Skip to content

Conversation

@github-actions
Copy link

A new tag (v6.22.1) has been released in the upstream repository (hashicorp/terraform-provider-aws). This PR updates the main branch to this version.

ewbankkit and others added 29 commits November 20, 2025 19:51
…dates

`aws-sdk-go-v2` updates (Release 2025-11-20)
…es/dot-ci/tools/golang.org/x/crypto-0.45.0

Bump golang.org/x/crypto from 0.44.0 to 0.45.0 in /.ci/tools
Bumps [github.com/rhysd/actionlint](https://github.com/rhysd/actionlint) from 1.7.8 to 1.7.9.
- [Release notes](https://github.com/rhysd/actionlint/releases)
- [Changelog](https://github.com/rhysd/actionlint/blob/main/CHANGELOG.md)
- [Commits](rhysd/actionlint@v1.7.8...v1.7.9)

---
updated-dependencies:
- dependency-name: github.com/rhysd/actionlint
  dependency-version: 1.7.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
…igent-rebalancing

Add intelligent rebalancing support to aws_msk_cluster resource
…kACMPCACertificateAuthorityActivateRootCA

Fix `acctest.CheckACMPCACertificateAuthorityActivateRootCA`
Previously the check for whether tag policy compliance was enabled and included required tags for the current resource type was nested in the middle of the required tag validation logic. It is now moved to the start to exit as early as possible and prevent unnecessary processing of tag values.

```console
% TF_ACC_REQUIRED_TAG_KEY=Owner make t K=iot T=TestAccIoTBillingGroup_requiredTags
make: Verifying source code with gofmt...
==> Checking that code complies with gofmt requirements...
make: Running acceptance tests on branch: 🌿 b-tag-policy-interceptor 🌿...
TF_ACC=1 go1.24.10 test ./internal/service/iot/... -v -count 1 -parallel 20 -run='TestAccIoTBillingGroup_requiredTags'  -timeout 360m -vet=off
2025/11/21 10:54:23 Creating Terraform AWS Provider (SDKv2-style)...
2025/11/21 10:54:23 Initializing Terraform AWS Provider (SDKv2-style)...

--- PASS: TestAccIoTBillingGroup_requiredTags_defaultTags (21.24s)
--- PASS: TestAccIoTBillingGroup_requiredTags (21.25s)
--- PASS: TestAccIoTBillingGroup_requiredTags_disabled (35.96s)
--- PASS: TestAccIoTBillingGroup_requiredTags_warning (39.28s)
PASS
ok      github.com/hashicorp/terraform-provider-aws/internal/service/iot        45.913s
```

```console
% TF_ACC_REQUIRED_TAG_KEY=Owner make t K=logs T=TestAccLogsLogGroup_requiredTags
make: Verifying source code with gofmt...
==> Checking that code complies with gofmt requirements...
make: Running acceptance tests on branch: 🌿 b-tag-policy-interceptor 🌿...
TF_ACC=1 go1.24.10 test ./internal/service/logs/... -v -count 1 -parallel 20 -run='TestAccLogsLogGroup_requiredTags'  -timeout 360m -vet=off
2025/11/21 10:57:30 Creating Terraform AWS Provider (SDKv2-style)...
2025/11/21 10:57:30 Initializing Terraform AWS Provider (SDKv2-style)...

--- PASS: TestAccLogsLogGroup_requiredTags (19.66s)
--- PASS: TestAccLogsLogGroup_requiredTags_defaultTags (19.75s)
--- PASS: TestAccLogsLogGroup_requiredTags_disabled (35.51s)
--- PASS: TestAccLogsLogGroup_requiredTags_warning (38.56s)
PASS
ok      github.com/hashicorp/terraform-provider-aws/internal/service/logs       45.089s
```
…} is nil, not map[string]interface {}' panic in 'expandAnalysisRuleCriteria'.
Previously the validate required tags interceptor would crash when the planned value for the `tags` attribute included unknown tag values. Validation now skips when planned values are not wholly known.

