Releases: hashicorp/terraform-provider-aws
Releases · hashicorp/terraform-provider-aws
Release list
v6.61.0
6.61.0 (August 19, 2026)
FEATURES:
- New Data Source:
aws_odb_iam_role_association(#46794) - New List Resource:
aws_ec2_ami_launch_permission(#49461) - New List Resource:
aws_iam_instance_profile(#49576) - New List Resource:
aws_lambdacore_network_connector(#49387) - New List Resource:
aws_mailmanager_relay(#49394) - New List Resource:
aws_resiliencehubv2_assertion(#48329) - New List Resource:
aws_resiliencehubv2_service_function(#48328) - New List Resource:
aws_resiliencehubv2_user_journey(#48330) - New Resource:
aws_dsql_cluster_policy(#47748) - New Resource:
aws_lambdacore_network_connector(#49387) - New Resource:
aws_lambdamicrovms_image(#48950) - New Resource:
aws_mailmanager_relay(#49394) - New Resource:
aws_odb_iam_role_association(#46794) - New Resource:
aws_resiliencehubv2_assertion(#48329) - New Resource:
aws_resiliencehubv2_service_function(#48328) - New Resource:
aws_resiliencehubv2_user_journey(#48330) - New Resource:
aws_securityhub_feature_v2(#49503)
ENHANCEMENTS:
- data-source/aws_fsx_ontap_file_system: Add
network_typeattribute (#49512) - data-source/aws_fsx_windows_file_system: Add
network_typeattribute (#49514) - data-source/aws_lb_listener_rule: Add
condition.source_ip.ip_address_typeattribute (#49476) - data-source/aws_resiliencehubv2_service: Add
associated_systemattribute (#49498) - data-source/aws_vpclattice_service: Add
idle_timeout_secondsattribute (#49540) - resource/aws_bedrockagentcore_harness: Adds attribute
environment_actual(#48815) - resource/aws_ec2_ami_launch_permission: Add resource identity support (#49461)
- resource/aws_fsx_ontap_file_system: Add
network_typeargument (#49512) - resource/aws_fsx_openzfs_file_system: Add
network_typeargument (#49513) - resource/aws_fsx_windows_file_system: Add
network_typeargument (#49514) - resource/aws_lb_listener_rule: Add
condition.source_ip.ip_address_typeargument (#49476) - resource/aws_lb_listener_rule: Change
condition.source_ip.valuesto Optional (#49476) - resource/aws_medialive_channel: Add resource identity (#49532)
- resource/aws_medialive_input: Add resource identity support (#49534)
- resource/aws_medialive_input_security_group: Add resource identity support (#49537)
- resource/aws_medialive_multiplex: Add resource identity support (#49557)
- resource/aws_medialive_multiplex_program: Add resource identity (#49561)
- resource/aws_observabilityadmin_centralization_rule_for_organization: Add
encryption_scopeargument to thelogs_encryption_configurationconfiguration block (#49563) - resource/aws_pinpointsmsvoicev2_phone_number: Add
statusattribute (#49485) - resource/aws_pinpointsmsvoicev2_phone_number: Add
wait_for_activeargument to allowcreateandupdateto return without waiting for the phone number to reachACTIVEstatus. Number types gated on carrier or registration approval (for exampleTEN_DLC,TOLL_FREE, or any number submitted withregistration_id) can remainPENDINGfor days to weeks, which previously causedterraform applyto time out (#49485) - resource/aws_resiliencehubv2_service: Add
associated_systemconfiguration block (#49498) - resource/aws_vpclattice_service: Add
idle_timeout_secondsargument (#49540)
BUG FIXES:
- list-resource/aws_bedrockagentcore_harness: Prevents error when remote resource disappears during List (#49446)
- list-resource/aws_bedrockagentcore_online_evaluation_config: Prevents error when remote resource disappears during List (#49479)
- list-resource/aws_bedrockagentcore_policy_engine: Prevents error when remote resource disappears during List (#49478)
- list-resource/aws_bedrockagentcore_registry: Prevents error when remote resource disappears during List (#49480)
- list-resource/aws_bedrockagentcore_resource_policy: Prevents error when remote resource disappears during List (#49481)
- resource/aws_bedrockagentcore_harness: Fix
Provider produced inconsistent result after applyerror forenvironment(#48815) - resource/aws_bedrockagentcore_online_evaluation_config: Retries additional IAM propagation errors on creation (#49479)
- resource/aws_mailmanager_ingress_point: Include
