chore(deps): update terraform cloudposse/s3-bucket/aws to v4 (release/v0) - #102
Open
renovate[bot] wants to merge 1 commit into
Open
chore(deps): update terraform cloudposse/s3-bucket/aws to v4 (release/v0)#102renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
requested review from
PePe Amengual (jamengual) and
Joe Niland (joe-niland)
and removed request for
a team
March 9, 2024 04:15
|
/terratest |
renovate
Bot
force-pushed
the
renovate/release/v0-cloudposse-s3-bucket-aws-4.x
branch
2 times, most recently
from
July 30, 2024 19:47
37d6741 to
3e4e3bf
Compare
renovate
Bot
force-pushed
the
renovate/release/v0-cloudposse-s3-bucket-aws-4.x
branch
2 times, most recently
from
August 13, 2024 17:46
e382b77 to
67efe71
Compare
renovate
Bot
force-pushed
the
renovate/release/v0-cloudposse-s3-bucket-aws-4.x
branch
from
August 14, 2024 19:04
67efe71 to
3c79a78
Compare
renovate
Bot
force-pushed
the
renovate/release/v0-cloudposse-s3-bucket-aws-4.x
branch
from
September 24, 2024 18:12
3c79a78 to
88e90e8
Compare
renovate
Bot
force-pushed
the
renovate/release/v0-cloudposse-s3-bucket-aws-4.x
branch
2 times, most recently
from
November 14, 2024 13:40
56c4e58 to
4f6c52d
Compare
renovate
Bot
force-pushed
the
renovate/release/v0-cloudposse-s3-bucket-aws-4.x
branch
from
January 28, 2025 06:40
4f6c52d to
e8f6bc1
Compare
renovate
Bot
force-pushed
the
renovate/release/v0-cloudposse-s3-bucket-aws-4.x
branch
from
February 26, 2026 23:11
e8f6bc1 to
d7a5b72
Compare
renovate
Bot
force-pushed
the
renovate/release/v0-cloudposse-s3-bucket-aws-4.x
branch
2 times, most recently
from
April 22, 2026 20:02
0f85ade to
7426047
Compare
renovate
Bot
force-pushed
the
renovate/release/v0-cloudposse-s3-bucket-aws-4.x
branch
from
June 27, 2026 07:11
7426047 to
0f1d4b1
Compare
renovate
Bot
force-pushed
the
renovate/release/v0-cloudposse-s3-bucket-aws-4.x
branch
from
July 21, 2026 03:39
0f1d4b1 to
48b9056
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.0.0→4.15.0Release Notes
cloudposse/terraform-aws-s3-bucket (cloudposse/s3-bucket/aws)
v4.15.0Compare Source
feat: enable Object Lock without a default retention rule @Benbentwo (#295)
what
object_lock_enabled(bool, defaultfalse) variable that enables S3 Object Lock on the bucket without configuring a bucket-wide default retention rule.default_retentionrule inaws_s3_bucket_object_lock_configuration.defaultto adynamicblock that is only rendered whenobject_lock_configurationis set.object_lock_configurationis provided, so existing configurations are unchanged.why
object_lock_enabledflag is to passobject_lock_configuration, and doing so always creates anaws_s3_bucket_object_lock_configurationwith a hardcodedrule { default_retention { … } }.PutObjectLockConfigurationwithObjectLockEnabled=Enabledand noRule). This change lets the module express that.usage
backward compatibility
Fully backward compatible.
local.object_lock_enabledbecomeslocal.enabled && (var.object_lock_enabled || var.object_lock_configuration != null), so any existing config that passesobject_lock_configurationproduces an identical plan (bucket flag on + the samedefault_retentionrule).references
v4.14.0Compare Source
feat(outputs): add bucket_hosted_zone_id output @RoseSecurity (#293)
what
bucket_hosted_zone_idoutputwhy
references
v4.13.0Compare Source
feat: add bucket_namespace argument @QuentinBtd (#291)
what
Add
bucket_namespaceargumentwhy
AWS added regional namespaces for bucket.
references
https://registry.terraform.io/providers/hashicorp/aws/6.37.0/docs/resources/s3_bucket.html#bucket_namespace-7
https://aws.amazon.com/fr/blogs/aws/introducing-account-regional-namespaces-for-amazon-s3-general-purpose-buckets/
v4.12.0Compare Source
🐛 Bug Fixes
Add blocked_encryption_types variable to fix perpetual SSE config drift @duality72 (#289)
what
blocked_encryption_typesvariable (typelist(string), defaultnull) to the module.ruleblock ofaws_s3_bucket_server_side_encryption_configuration.variables.tfand the inputs table inREADME.md.why
Fixes #287.
On
hashicorp/awsprovider >= 6.22.0,GetBucketEncryptionreturnsblocked_encryption_types = ["NONE"]by default. The module's encryption rule omits the field, which the provider treats as an empty list. The two do not round-trip, soterraform planshows a perpetual in-place update onaws_s3_bucket_server_side_encryption_configuration— applying does not stabilize the plan.Exposing the field as an opt-in variable lets callers on provider >= 6.22.0 silence the drift by setting
blocked_encryption_types = ["NONE"], without forcing a provider floor bump on callers still on older providers.design note: why
nulldefault, not["NONE"]The module's current provider floor is
hashicorp/aws >= 4.9.0. Theblocked_encryption_typesargument was added to the AWS provider in v6.22.0. Defaulting to["NONE"]would break every caller on provider < 6.22.0 with an "Unsupported argument" error.There is no clean way to conditionally default based on resolved provider version (Terraform does not expose
required_providersversions as HCL values). Thenulldefault mirrors the pattern used elsewhere in cloudposse modules for attributes gated behind newer provider versions: safe default, opt-in for callers who know they're on a new enough provider.reviewer guide
variables.tf— newvariable "blocked_encryption_types"block added immediately afterbucket_key_enabled. Note thedefault = nulland the description explaining the provider-version nuance.main.tf(~line 86) — one new line inside theruleblock:blocked_encryption_types = var.blocked_encryption_types. When the variable isnull, the provider omits the attribute (standard Terraform null-handling), preserving existing behavior for all current callers.README.md(inputs table, alphabetical position beforebucket_key_enabled) — new row documenting the variable. Matches the style of adjacent rows.test plan
terraform fmt -checkpassesterraform validatepasses with the current provider floorblocked_encryption_types = ["NONE"]eliminates the drift described in #287null) keeps behavior unchanged — no "Unsupported argument" errorv4.11.0Compare Source
Add S3 Intelligent-Tiering archive configuration support @milldr (#286)
What
Add
aws_s3_bucket_intelligent_tiering_configurationresource andintelligent_tiering_configurationvariable to support configuring archive access tiers within the INTELLIGENT_TIERING storage class.Why
The module already supports
INTELLIGENT_TIERINGas a lifecycle transition storage class, but there's no way to configure the archive access tiers (Archive Access, Deep Archive Access) that control when objects within Intelligent-Tiering are moved to cheaper archive storage. This is needed for cost optimization on buckets with infrequently accessed data.Ref
🤖 Automatic Updates
Fix go version in tests @osterman (#276)
what
1.24why
References
Replace Makefile with atmos.yaml @osterman (#275)
what
Makefileatmos.yamlwhy
build-harnesswithatmosfor readme genrationReferences
v4.10.0Compare Source
feat: Add filter_prefix, filter_suffix config options for queues and topics @vonZeppelin (#261)
what
Signed-off-by: Leonid Bogdanov <leonidbogdanov86@gmail.com>
references
v4.9.0Compare Source
feat: add s3 request payment config @nitrocode (#259)
what
why
references
v4.8.0Compare Source
feat: support eventbridge bucket notification @nitrocode (#255)
what
why
references
v4.7.3Compare Source
🚀 Enhancements
fix: use new destination.bucket key in policy @nitrocode (#256)
what
why
destination_bucketand newdestination.bucketdestination.bucketand leftdestination_bucketfor backwards compatibility, as stated in variables.tf, and forgot to include the new value in the IAM policyreferences
🐛 Bug Fixes
fix: use new destination.bucket key in policy @nitrocode (#256)
what
why
