cert-manager/cert-manager (cert-manager/cert-manager)
### [`v1.15.0`](https://togithub.com/cert-manager/cert-manager/releases/tag/v1.15.0)
[Compare Source](https://togithub.com/cert-manager/cert-manager/compare/v1.14.6...v1.15.0)
cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters.
cert-manager 1.15 promotes several features to beta, including GatewayAPI support (`ExperimentalGatewayAPISupport`), the ability to provide a subject in the Certificate that will be used literally in the CertificateSigningRequest (`LiteralCertificateSubject`) and the outputting of additional certificate formats (`AdditionalCertificateOutputFormats`).
> \[!NOTE]
>
> The `cmctl` binary have been moved to https://github.com/cert-manager/cmctl/releases.
> For the startupapicheck Job you should update references to point at `quay.io/jetstack/cert-manager-startupapicheck`
> \[!NOTE]
>
> From this release, the Helm chart will no longer uninstall the CRDs when the chart is uninstalled. If you want the CRDs to be removed on uninstall use `crds.keep=false` when installing the Helm chart.
#### Community
Thanks again to all open-source contributors with commits in this release, including: [@Pionerd](https://togithub.com/Pionerd), [@SgtCoDFish](https://togithub.com/SgtCoDFish), [@ThatsMrTalbot](https://togithub.com/ThatsMrTalbot), [@andrey-dubnik](https://togithub.com/andrey-dubnik), [@bwaldrep](https://togithub.com/bwaldrep), [@eplightning](https://togithub.com/eplightning), [@erikgb](https://togithub.com/erikgb), [@findnature](https://togithub.com/findnature), [@gplessis](https://togithub.com/gplessis), [@import-shiburin](https://togithub.com/import-shiburin), [@inteon](https://togithub.com/inteon), [@jkroepke](https://togithub.com/jkroepke), [@lunarwhite](https://togithub.com/lunarwhite), [@mangeshhambarde](https://togithub.com/mangeshhambarde), [@pwhitehead-splunk](https://togithub.com/pwhitehead-splunk) & [@rodrigorfk](https://togithub.com/rodrigorfk), [@wallrj](https://togithub.com/wallrj).
Thanks also to the following cert-manager maintainers for their contributions during this release: [@SgtCoDFish](https://togithub.com/SgtCoDFish), [@SpectralHiss](https://togithub.com/SpectralHiss), [@ThatsMrTalbot](https://togithub.com/ThatsMrTalbot), [@hawksight](https://togithub.com/hawksight), [@inteon](https://togithub.com/inteon), [@maelvls](https://togithub.com/maelvls) & [@wallrj](https://togithub.com/wallrj).
Equally thanks to everyone who provided feedback, helped users and raised issues on GitHub and Slack and joined our meetings!
Thanks also to the CNCF, which provides resources and support, and to the AWS open source team for being good community members and for their maintenance of the PrivateCA Issuer.
In addition, massive thanks to Venafi for contributing developer time and resources towards the continued maintenance of cert-manager projects.
#### Changes by Kind
##### Feature
- GatewayAPI support has graduated to Beta. Add the `--enable-gateway-api` flag to enable the integration. ([#6961](https://togithub.com/cert-manager/cert-manager/issues/6961), [@ThatsMrTalbot](https://togithub.com/ThatsMrTalbot))
- Add support to specify a custom key alias in a JKS Keystore ([#6807](https://togithub.com/cert-manager/cert-manager/issues/6807), [@bwaldrep](https://togithub.com/bwaldrep))
- Add the ability to communicate with Vault via mTLS when strict client certificates is enabled at Vault server side ([#6614](https://togithub.com/cert-manager/cert-manager/issues/6614), [@rodrigorfk](https://togithub.com/rodrigorfk))
- Added option to provide additional audiences in the service account auth section for vault ([#6718](https://togithub.com/cert-manager/cert-manager/issues/6718), [@andrey-dubnik](https://togithub.com/andrey-dubnik))
- Venafi Issuer now sends a cert-manager HTTP User-Agent header in all Venafi Rest API requests.
For example: `cert-manager-certificaterequests-issuer-venafi/v1.15.0+(linux/amd64)+cert-manager/ef068a59008f6ed919b98a7177921ddc9e297200`. ([#6865](https://togithub.com/cert-manager/cert-manager/issues/6865), [@wallrj](https://togithub.com/wallrj))
- Add hint to validation error message to help users of external issuers more easily fix the issue if they specify a Kind but forget the Group ([#6913](https://togithub.com/cert-manager/cert-manager/issues/6913), [@SgtCoDFish](https://togithub.com/SgtCoDFish))
- Add support for numeric OID types in LiteralSubject. Eg. "1.2.3.4=String Value" ([#6775](https://togithub.com/cert-manager/cert-manager/issues/6775), [@inteon](https://togithub.com/inteon))
- Promote the `LiteralCertificateSubject` feature to Beta. ([#7030](https://togithub.com/cert-manager/cert-manager/issues/7030), [@inteon](https://togithub.com/inteon))
- Promoted the AdditionalCertificateOutputFormats feature gate to Beta (enabled by default). ([#6970](https://togithub.com/cert-manager/cert-manager/issues/6970), [@erikgb](https://togithub.com/erikgb))
- The Helm chart now allows you to supply `extraObjects`; a list of yaml manifests which will helm will install and uninstall with the cert-manager manifests. ([#6424](https://togithub.com/cert-manager/cert-manager/issues/6424), [@gplessis](https://togithub.com/gplessis))
- Update the Route53 provider to support fetching credentials using AssumeRoleWithWebIdentity ([#6878](https://togithub.com/cert-manager/cert-manager/issues/6878), [@pwhitehead-splunk](https://togithub.com/pwhitehead-splunk))
- Helm can now add optional hostAliases to cert-manager Pod to allow the DNS self-check to pass in custom scenarios. ([#6456](https://togithub.com/cert-manager/cert-manager/issues/6456), [@Pionerd](https://togithub.com/Pionerd))
- Added a new Ingress annotation for copying specific Ingress annotations to Certificate's secretTemplate ([#6839](https://togithub.com/cert-manager/cert-manager/issues/6839), [@mangeshhambarde](https://togithub.com/mangeshhambarde))
- Added option to define additional token audiences for the Vault Kubernetes auth ([#6744](https://togithub.com/cert-manager/cert-manager/issues/6744), [@andrey-dubnik](https://togithub.com/andrey-dubnik))
- Allow `cert-manager.io/allow-direct-injection` in annotations ([#6801](https://togithub.com/cert-manager/cert-manager/issues/6801), [@jkroepke](https://togithub.com/jkroepke))
##### Design
- Remove repetitive words ([#6949](https://togithub.com/cert-manager/cert-manager/issues/6949), [@findnature](https://togithub.com/findnature))
##### Bug or Regression
- BUGFIX: Fixes issue with JSON-logging, where only a subset of the log messages were output as JSON. ([#6779](https://togithub.com/cert-manager/cert-manager/issues/6779), [@inteon](https://togithub.com/inteon))
- BUGFIX: JKS and PKCS12 stores now contain the full set of CAs specified by an issuer ([#6806](https://togithub.com/cert-manager/cert-manager/issues/6806), [@bwaldrep](https://togithub.com/bwaldrep))
- BUGFIX: cainjector leaderelection flag/config option defaults are missing ([#6816](https://togithub.com/cert-manager/cert-manager/issues/6816), [@inteon](https://togithub.com/inteon))
- BUGFIX: cert-manager issuers incorrectly copied the critical flag from the CSR instead of re-calculating that field themselves. ([#6724](https://togithub.com/cert-manager/cert-manager/issues/6724), [@inteon](https://togithub.com/inteon))
- Breaking Change: Fixed unintended certificate chain is used if `preferredChain` is configured. ([#6755](https://togithub.com/cert-manager/cert-manager/issues/6755), [@import-shiburin](https://togithub.com/import-shiburin))
- Bugfix: LiteralSubjects with a #= value can result in memory issues due to faulty BER parser (github.com/go-asn1-ber/asn1-ber). ([#6770](https://togithub.com/cert-manager/cert-manager/issues/6770), [@inteon](https://togithub.com/inteon))
- DigitalOcean: Ensure that only TXT records are considered for deletion when cleaning up after an ACME challenge ([#6875](https://togithub.com/cert-manager/cert-manager/issues/6875), [@SgtCoDFish](https://togithub.com/SgtCoDFish))
- Fix backwards incompatible removal of default prometheus Service resource. ([#6699](https://togithub.com/cert-manager/cert-manager/issues/6699), [@inteon](https://togithub.com/inteon))
- Fix broken cainjector image value in Helm chart ([#6692](https://togithub.com/cert-manager/cert-manager/issues/6692), [@SgtCoDFish](https://togithub.com/SgtCoDFish))
