6.23.0 (November 26, 2025)
NOTES:
- resource/aws_s3_bucket: To support ABAC (Attribute Based Access Control) in general purpose buckets, this resource will now attempt to send tags in the create request and use the S3 Control tagging APIs
TagResource,UntagResource, andListTagsForResourcefor read and update operations. The calling principal must have the correspondings3:TagResource,s3:UntagResource, ands3:ListTagsForResourceIAM permissions. If the principal lacks the appropriate permissions, the provider will fall back to tagging after creation and using the S3 tagging APIsPutBucketTagging,DeleteBucketTagging, andGetBucketTagginginstead. With ABAC enabled, tag modifications may fail with the fall back behavior. See the AWS documentation for additional details on enabling ABAC in general purpose buckets. (#45251)
FEATURES:
- New Resource:
aws_ecs_express_gateway_service(#45235) - New Resource:
aws_s3_bucket_abac(#45251) - New Resource:
aws_vpc_encryption_control(#45263) - New Resource:
aws_vpn_concentrator(#45175)
ENHANCEMENTS:
- action/aws_lambda_invoke: Add
tenant_idargument (#45170) - data-source/aws_eks_cluster: Add
control_plane_scaling_configattribute (#45258) - data-source/aws_lambda_function: Add
tenancy_configattribute (#45170) - data-source/aws_lambda_invocation: Add
tenant_idargument (#45170) - data-source/aws_vpn_connection: Add
vpn_concentrator_idattribute (#45175) - resoource/aws_ecs_capacity_provider: Add
managed_instances_provider.infrastructure_optimizationargument (#45142) - resource/aws_docdb_cluster: Add
network_typeargument (#45140) - resource/aws_docdb_subnet_group: Add
supported_network_typesattribute (#45140) - resource/aws_eks_cluster: Add
control_plane_scaling_configconfiguration block to support EKS Provisioned Control Plane (#45258) - resource/aws_lambda_function: Add
tenancy_configargument (#45170) - resource/aws_lambda_invocation: Add
tenant_idargument (#45170) - resource/aws_s3_bucket: Tag on creation when the
s3:TagResourcepermission is present (#45251) - resource/aws_s3_bucket: Use the S3 Control tagging APIs when the
s3:TagResource,s3:UntagResource, ands3:ListTagsForResourcepermissions are present (#45251) - resource/aws_vpn_connection: Add
vpn_concentrator_idargument to support Site-to-Site VPN Concentrator (#45175)