NOTES:
- resource/aws_resourcegroups_resource: The format of the read-only
id
attribute has changed to prevent inconsistent parsing which resulted in provider crashes under certain conditions. The new format is a comma-delimited string combininggroup_arn
andresource_arn
in their entirety. Configuarations relying on the previous format may need to be updated to continue functioning correctly. (#40579)
FEATURES:
- New Data Source:
aws_servicecatalogappregistry_attribute_group_associations
(#38306) - New Resource:
aws_api_gateway_domain_name_access_association
(#40566) - New Resource:
aws_cloudfront_vpc_origin
(#40239) - New Resource:
aws_memorydb_multi_region_cluster
(#40376) - New Resource:
aws_networkmanager_dx_gateway_attachment
(#40546) - New Resource:
aws_rds_cluster_snapshot_copy
(#40398)
ENHANCEMENTS:
- data-source/aws_dx_gateway: Add
arn
attribute (#40546) - data-source/aws_iam_policy_document: Add plan-time validation that the
statement
sid
is valid, including on alphanumeric characters (#40562) - data-source/aws_vpc_endpoint: Add
service_region
attribute (#40583) - resource/aws_bedrockagent_agent: Add
agent_collaboration
attribute to configure agent collaboration role (#40543) - resource/aws_cloudfront_distribution: Add
origin.vpc_origin_config
argument (#40239) - resource/aws_db_parameter_group: Support import of
name_prefix
argument (#40622) - resource/aws_dx_gateway: Add
arn
attribute (#40546) - resource/aws_fsx_lustre_file_system: Add
efa_enabled
argument (#40381) - resource/aws_lb_listener: Add
advertise_trust_store_ca_names
attribute to themutual_authentication
configuration block (#40550) - resource/aws_memorydb_cluster: Add
multi_region_cluster_name
argument (#40376) - resource/aws_networkmanager_attachment_accepter: Add
edge_locations
attribute (#40546) - resource/aws_resourcegroups_resource: Add import support (#40579)
- resource/aws_vpc_endpoint: Add
service_region
argument (#40583)
BUG FIXES:
- data-source/aws_acmpca_certificate_authority: Ignore
AccessDeniedException: ... is not authorized to perform: acm-pca:GetCertificateAuthorityCsr on resource: ...
errors for RAM-shared CAs (#39952) - data-source/aws_licensemanager_received_license: Fix
setting entitlements: Invalid address to set: []string{"entitlements", "0", "overage"}
errors (#40621) - resource/aws_amplify_domain_association: No longer ignores changes to
certificate_settings
when updating. (#40589) - resource/aws_amplify_domain_association: Prevent "unexpected state" error when setting
certificate_settings.type
toCUSTOM
. (#40589) - resource/aws_amplify_domain_association: Prevent
ValidationException
when settingcertificate_settings.type
toAMPLIFY_MANAGED
. (#40589) - resource/aws_amplify_domain_association: Prevent permanent diff when
certificate_settings
not set. (#40589) - resource/aws_amplify_domain_association: Prevents panic in some circumstances when
certificate_settings
is not set during update. (#40589) - resource/aws_api_gateway_domain_name: Correct
arn
for private custom domain names (#40566) - resource/aws_codeconnections_host: Mark
vpc_configuration.tls_certificate
as Optional (#40574) - resource/aws_elasticache_replication_group: Prevent perpetual diff which triggers resource replacement on
at_rest_encryption_enabled
whenengine
isvalkey
. (#40514) - resource/aws_lakeformation_permissions: Add support for
IAMPrincipals
principal group (#38600) - resource/aws_lakeformation_permissions: Fix refreshing state so order is not considered in
permissions
andpermissions_with_grant_option
attributes (#38047) - resource/aws_lakeformation_resource_lf_tag: Fix panic when resource tries to destroy a LFTag reference that does not exist (#40584)
- resource/aws_lambda_invocation: Set new computed value for
result
attribute when changinginput
attribute, for lifecycle scope "CRUD" (#34263) - resource/aws_medialive_channel: Added missing
teletext_destination_settings
. (#33797) - resource/aws_rds_cluster: Fix issue with waiter when modifying
allocated_storage
(#40601) - resource/aws_resourcegroups_resource: Fix crash when parsing certain ARN formats (#40579)
- resource/aws_s3_bucket: Destroying a bucket with
force_destroy = true
can now delete objects with non-XML-safe keys (#40537) - resource/aws_s3_directory_bucket: Destroying a directory bucket with
force_destroy = true
can now delete objects with non-XML-safe keys (#40537) - resource/aws_secretsmanager_secret_rotation: Fix bug where
automatically_after_days
was not being set properly whenschedule_expression
had been set previously (#34295) - resource/aws_secretsmanager_secret_rotation: Retry rotation in case it has not yet propagated when previously an error would occur:
InvalidRequestException: A previous rotation isn't complete. That rotation will be reattempted.
(#34295) - resource/aws_sqs_queue_redrive_allow_policy: Fix perpetual
redrive_allow_policy
diffs (#40604)