This repository was archived by the owner on Feb 10, 2026. It is now read-only.
v1.75.0
VPC, DNS, CloudTrail, testing Nuru (@Nuru) (#501)
breaking changes
- VPC
- Removed
region_availability_zones. It was a pre-Atmos way of providing defaults, no longer needed now that we have Atmos. - Removed
ec2_vpc_endpoint_enabled. It was overly specific, and the functionality has been generalized ininterface_vpc_endpoints - Removed ineffective IPAM support, including
ipv4_primary_cidr_block_associationas it did not work: did not configure pool ID, did not support IPv6. Will need to be implemented better in the future. - Removed Kubernetes
kubernetes.io/cluster/<cluster-name>tags from subnets, as they are no longer needed as of Kubernetes 1.19 - Removed
eks_component_namesinput andeksremote state lookup as they were only used to create the tag which is no longer created - Added
availability_zone_idsto allow specifying subnet availability zones by ID rather than name, which we should do as best practice inus-east-1at least so that components in different accounts are nevertheless in the same AZ. Also, required forus-east-1using Amazon Workstations, as it is not supported in some AZs. - Added
ipv4_cidrsinput to allow complete manual configuration of subnet CIDRs - Added
public_subnets_enabled(defaulttrue) to allow for disabling creation of public subnets - Added default of
falsefornat instance_enabledsince NAT instances are deprecated and this option will likely be removed in the future. - Added default of
truefornat_gateway_enabled - Added
gateway_vpc_endpointsfor provisioning VPC Gateway endpoints - Added
interface_vpc_endpointsfor provisioning VPC Interface endpoints for an arbitrary set of services
- Removed
what
- Upstream changes to
- cloudtrail
- cloudtrail-bucket
- dns-delegated
- dns-primary
- vpc
- Run
batstests on modified modules - Remove
default.auto.tfvarsper latest standard
why
- VPC
- Improve support for VPC Endpoints
- Remove support for deprecated features
- DNS
- Change default negative TTL to 60 seconds
- Make SOA configurable in
dns-delegated - Improve SOA documentation
- CloudTrail: update
remote-state, fix provider version pinning - Testing: enforce relevant standards from our Open Source Terraform modules