FAILEDas a pending state while an ingress point is deleting (#49502) - resource/aws_nat_gateway: Allow updating
secondary_private_ip_address_countin-place for private NAT gateways (#47477) - resource/aws_observabilityadmin_telemetry_enrichment: Prevent
couldn't find resource (21 retries)errors on delete if enrichment has never been started in the Region (#49502) - resource/aws_observabilityadmin_telemetry_evaluation: Include
NOT_STARTEDas a target state while the resource is deleting (#49502)
v6.60.0
v6.59.0
6.59.0 (August 12, 2026)
FEATURES:
- New Data Source:
aws_rds_snapshots(#49259) - New Data Source:
aws_resiliencehubv2_policy(#48324) - New Data Source:
aws_resiliencehubv2_service(#48326) - New Data Source:
aws_resiliencehubv2_system(#48325) - New Data Source:
aws_vpclattice_service_network_service_associations(#42680) - New List Resource:
aws_backup_plan(#49329) - New List Resource:
aws_backup_selection(#49283) - New List Resource:
aws_backup_vault(#49423) - New List Resource:
aws_bedrockagentcore_gateway_rule(#48804) - New List Resource:
aws_mailmanager_ingress_point(#49322) - New List Resource:
aws_neptunegraph_private_graph_endpoint(#45929) - New List Resource:
aws_networkfirewall_container_association(#49321) - New List Resource:
aws_pinpointsmsvoicev2_resource_policy(#48771) - New List Resource:
aws_pinpointsmsvoicev2_sender_id(#46472) - New List Resource:
aws_resiliencehubv2_service(#48323) - New List Resource:
aws_resiliencehubv2_system(#48322) - New List Resource:
aws_ssm_patch_baseline(#49332) - New Resource:
aws_bedrockagentcore_gateway_rule(#48804) - New Resource:
aws_mailmanager_ingress_point(#49322) - New Resource:
aws_neptunegraph_private_graph_endpoint(#45929) - New Resource:
aws_networkfirewall_container_association(#49321) - New Resource:
aws_pinpointsmsvoicev2_resource_policy(#48771) - New Resource:
aws_pinpointsmsvoicev2_sender_id(#46472) - New Resource:
aws_resiliencehubv2_service(#48323) - New Resource:
aws_resiliencehubv2_system(#48322)
ENHANCEMENTS:
- data-source/aws_eks_cluster: Add
kube_api_server_config,kube_controller_manager_config, andkube_scheduler_configattributes (#49420) - data-source/aws_eks_cluster_versions: Add
control_plane_component_configandcontrol_plane_scaling_tiersattributes (#49421) - resource/aws_arcregionswitch_plan: Add
step.aurora_provisioned_scaling_config,step.aurora_serverless_scaling_config,step.neptune_global_database_config, andstep.lambda_event_source_mapping_configarguments (#48392) - resource/aws_arcregionswitch_plan: Add provider-side validation restricting
report_configurationandreport_configuration.report_output.s3_configurationto a single block each (#46758) - resource/aws_backup_plan: Add resource identity support (#49329)
- resource/aws_backup_selection: Add resource identity support (#49283)
- resource/aws_backup_vault: Add resource identity support (#49423)
- resource/aws_bedrockagentcore_gateway_target: Add
target_configuration.mcp.mcp_server.mcp_tool_schemaconfiguration block andtarget_configuration.mcp.mcp_server.resource_priorityargument (#48703) - resource/aws_bedrockagentcore_harness: Adds computed attribute
memory_actual(#49383) - resource/aws_bedrockagentcore_harness: Adds support for
memory.disabled(#49334) - resource/aws_bedrockagentcore_harness: Adds support for
memory.managed_memory_configuration(#49285) - resource/aws_dlm_lifecycle_policy: Add
policy_details.parameters.exclude_data_volume_tagsargument (#45113) - resource/aws_ec2_client_vpn_route: Add
transit_gateway_attachment_idattribute (#49274) - resource/aws_ec2_client_vpn_route: Change
target_vpc_subnet_idto Optional (#49274) - resource/aws_ec2_client_vpn_route: Increase default
timeoutsvalues to30m(#49274) - resource/aws_eks_cluster: Add
kube_api_server_config,kube_controller_manager_config, andkube_scheduler_configarguments (#49412) - resource/aws_prometheus_scraper: Add
exporterconfiguration block with OpenSearch exporter support (#49346) - resource/aws_wafv2_rule_group: Add
pre_parse_text_transformationargument tobyte_match_statement,regex_match_statement,regex_pattern_set_reference_statement,size_constraint_statement,sqli_match_statement, andxss_match_statementrule statements (#49381) - resource/aws_wafv2_web_acl: Add
