Conversation
Open in Overmind ↗
🔴 Change SignalsRoutine 🔴 🔥 RisksReplacement API server will remain directly exposed to the internet with SSH open to the world When this replacement deploys, the new instance will inherit the same direct exposure while changing the AMI and bootstrap configuration at the same time. That creates a real compromise risk: attackers can continue to reach SSH and web ports from the internet, and any mistake or regression in the new image or startup script will be exposed immediately on a public endpoint. This violates the org requirement that EC2 instances must not be directly internet-reachable and that SSH must never be open to
|
ba884cb to
12213ca
Compare
12213ca to
97c66a8
Compare
97c66a8 to
602c793
Compare
602c793 to
0f43049
Compare

This PR contains the following updates:
< 6.38→< 6.416.37.0→6.40.07.25.0→7.27.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
hashicorp/terraform-provider-aws (aws)
v6.40.0Compare Source
FEATURES:
aws_opensearchserverless_collection_group(#46308)aws_opensearchserverless_collection_groups(#46308)aws_s3files_access_point(#47352)aws_s3files_file_system(#47344)aws_s3files_file_systems(#47344)aws_s3files_mount_target(#47347)aws_config_config_rule(#47319)aws_glue_job(#47266)aws_opensearchserverless_collection_group(#46308)aws_s3files_access_point(#47352)aws_s3files_file_system(#47325)aws_s3files_file_system_policy(#47355)aws_s3files_mount_target(#47347)aws_s3files_synchronization_configuration(#47353)aws_ssm_association(#47321)aws_ssm_patch_group(#47329)aws_opensearchserverless_collection_group(#46308)aws_s3files_access_point(#47352)aws_s3files_file_system(#47325)aws_s3files_file_system_policy(#47355)aws_s3files_mount_target(#47347)aws_s3files_synchronization_configuration(#47353)aws_servicequotas_auto_management(#45968)ENHANCEMENTS:
broker_node_group_info.connectivity_info.network_typeattribute (#47279)depends_on_stack_setstoauto_deploymentconfiguration block (#47269)remediation_typesattribute (#46549)FLINK-2_2as a valid value forruntime_environment(#47207)broker_node_group_info.connectivity_info.network_typeargument (#47279)storage_lens_configuration.data_export.storage_lens_table_destinationargument (#47152)BUG FIXES:
export.data_query.table_configurations(#47261)patternlength in UTF-8 characters (#47287)nameas asForceNew(#47286)AccountAlreadyClosedExceptionerror when deleting an account that has already been closed withclose_on_deletionset totrue(#46627)rule.apply_server_side_encryption_by_default.kms_master_key_id,rule.blocked_encryption_types, andrule.bucket_key_enabledto Optional and Computed, preventings diffs once SSE-C is disabled for all new general purpose buckets (#47359)visible_regionsorvisible_servicesis set to an explicit empty set ([]) (#47290)v6.39.0Compare Source
NOTES:
tags_allattribute is deprecated and will be removed in a future major version (#47133)FEATURES:
aws_iam_role_policies(#46936)aws_iam_role_policy_attachments(#47119)aws_networkmanager_core_network(#45798)aws_uxc_services(#47115)aws_eks_cluster(#47133)aws_organizations_aws_service_access(#46993)aws_sagemaker_training_job(#46892)aws_workmail_group(#47131)aws_workmail_user(#47131)aws_organizations_aws_service_access(#46993)aws_sagemaker_training_job(#46892)aws_uxc_account_customizations(#47115)aws_workmail_group(#47131)aws_workmail_user(#47131)ENHANCEMENTS:
instance_familiesattribute (#47153)tier-8xlas a valid value forcontrol_plane_scaling_config.tier(#46976)source.source_logs_configuration.data_source_selection_criteriaargument. Changesource.source_logs_configuration.log_group_selection_criteriato Optional (#47154)source.vpcargument. Changesource.eksto Optional (#47155)storage_lens_configuration.account_level.advanced_performance_metricsandstorage_lens_configuration.account_level.bucket_level.advanced_performance_metricsarguments (#46865)BUG FIXES:
aws-cnpartition (#47141)Error: waiting for creation AWS DynamoDB Table (xxxxx): couldn't find resourcein highly active accounts by restoring5sdelay before polling for table status. This fixes a regression introduced in v6.28.0. (#47143)bootstrap_self_managed_addonstotruewhen importing (#47133)InvalidParameterCombinationerror whencache_usage_limitsis removed (#46134)v6.38.0Compare Source
FEATURES:
aws_dms_start_replication_task_assessment_run(#47058)aws_dynamodb_backups(#47036)aws_msk_topic(#46490)aws_savingsplans_offerings(#47081)aws_msk_cluster(#46490)aws_msk_serverless_cluster(#46490)aws_msk_topic(#46490)aws_route53_resolver_rule(#47063)aws_sagemaker_algorithm(#47051)aws_ssm_document(#46974)aws_ssoadmin_account_assignment(#47067)aws_vpc_endpoint(#46977)aws_workmail_domain(#46931)aws_msk_topic(#46490)aws_observabilityadmin_telemetry_enrichment(#47089)aws_sagemaker_algorithm(#47051)aws_workmail_default_domain(#46931)aws_workmail_domain(#46931)ENHANCEMENTS:
firewall_policy.enable_tls_session_holdingattribute (#47065)authorizer_configuration.custom_jwt_authorizer.custom_claimconfiguration block (#47049)authorizer_configuration.custom_jwt_authorizer.custom_claimconfiguration block (#47049)target_configuration.mcp.api_gatewayconfiguration block (#46916)restore_backup_arnargument (#47068)KinesisStreamsas a value foraction.target.key(#47010)VPCEndpointsas a value foraction.target.key(#47045)userblock to Optional (#46883)firewall_policy.enable_tls_session_holdingargument (#47065)filters.aws_account_nameconfiguration block (#47027)filters.compliance_associated_standards_idconfiguration block (#47027)filters.compliance_security_control_idconfiguration block (#47027)filters.compliance_security_control_parameters_nameconfiguration block (#47027)filters.compliance_security_control_parameters_valueconfiguration block (#47027)BUG FIXES:
@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)Provider produced inconsistent result after applyerror whenenvironmentvariables are defined in non-alphabetical order (#46771)Provider returned invalid result object after applyerrors where computed attributes remained unknown after create (#47012)@regionsuffix when using resource-levelregionattribute (#47043)userblock (#46883)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)Unable to unmarshal DynamicValueerror whenstatement.managed_rule_group_statement.rule_action_overrideblock is specified (#46998)WAFOptimisticLockExceptionerrors when multiple associations target the same Web ACL (#47037)hashicorp/terraform-provider-google (google)
v7.27.0Compare Source
v7.26.0Compare Source
BREAKING CHANGES:
google_compute_region_backend_bucketfrom thegoogle(GA) provider. It is currently beta-only, and calls to the nonexistent GA API always returned a 404. Until released ingoogle, usegoogle-betainstead. (#26597)FEATURES:
google_network_security_address_groups(#26562)google_iam_workload_identity_pool_iam_policy(#26598)google_bigqueryreservation_reservation_group(#26560)google_compute_region_composite_health_check(#26591)google_compute_region_health_aggregation_policy(#26591)google_compute_region_health_source(#26591)google_contact_center_insights_assessment_rule(#26530)google_iam_workload_identity_pool_iam_*(#26598)google_workstations_workstation(#26561)google_workstations_workstation_iam_*(#26561)google_workstations_workstation_cluster(#26561)google_workstations_workstation_config(#26561)google_workstations_workstation_config_iam_*(#26561)IMPROVEMENTS:
reservation_groupfield togoogle_bigquery_reservationresource (#26560)remote_dialogflow_agent.respect_response_interruption_settingsfield togoogle_ces_agentresource (#26578)boot_disk.size_gbandboot_disk.typeeditable within nodesets and login nodes ingoogle_hypercomputecluster_cluster(#26615)colab_imagefield togoogle_colab_runtime_templateresource (#26582)google_colab_runtime_templateresource updatable (#26582)hyperdisk-balancedas an option fordisk_typefield ingoogle_container_clusterresource (#26581)backend_servicefield optional forgoogle_compute_target_tcp_proxyresource (#26519)resolve_subnet_fieldfield ingoogle_compute_subnetworkresource to GA (#26570)mode,inline_certificate_issuance_config, andinline_trust_configfields ingoogle_iam_workload_identity_poolresource to GA (#26598)google_spanner_instanceresource (#26577)server_certificate_rotation_modefield togoogle_sql_database_instanceresource (#26572)google_managed_encryption_enforcement_config,customer_managed_encryption_enforcement_configandcustomer_supplied_encryption_enforcement_configtogoogle_storage_bucketresource (#26529)BUG FIXES:
password_woandpassword_wo_versionfields were not functioning properly during update requests ingoogle_alloydb_userresource (#26571)propertiesfield in thegoogle_biglake_iceberg_tableandgoogle_biglake_iceberg_namespaceresources (#26595)direct_vpc_network_interfaceorvpc_connectorongoogle_cloudfunctions2_functionresource (#26567)network_interfacesorconnectorongoogle_cloud_run_v2_serviceandgoogle_cloud_run_v2_jobresources (#26567)google_compute_region_backend_bucketbeing present in thegoogle(GA) provider. It is currently beta-only, and calls to the nonexistent GA API always returned a 404. (#26597)rate_limit_optionsfield ingoogle_compute_region_security_policy_ruleresource (#26527)rate_limit_optionsfield ingoogle_compute_security_policyandgoogle_compute_security_policy_ruleresources (#26526)modefield forgoogle_iam_workload_identity_poolresource (#26601)http://(#26600)google_vertex_ai_resources not respectinguniverse_domainandvertex_custom_endpoint(#26556)Configuration
📅 Schedule: (in timezone Europe/London)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.