certificate_chain, andprivate_keyarguments for new or recreated resources (#14187) - resource/aws_instance: Return an error when
ebs_block_deviceiopsorroot_block_deviceiopsargument set to a value greater than0for volume types other thanio1(#14310) - resource/aws_lambda_alias: Resource import no longer converts Lambda Function name to ARN (#12876)
- resource/aws_launch_template:
network_interfacesdelete_on_terminationargument changed frombooltostringtype (#8612) - resource/aws_lb_listener_rule: Remove deprecated
conditionconfiguration blockfieldandvaluesarguments (#14309) - resource/aws_msk_cluster: Update
encryption_infoencryption_in_transitclient_brokerargument default to match API default ofTLS(#14132) - resource/aws_rds_cluster: Update
scaling_configurationmin_capacityargument default to match API default of1(#14268) - resource/aws_route53_resolver_rule: Trailing period removed from
domain_nameargument set in resource (#14220) - resource/aws_route53_zone: Trailing period removed from
nameargument set in resource (#14220) - resource/aws_s3_bucket: Remove automatic
aws_s3_bucket_policyresource import (#14121) - resource/aws_s3_bucket: Convert
regionto read-only attribute (#14127) - resource/aws_s3_bucket_metric: Update
filterargument to require at least one of theprefixortagsnested arguments (#14230) - resource/aws_security_group: Remove automatic
aws_security_group_ruleresource import (#12616) - resource/aws_ses_domain_identity: Plan-time validation added to
domainargument to prevent usage of strings with trailing periods (#14220) - resource/aws_ses_domain_identity_verification: Plan-time validation added to
domainargument to prevent usage of strings with trailing periods (#14220) - resource/aws_sns_platform_application:
platform_credentialandplatform_principalattributes are no longer stored in the Terraform state with hash values (#3894) - resource/aws_spot_fleet_request: Remove 24 hour default for
valid_untilargument (#9718) - resource/aws_ssm_maintenance_window_task: Remove deprecated
logging_infoandtask_parametersconfiguration blocks (#14311)
FEATURES
- New Data Source: aws_workspaces_directory (#13529)
ENHANCEMENTS
- provider: Always enable shared configuration file support (no longer require
AWS_SDK_LOAD_CONFIGenvironment variable) (#14077) - provider: Add
assume_roleconfiguration blockduration_seconds,policy_arns,tags, andtransitive_tag_keysarguments (#14077) - data-source/aws_instance: Add
secondary_private_ipsattribute (#14079) - data-source/aws_s3_bucket: Replace
GetBucketLocationAPI call with custom HTTP call for FIPS endpoint support (#14221) - resource/aws_acm_certificate: Enable
domain_validation_optionsusage in downstream resourcecountandfor_eachreferences (#14199) - resource/aws_api_gateway_authorizer: Add plan-time validation to
authorizer_credentialsargument (#12643) - resource/aws_api_gateway_method_settings: Add import support (#14266)
- resource/aws_apigatewayv2_integration: Add
request_parametersattribute (#14080) - resource/aws_apigatewayv2_integration: Add
tls_configattribute (#13013) - resource/aws_apigatewayv2_route: Support for updating route key (#13833)
- resource/aws_apigatewayv2_stage: Make
deployment_idaComputedattribute (#13644) - resource/aws_fsx_lustre_file_system: Add
deployment_typeandper_unit_storage_throughputattributes (#13639) - resource_aws_fsx_windows_file_system - add
storage_typeargument. (#14316) - resource_aws_fsx_windows_file_system: add support for multi-az (#12676)
- resource_aws_fsx_windows_file_system: add
SINGLE_AZ_2deployment type (#12676) - resource_aws_fsx_windows_file_system: adds
preferred_file_server_ip,remote_administration_endpointattributes (#12676) - resource/aws_instance: Add
secondary_private_ipsargument (conflicts withnetwork_interfaceconfiguration block) (#14079)
BUG FIXES
- provider: Ensure nil is not passed to RetryError helpers, may result in some bug fixes (#14104)
- provider: Ensure configured STS endpoint is used during
AssumeRoleAPI calls (#14077) - provider: Prefer AWS shared configuration over EC2 metadata credentials by default (#14077)
- provider: Prefer CodeBuild, ECS, EKS credentials over EC2 metadata credentials by default (#14077)
- data-source/aws_lb:
enable_http2now properly set (#14167) - resource/aws_acm_certificate: Prevent unexpected ordering differences with
domain_validation_optionsattribute (#14199) - resource/aws_api_gateway_authorizer: Allow
authorizer_result_ttl_in_secondsto be set to 0 (#12643) - resource/aws_apigatewayv2_integration: Correctly handle the
integration_methodattribute for AWS Lambda integrations(#13266) - resource/aws_apigatewayv2_integration: Correctly handle the
passthrough_behaviorattribute for HTTP APIs (#13062) - resource/aws_apigatewayv2_stage: Correctly handle
default_route_settingandroute_settingdata_trace_enabledandlogging_levelfor HTTP APIs.logging_levelis nowComputed, meaning Terraform will only perform drift detection of its value when present in a configuration. (#13809) - resource/aws_appautoscaling_target: Only retry
DeregisterScalableTargetretries on all errors on deletion (#14259) - resource/aws_dx_gateway_association: Increase default create/update/delete timeouts to 30 minutes (#14144)
- resource/aws_codepipeline: Only retry
CreatePipelineerrors for IAM eventual consistency errors (#14264) - resource/aws_elasticsearch_domain: Update method to properly set
advanced_security_options(#14167) - resource/aws_lambda_function: Increase IAM retry timeout for creation to standard 2 minute timeout (#14291)
- resource/aws_lb_cookie_stickiness_policy:
lb_portnow properly set (#14167) - resource/aws_network_acl_rule: Immediately return
DescribeNetworkAclserrors on creation (#14261) - resource/aws_s3_bucket: Replace
GetBucketLocationAPI call with custom HTTP call for FIPS endpoint support (#14221) - resource/aws_sns_topic_subscription: Immediately return
ListSubscriptionsByTopicerrors (#14262) - resource/aws_spot_fleet_request: Only retry
RequestSpotFleeton IAM eventual consistency errors and use standard 2 minute timeout (#14265) - resource/aws_spot_instance_request:
primary_network_interface_idnow properly set (#14167) - resource/aws_ssm_activation: Only retry
CreateActivationon IAM eventual consistency errors and use standard 2 minute timeout (#14263) - resource/aws_ssm_association:
parametersnow properly set (#14167)
For information on prior major releases, see their changelogs: