Repository navigation
chore(deps): update terraform aws to v6.68.0 - #33
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
February 12, 2026 06:12
9d849ef to
0325594
Compare
📝 Terraform Plan→ Resource Changes: 0 to create, 17 to update, 1 to re-create, 0 to delete, 0 ephemeral. ♻️ Update
|
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
February 13, 2026 17:44
0325594 to
e848a0b
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
February 18, 2026 21:15
e848a0b to
8c398bd
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
2 times, most recently
from
March 4, 2026 22:07
8bab59e to
5492ed9
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
March 5, 2026 22:01
5492ed9 to
60ec029
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
March 11, 2026 21:10
60ec029 to
96ede75
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
March 18, 2026 21:38
96ede75 to
00680d3
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
March 26, 2026 01:05
00680d3 to
243450b
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
April 2, 2026 02:04
243450b to
76e08df
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
April 9, 2026 00:50
76e08df to
0a37b8d
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
April 16, 2026 10:50
0a37b8d to
dad1c0e
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
April 23, 2026 02:44
dad1c0e to
04f8b79
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
April 30, 2026 05:27
04f8b79 to
382e601
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
May 7, 2026 02:00
382e601 to
f58add7
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
June 18, 2026 03:09
887759a to
9bc38c3
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
June 24, 2026 20:57
9bc38c3 to
1e1d5fb
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
July 1, 2026 21:06
1e1d5fb to
d389b35
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
July 8, 2026 23:29
d389b35 to
1004b2e
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
July 15, 2026 21:31
1004b2e to
914174a
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
July 25, 2026 03:55
914174a to
9956f2b
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
July 29, 2026 12:36
9956f2b to
a82f5bf
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
July 29, 2026 18:00
a82f5bf to
86668b7
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
July 29, 2026 22:41
86668b7 to
5e4275f
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
August 5, 2026 14:39
5e4275f to
930e484
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
August 12, 2026 23:15
930e484 to
f284a06
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
August 13, 2026 19:43
f284a06 to
2775ea9
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
August 19, 2026 22:41
2775ea9 to
91df4ca
Compare
renovate
Bot
force-pushed
the
renovate/aws-6.x
branch
from
August 26, 2026 23:35
91df4ca to
3601934
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
6.30.0→6.68.0Release Notes
hashicorp/terraform-provider-aws (aws)
v6.68.0Compare Source
BREAKING CHANGES:
availability_zonesnow validates that at most 3 items are provided at plan time. This is acceptable in a minor version because AWS would always reject requests with more than 3 availability zones at apply time. (#50015)availability_zonesnow validates that at most 3 items are provided at plan time. This is acceptable in a minor version because AWS would always reject requests with more than 3 availability zones at apply time. (#50014)FEATURES:
aws_lambdamicrovms_image_version(#50299)aws_odb_autonomous_database(#48991)aws_ec2_transit_gateway_route(#50202)aws_ram_resource_association(#49901)aws_odb_autonomous_database(#48991)aws_odb_autonomous_database_secrets_manager_integration(#48991)ENHANCEMENTS:
platform_versionargument (#50081)availability_zonescontains at most 3 items, failing at plan time instead of forcing a destructive replacement (#50015)grafana_versionargument to support v13.2 (#50234)connection_tracking_specificationargument (#50119)availability_zonescontains at most 3 items, failing at plan time instead of forcing a destructive replacement (#50014)BUG FIXES:
config_parameterwhen not specified (#50255)v6.67.0Compare Source
NOTES:
FEATURES:
aws_bedrockruntime_apply_guardrail(#50155)aws_default_security_group(#50120)aws_directory_service_ip_route(#50138)aws_directoryservicedata_user(#50001)aws_ec2_transit_gateway_route_table_propagation(#50193)aws_directory_service_ip_route(#50138)aws_directory_service_ip_routes_exclusive(#50204)aws_directoryservicedata_user(#50001)ENHANCEMENTS:
domain_name(#50189)enable_www_subdomainto befalsefor wildcard domain (#50189)tagsandtags_allattributes (#49746)TF_AWS_ROUTE53_RECORD_BATCH_READSenvironment variable to reduce AWS API calls when managing many records in a zone (#48525)maximum_message_sizeargument (#50111)BUG FIXES:
dns_targetwhen importing (#50206)interface conversion: interface {} is nil, not map[string]interface {}panics whencapacity_reservation_targetis empty (#50084)environment_variablesis unset (#50088)regiontoauthorized_aws_regionmigration incorrectly forcing resource replacement (#49851)source_db_cluster_identifieris specified, fixing race condition with downstream resources (#48076)v6.66.0Compare Source
NOTES:
FEATURES:
aws_efs_mount_target(#50057)aws_iam_openid_connect_provider(#50024)aws_msk_channel(#49266)ENHANCEMENTS:
target_typeandtimeout_configurationattributes to thelifecycle_hookblock. (#48128)api_key_secret_sourceargument andapi_key_secret_configconfiguration block to support customer-managed AWS Secrets Manager secrets (#48629)target_typeandtimeout_configurationarguments to thelifecycle_hookconfiguration block to support ECSPAUSEdeployment hooks.hook_target_arnandrole_arnare now Optional (still required forAWS_LAMBDAhooks). (#48128)BUG FIXES:
source_parameters.self_managed_kafka_parameters.server_root_ca_certificatebeing sent to the API as an empty string instead of being omitted, which causedUpdatePipeto fail with aValidationExceptionwhen the attribute was unset (#40116)config_parameterentries from state and allow newly returned config parameter keys without a provider update (#49939)v6.65.0Compare Source
NOTES:
FEATURES:
aws_api_gateway_deployment(#49820)aws_apigatewayv2_integration(#48425)aws_dms_migration_project(#49936)aws_ec2_transit_gateway_policy_table_entry(#49256)aws_glue_catalog_table(#49953)aws_iam_group(#49994)aws_iam_user_policy(#49993)aws_lambda_resource_policy(#49866)aws_network_acl(#50020)aws_network_acl_rule(#49916)aws_rds_cluster_instance(#50036)aws_wafv2_ip_set(#50031)aws_dms_migration_project(#49936)aws_ec2_transit_gateway_policy_table_entry(#49256)aws_lambda_resource_policy(#49866)ENHANCEMENTS:
discovery_configuration.authorizer_configuration.custom_jwt_authorizer.private_endpointanddiscovery_configuration.authorizer_configuration.custom_jwt_authorizer.private_endpoint_overrideattributes (#49964)encryption_configurationattribute (#49964)auto_detection_configurationandencryption_configurationconfiguration blocks (#49964)discovery_configuration.authorizer_configuration.custom_jwt_authorizer.private_endpointanddiscovery_configuration.authorizer_configuration.custom_jwt_authorizer.private_endpoint_overrideconfiguration blocks (#49964)callback_urlattribute (#48517)client_authentication_method,on_behalf_of_token_exchange_config,private_endpoint,private_endpoint_override, andprivate_key_jwt_configarguments tooauth2_provider_config.custom_oauth2_provider_configconfiguration block (#48517)client_secret_configandclient_secret_sourcearguments tooauth2_provider_config.custom_oauth2_provider_config,oauth2_provider_config.github_oauth2_provider_config,oauth2_provider_config.google_oauth2_provider_config,oauth2_provider_config.microsoft_oauth2_provider_config,oauth2_provider_config.salesforce_oauth2_provider_config, andoauth2_provider_config.slack_oauth2_provider_configconfiguration blocks (#48517)oauth2_provider_config.atlassian_oauth2_provider_config,oauth2_provider_config.included_oauth2_provider_config, andoauth2_provider_config.linkedin_oauth2_provider_configconfiguration blocks (#48517)oauth2_provider_config.microsoft_oauth2_provider_config.tenant_id,oauth2_provider_config.microsoft_oauth2_provider_config.tenant_id_wo, andoauth2_provider_config.microsoft_oauth2_provider_config.tenant_id_wo_versionarguments (#48517)token_endpoint_auth_methodsattribute to alloauth2_provider_config.*.oauth_discoveryconfiguration blocks (#48517)bgp_asn_longargument (#49590)bgp_asn_longargument (#49591)bgp_asn_longargument (#49591)bgp_asn_longargument (#49591)bgp_asn_longargument (#49589)storage_descriptor.additional_locations,storage_descriptor.bucket_columns,storage_descriptor.columns.parameters,storage_descriptor.parameters,storage_descriptor.ser_de_info,storage_descriptor.ser_de_info.parameters,view_definition,view_definition.definer,view_definition.is_protected,view_definition.representations.validation_connection,view_definition.representations.view_expanded_text,view_definition.representations.view_original_text,view_definition.sub_object_version_ids, andview_definition.sub_objectsto Optional and Computed (#49953)status_to_updateargument (#49954)BUG FIXES:
discovery_configuration.authorizer_configuration.custom_jwt_authorizer.allowed_audience,discovery_configuration.authorizer_configuration.custom_jwt_authorizer.allowed_clients, ordiscovery_configuration.authorizer_configuration.custom_jwt_authorizer.allowed_scopesis configured (#50025)BadRequestException: Environment variables cannot have an empty keywhen clearingauto_branch_creation_config.environment_variables(#49858)BadRequestException: Environment variables cannot have an empty keywhen clearingenvironment_variables(#49858)data_source_configuration.managed_knowledge_base_connector_configuration.deletion_protection_configuration.deletion_protection_thresholdto Optional and Computed (#49977)policy_statementoptional (#49509)replicablocks not being detected as a change (#39235)field_to_match.single_header.nameandfield_to_match.single_query_argument.namerejecting values the AWS WAF API accepts, such as names containing.(#49984)field_to_match.single_header.nameandfield_to_match.single_query_argument.namerejecting values the AWS WAF API accepts, such as names containing.(#49984)v6.64.0Compare Source
FEATURES:
aws_accountaccess_application(#49553)aws_accountaccess_entitlements(#49554)aws_agentregistry_registry(#49806)aws_rds_events(#49783)aws_accountaccess_entitlement(#49552)aws_agentregistry_registry(#49549)aws_bedrock_model_invocation_job(#49877)aws_dms_data_provider(#49897)aws_dms_instance_profile(#49747)aws_fis_safety_lever_state(#49841)aws_lambda_alias(#49706)aws_accountaccess_entitlement(#49552)aws_agentregistry_registry(#49549)aws_bedrock_model_invocation_job(#49877)aws_dms_data_provider(#49897)aws_dms_instance_profile(#49747)aws_fis_safety_lever_state(#49841)ENHANCEMENTS:
workspace_access_properties.access_endpoint_configattribute (#49849)version_labelargument (#49881)model.bedrock_model_config.additional_paramsargument (#48498)model.bedrock_model_config.api_formatandmodel.openai_model_config.api_formatarguments (#48521)model.gemini_model_config.additional_paramsandmodel.openai_model_config.additional_paramsarguments (#48656)model.litellm_model_configconfiguration block (#48656)skill.aws_skills,skill.git, andskill.s3configuration blocks (#48656)max_tokensto Optional and Computed (#48656)skill.pathto Optional (#48656)system_promptto Required (#48656)warm_up_configurationconfiguration block (#49873)warning_event_categoriesargument. When set, surface a warning diagnostic for each matching RDS event reported during create or update. Requires therds:DescribeEventsIAM permission (#49783)managed_instances_provider.auto_repair_configurationconfiguration block (#49763)kafka_cluster.client_authenticationto configuremtlsorsasl_scramauthentication to an Apache Kafka cluster (#49265)kafka_cluster.encryption_in_transitto supply a custom root CA certificate for an Apache Kafka cluster (#49265)kafka_cluster.apache_kafka_clusterblock and thereplication_info_list.source_kafka_cluster_idandtarget_kafka_cluster_idarguments (#49265)warning_event_categoriesargument. When set, surface a warning diagnostic for each matching RDS event reported during create or update. Requires therds:DescribeEventsIAM permission (#49783)warning_event_categoriesargument. When set, surface a warning diagnostic for each matching RDS event reported during create or update. Requires therds:DescribeEventsIAM permission (#49783)BUG FIXES:
setting workspace_access_properties: Invalid address to seterrors (#49849)Role validation failed for '...'. Please verify that the role exists and its trust policy allows assumption by this serviceIAM eventual consistency errors on Create. Because this error is returned while waiting for a newly-created harness to stabilize, the failed harness is deleted and creation is restarted. You may see CloudTrail events that reflect this sequence of operations (#48656)v6.63.0Compare Source
FEATURES:
aws_accountaccess_application(#49551)aws_key_pair(#49712)aws_lambdamicrovms_image(#49724)aws_lambdamicrovms_microvm(#48984)aws_mailmanager_archive(#49580)aws_opensearchserverless_access_policy(#49717)aws_opensearchserverless_lifecycle_policy(#49718)aws_opensearchserverless_security_config(#49769)aws_opensearchserverless_security_policy(#49770)aws_opensearchserverless_vpc_endpoint(#49774)aws_accountaccess_application(#49551)aws_datazone_policy_grant(#47050)aws_lambdamicrovms_microvm(#48984)aws_mailmanager_archive(#49580)ENHANCEMENTS:
prefix_pool_size_ipv4,prefix_pool_size_ipv6,prefix_pool_unallocated_count_ipv4, andprefix_pool_unallocated_count_ipv6attributes (#49711)rate_limiter_statusattribute (#48910)pod_gc_controller_configattribute to thekube_controller_manager_configconfiguration block (#49728)pod_gc_controller_configattribute to thecontrol_plane_component_config.kube_controller_manager_configconfiguration block (#49730)target_configuration.http.agentcore_runtime.schemaandtarget_configuration.http.passthroughconfiguration blocks (#48704)target_configuration.inferenceconfiguration block (#48705)target_configuration.mcp.connectorconfiguration block (#48706)prefix_pool_size_ipv4,prefix_pool_size_ipv6,prefix_pool_unallocated_count_ipv4, andprefix_pool_unallocated_count_ipv6attributes (#49711)rate_limiter_statusattribute (#48910)prefix_pool_allocated_count_ipv4andprefix_pool_allocated_count_ipv6attributes (#49711)rate_limitargument (#48910)prefix_pool_allocated_count_ipv4andprefix_pool_allocated_count_ipv6arguments (#49711)rate_limitargument (#48910)prefix_pool_allocated_count_ipv4andprefix_pool_allocated_count_ipv6attributes (#49711)rate_limitargument (#48910)prefix_pool_allocated_count_ipv4andprefix_pool_allocated_count_ipv6arguments (#49711)rate_limiter_statusattribute (#48910)prefix_pool_allocated_count_ipv4andprefix_pool_allocated_count_ipv6arguments (#49711)rate_limitargument (#48910)rate_limitargument (#48910)prefix_pool_allocated_count_ipv4andprefix_pool_allocated_count_ipv6arguments (#49711)rate_limitargument (#48910)pod_gc_controller_configargument to thekube_controller_manager_configconfiguration block (#49725)kms_key_arnargument (#49406)BUG FIXES:
assume_role_with_web_identity.web_identity_tokenbeing rejected whenAWS_WEB_IDENTITY_TOKEN_FILEis set (#49671)name_prefixlength validation to allow the correct maximum of 229 characters (#49197)name_prefixlength validation to allow the correct maximum of 229 characters (#49197)all_regionsis enabled (#49743)name_prefixlength validation to allow the correct maximum of 229 characters (#49197)object_lock_configuration.object_lock_enabledtoEnabledno longer forces a replacement (#36530)object_lock_enabledtotrueno longer forces a replacement (#36530)v6.62.0Compare Source
NOTES:
manage_master_user_passwordis enabled, the managed secret's automatic rotation can now be disabled usingaws_secretsmanager_secret_rotationwithrotation_enabled = false(#49659)manage_master_user_passwordis enabled, the managed secret's automatic rotation can now be disabled usingaws_secretsmanager_secret_rotationwithrotation_enabled = false(#49659)FEATURES:
aws_db_instance(#49602)aws_dsql_cluster(#49657)aws_dsql_cluster_policy(#49676)aws_ecr_lifecycle_policy(#49696)aws_ecs_cluster(#49682)aws_pinpointsmsvoicev2_keyword(#48967)aws_pinpointsmsvoicev2_keyword(#48967)aws_sesv2_multi_region_endpoint(#49660)ENHANCEMENTS:
associated_system.user_journey_idsattribute (#49603)name(#48766)indexed_keyentries in place instead of forcing a new resource (#48877)indexed_keyfromListtoSetto ignore ordering (#48877)configuration.self_managed_configurationargument in support of self-managed strategies (#48766)memory_record_schemaargument (#48765)description(#48766)descriptionto Optional and Computed (#48766)name,code, andcommentagainst CloudFront's documented constraints during plan instead of failing at apply time (#49395)bgp_asn_longargument (#49587)bgp_asn_longargument (#49588)auth_token_woandauth_token_wo_versionwrite-only arguments (#49268)tag_propagation_configurationconfiguration block torule.destination.destination_logs_configuration, andtag_propagation_statusandtag_propagation_failure_reasonattributes (#49656)user_journey_idsargument to theassociated_systemconfiguration block (#49603)rotation_enabledis now configurable (previously read-only) and can be set tofalseto disable rotation for a secret. This is particularly useful for secrets whose rotation is otherwise managed by AWS, such as an RDS master user password secret created withmanage_master_user_password(#49659)rotation_rulesis now optional, and must be omitted whenrotation_enabledisfalse(#49659)workspace_access_properties.access_endpoint_configargument (#49668)BUG FIXES:
name(#48766)nameis modified (#48766)name(#48766)resource_configuration.resource_tagfromListtoSetto ignore ordering (#49585)purchase_timeasOptionalandComputed(#49679)queuedas a target state during creation (#49678)upfront_payment_amountasComputedto fix aProvider produced inconsistent result after applyerror forNo Upfrontsavings plans (#49264)v6.61.0Compare Source
FEATURES:
aws_odb_iam_role_association(#46794)aws_ec2_ami_launch_permission(#49461)aws_iam_instance_profile(#49576)aws_lambdacore_network_connector(#49387)aws_mailmanager_relay(#49394)aws_resiliencehubv2_assertion(#48329)aws_resiliencehubv2_service_function(#48328)aws_resiliencehubv2_user_journey(#48330)aws_dsql_cluster_policy(#47748)aws_lambdacore_network_connector(#49387)aws_lambdamicrovms_image(#48950)aws_mailmanager_relay(#49394)aws_odb_iam_role_association(#46794)aws_resiliencehubv2_assertion(#48329)aws_resiliencehubv2_service_function(#48328)aws_resiliencehubv2_user_journey(#48330)aws_securityhub_feature_v2(#49503)ENHANCEMENTS:
network_typeattribute (#49512)network_typeattribute (#49514)condition.source_ip.ip_address_typeattribute (#49476)associated_systemattribute (#49498)idle_timeout_secondsattribute (#49540)environment_actual(#48815)network_typeargument (#49512)network_typeargument (#49513)network_typeargument (#49514)condition.source_ip.ip_address_typeargument (#49476)condition.source_ip.valuesto Optional (#49476)Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.