github crossplane-contrib/provider-upjet-azure v2.8.0

5 hours ago

The v2.8.0 release introduces a minor Terraform Azure provider upgrade, 10 new resources, a bug fix for namespaced resources, a new internal gRPC diff-service, and dependency updates.

There are no breaking API changes in this release.

Support for New Resources

  • AccountProject.cognitiveservices
  • AccountCustomerManagedKey.cognitiveservices
  • AccountConnectionAccountKey.cognitiveservices
  • AccountConnectionAccountManagedIdentity.cognitiveservices
  • AccountConnectionApiKey.cognitiveservices
  • AccountConnectionCustomKeys.cognitiveservices
  • AccountConnectionEntraId.cognitiveservices
  • DatastoreBlobStorage.machinelearningservices
  • DatastoreDataLakeGen2.machinelearningservices
  • DatastoreFileShare.machinelearningservices
  • InferenceCluster.machinelearningservices

Terraform provider upgrade: v4.80.0 → v4.81.0

All changes apply to both API scopes — cluster (<group>.azure.upbound.io) and namespaced (<group>.azure.m.upbound.io), and are backported to frozen v1beta1 spokes where a v1beta2 hub exists.

Non-breaking schema changes

New optional fields added; no field removed or made required.

Logger.apimanagement (v1beta1 + v1beta2):

  • applicationInsights.identityClientId — new optional field (identity-based Application Insights authentication)

LinuxVirtualMachineScaleSet.compute / WindowsVirtualMachineScaleSet.compute (v1beta1 + v1beta2):

  • dataDisk.diskIopsReadWrite / dataDisk.diskMbpsReadWrite — new optional fields (aliases alongside the existing ultraSsdDiskIopsReadWrite / ultraSsdDiskMbpsReadWrite, applicable to PremiumV2_LRS disks too)

OrchestratedVirtualMachineScaleSet.compute (v1beta1 + v1beta2):

  • networkInterface.tags — new optional field

PrivateEndpoint.network (v1beta1 + v1beta2):

  • edgeZone — new optional field

Vault.keyvault (v1beta1 + v1beta2):

  • rbacAuthorizationEnabled — documentation clarified (defaults to false); no schema change

Offline Diff Server (alpha)

This provider now support an offline gRPC-based diff server that computes diffs/plans for managed resources without connecting to Kubernetes or making cloud API calls.

The diff server allows users to preview what would change before applying a resource, without interacting with live infrastructure.

Key capabilities:

  • Computes CREATE, UPDATE, REPLACE, and NO_OP actions from the desired resource and its optional observed state.
  • Reports field-level changes, including planned values, replacement requirements, and change origins.
  • Accepts a PlanRequest with the desired resource, an optional actual resource, and an in-memory store containing the required ProviderConfig and referenced Secrets.
  • Supports both namespaced and cluster-scoped managed resources, including previously served API versions.
  • Runs without cloud credentials or live infrastructure access.
  • Exposes the PlanService.Plan gRPC API through the internal diff-server subcommand. Support is advertised through the DiffServer package capability.

Known limitations:

  • Some resources require cloud API calls during planning and cannot be fully evaluated offline. These requests may return FAILED_PRECONDITION, allowing callers to fall back to a raw diff.
  • Accurate plans depend on a complete observed state. Missing fields in status.atProvider may produce unexpected changes.
  • The gRPC API is experimental and may change without backward compatibility guarantees.

Resource coverage and planning behavior may vary between providers.

What's Changed

New Contributors

Full Changelog: v2.7.0...v2.8.0

Don't miss a new provider-upjet-azure release

NewReleases is sending notifications on new releases.