pre_parse_text_transformationargument tobyte_match_statement,regex_match_statement,regex_pattern_set_reference_statement,size_constraint_statement,sqli_match_statement, andxss_match_statementrule statements (#49381)
BUG FIXES:
- data-source/aws_lakeformation_permissions: Fix failure to read cross-account IAM principals (#49398)
- data-source/aws_mq_broker: Fix
reading MQ Broker (...) shared resourceserrors when reading RabbitMQ brokers in partitions wheremq:DescribeSharedResourcesis unavailable, such as AWS GovCloud (US) (#49340) - resource/aws_bedrockagentcore_gateway_target: Remove client-side count validation for
metadata_configurationrequest and response headers (#49374) - resource/aws_bedrockagentcore_gateway_target: Treat OAuth
CREATE_PENDING_AUTHandUPDATE_PENDING_AUTHstatuses as successful terminal states (#48703) - resource/aws_lakeformation_permissions: Fix failure to read cross-account IAM principals (#49398)
- resource/aws_mq_broker: Fix
reading MQ Broker (...) shared resourceserrors when reading RabbitMQ brokers in partitions wheremq:DescribeSharedResourcesis unavailable, such as AWS GovCloud (US) (#49340) - resource/aws_rds_cluster: Fix
InvalidParameterCombinationerror whenengine_versionis updated externally (#49396) - resource/aws_route53domains_registered_domain: Fix
UpdateDomainContactPrivacybeing incorrectly triggered whenbilling_contactchanges (#49314) - resource/aws_ssm_parameter: Fixes error where
namewith a leading slash and no other slashes was stripping the leading slash. (#49339)
v6.58.0
6.58.0 (August 5, 2026)
FEATURES:
- New List Resource:
aws_mailmanager_rule_set(#49257) - New List Resource:
aws_prometheus_anomaly_detector(#49139) - New List Resource:
aws_prometheus_scraper(#47466) - New List Resource:
aws_prometheus_scraper_logging_configuration(#47466) - New List Resource:
aws_resiliencehubv2_policy(#48321) - New Resource:
aws_mailmanager_rule_set(#49257) - New Resource:
aws_prometheus_anomaly_detector(#49139) - New Resource:
aws_prometheus_scraper_logging_configuration(#47466) - New Resource:
aws_resiliencehubv2_policy(#48321)
ENHANCEMENTS:
- resource/aws_api_gateway_rest_api: Add configurable resource timeouts. (#49205)
- resource/aws_dx_connection: Add
stateattribute (#42150) - resource/aws_ecs_capacity_provider: Add
RESERVEDas a valid value formanaged_instances_provider.instance_launch_template.capacity_option_type(#48816) - resource/aws_ecs_capacity_provider: Add
local_storage_configurationattribute tomanaged_instances_provider.instance_launch_template(#47513) - resource/aws_ecs_capacity_provider: Add
managed_instances_provider.instance_launch_template.capacity_reservationsargument (#48816) - resource/aws_glue_catalog_table_optimizer: Add
configuration.compaction_configurationargument (#43868) - resource/aws_prometheus_scraper: Add Resource Identity support (#47466)
- resource/aws_prometheus_scraper: Add
destination.cloudwatchconfiguration block for CloudWatch Metrics destination support (#49088)
BUG FIXES:
- resource/aws_api_gateway_rest_api: Wait for the REST API to reach an available state on create and update, and to be fully deleted on delete, preventing intermittent
BadRequestException: There is already an update in progresserrors (#49205) - resource/aws_appstream_stack: Fix
embed_host_domainsnot being sent to the AWS API on update, which caused a permanent plan diff when the argument was added or changed on an existing stack (#49015) - resource/aws_bedrockagent_data_source: Fix validator incorrectly requiring
bedrock_data_automation_configurationwhenparsing_strategy = "BEDROCK_DATA_AUTOMATION", a regression introduced in v6.56.0 (#49111) - resource/aws_bedrockagentcore_agent_runtime: Allow
:(colon) in thematch_value_stringandmatch_value_string_listattributes ofauthorizer_configuration.custom_jwt_authorizer.custom_claim.authorizing_claim_match_value.claim_match_value(#48437) - resource/aws_bedrockagentcore_memory_strategy: Fix
Value Conversion Error ... Received null value, however the target type cannot handle null valueserrors (#49188) - resource/aws_bedrockagentcore_memory_strategy: Fix
too many results: wanted 1, got 2error when creating or updating a strategy on a memory that already has another strategy of a different type (#49250) - resource/aws_bedrockagentcore_memory_strategy: Replace resource rather than erroring when
configuration.consolidation,configuration.extraction, orconfiguration.reflectionblocks are removed (#49188) - resource/aws_ecs_service: Fix
sigint_rollbackfalsely rolling back healthy deployments duringwait_for_steady_state(#49077) - resource/aws_ecs_service: Prevent non-EBS deployment volume configurations from being written to state (#48947)
- resource/aws_elasticache_replication_group: Fix perpetual diff when changes are pending for the next maintenance window (
apply_immediately = false) (#48246) - resource/aws_glue_catalog_table: Fix
InvalidInputException: StorageDescriptor is not allowederror when creating or updating ATHENA-dialect views (#49156) - resource/aws_glue_catalog_table: Fix
InvalidInputExceptionerror when creating or updating SPARK-dialect views without an explicitstorage_descriptorblock (#49156) - resource/aws_glue_catalog_table: Fix perpetual diff on
view_definition.representationsfields (validation_connection,view_original_text,view_expanded_text) that AWS Glue does not echo back for validated ATHENA views (#49156) - resource/aws_iam_user: Retry destroying users when there are conflicts, and ignore non-errors during destroy (#49260)
- resource/aws_route53recoverycontrolconfig_safety_rule: Fix crash when the create operation returns an error (#49155)
- resource/aws_ssm_parameter: Correctly imports when passing ARN value. (#49134)
- resource/aws_ssm_parameter: Prevents errors when importing specific version. (#49134)
v6.57.1
6.57.1 (July 29, 2026)
NOTES:
- resource/aws_bedrockagentcore_memory_strategy: The
memory_execution_role_arnattribute has been deprecated. Use thememory_execution_role_arnattribute on theaws_bedrockagentcore_memoryresource instead (#49140) - resource/aws_bedrockagentcore_memory_strategy: The
namespacesattribute has been deprecated. All configurations usingnamespacesshould be updated to use thenamespace_templatesattribute instead (#49140)
FEATURES:
- New Data Source:
aws_eks_access_policies(#49090) - New List Resource:
aws_bedrock_evaluation_job(#49044) - New List Resource:
aws_eks_access_entry(#49090) - New List Resource:
aws_eks_access_policy_association(#49121) - New List Resource:
aws_eks_node_group(#49073) - New List Resource:
aws_flow_log(#49086) - New List Resource:
aws_mailmanager_traffic_policy(#49043) - New List Resource:
aws_osis_pipeline(#49157) - New List Resource:
aws_osis_pipeline_endpoint(#44383) - New List Resource:
aws_osis_resource_policy(#44383) - New List Resource:
aws_rekognition_collection(#49135) - New Resource:
aws_bedrock_evaluation_job(#49044) - New Resource:
aws_cloudwatch_log_storage_tier_policy(#49076) - New Resource:
aws_mailmanager_traffic_policy(#49043) - New Resource:
aws_osis_pipeline_endpoint(#44383) - New Resource:
aws_osis_resource_policy(#44383)
ENHANCEMENTS:
- data-source/aws_launch_template: Add
ena_queue_countattribute tonetwork_interfacesconfiguration block (#48892) - data-source/aws_secretsmanager_secret: Add
typeattribute (#46414) - data-source/aws_secretsmanager_secret_rotation: Add
external_secret_rotation_metadataandexternal_secret_rotation_role_arnattributes (#46414) - data-source/aws_vpc: Adds support for
ipv6_cidr_block_associations. (#46918) - data-source/aws_vpc: Deprecates
ipv6_association_idandipv6_cidr_block. (#46918) - resource/aws_autoscaling_group: Add
reservations-then-balancedvalid value foravailability_zone_distribution.capacity_distribution_strategy(#48934) - resource/aws_bedrockagentcore_memory: Add
timeouts.updatewith a default value of30m(#49140) - resource/aws_bedrockagentcore_memory_strategy: Add
configuration.reflectionconfiguration block forEPISODIC_OVERRIDEstrategy type (#49140) - resource/aws_bedrockagentcore_memory_strategy: Add
namespace_templatesargument (#49140) - resource/aws_bedrockagentcore_memory_strategy: Add
reflection_configurationconfiguration block forEPISODICstrategy type (#49140) - resource/aws_bedrockagentcore_memory_strategy: Increase default
timeoutsvalues to45m(#49140) - resource/aws_codepipeline: Add
stage.action.commandsandstage.action.output_artifacts_for_compute_actionarguments to support Compute action types (#42507) - resource/aws_codepipeline:
stage.action.output_artifacts_for_compute_actionandstage.action.output_artifactsnow conflict (#42507) - resource/aws_eks_pod_identity_association: Add
policyargument to support inline session policies (#48869) - resource/aws_fis_experiment_template: Support
MultiRegionClustersas a value foraction.target.key(#48781) - resource/aws_flow_log: Add resource identity support (#49086)
- resource/aws_launch_template: Add
ena_queue_countargument tonetwork_interfacesconfiguration block (#48892) - resource/aws_rekognition_collection: Add Resource Identity support (#49022)
- resource/aws_rekognition_project: Add Resource Identity support (#49022)
- resource/aws_rekognition_stream_processor: Add Resource Identity support (#49022)
- resource/aws_secretsmanager_secret: Add
typeargument in support of managed external secrets (#46414) - resource/aws_secretsmanager_secret_rotation: Add
external_secret_rotation_metadataandexternal_secret_rotation_role_arnarguments in support of managed external secrets (#46414)
BUG FIXES:
v6.57.0
6.57.0 (July 29, 2026)
Important
Release v6.57.0 had a significant bug and has been removed from GitHub and the Terraform Registry. However, if you successfully used v6.57.0 and then downgraded to v6.56.0, your state may refer to features that are not available in the downgraded version. This will cause errors. In that scenario, it is important to upgrade to v6.57.1.
v6.56.0
6.56.0 (July 22, 2026)
FEATURES:
- New Action:
aws_elasticache_apply_service_update(#48963) - New Data Source:
aws_elasticache_service_update_actions(#48958) - New Data Source:
aws_s3_buckets(#48965) - New List Resource:
aws_eks_addon(#49067) - New List Resource:
aws_s3_bucket_notification(#48974) - New List Resource:
aws_secretsmanager_secret_policy(#49058)
ENHANCEMENTS:
- data-source/aws_eks_node_group: Add
warm_pool_configattribute (#48977) - data-source/aws_msk_bootstrap_brokers: Add
bootstrap_brokers_ipv6,bootstrap_brokers_sasl_iam_ipv6,bootstrap_brokers_sasl_scram_ipv6, andbootstrap_brokers_tls_ipv6attributes to expose IPv6 bootstrap broker URLs (#48975) - data-source/aws_opensearchserverless_security_config: Add
iam_federation_optionsblock (#48495) - data-source/aws_opensearchserverless_security_config: Add
iam_identity_center_optionsblock (#48495) - provider: Web identity tokens can be configured via the
TF_AWS_WEB_IDENTITY_TOKENenvironment variable. Any value configured viaassume_role_with_web_identity.web_identity_tokentakes precedence (#48736) - resource/aws_autoscaling_group: Add
instance_lifecycle_policyconfiguration block (#48973) - resource/aws_bedrockagent_data_source: Add
data_source_configuration.managed_knowledge_base_connector_configurationblock (#48904) - resource/aws_bedrockagent_data_source: Add
timeouts.updatewith a default value of30m(#48904) - resource/aws_bedrockagent_knowledge_base: Add
vector_knowledge_base_configuration.bedrock_embedding_model_configuration.audioandvector_knowledge_base_configuration.bedrock_embedding_model_configuration.videoconfiguration blocks (#48538) - resource/aws_bedrockagent_knowledge_base: Add support for Managed Knowledge Base type (
type = "MANAGED") withmanaged_knowledge_base_configurationblock (#48904) - resource/aws_cloudwatch_log_subscription_filter: Add
@source.logas a valid value foremit_system_fields(#48956) - resource/aws_eks_node_group: Add
warm_pool_configconfiguration block (#48977) - resource/aws_flow_log: Add
tag_field_specificationconfiguration block (#48913) - resource/aws_guardduty_detector_feature: Support
AI_PROTECTIONandAI_ANALYSTfeature names (#48972) - resource/aws_guardduty_organization_configuration_feature: Support
AI_PROTECTIONandAI_ANALYSTfeature names (#48972) - resource/aws_msk_cluster: Add
bootstrap_brokers_ipv6,bootstrap_brokers_sasl_iam_ipv6,bootstrap_brokers_sasl_scram_ipv6, andbootstrap_brokers_tls_ipv6attributes to expose IPv6 bootstrap broker URLs (#48975) - resource/aws_opensearch_package_association: Add import support (#46690)
- resource/aws_opensearchserverless_security_config: Add
iam_federation_optionsconfiguration block (#48495) - resource/aws_opensearchserverless_security_config: Add
