Overview
v2.9.0 is a minor release on top of v2.8.1. It introduces Plan: an offline, credential-free preview of what applying a managed resource would change, computed by the provider itself. It also adds 26 new managed resources, including three new API groups (agentregistry, lambdacore and lambdamicrovms), filesystem mounts for CodeInterpreter.bedrockagentcore, and fixes for several perpetual update loops. Among them: PutBucketEncryption calls on every reconcile of BucketServerSideEncryptionConfiguration, rejected access_logs updates on Gateway Load Balancers, and drift on RDS Cluster members.
The Terraform AWS provider stays at v6.65.0. The fork release moves from v6.65.0-upjet.1 to v6.65.0-upjet.2 to add the CodeInterpreter filesystem configuration, and the pinned fork commit carries a DynamoDB GSI fix.
The release carries one breaking bugfix API change: OriginRequestPolicy.cloudfront is now identified by its policy ID instead of its name, and name moves back into spec.forProvider. See the breaking bugfix API changes section below before upgrading.
Field paths below apply to both the cluster-scoped (*.aws.upbound.io) and namespaced (*.aws.m.upbound.io) variants of each resource.
⚠️ Breaking bugfix API changes
OriginRequestPolicy.cloudfront: external name is now the policy ID (#2227)
aws_cloudfront_origin_request_policy was configured to use the policy name as its external name and Terraform ID, but CloudFront reads origin request policies by ID. The provider could never observe a policy addressed by its name: every reconcile tried to create it again, which failed with OriginRequestPolicyAlreadyExists or, when the name was free, created an extra policy (#2226). The resource now works like CachePolicy, ResponseHeadersPolicy and OriginAccessControl in the same group. Consequently:
crossplane.io/external-namenow holds the policy ID that CloudFront assigns, not the policy name.spec.forProvider.nameandspec.initProvider.nameare added to the CRD, andnameis required whenmanagementPoliciesincludeCreate,Updateor*.status.atProvider.namereports the observed name.- On the cluster-scoped API,
nameexists only incloudfront.aws.upbound.io/v1beta2. Move manifests that still usev1beta1tov1beta2. The namespaced API usescloudfront.aws.m.upbound.io/v1beta1.
Update every
OriginRequestPolicyas part of the upgrade. Setspec.forProvider.nameto the policy name, and ifcrossplane.io/external-namestill holds the name, replace it with the policy ID (aws cloudfront list-origin-request-policies --type customlists both). A resource whose external name is the policy name is seen as absent, and the provider tries to create the policy again.⚠️ If your compositions set the
crossplane.io/external-nameannotation to choose the policy name, update them. Setspec.forProvider.nameinstead, and either drop the annotation or set it to the policy ID.
# v2.8.1
metadata:
annotations:
crossplane.io/external-name: example-policy
spec:
forProvider:
comment: Example origin request policy
# v2.9.0
metadata:
annotations:
crossplane.io/external-name: <policy-id> # omit when creating a new policy
spec:
forProvider:
name: example-policy
comment: Example origin request policyOffline Diff Server (alpha)
This provider now support an offline gRPC-based diff server that computes diffs/plans for managed resources without connecting to Kubernetes or making cloud API calls.
The diff server allows users to preview what would change before applying a resource, without interacting with live infrastructure.
Key capabilities:
Computes CREATE, UPDATE, REPLACE, and NO_OP actions from the desired resource and its optional observed state.
Reports field-level changes, including planned values, replacement requirements, and change origins.
Accepts a PlanRequest with the desired resource, an optional actual resource, and an in-memory store containing the required ProviderConfig and referenced Secrets.
Supports both namespaced and cluster-scoped managed resources, including previously served API versions.
Runs without cloud credentials or live infrastructure access.
Exposes the PlanService.Plan gRPC API through the internal diff-server subcommand. Support is advertised through the DiffServer package capability.
Known limitations:
Some resources require cloud API calls during planning and cannot be fully evaluated offline. These requests may return FAILED_PRECONDITION, allowing callers to fall back to a raw diff.
Accurate plans depend on a complete observed state. Missing fields in status.atProvider may produce unexpected changes.
The gRPC API is experimental and may change without backward compatibility guarantees.
Resource coverage and planning behavior may vary between providers.
