Conversation
Open in Overmind ↗
🔴 Change SignalsRoutine 🔴 🔥 RisksReplacing the directly exposed API instance will interrupt the public EIP endpoint during cutover Because the instance is not being updated in place but replaced, the EIP and public DNS mapping have to move from the old instance/ENI to a new one. That creates a real cutover risk: any external client, monitor, or runbook using the current direct EC2 identity rather than a managed endpoint will lose continuity during the reassociation, and there is no load balancer or edge service absorbing that swap on the public path. The internal Attachment replacement will leave both load balancers with zero healthy targets during re-registration The NLB path is especially exposed because the backend instance that owns Simultaneous EC2 replacement can remove all healthy load balancer targets if the new AMIs/bootstrap differ Because these instances are not in an Auto Scaling Group and there is no evidence of a canary or phased rollout, any regression in the new AMI or bootstrap script will remove healthy targets faster than the load balancers can recover. Single healthy backend replacement will create a real service gap during ALB/NLB and EIP cutover When Terraform replaces these resources, the old instance target and old IP attachment cannot continue serving indefinitely while the new instances bootstrap, register, and satisfy load balancer health checks. The ALB target group requires two successful
|
ba884cb to
12213ca
Compare
12213ca to
97c66a8
Compare

This PR contains the following updates:
< 6.38→< 6.406.37.0→6.39.07.25.0→7.26.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
hashicorp/terraform-provider-aws (aws)
v6.39.0Compare Source
NOTES:
tags_allattribute is deprecated and will be removed in a future major version (#47133)FEATURES:
aws_iam_role_policies(#46936)aws_iam_role_policy_attachments(#47119)aws_networkmanager_core_network(#45798)aws_uxc_services(#47115)aws_eks_cluster(#47133)aws_organizations_aws_service_access(#46993)aws_sagemaker_training_job(#46892)aws_workmail_group(#47131)aws_workmail_user(#47131)aws_organizations_aws_service_access(#46993)aws_sagemaker_training_job(#46892)aws_uxc_account_customizations(#47115)aws_workmail_group(#47131)aws_workmail_user(#47131)ENHANCEMENTS:
instance_familiesattribute (#47153)tier-8xlas a valid value forcontrol_plane_scaling_config.tier(#46976)source.source_logs_configuration.data_source_selection_criteriaargument. Changesource.source_logs_configuration.log_group_selection_criteriato Optional (#47154)source.vpcargument. Changesource.eksto Optional (#47155)storage_lens_configuration.account_level.advanced_performance_metricsandstorage_lens_configuration.account_level.bucket_level.advanced_performance_metricsarguments (#46865)BUG FIXES:
aws-cnpartition (#47141)Error: waiting for creation AWS DynamoDB Table (xxxxx): couldn't find resourcein highly active accounts by restoring5sdelay before polling for table status. This fixes a regression introduced in v6.28.0. (#47143)bootstrap_self_managed_addonstotruewhen importing (#47133)InvalidParameterCombinationerror whencache_usage_limitsis removed (#46134)v6.38.0Compare Source
FEATURES:
aws_dms_start_replication_task_assessment_run(#47058)aws_dynamodb_backups(#47036)aws_msk_topic(#46490)aws_savingsplans_offerings(#47081)aws_msk_cluster(#46490)aws_msk_serverless_cluster(#46490)aws_msk_topic(#46490)aws_route53_resolver_rule(#47063)aws_sagemaker_algorithm(#47051)aws_ssm_document(#46974)aws_ssoadmin_account_assignment(#47067)aws_vpc_endpoint(#46977)aws_workmail_domain(#46931)aws_msk_topic(#46490)aws_observabilityadmin_telemetry_enrichment(#47089)aws_sagemaker_algorithm(#47051)aws_workmail_default_domain(#46931)aws_workmail_domain(#46931)ENHANCEMENTS:
firewall_policy.enable_tls_session_holdingattribute (#47065)authorizer_configuration.custom_jwt_authorizer.custom_claimconfiguration block (#47049)authorizer_configuration.custom_jwt_authorizer.custom_claimconfiguration block (#47049)target_configuration.mcp.api_gatewayconfiguration block (#46916)restore_backup_arnargument (#47068)KinesisStreamsas a value foraction.target.key(#47010)VPCEndpointsas a value foraction.target.key(#47045)userblock to Optional (#46883)firewall_policy.enable_tls_session_holdingargument (#47065)filters.aws_account_nameconfiguration block (#47027)filters.compliance_associated_standards_idconfiguration block (#47027)filters.compliance_security_control_idconfiguration block (#47027)filters.compliance_security_control_parameters_nameconfiguration block (#47027)filters.compliance_security_control_parameters_valueconfiguration block (#47027)BUG FIXES:
@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)Provider produced inconsistent result after applyerror whenenvironmentvariables are defined in non-alphabetical order (#46771)Provider returned invalid result object after applyerrors where computed attributes remained unknown after create (#47012)@regionsuffix when using resource-levelregionattribute (#47043)userblock (#46883)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)@regionsuffix when using resource-levelregionattribute (#47043)Unable to unmarshal DynamicValueerror whenstatement.managed_rule_group_statement.rule_action_overrideblock is specified (#46998)WAFOptimisticLockExceptionerrors when multiple associations target the same Web ACL (#47037)hashicorp/terraform-provider-google (google)
v7.26.0Compare Source
Configuration
📅 Schedule: Branch creation - "before 10am on friday" in timezone Europe/London, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.