iam_identity_center_optionsconfiguration block (#48495) - resource/aws_s3tables_table: Add
metadata.iceberg.propertiesargument (#48635)
BUG FIXES:
- provider: Fix "one of
assume_role_with_web_identity.0.web_identity_token,assume_role_with_web_identity.0.web_identity_token_filemust be specified" errors, allowing anyAWS_WEB_IDENTITY_TOKEN_FILEenvironment variable value to be used (#48736) - resource/aws_bedrockagent_data_source: Short-circuit waiting for creation if the resource reaches a
FAILEDstate (#48904) - resource/aws_datazone_domain: Fixed
AccessDeniedExceptionerror when deleting (#48516) - resource/aws_fsx_lustre_file_system: Fix perpetual diff in
data_read_cache_configuration.sizewhensizing_modeisPROPORTIONAL_TO_THROUGHPUT_CAPACITYandsizeis not specified (#49023) - resource/aws_mq_broker: Fix perpetual
shared_resourcesdiffs for ActiveMQ brokers (#48962) - resource/aws_mq_configuration: Retry
ConflictException: Configuration ID [...] is in useerrors on delete (#48962) - resource/aws_sagemaker_endpoint: Prevents
Cannot create already existing endpointerror when retrying creation. (#48966) - resource/aws_subnet: Wait for IPAM to release its CIDR on delete (#46523)
- resource/aws_vpc_ipam_pool: Fix "Error: reading EC2 VPC" when creating an IPAM VPC resource planning pool for a VPC in another account. (#46483)
v6.55.0
6.55.0 (July 15, 2026)
FEATURES:
- New Data Source:
aws_elasticache_service_updates(#44608) - New List Resource:
aws_autoscaling_group(#48928) - New List Resource:
aws_cloudwatch_log_stream(#48878) - New List Resource:
aws_kinesis_firehose_delivery_stream(#48946) - New List Resource:
aws_network_interface(#48887) - New List Resource:
aws_rds_cluster(#48948) - New List Resource:
aws_sfn_state_machine(#48840)
ENHANCEMENTS:
- resource/aws_bedrock_guardrail: Add
updated_atattribute (#48881) - resource/aws_bedrockagentcore_agent_runtime: Add
allowed_workload_configuration,private_endpoint, andprivate_endpoint_overridesconfiguration blocks toauthorizer_configuration.custom_jwt_authorizer, and the read-onlyrequire_service_s3_endpointattribute tonetwork_configuration.network_mode_config(#48654) - resource/aws_bedrockagentcore_gateway: Add
allowed_workload_configuration,private_endpoint, andprivate_endpoint_overridesconfiguration blocks toauthorizer_configuration.custom_jwt_authorizer(#48654) - resource/aws_bedrockagentcore_harness: Add
allowed_workload_configuration,private_endpoint, andprivate_endpoint_overridesconfiguration blocks toauthorizer_configuration.custom_jwt_authorizer(#48654) - resource/aws_bedrockagentcore_harness: Add
require_service_s3_endpointargument tonetwork_configuration.network_mode_config(#48654) - resource/aws_bedrockagentcore_registry: Add
allowed_workload_configuration,private_endpoint, andprivate_endpoint_overridesconfiguration blocks toauthorizer_configuration.custom_jwt_authorizer(#48654) - resource/aws_msk_replicator: Add
consumer_group_offset_sync_modeattribute toconsumer_group_replicationblock (#47670) - resource/aws_network_interface: Add resource identity support (#48887)
- resource/aws_rds_cluster: Add resource identity support (#48948)
BUG FIXES:
v6.54.0
6.54.0 (July 8, 2026)
NOTES:
- resource/aws_sagemaker_endpoint_configuration: Because we cannot easily test the behavior of
capacity_reservation_config, it is best effort and we ask for community help in testing (#45926) - resource/aws_ssoadmin_region: Because we cannot easily test this functionality, it is best effort and we ask for community help in testing (#48126)
FEATURES:
- New Data Source:
aws_route53profiles_profile(#48780) - New List Resource:
aws_bedrockagentcore_browser_profile(#46862) - New List Resource:
aws_codepipeline(#48808) - New List Resource:
aws_lambda_function_scaling_config(#48229) - New List Resource:
aws_scheduler_schedule(#48828) - New List Resource:
aws_ssoadmin_region(#48126) - New List Resource:
aws_workspaces_pool(#42678) - New Resource:
aws_bedrockagentcore_browser_profile(#46862) - New Resource:
aws_lambda_function_scaling_config(#48229) - New Resource:
aws_ssoadmin_region(#48126) - New Resource:
aws_workspaces_pool(#42678)
ENHANCEMENTS:
- action/aws_codebuild_start_build: Add
