-
Notifications
You must be signed in to change notification settings - Fork 9.6k
feat: Add internal access analyzer support to aws_accessanalyzer_analyzer #43138
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat: Add internal access analyzer support to aws_accessanalyzer_analyzer #43138
Conversation
Community GuidelinesThis comment is added to every new Pull Request to provide quick reference to how the Terraform AWS Provider is maintained. Please review the information below, and thank you for contributing to the community that keeps the provider thriving! 🚀 Voting for Prioritization
Pull Request Authors
|
✅ Thank you for correcting the previously detected issues! The maintainers appreciate your efforts to make the review process as smooth as possible. |
e99d6a7
to
cb09c3c
Compare
cb09c3c
to
e5a9a51
Compare
…invalid_type until enum values are updated
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM 🚀.
% make testacc TESTARGS='-run=TestAccAccessAnalyzer_serial/^Analyzer$$' PKG=accessanalyzer
make: Verifying source code with gofmt...
==> Checking that code complies with gofmt requirements...
TF_ACC=1 go1.24.4 test ./internal/service/accessanalyzer/... -v -count 1 -parallel 20 -run=TestAccAccessAnalyzer_serial/^Analyzer$ -timeout 360m -vet=off
2025/06/25 12:22:13 Creating Terraform AWS Provider (SDKv2-style)...
2025/06/25 12:22:13 Initializing Terraform AWS Provider (SDKv2-style)...
=== RUN TestAccAccessAnalyzer_serial
=== PAUSE TestAccAccessAnalyzer_serial
=== CONT TestAccAccessAnalyzer_serial
=== RUN TestAccAccessAnalyzer_serial/Analyzer
=== RUN TestAccAccessAnalyzer_serial/Analyzer/organizationInternalAccess
analyzer_test.go:213: skipping tests; this AWS account must not be an existing member of an AWS Organization
=== RUN TestAccAccessAnalyzer_serial/Analyzer/organizationUnusedAccess
analyzer_test.go:281: skipping tests; this AWS account must not be an existing member of an AWS Organization
=== RUN TestAccAccessAnalyzer_serial/Analyzer/type_Organization
analyzer_test.go:89: skipping tests; this AWS account must not be an existing member of an AWS Organization
=== RUN TestAccAccessAnalyzer_serial/Analyzer/basic
=== RUN TestAccAccessAnalyzer_serial/Analyzer/accountUnusedAccess
=== RUN TestAccAccessAnalyzer_serial/Analyzer/disappears
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnUpdate_Replace
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_providerOnly
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nonOverlapping
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_updateToResourceOnly
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nullOverlappingResourceTag
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyMap
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnCreate
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnUpdate_Add
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_emptyResourceTag
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnCreate
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/basic
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/IgnoreTags_Overlap_ResourceTag
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_overlapping
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_updateToProviderOnly
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nullNonOverlappingResourceTag
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnUpdate_Add
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnUpdate_Replace
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/IgnoreTags_Overlap_DefaultTag
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/null
=== RUN TestAccAccessAnalyzer_serial/Analyzer/tags/AddOnUpdate
=== RUN TestAccAccessAnalyzer_serial/Analyzer/upgradeV5_95_0
=== RUN TestAccAccessAnalyzer_serial/Analyzer/accountInternalAccess
--- PASS: TestAccAccessAnalyzer_serial (661.29s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer (661.29s)
--- SKIP: TestAccAccessAnalyzer_serial/Analyzer/organizationInternalAccess (1.09s)
--- SKIP: TestAccAccessAnalyzer_serial/Analyzer/organizationUnusedAccess (0.26s)
--- SKIP: TestAccAccessAnalyzer_serial/Analyzer/type_Organization (2.02s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/basic (13.12s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/accountUnusedAccess (13.36s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/disappears (11.30s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags (543.71s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnUpdate_Replace (23.21s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_providerOnly (49.48s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nonOverlapping (37.87s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_updateToResourceOnly (22.59s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nullOverlappingResourceTag (14.39s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyMap (17.57s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnCreate (25.77s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/EmptyTag_OnUpdate_Add (35.00s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_emptyResourceTag (14.55s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnCreate (17.96s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/basic (48.96s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/IgnoreTags_Overlap_ResourceTag (34.14s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_overlapping (38.47s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_updateToProviderOnly (23.27s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/DefaultTags_nullNonOverlappingResourceTag (14.42s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnUpdate_Add (27.57s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/ComputedTag_OnUpdate_Replace (27.35s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/IgnoreTags_Overlap_DefaultTag (29.79s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/null (18.06s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/tags/AddOnUpdate (23.28s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/upgradeV5_95_0 (45.36s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/accountInternalAccess (31.07s)
PASS
ok github.com/hashicorp/terraform-provider-aws/internal/service/accessanalyzer 666.140s
% make testacc TESTARGS='-run=TestAccAccessAnalyzer_serial/^Analyzer$$/organization\|TestAccAccessAnalyzer_serial/^Analyzer$$/type_Organization' PKG=accessanalyzer
make: Verifying source code with gofmt...
==> Checking that code complies with gofmt requirements...
TF_ACC=1 go1.24.4 test ./internal/service/accessanalyzer/... -v -count 1 -parallel 20 -run=TestAccAccessAnalyzer_serial/^Analyzer$/organization\|TestAccAccessAnalyzer_serial/^Analyzer$/type_Organization -timeout 360m -vet=off
2025/06/25 13:02:22 Creating Terraform AWS Provider (SDKv2-style)...
2025/06/25 13:02:22 Initializing Terraform AWS Provider (SDKv2-style)...
=== RUN TestAccAccessAnalyzer_serial
=== PAUSE TestAccAccessAnalyzer_serial
=== CONT TestAccAccessAnalyzer_serial
=== RUN TestAccAccessAnalyzer_serial/Analyzer
=== RUN TestAccAccessAnalyzer_serial/Analyzer/organizationInternalAccess
=== RUN TestAccAccessAnalyzer_serial/Analyzer/organizationUnusedAccess
=== RUN TestAccAccessAnalyzer_serial/Analyzer/type_Organization
--- PASS: TestAccAccessAnalyzer_serial (71.21s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer (71.21s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/organizationInternalAccess (39.44s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/organizationUnusedAccess (15.66s)
--- PASS: TestAccAccessAnalyzer_serial/Analyzer/type_Organization (16.10s)
PASS
ok github.com/hashicorp/terraform-provider-aws/internal/service/accessanalyzer 75.973s
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM 🚀
@acwwat Thanks for the contribution 🎉 👏. |
Warning This Issue has been closed, meaning that any additional comments are much easier for the maintainers to miss. Please assume that the maintainers will not see them. Ongoing conversations amongst community members are welcome, however, the issue will be locked after 30 days. Moving conversations to another venue, such as the AWS Provider forum, is recommended. If you have additional concerns, please open a new issue, referencing this one where needed. |
This functionality has been released in v6.1.0 of the Terraform AWS Provider. Please see the Terraform documentation on provider versioning or reach out if you need any assistance upgrading. For further feature requests or bug reports with this functionality, please create a new GitHub issue following the template. Thank you! |
Rollback Plan
If a change needs to be reverted, we will publish an updated version of the library.
Changes to Security Controls
n/a
Description
This PR adds internal access analyzer support to the
aws_accessanalyzer_analyzer
resource.Relations
Closes #43083
References
Referred to AnalyzerSummary for specs and wordings.
Output from Acceptance Testing
Account analyzer tests:
Organization analyzer tests (had to run them in a separate account):