Design and implementation:
- Plan service one-pager - upjet (crossplane/upjet#694)
- crossplane/upjet#765, crossplane/upjet#769
- Provider integration: #2257
New Features
New Resources
All new resources are available at v1beta1 in both the cluster-scoped and namespaced APIs.
| Group | Kind(s) | Terraform resource(s) | PR |
|---|---|---|---|
agentregistry
| Registry | aws_agentregistry_registry
| #2256 |
apigateway
| DomainNameAccessAssociation | aws_api_gateway_domain_name_access_association
| #2131 |
apigatewayv2
| RoutingRule | aws_apigatewayv2_routing_rule
| #2205 |
bedrock
| CustomModel, EvaluationJob, FoundationModelAgreement, GuardrailVersion, ModelInvocationJob, ModelInvocationLoggingConfiguration, ProvisionedModelThroughput, UseCaseForModelAccess | aws_bedrock_custom_model, _evaluation_job, _foundation_model_agreement, _guardrail_version, _model_invocation_job, _model_invocation_logging_configuration, _provisioned_model_throughput, _use_case_for_model_access
| #2256 |
bedrockagent
| AgentKnowledgeBaseAssociation, DataSource, KnowledgeBase | aws_bedrockagent_agent_knowledge_base_association, _data_source, _knowledge_base
| #2253 |
bedrockagent
| Flow, Prompt | aws_bedrockagent_flow, aws_bedrockagent_prompt
| #2256 |
cloudfront
| KeyValueStore | aws_cloudfront_key_value_store
| #2249 |
cloudwatchlogs
| Delivery, DeliveryDestination, DeliveryDestinationPolicy, DeliverySource | aws_cloudwatch_log_delivery, _delivery_destination, _delivery_destination_policy, _delivery_source
| #2255 |
grafana
| WorkspaceServiceAccount, WorkspaceServiceAccountToken | aws_grafana_workspace_service_account, _service_account_token
| #2241 |
lambdacore
| NetworkConnector | aws_lambdacore_network_connector
| #2256 |
lambdamicrovms
| Image, MicroVM | aws_lambdamicrovms_image, aws_lambdamicrovms_microvm
| #2256 |
agentregistry, lambdacore and lambdamicrovms are new API groups, published as new family packages: provider-aws-agentregistry, provider-aws-lambdacore and provider-aws-lambdamicrovms.
Notes on the new resources:
KeyValueStore.cloudfrontuses the store name as its external name.Function.cloudfrontcan now resolvekeyValueStoreAssociationsfromKeyValueStoreARNs throughkeyValueStoreAssociationsRefsandkeyValueStoreAssociationsSelector.- CloudWatch Logs delivery resources configure vended logs, such as CloudFront standard logging v2 to CloudWatch Logs, S3 or Firehose.
DeliverySource.resourceArncan reference a CloudFrontDistribution,DeliveryDestinationa logGroup, andDeliveryitsDeliverySourceandDeliveryDestination. WorkspaceServiceAccountToken.grafanapublishes the token to its connection details Secret underattribute.key.Registry.agentregistryis the replacement foraws_bedrockagentcore_registry, which the Terraform provider deprecates and this provider does not add.aws_bedrockagent_agent_alias,_agent_action_groupand_agent_collaboratorare also left out, because Bedrock Agents Classic is in maintenance mode.- Not covered by end-to-end tests:
CustomModel,EvaluationJob,ModelInvocationJobandProvisionedModelThroughputstart billed or long-running workloads;FoundationModelAgreementneeds an offer token;UseCaseForModelAccesssubmits an account-wide form that cannot be deleted;AgentKnowledgeBaseAssociationneeds a Bedrock Agents ClassicAgent, which AWS rejects in accounts without prior usage.
CodeInterpreter.bedrockagentcore: filesystem mounts
CodeInterpreter accepts a new filesystemConfiguration that mounts an S3 Files or EFS access point into code interpreter sessions (s3FilesConfiguration or efsConfiguration, each with accessPointArn, fileSystemArn and mountPath). The ARNs can reference AccessPoint.s3files, FileSystem.s3files, AccessPoint.efs and FileSystem.efs. A filesystem mount requires the VPC network mode, so networkConfiguration.vpcConfig.securityGroups and subnets can now reference SecurityGroup.ec2 and Subnet.ec2.
The field is not in the upstream Terraform provider. It comes from the fork release v6.65.0-upjet.2 (upbound/terraform-provider-aws#333). (#2252)
Dependency Updates
| Dependency | v2.8.1 | v2.9.0 |
|---|---|---|
| Terraform AWS Provider | v6.65.0 (fork v6.65.0-upjet.1, d7cd6f2fe022)
| v6.65.0 (fork v6.65.0-upjet.2, 1f5ae7c90e44)
|
| Upjet | v2.5.0 | v2.5.1-0.20261005082904-c3b7d449d0d4 |
| Kubernetes libraries | v0.36.2 | v0.37.1 |
| controller-runtime | v0.24.1 | v0.25.2 |
| controller-tools | v0.20.1 | v0.22.0 |
| Go | 1.26.8 | 1.27.1 |
crossplane-runtime (v2.5.0-rc.0.0.20260908074656-9b2fb6b1d1ff) and the crossplane/crossplane APIs (v2.4.1) are unchanged. Every CRD is regenerated with controller-tools v0.22.0; apart from the changes in these notes, the CRD schemas are unchanged.
Bug Fixes
BucketServerSideEncryptionConfiguration.s3: stopped aPutBucketEncryptioncall on every reconcile whenrule.blockedEncryptionTypesis unset. S3 returns["SSE-C"]for new buckets, which never matched a spec without the field. An unsetblockedEncryptionTypesnow accepts the value S3 reports; an explicit value is still enforced. (#2258, #2259)LB.elbv2: Gateway Load Balancers no longer send anaccess_logsupdate on every reconcile. AWS rejected the call withLoad balancer attribute key 'access_logs.s3.enabled' is not recognized, but the Terraform provider dropped the error, so the resource stayedReadyandSyncedand the rejected calls showed up only in CloudTrail. (#2075, #2187)Cluster.rds:clusterMembersis no longer late-initialized intospec.forProvider. The value was written once, so after aClusterInstancejoined or left the cluster it went stale and caused a perpetual diff. (#2052, #2246)Existing
Clusterresources keep the value already late-initialized intospec.forProvider.clusterMembers. Remove the field from those resources to stop the diff.Table.dynamodb:globalSecondaryIndexreadCapacityandwriteCapacitychanges on an existing table are now applied. The provider dropped them from the diff and reported the table as up to date. (#2264)PlatformApplication.sns: the Terraform import ID is now built fromspec.forProvider.platforminstead of always usingGCM. APlatformApplicationfor any other platform, such asAPNSorAPNS_SANDBOX, could not be imported by its external name. (#2184, #2186)VectorBucket.s3vectors,Index.s3vectors: creation works again. AWS now answers the placeholder ARN that the first observe reads withAccessDeniedExceptioninstead of a not-found error, so the provider never called Create. (#2253)- Plugin Framework resources: updates are no longer refused with
diff contains fields that require resource replacementafter a provider restart or an import, when the resource has an empty list, set or map attribute, or an empty singleton block. As part of this fix, upjet omits an empty singleton block fromstatus.atProviderinstead of reporting it as{}. Fixed by the upjet bump (crossplane/upjet#766).
What's Changed
- fix(cloudfront): map origin request policy by id, not name by @ottramst in #2227
- Add filesystem_configuration to bedrockagentcore CodeInterpreter by @sergenyalcin in #2252
- feat(bedrockagent): add
KnowledgeBase,DataSourceandAgentKnowledgeBaseAssociationby @jonasz-lasut in #2253 - Add aws_cloudfront_key_value_store resource by @danielabelski in #2249
- feat(cloudwatchlogs): add Delivery, DeliverySource, DeliveryDestination and DeliveryDestinationPolicy by @rr-keys in #2255
- fix(elbv2): suppress spurious access_logs diff for Gateway Load Balancers by @pujitha24 in #2187
- fix(s3): suppress rule set re-hash diff on BucketServerSideEncryptionConfiguration by @jakubramut in #2259
- fix(sns): derive platform application import IDs by @alexdor in #2186
- Update jlumbroso/free-disk-space action to v2 by @renovate[bot] in #2237
- Update dependency ubuntu to v26 by @renovate[bot] in #2244
- Update dependency golangci/golangci-lint to v2.14.0 by @renovate[bot] in #2250
- Update kubernetes monorepo to v0.37.1 by @renovate[bot] in #2247
- Update module sigs.k8s.io/controller-runtime to v0.25.2 by @renovate[bot] in #2260
- fix: add RDS Cluster cluster_members to ignored fields by @fernandezcuesta in #2246
- Update go module directive to v1.27.1 by @renovate[bot] in #2261
- Update dependency crossplane/crossplane to v2.4.2 by @renovate[bot] in #2206
- Update module sigs.k8s.io/controller-tools to v0.22.0 by @renovate[bot] in #2262
- Add a gRPC diff service implementation by @sergenyalcin in #2257
- feat: add Bedrock, Agent Registry and Lambda MicroVMs resources by @jonasz-lasut in #2256
- feat(apigateway): add external-name config for DomainNameAccessAssociation by @aditmeno in #2131
- Configure aws_apigatewayv2_routing_rule by @scalapaymdacrema in #2205
- feat(grafana): add WorkspaceServiceAccount and WorkspaceServiceAccountToken resources by @coolguy1771 in #2241
- Table.dynamodb: apply GSI changes on existing tables by @jonasz-lasut in #2264
New Contributors
- @ottramst made their first contribution in #2227
- @danielabelski made their first contribution in #2249
- @rr-keys made their first contribution in #2255
- @pujitha24 made their first contribution in #2187
- @jakubramut made their first contribution in #2259
- @alexdor made their first contribution in #2186
- @scalapaymdacrema made their first contribution in #2205
- @coolguy1771 made their first contribution in #2241
Full Changelog: v2.8.1...v2.9.0