host_kernel_overrideargument (#48777) - data-source/aws_mq_broker: Add
resource_share_arnsandshared_resourcesattributes (#48729) - resource/aws_cloudfront_key_value_store: Add
tagsandtags_allattributes (#48458) - resource/aws_cloudwatch_event_api_destination: Add Resource Identity support (#48819)
- resource/aws_cloudwatch_event_archive: Add Resource Identity support (#48819)
- resource/aws_cloudwatch_event_bus: Add Resource Identity support (#48819)
- resource/aws_cloudwatch_event_bus_policy: Add Resource Identity support (#48819)
- resource/aws_cloudwatch_event_connection: Add Resource Identity support (#48819)
- resource/aws_cloudwatch_event_endpoint: Add Resource Identity support (#48819)
- resource/aws_cloudwatch_event_permission: Add Resource Identity support (#48819)
- resource/aws_codebuild_project: Add
host_kernelargument to theenvironmentconfiguration block (#48777) - resource/aws_codepipeline: Add resource identity support (#48808)
- resource/aws_iam_policy_attachment: Add resource identity support (#48639)
- resource/aws_lambda_event_source_mapping: Add
use_resource_timeout_for_propagationargument (#46405) - resource/aws_lambda_event_source_mapping: Add configurable resource timeouts. Defaults to
10mforcreateandupdate,5mfordelete. (#46405) - resource/aws_lambda_function: Add
use_resource_timeout_for_propagationargument (#46405) - resource/aws_lambda_permission: Add configurable resource timeouts. Defaults to
5mforcreate,read, anddelete. (#46405) - resource/aws_lambda_permission: Hard-coded timeouts to account for eventual consistency have been replaced with configurable resource timeouts (#46405)
- resource/aws_mq_broker: Add
resource_share_arnsargument andshared_resourcesattribute (#48729) - resource/aws_prometheus_workspace_configuration: Add
out_of_order_time_window_in_secondsandrule_query_offset_in_secondsarguments (#48659) - resource/aws_rds_cluster: Add support for
auto_minor_version_upgradeargument (#42472) - resource/aws_sagemaker_endpoint_configuration: Add Resource Identity support (#45926)
- resource/aws_sagemaker_endpoint_configuration: Add
production_variants.capacity_reservation_configandshadow_production_variants.capacity_reservation_configconfiguration blocks (#45926) - resource/aws_scheduler_schedule: Add resource identity support (#48828)
BUG FIXES:
- resource/aws_bedrock_guardrail: Prevents "inconsistent result" error when adding
content_policy_configblock. (#48772) - resource/aws_bedrock_guardrail: Prevents "inconsistent result" error when adding
topic_policy_configblock. (#48772) - resource/aws_bedrock_guardrail: Prevents "inconsistent result" error with multiple
content_policy_config.filters_config.input_modalitiesvalues. (#48772) - resource/aws_bedrock_guardrail: Prevents "inconsistent result" error with multiple
content_policy_config.filters_config.output_modalitiesvalues. (#48772) - resource/aws_cloudfront_multitenant_distribution: Correctly handles default tags. (#48783)
- resource/aws_cloudfront_multitenant_distribution: Correctly taints resource if Create fails. (#48782)
- resource/aws_cloudfront_multitenant_distribution: Sets
etagon Import. (#48782) - resource/aws_cloudfront_multitenant_distribution: Updates
etagwhen onlytagsupdated. (#48782) - resource/aws_cloudfront_multitenant_distribution: Waits for deployment on Update. (#48782)
- resource/aws_directory_service_directory: Fix
UnsupportedOperationExceptionerror when readingenable_directory_data_accessin regions where Directory Service Data is not available (e.g. GovCloud) (#47660)
v6.53.0
6.53.0 (July 1, 2026)
BREAKING CHANGES:
- resource/aws_pinpointsmsvoicev2_phone_number: Remove provider-side defaults for
opt_out_list_nameandtwo_way_channel_enabledin favor of AWS server-side defaults (Defaultandfalserespectively). Configurations that omit these attributes will now show(known after apply)on first plan instead of the previous static value; the post-apply state is unchanged. This change mitigates persistent drift when the phone number is managed by anaws_pinpointsmsvoicev2_pool. (#48414)
NOTES:
- list-resource/aws_bedrockagentcore_registry: This resource is deprecated. AWS Agent Registry is currently available in public preview. On August 6, 2026 this functionality will move from the