Without the patch:

```console
% go test -count=1 ./internal/provider/framework/... -run Test_resourceValidateRequiredTagsInterceptor
--- FAIL: Test_resourceValidateRequiredTagsInterceptor (0.00s)
    --- FAIL: Test_resourceValidateRequiredTagsInterceptor/create,_unknown_tag_values (0.00s)
--- FAIL: Test_resourceValidateRequiredTagsInterceptor (0.00s)
    --- FAIL: Test_resourceValidateRequiredTagsInterceptor/update,_unknown_tag_values (0.00s)
panic: Value Conversion Error

        An unexpected error was encountered trying to build a value. This is always an error in the provider. Please report the following to the provider developer:

        Received unknown value, however the target type cannot handle unknown values. Use the corresponding `types` package type or a custom type that handles unknown values.

        Path: ["foo"]
        Target Type: *string
        Suggested Type: basetypes.StringValue
        ["foo"] [recovered]
        panic: Value Conversion Error

        An unexpected error was encountered trying to build a value. This is always an error in the provider. Please report the following to the provider developer:

        Received unknown value, however the target type cannot handle unknown values. Use the corresponding `types` package type or a custom type that handles unknown values.

        Path: ["foo"]
        Target Type: *string
        Suggested Type: basetypes.StringValue
        ["foo"]

goroutine 28 [running]:
testing.tRunner.func1.2({0x101701aa0, 0x14001282150})
        /Users/jaredbaker/sdk/go1.24.10/src/testing/testing.go:1734 +0x1ac
testing.tRunner.func1()
        /Users/jaredbaker/sdk/go1.24.10/src/testing/testing.go:1737 +0x334
panic({0x101701aa0?, 0x14001282150?})
        /Users/jaredbaker/sdk/go1.24.10/src/runtime/panic.go:792 +0x124
github.com/hashicorp/terraform-provider-aws/internal/errs.Must[...](...)
        /Users/jaredbaker/development/_worktrees/b-tag-policy-interceptor/internal/errs/must.go:13
github.com/hashicorp/terraform-provider-aws/internal/errs/fwdiag.Must[...]({0x0?, 0x0}, {0x14001280920, 0x1016b17a0?, 0x1400009a298?})
        /Users/jaredbaker/development/_worktrees/b-tag-policy-interceptor/internal/errs/fwdiag/must.go:17 +0x58
github.com/hashicorp/terraform-provider-aws/internal/framework/flex.must(...)
        /Users/jaredbaker/development/_worktrees/b-tag-policy-interceptor/internal/framework/flex/errs.go:13
github.com/hashicorp/terraform-provider-aws/internal/framework/flex.ExpandFrameworkStringMap({0x1017c9e08, 0x140011020c0}, {0x1017cea10, 0x1400138c1c0})
        /Users/jaredbaker/development/_worktrees/b-tag-policy-interceptor/internal/framework/flex/map.go:17 +0x94
github.com/hashicorp/terraform-provider-aws/internal/tags.New({0x1017c9e08, 0x140011020c0}, {0x101795120?, 0x1400110dd68})
        /Users/jaredbaker/development/_worktrees/b-tag-policy-interceptor/internal/tags/key_value_tags.go:650 +0x2fc
github.com/hashicorp/terraform-provider-aws/internal/provider/framework.resourceValidateRequiredTagsInterceptor.modifyPlan({}, {0x1017c9e08, 0x140011020c0}, {{0x1017cfb58, 0x14000aec160}, 0x140000fc700, 0x14001049580, 0x1})
        /Users/jaredbaker/development/_worktrees/b-tag-policy-interceptor/internal/provider/framework/tags_interceptor.go:308 +0x4d8
github.com/hashicorp/terraform-provider-aws/internal/provider/framework.Test_resourceValidateRequiredTagsInterceptor.func2(0x14000003c00)
        /Users/jaredbaker/development/_worktrees/b-tag-policy-interceptor/internal/provider/framework/tags_interceptor_test.go:404 +0x16c
testing.tRunner(0x14000003c00, 0x14001063570)
        /Users/jaredbaker/sdk/go1.24.10/src/testing/testing.go:1792 +0xe4
created by testing.(*T).Run in goroutine 24
        /Users/jaredbaker/sdk/go1.24.10/src/testing/testing.go:1851 +0x374
FAIL    github.com/hashicorp/terraform-provider-aws/internal/provider/framework 0.850s
```

```console
% TF_ACC_REQUIRED_TAG_KEY=Owner make t K=iot T=TestAccIoTBillingGroup_requiredTags && TF_ACC_REQUIRED_TAG_KEY=Owner make t K=logs T=TestAccLogsLogGroup_requiredTags
make: Verifying source code with gofmt...
==> Checking that code complies with gofmt requirements...
make: Running acceptance tests on branch: 🌿 b-tag-policy-interceptor 🌿...
TF_ACC=1 go1.24.10 test ./internal/service/iot/... -v -count 1 -parallel 20 -run='TestAccIoTBillingGroup_requiredTags'  -timeout 360m -vet=off
2025/11/21 11:54:39 Creating Terraform AWS Provider (SDKv2-style)...
2025/11/21 11:54:39 Initializing Terraform AWS Provider (SDKv2-style)...

--- PASS: TestAccIoTBillingGroup_requiredTags_defaultTags (19.31s)
--- PASS: TestAccIoTBillingGroup_requiredTags (19.33s)
--- PASS: TestAccIoTBillingGroup_requiredTags_disabled (34.01s)
--- PASS: TestAccIoTBillingGroup_requiredTags_warning (37.18s)
PASS
ok      github.com/hashicorp/terraform-provider-aws/internal/service/iot        43.681s
make: Verifying source code with gofmt...
==> Checking that code complies with gofmt requirements...
make: Running acceptance tests on branch: 🌿 b-tag-policy-interceptor 🌿...
TF_ACC=1 go1.24.10 test ./internal/service/logs/... -v -count 1 -parallel 20 -run='TestAccLogsLogGroup_requiredTags'  -timeout 360m -vet=off
2025/11/21 11:55:37 Creating Terraform AWS Provider (SDKv2-style)...
2025/11/21 11:55:37 Initializing Terraform AWS Provider (SDKv2-style)...

--- PASS: TestAccLogsLogGroup_requiredTags (19.59s)
--- PASS: TestAccLogsLogGroup_requiredTags_defaultTags (19.67s)
--- PASS: TestAccLogsLogGroup_requiredTags_disabled (35.34s)
--- PASS: TestAccLogsLogGroup_requiredTags_warning (38.32s)
PASS
ok      github.com/hashicorp/terraform-provider-aws/internal/service/logs       44.717s
```
…es/dot-ci/tools/github.com/rhysd/actionlint-1.7.9

Bump github.com/rhysd/actionlint from 1.7.8 to 1.7.9 in /.ci/tools
…r_analyzer.resource_tags-crash

r/aws_accessanalyzer_analyzer Fix crash when `resource_tags` are `null`
…eptor

Provider: Fix required tag validation regressions
…lidation

b/aws_odb_cloud_vm_cluster: Fix validation error when using variables
@github-actions github-actions bot requested a review from a team as a code owner November 22, 2025 12:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants