github crossplane-contrib/provider-upjet-aws v2.9.0

5 hours ago

Overview

v2.9.0 is a minor release on top of v2.8.1. It introduces Plan: an offline, credential-free preview of what applying a managed resource would change, computed by the provider itself. It also adds 26 new managed resources, including three new API groups (agentregistry, lambdacore and lambdamicrovms), filesystem mounts for CodeInterpreter.bedrockagentcore, and fixes for several perpetual update loops. Among them: PutBucketEncryption calls on every reconcile of BucketServerSideEncryptionConfiguration, rejected access_logs updates on Gateway Load Balancers, and drift on RDS Cluster members.

The Terraform AWS provider stays at v6.65.0. The fork release moves from v6.65.0-upjet.1 to v6.65.0-upjet.2 to add the CodeInterpreter filesystem configuration, and the pinned fork commit carries a DynamoDB GSI fix.

The release carries one breaking bugfix API change: OriginRequestPolicy.cloudfront is now identified by its policy ID instead of its name, and name moves back into spec.forProvider. See the breaking bugfix API changes section below before upgrading.

Field paths below apply to both the cluster-scoped (*.aws.upbound.io) and namespaced (*.aws.m.upbound.io) variants of each resource.


⚠️ Breaking bugfix API changes

OriginRequestPolicy.cloudfront: external name is now the policy ID (#2227)

aws_cloudfront_origin_request_policy was configured to use the policy name as its external name and Terraform ID, but CloudFront reads origin request policies by ID. The provider could never observe a policy addressed by its name: every reconcile tried to create it again, which failed with OriginRequestPolicyAlreadyExists or, when the name was free, created an extra policy (#2226). The resource now works like CachePolicy, ResponseHeadersPolicy and OriginAccessControl in the same group. Consequently:

  • crossplane.io/external-name now holds the policy ID that CloudFront assigns, not the policy name.
  • spec.forProvider.name and spec.initProvider.name are added to the CRD, and name is required when managementPolicies include Create, Update or *. status.atProvider.name reports the observed name.
  • On the cluster-scoped API, name exists only in cloudfront.aws.upbound.io/v1beta2. Move manifests that still use v1beta1 to v1beta2. The namespaced API uses cloudfront.aws.m.upbound.io/v1beta1.

Update every OriginRequestPolicy as part of the upgrade. Set spec.forProvider.name to the policy name, and if crossplane.io/external-name still holds the name, replace it with the policy ID (aws cloudfront list-origin-request-policies --type custom lists both). A resource whose external name is the policy name is seen as absent, and the provider tries to create the policy again.

⚠️ If your compositions set the crossplane.io/external-name annotation to choose the policy name, update them. Set spec.forProvider.name instead, and either drop the annotation or set it to the policy ID.

# v2.8.1
metadata:
  annotations:
    crossplane.io/external-name: example-policy
spec:
  forProvider:
    comment: Example origin request policy

# v2.9.0
metadata:
  annotations:
    crossplane.io/external-name: <policy-id> # omit when creating a new policy
spec:
  forProvider:
    name: example-policy
    comment: Example origin request policy

Offline Diff Server (alpha)

This provider now support an offline gRPC-based diff server that computes diffs/plans for managed resources without connecting to Kubernetes or making cloud API calls.

The diff server allows users to preview what would change before applying a resource, without interacting with live infrastructure.

Key capabilities:

Computes CREATE, UPDATE, REPLACE, and NO_OP actions from the desired resource and its optional observed state.
Reports field-level changes, including planned values, replacement requirements, and change origins.
Accepts a PlanRequest with the desired resource, an optional actual resource, and an in-memory store containing the required ProviderConfig and referenced Secrets.
Supports both namespaced and cluster-scoped managed resources, including previously served API versions.
Runs without cloud credentials or live infrastructure access.
Exposes the PlanService.Plan gRPC API through the internal diff-server subcommand. Support is advertised through the DiffServer package capability.
Known limitations:

Some resources require cloud API calls during planning and cannot be fully evaluated offline. These requests may return FAILED_PRECONDITION, allowing callers to fall back to a raw diff.
Accurate plans depend on a complete observed state. Missing fields in status.atProvider may produce unexpected changes.
The gRPC API is experimental and may change without backward compatibility guarantees.
Resource coverage and planning behavior may vary between providers.

Design and implementation:


New Features

New Resources

All new resources are available at v1beta1 in both the cluster-scoped and namespaced APIs.

Group Kind(s) Terraform resource(s) PR
agentregistry Registry aws_agentregistry_registry #2256
apigateway DomainNameAccessAssociation aws_api_gateway_domain_name_access_association #2131
apigatewayv2 RoutingRule aws_apigatewayv2_routing_rule #2205
bedrock CustomModel, EvaluationJob, FoundationModelAgreement, GuardrailVersion, ModelInvocationJob, ModelInvocationLoggingConfiguration, ProvisionedModelThroughput, UseCaseForModelAccess aws_bedrock_custom_model, _evaluation_job, _foundation_model_agreement, _guardrail_version, _model_invocation_job, _model_invocation_logging_configuration, _provisioned_model_throughput, _use_case_for_model_access #2256
bedrockagent AgentKnowledgeBaseAssociation, DataSource, KnowledgeBase aws_bedrockagent_agent_knowledge_base_association, _data_source, _knowledge_base #2253
bedrockagent Flow, Prompt aws_bedrockagent_flow, aws_bedrockagent_prompt #2256
cloudfront KeyValueStore aws_cloudfront_key_value_store #2249
cloudwatchlogs Delivery, DeliveryDestination, DeliveryDestinationPolicy, DeliverySource aws_cloudwatch_log_delivery, _delivery_destination, _delivery_destination_policy, _delivery_source #2255
grafana WorkspaceServiceAccount, WorkspaceServiceAccountToken aws_grafana_workspace_service_account, _service_account_token #2241
lambdacore NetworkConnector aws_lambdacore_network_connector #2256
lambdamicrovms Image, MicroVM aws_lambdamicrovms_image, aws_lambdamicrovms_microvm #2256

agentregistry, lambdacore and lambdamicrovms are new API groups, published as new family packages: provider-aws-agentregistry, provider-aws-lambdacore and provider-aws-lambdamicrovms.

Notes on the new resources:

  • KeyValueStore.cloudfront uses the store name as its external name. Function.cloudfront can now resolve keyValueStoreAssociations from KeyValueStore ARNs through keyValueStoreAssociationsRefs and keyValueStoreAssociationsSelector.
  • CloudWatch Logs delivery resources configure vended logs, such as CloudFront standard logging v2 to CloudWatch Logs, S3 or Firehose. DeliverySource.resourceArn can reference a CloudFront Distribution, DeliveryDestination a log Group, and Delivery its DeliverySource and DeliveryDestination.
  • WorkspaceServiceAccountToken.grafana publishes the token to its connection details Secret under attribute.key.
  • Registry.agentregistry is the replacement for aws_bedrockagentcore_registry, which the Terraform provider deprecates and this provider does not add. aws_bedrockagent_agent_alias, _agent_action_group and _agent_collaborator are also left out, because Bedrock Agents Classic is in maintenance mode.
  • Not covered by end-to-end tests: CustomModel, EvaluationJob, ModelInvocationJob and ProvisionedModelThroughput start billed or long-running workloads; FoundationModelAgreement needs an offer token; UseCaseForModelAccess submits an account-wide form that cannot be deleted; AgentKnowledgeBaseAssociation needs a Bedrock Agents Classic Agent, which AWS rejects in accounts without prior usage.

CodeInterpreter.bedrockagentcore: filesystem mounts

CodeInterpreter accepts a new filesystemConfiguration that mounts an S3 Files or EFS access point into code interpreter sessions (s3FilesConfiguration or efsConfiguration, each with accessPointArn, fileSystemArn and mountPath). The ARNs can reference AccessPoint.s3files, FileSystem.s3files, AccessPoint.efs and FileSystem.efs. A filesystem mount requires the VPC network mode, so networkConfiguration.vpcConfig.securityGroups and subnets can now reference SecurityGroup.ec2 and Subnet.ec2.

The field is not in the upstream Terraform provider. It comes from the fork release v6.65.0-upjet.2 (upbound/terraform-provider-aws#333). (#2252)


Dependency Updates

Dependency v2.8.1 v2.9.0
Terraform AWS Provider v6.65.0 (fork v6.65.0-upjet.1, d7cd6f2fe022) v6.65.0 (fork v6.65.0-upjet.2, 1f5ae7c90e44)
Upjet v2.5.0 v2.5.1-0.20261005082904-c3b7d449d0d4
Kubernetes libraries v0.36.2 v0.37.1
controller-runtime v0.24.1 v0.25.2
controller-tools v0.20.1 v0.22.0
Go 1.26.8 1.27.1

crossplane-runtime (v2.5.0-rc.0.0.20260908074656-9b2fb6b1d1ff) and the crossplane/crossplane APIs (v2.4.1) are unchanged. Every CRD is regenerated with controller-tools v0.22.0; apart from the changes in these notes, the CRD schemas are unchanged.


Bug Fixes

  • BucketServerSideEncryptionConfiguration.s3: stopped a PutBucketEncryption call on every reconcile when rule.blockedEncryptionTypes is unset. S3 returns ["SSE-C"] for new buckets, which never matched a spec without the field. An unset blockedEncryptionTypes now accepts the value S3 reports; an explicit value is still enforced. (#2258, #2259)
  • LB.elbv2: Gateway Load Balancers no longer send an access_logs update on every reconcile. AWS rejected the call with Load balancer attribute key 'access_logs.s3.enabled' is not recognized, but the Terraform provider dropped the error, so the resource stayed Ready and Synced and the rejected calls showed up only in CloudTrail. (#2075, #2187)
  • Cluster.rds: clusterMembers is no longer late-initialized into spec.forProvider. The value was written once, so after a ClusterInstance joined or left the cluster it went stale and caused a perpetual diff. (#2052, #2246)

    Existing Cluster resources keep the value already late-initialized into spec.forProvider.clusterMembers. Remove the field from those resources to stop the diff.

  • Table.dynamodb: globalSecondaryIndex readCapacity and writeCapacity changes on an existing table are now applied. The provider dropped them from the diff and reported the table as up to date. (#2264)
  • PlatformApplication.sns: the Terraform import ID is now built from spec.forProvider.platform instead of always using GCM. A PlatformApplication for any other platform, such as APNS or APNS_SANDBOX, could not be imported by its external name. (#2184, #2186)
  • VectorBucket.s3vectors, Index.s3vectors: creation works again. AWS now answers the placeholder ARN that the first observe reads with AccessDeniedException instead of a not-found error, so the provider never called Create. (#2253)
  • Plugin Framework resources: updates are no longer refused with diff contains fields that require resource replacement after a provider restart or an import, when the resource has an empty list, set or map attribute, or an empty singleton block. As part of this fix, upjet omits an empty singleton block from status.atProvider instead of reporting it as {}. Fixed by the upjet bump (crossplane/upjet#766).

What's Changed

  • fix(cloudfront): map origin request policy by id, not name by @ottramst in #2227
  • Add filesystem_configuration to bedrockagentcore CodeInterpreter by @sergenyalcin in #2252
  • feat(bedrockagent): add KnowledgeBase, DataSource and AgentKnowledgeBaseAssociation by @jonasz-lasut in #2253
  • Add aws_cloudfront_key_value_store resource by @danielabelski in #2249
  • feat(cloudwatchlogs): add Delivery, DeliverySource, DeliveryDestination and DeliveryDestinationPolicy by @rr-keys in #2255
  • fix(elbv2): suppress spurious access_logs diff for Gateway Load Balancers by @pujitha24 in #2187
  • fix(s3): suppress rule set re-hash diff on BucketServerSideEncryptionConfiguration by @jakubramut in #2259
  • fix(sns): derive platform application import IDs by @alexdor in #2186
  • Update jlumbroso/free-disk-space action to v2 by @renovate[bot] in #2237
  • Update dependency ubuntu to v26 by @renovate[bot] in #2244
  • Update dependency golangci/golangci-lint to v2.14.0 by @renovate[bot] in #2250
  • Update kubernetes monorepo to v0.37.1 by @renovate[bot] in #2247
  • Update module sigs.k8s.io/controller-runtime to v0.25.2 by @renovate[bot] in #2260
  • fix: add RDS Cluster cluster_members to ignored fields by @fernandezcuesta in #2246
  • Update go module directive to v1.27.1 by @renovate[bot] in #2261
  • Update dependency crossplane/crossplane to v2.4.2 by @renovate[bot] in #2206
  • Update module sigs.k8s.io/controller-tools to v0.22.0 by @renovate[bot] in #2262
  • Add a gRPC diff service implementation by @sergenyalcin in #2257
  • feat: add Bedrock, Agent Registry and Lambda MicroVMs resources by @jonasz-lasut in #2256
  • feat(apigateway): add external-name config for DomainNameAccessAssociation by @aditmeno in #2131
  • Configure aws_apigatewayv2_routing_rule by @scalapaymdacrema in #2205
  • feat(grafana): add WorkspaceServiceAccount and WorkspaceServiceAccountToken resources by @coolguy1771 in #2241
  • Table.dynamodb: apply GSI changes on existing tables by @jonasz-lasut in #2264

New Contributors

Full Changelog: v2.8.1...v2.9.0

Don't miss a new provider-upjet-aws release

NewReleases is sending notifications on new releases.