bedrock-agentcorenamespace to theagent-registrynamespace. Theaws_bedrockagentcore_browserresource will continue to work until September 17, 2026 (#48693) - resource/aws_bedrockagentcore_registry: This resource is deprecated. AWS Agent Registry is currently available in public preview. On August 6, 2026 this functionality will move from the
bedrock-agentcorenamespace to theagent-registrynamespace. Theaws_bedrockagentcore_browserresource will continue to work until September 17, 2026 (#48693) - resource/aws_ecs_capacity_provider: When a change forces replacement of a capacity provider that is associated with a cluster via
aws_ecs_cluster_capacity_providers, add areplace_triggered_bylifecycle rule to the association so the old capacity provider is detached before it is deleted (#48156)
FEATURES:
- New Data Source:
aws_bedrock_foundation_model_agreement_offers(#47665) - New Data Source:
aws_bedrock_use_case_for_model_access(#47665) - New Data Source:
aws_ec2_capacity_block_reservation(#48185) - New List Resource:
aws_pinpointsmsvoicev2_pool(#48414) - New Resource:
aws_bedrock_foundation_model_agreement(#47665) - New Resource:
aws_bedrock_use_case_for_model_access(#47665) - New Resource:
aws_pinpointsmsvoicev2_pool(#48414)
ENHANCEMENTS:
- data-source/aws_api_gateway_rest_api: Add
security_policyandendpoint_access_modeattributes (#47973) - data-source/aws_msk_cluster: Add
customer_action_statusattribute (#48536) - resource/aws_api_gateway_rest_api: Add
security_policyandendpoint_access_modearguments (#47973) - resource/aws_bedrockagentcore_browser: Add
browser_signing,certificate, andenterprise_policyconfiguration blocks (#47816) - resource/aws_bedrockagentcore_code_interpreter: Add
certificateargument (#47817) - resource/aws_cloudwatch_composite_alarm: Add Resource Identity support (#48679)
- resource/aws_cloudwatch_contributor_insight_rule: Add Resource Identity support (#48679)
- resource/aws_cloudwatch_contributor_insight_rule: Add plan-time validation of
rule_definition(#48679) - resource/aws_cloudwatch_contributor_insight_rule: Change
rule_stateto Optional and Computed (#48679) - resource/aws_cloudwatch_contributor_managed_insight_rule: Add Resource Identity support (#48679)
- resource/aws_cloudwatch_contributor_managed_insight_rule: Add plan-time validation of
resource_arnandtemplate_name(#48679) - resource/aws_cloudwatch_dashboard: Add Resource Identity support (#48679)
- resource/aws_cloudwatch_metric_stream: Add Resource Identity support (#48679)
- resource/aws_default_vpc: Add resource identity support (#47590)
- resource/aws_msk_cluster: Add
customer_action_statusattribute (#48536) - resource/aws_pinpointsmsvoicev2_phone_number: Add
force_disassociateargument (#48414) - resource/aws_securityhub_automation_rule: Deprecates
idin favor ofarn(#48636) - resource/aws_ssmcontacts_rotation: Deprecates
idin favor ofarn(#48636) - resource/aws_ssoadmin_trusted_token_issuer: Deprecates
idin favor ofarn(#48636)
BUG FIXES:
- data-source/aws_codeartifact_authorization_token: Mark
authorization_tokenas sensitive (#48577) - resource/aws_cloudwatch_contributor_managed_insight_rule: Mark
resource_arn,tagsandtemplate_nameasForceNew(#48679) - resource/aws_default_vpc: Fix provider panic (nil pointer dereference) when importing via an
importblock orterraform import(#47590) - resource/aws_ecs_capacity_provider: Return the underlying error immediately instead of timing out after 20 minutes when deleting a capacity provider that is still associated with a cluster (#48156)
- resource/aws_iam_user: Handle
InvalidActionerrors in partitions where access key cleanup operations are not supported (#48473) - resource/aws_instance: Fix perpetual diff when
instance_market_options.market_typeis set tocapacity-block(#48701) - resource/aws_lightsail_bucket_access_key: Mark
secret_access_keyas sensitive (#48577) - resource/aws_lightsail_key_pair: Mark
private_keyas sensitive (#48577) - resource/aws_route53_record: Fix the
typeattribute to no longer force resource replacement on change (#47105) - resource/aws_sqs_queue: Reduce the wait time for queue deletion. This fixes a regression introduced in v6.34.0. (#48722)