github Azure/terraform-azurerm-avm-res-network-networksecuritygroup v0.6.0

3 hours ago

Breaking changes

This release moves the module from the AzureRM provider to AzAPI. Existing deployments are adopted in place through moved blocks, and nothing is destroyed or recreated. Read the upgrade steps below before you upgrade.

  • Requires Terraform 1.11 or later (was 1.9).
  • Replaces the resource_group_name input with parent_id, the resource ID of the resource group.
  • Manages every resource with AzAPI. The module no longer requires the AzureRM provider, and it now requires the hashicorp/time provider (~> 0.13).
  • The security_rules output no longer includes timeouts.
  • Role names are looked up in the resource group, so a custom role that can only be assigned on the network security group itself must be given by ID.

Upgrading from 0.5.x

  1. Replace resource_group_name with parent_id:

    parent_id = "/subscriptions/<subscription-id>/resourceGroups/<resource-group-name>"
  2. Run terraform init -upgrade, then terraform plan.

  3. Expect in-place updates, plus new resources that create nothing in Azure: random_uuid resources that name role assignments, a time_sleep resource when a lock is configured, and telemetry resources when enable_telemetry is true. Don't apply a plan that destroys or replaces anything.

  4. Apply the plan. A second plan reports no changes.

A ReadOnly lock and cross-tenant role assignments need extra steps. See Upgrading from a version that used the AzureRM provider in the README.

Other changes

  • Adds the resource_types, retry, ignore_body_changes and lock.notes inputs. timeouts now applies to every resource.
  • Updating the network security group, for example its tags, keeps every security rule, including rules added by other configurations, Azure services or policy.
  • Fixes role assignments that set a tenant-level role definition ID (/providers/Microsoft.Authorization/roleDefinitions/<guid>), which were replaced on every apply.
  • A role name that doesn't exist now fails during plan.
  • Adds the with_interfaces example.

What's Changed

Other Changes

  • feat!: migrate the network security group module to azapi by @thomascoats in #185

New Contributors

Full Changelog: v0.5.2...v0.6.0

Don't miss a new terraform-azurerm-avm-res-network-networksecuritygroup release

NewReleases is sending notifications on new releases.