destination_bucketand newdestination.bucketdestination.bucketand leftdestination_bucketfor backwards compatibility, as stated in variables.tf, and forgot to include the new value in the IAM policyreferences
v4.7.2Compare Source
🚀 Enhancements
fix: correct bucket name to fix broken `-replication` role @amila-ku (#250)
what
why
references
v4.7.1Compare Source
🚀 Enhancements
fix: s3 lambda event notification assignments @mpajuelofernandez (#253)
what
It seems there is a typo kind if error here
I think it should be
why
The S3 notification can not be created unless this is fixed
references
This should fix #252
🐛 Bug Fixes
fix: s3 lambda event notification assignments @mpajuelofernandez (#253)
what
It seems there is a typo kind if error here
I think it should be
why
The S3 notification can not be created unless this is fixed
references
This should fix #252
🤖 Automatic Updates
Update terratest to '>= 0.46.0' @osterman (#235)
what
>= 0.46.0why
References
Migrate new test account @osterman (#248)
what
.github/settings.yml.github/chatops.ymlfileswhy
.github/settings.ymlfrom org level to getterratestenvironmenttestaccountReferences
Update .github/settings.yml @osterman (#247)
what
.github/settings.yml.github/auto-release.ymlfileswhy
.github/settings.ymlfrom org levelreferences
Update .github/settings.yml @osterman (#246)
what
.github/settings.yml.github/auto-release.ymlfileswhy
.github/settings.ymlfrom org levelreferences
v4.7.0Compare Source
Make sure replica_kms_key_id is truly empty @stephan242 (#244)
references
closes #243
v4.6.0Compare Source
Addition of S3 bucket event notification resource and Addition of S3 directory optional resource @mayank0202 (#240)
Issue - GH-239
what
This feature will make s3 event notifications which will have 3 options to trigger lambda or queue or topic so we can define a resource from this documentation.
aws_s3_bucket_notificationwe also added s3 directory bucket which is a new feature in aws so addition of optional resource can be done if someone needs to use that with the help of terraform
aws_s3_directory_bucketwhy
Enhanced Event-Driven Architecture: The introduction of S3 event notifications allows the S3 bucket to trigger Lambda functions, SQS queues, or SNS topics. This facilitates seamless integration with other AWS services and enables real-time processing of data, which is crucial for building event-driven architectures.
New AWS Feature Adoption: The addition of the aws_s3_directory_bucket resource reflects the latest AWS capabilities, ensuring that our infrastructure is up-to-date with current AWS offerings. This optional resource allows users to leverage new AWS features as they become available, promoting flexibility and future-proofing our Terraform configurations.
Improved Flexibility: By providing options to trigger different AWS services (Lambda, SQS, SNS), the solution becomes more versatile, catering to a wide range of use cases and workflows. This flexibility can lead to more efficient and effective data processing pipelines.
Reduced Operational Overhead: Automating responses to S3 events using Lambda functions, queues, or topics can significantly reduce manual intervention and operational overhead. This leads to improved efficiency and allows teams to focus on higher-value tasks.
references
https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_bucket_notification
https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/s3_directory_bucket
https://docs.aws.amazon.com/AmazonS3/latest/userguide/directory-buckets-overview.html
v4.5.0Compare Source
feat: Add missed tags @MaxymVlasov (#241)
what
Add tags to resources where they missed
v4.4.0Compare Source
226: Add Expected Bucket Owner @houserx-ioannis (#238)
what
This PR addresses #226 about not being able to specify expected bucket owner in various S3 resources.
why
From AWS docs:
Because Amazon S3 identifies buckets based on their names, an application that uses an incorrect bucket name in a request could inadvertently perform operations against a different bucket than expected. To help avoid unintentional bucket interactions in situations like this, you can use bucket owner condition. Bucket owner condition enables you to verify that the target bucket is owned by the expected AWS account, providing an additional layer of assurance that your S3 operations are having the effects you intend.
references
#226
v4.3.0Compare Source
Enforce the usage of modern TLS versions (1.2 or higher) for S3 connections @amontalban (#237)
what
This variables adds a policy to the bucket to deny connections that do not use TLS 1.2 or higher.
why
This is required by our security team.
references
https://repost.aws/knowledge-center/s3-enforce-modern-tls
🚀 Enhancements
Bump github.com/hashicorp/go-getter from 1.7.1 to 1.7.4 in /test/src @dependabot (#230)
Bumps github.com/hashicorp/go-getter from 1.7.1 to 1.7.4.
Release notes
Sourced from github.com/hashicorp/go-getter's releases.
Commits
268c11cescape user provide string to git (#483)975961fMerge pull request #433 from adrian-bl/netrc-fix0298a22Merge pull request #459 from hashicorp/jbardin/setup-git-envc70d9c9don't change GIT_SSH_COMMAND if there's no keyfile3d5770fMerge pull request #458 from hashicorp/tsccr-auto-pinning/trusted/2023-09-180688979Result of tsccr-helper -log-level=info -pin-all-workflows .e66f244Merge pull request #454 from hashicorp/tsccr-auto-pinning/trusted/2023-09-11e80b3dcResult of tsccr-helper -log-level=info -pin-all-workflows .2d49e24Merge pull request #432 from hashicorp/tsccr-auto-pinning/trusted/2023-04-215ccb39aMake addAuthFromNetrc ignore ENOTDIR errorsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
🤖 Automatic Updates
Bump github.com/hashicorp/go-getter from 1.7.1 to 1.7.4 in /test/src @dependabot (#230)
Bumps github.com/hashicorp/go-getter from 1.7.1 to 1.7.4.
Release notes
Sourced from github.com/hashicorp/go-getter's releases.
Commits
268c11cescape user provide string to git (#483)975961fMerge pull request #433 from adrian-bl/netrc-fix0298a22Merge pull request #459 from hashicorp/jbardin/setup-git-envc70d9c9don't change GIT_SSH_COMMAND if there's no keyfile3d5770fMerge pull request #458 from hashicorp/tsccr-auto-pinning/trusted/2023-09-180688979Result of tsccr-helper -log-level=info -pin-all-workflows .e66f244Merge pull request #454 from hashicorp/tsccr-auto-pinning/trusted/2023-09-11e80b3dcResult of tsccr-helper -log-level=info -pin-all-workflows .2d49e24Merge pull request #432 from hashicorp/tsccr-auto-pinning/trusted/2023-04-215ccb39aMake addAuthFromNetrc ignore ENOTDIR errorsDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Update release workflow to allow pull-requests: write @osterman (#234)
what
.github/workflows/release.yaml) to have permission to comment on PRwhy
Update GitHub Workflows to use shared workflows from '.github' repo @osterman (#233)
what
.github/workflows) to use shared workflows from.githubrepowhy
Update GitHub Workflows to Fix ReviewDog TFLint Action @osterman (#232)
what
.github/workflows) to addissue: writepermission needed by ReviewDogtflintactionwhy
Update GitHub workflows @osterman (#231)
what
.github/workflows/settings.yaml)why
Bump golang.org/x/net from 0.8.0 to 0.23.0 in /test/src @dependabot (#229)
Bumps golang.org/x/net from 0.8.0 to 0.23.0.
Commits
c48da13http2: fix TestServerContinuationFlood flakes762b58dhttp2: fix tipos in commentba87210http2: close connections when receiving too many headersebc8168all: fix some typos3678185http2: make TestCanonicalHeaderCacheGrowth faster448c44fhttp2: remove clientTesterc7877achttp2: convert the remaining clientTester tests to testClientConnd8870b0http2: use synthetic time in TestIdleConnTimeoutd73acffhttp2: only set up deadline when Server.IdleTimeout is positive89f602bhttp2: validate client/outgoing trailersDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.
Use GitHub Action Workflows from `cloudposse/.github` Repo @osterman (#227)
what
why
cldouposse/.githubrepositoryAdd GitHub Settings @osterman (#221)
what
.github/settings.yaml)why
Update README.md and docs @cloudpossebot (#218)
what
This is an auto-generated PR that updates the README.md and docs
why
To have most recent changes of README.md and doc from origin templates
Update Scaffolding @osterman (#219)
what
make readmeto rebuildREADME.mdfromREADME.yamlwhy
.githubrepov4.2.0Compare Source
Added IP-based statement in bucket policy @soya-miyoshi (#216)
what
source_ip_allow_listvariable.why
Use cases:
references
v4.1.0Compare Source
🚀 Enhancements
fix: use for_each instead of count in aws_s3_bucket_logging @wadhah101 (#212)
what
Replaced the count with a for_each inside
aws_s3_bucket_logging.defaultthere's no point in the try since the type is clearly defined as list
why
When the
bucket_namewithinloggingattribute is dynamically defined, like in the case of referencing a bucket created by terraform for loggingwe get this error
For each can work better in this case and will solve the previous error
references
🤖 Automatic Updates
Update README.md and docs @cloudpossebot (#214)
what
This is an auto-generated PR that updates the README.md and docs
why
To have most recent changes of README.md and doc from origin templates
Update README.md and docs @cloudpossebot (#213)
what
This is an auto-generated PR that updates the README.md and docs
why
To have most recent changes of README.md and doc from origin templates
Update README.md and docs @cloudpossebot (#209)
what
This is an auto-generated PR that updates the README.md and docs
why
To have most recent changes of README.md and doc from origin templates
v4.0.1Compare Source
🐛 Bug Fixes
Fix bug in setting dynamic `encryption_configuration` value @LawrenceWarren (#206)
what
s3_replication_rules.destination.encryption_configuration.replica_kms_key_idset.why
There is a bug when trying to create an S3 bucket, which causes an error that stops the bucket being created
s3_replication_rules.destination.encryption_configuration.replica_kms_key_id(newer)s3_replication_rules.destination.replica_kms_key_id(older)This error is easily replicable by trying
compact(concat([try("string", "")], [try("string", "")]))[0]in the Terraform console, which is a simplified version of the existing logic used aboveThe table below demonstrates the possible values of the existing code - you can see the outputs for value 2, value 3, and value 4 are not lists:
null"string1"null"string1"nullnull"string2""string2"[]"string1""string2""string1"v4.0.0Compare Source
Bug fixes and enhancements combined into a single breaking release @aknysh (#202)
Breaking Changes
Terraform version 1.3.0 or later is now required.
policyinput removedThe deprecated
policyinput has been removed. Usesource_policy_documentsinstead.Convert from
to
Do not use list modifiers like
sort,compact, ordistincton the list, or it will trigger anError: Invalid count argument. The length of the list must be known at plan time.Logging configuration converted to list
To fix #182, the
logginginput has been converted to a list. If you have a logging configuration, simply surround it with brackets.Replication rules brought into alignment with Terraform resource
Previously, the
s3_replication_rulesinput had some deviations from the aws_s3_bucket_replication_configuration Terraform resource. Via the use of optional attributes, the input now closely matches the resource while providing backward compatibility, with a few exceptions.source_selection_criteria.sse_kms_encrypted_objectswas documented as an object with one member,enabled, of typebool. However, it only worked when set to thestring"Enabled". It has been replaced with the resource's choice ofstatusof type String.replication_time. To enable Metrics without Replication Time Control, you must setreplication_time.status = "Disabled".These are not changes, just continued deviations from the resources:
existing_object_replicationcannot be set.tokento allow replication to be enabled on an Object Lock-enabled bucket cannot be set.what
local.source_policy_documentsand deprecated variablepolicy(because of that, pump the module to a major version)lifecycle_configuration_rulesands3_replication_rulesfrom loosely typed objects to fully typed objects with optional attributes.bucket_idvariablewhy
policywas empty, meaning it had to be removed based on content, which would not be known at plan time if thepolicyinput was being generated.Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.