- Helm: Fix a bug in the logic that differentiates between 0 and an empty value. ([#6713](https://togithub.com/cert-manager/cert-manager/issues/6713), [@inteon](https://togithub.com/inteon))
- Make sure the Azure SDK error messages are stable. ([#6676](https://togithub.com/cert-manager/cert-manager/issues/6676), [@inteon](https://togithub.com/inteon))
- When using the literalSubject on a Certificate, the webhook validation for the common name now also points to the literalSubject. ([#6767](https://togithub.com/cert-manager/cert-manager/issues/6767), [@lunarwhite](https://togithub.com/lunarwhite))
- Bump golang.org/x/net to fix CVE-2023-45288 ([#6929](https://togithub.com/cert-manager/cert-manager/issues/6929), [@SgtCoDFish](https://togithub.com/SgtCoDFish))
- Fix ACME issuer being stuck waiting for DNS propagation when using Azure DNS with multiple instances issuing for the same FQDN ([#6351](https://togithub.com/cert-manager/cert-manager/issues/6351), [@eplightning](https://togithub.com/eplightning))
- Fix cainjector ConfigMap not mounted in the cainjector deployment. ([#7055](https://togithub.com/cert-manager/cert-manager/issues/7055), [@inteon](https://togithub.com/inteon))
- Added `disableAutoApproval` and `approveSignerNames` Helm chart options. ([#7054](https://togithub.com/cert-manager/cert-manager/issues/7054), [@inteon](https://togithub.com/inteon))
##### Other (Cleanup or Flake)
- ⚠️ Possibly breaking: Helm will now keep the CRDs when you uninstall cert-manager by default to prevent accidental data loss. ([#6760](https://togithub.com/cert-manager/cert-manager/issues/6760), [@inteon](https://togithub.com/inteon))
- New `crds.keep` and `crds.enabled` Helm options can now be used instead of the `installCRDs` option. ([#6760](https://togithub.com/cert-manager/cert-manager/issues/6760), [@inteon](https://togithub.com/inteon))
- Bump base images ([#6840](https://togithub.com/cert-manager/cert-manager/issues/6840), [@inteon](https://togithub.com/inteon))
- Bump github.com/go-jose/go-jose to v3.0.3 to fix CVE-2024-28180 ([#6854](https://togithub.com/cert-manager/cert-manager/issues/6854), [@wallrj](https://togithub.com/wallrj))
- Removed deprecated util functions that have been replaced by the `slices` and `k8s.io/apimachinery/pkg/util` packages.
Removed deprecated CSR functions which have been replaced with other functions in the `pkg/util/pki` package. ([#6730](https://togithub.com/cert-manager/cert-manager/issues/6730), [@inteon](https://togithub.com/inteon))
- Upgrade go to 1.21.8: fixes CVE-2024-24783 ([#6823](https://togithub.com/cert-manager/cert-manager/issues/6823), [@inteon](https://togithub.com/inteon))
- Upgrade go to latest version 1.22.1 ([#6831](https://togithub.com/cert-manager/cert-manager/issues/6831), [@inteon](https://togithub.com/inteon))
- Upgrade google.golang.org/protobuf: fixing GO-2024-2611 ([#6827](https://togithub.com/cert-manager/cert-manager/issues/6827), [@inteon](https://togithub.com/inteon))
- `cmctl` and `kubectl cert-manger` have been moved to the https://github.com/cert-manager/cmctl repo and will be versioned separately starting with cmctl v2.0.0 ([#6663](https://togithub.com/cert-manager/cert-manager/issues/6663), [@inteon](https://togithub.com/inteon))
- Graduate the 'DisallowInsecureCSRUsageDefinition' feature gate to GA. (part 2) ([#6963](https://togithub.com/cert-manager/cert-manager/issues/6963), [@inteon](https://togithub.com/inteon))
- Remove deprecated `pkg/util/pki/ParseSubjectStringToRawDERBytes` function. ([#6994](https://togithub.com/cert-manager/cert-manager/issues/6994), [@inteon](https://togithub.com/inteon))
- Upgrade Kind to v0.23.0 and update supported node image digests ([#7020](https://togithub.com/cert-manager/cert-manager/issues/7020), [@github-actions](https://togithub.com/github-actions)\[bot])
- If the `--controllers` flag only specifies disabled controllers, the default controllers are now enabled implicitly. ([#7054](https://togithub.com/cert-manager/cert-manager/issues/7054), [@inteon](https://togithub.com/inteon))
- Upgrade to Go 1.22.3, fixing `GO-2024-2824`. ([#6996](https://togithub.com/cert-manager/cert-manager/issues/6996), [@github-actions](https://togithub.com/github-actions)\[bot])
### [`v1.14.6`](https://togithub.com/cert-manager/cert-manager/releases/tag/v1.14.6)
[Compare Source](https://togithub.com/cert-manager/cert-manager/compare/v1.14.5...v1.14.6)
#### Changes by Kind
##### Other (Cleanup or Flake)
- Upgrade Go to 1.21.10, fixing GO-2024-2824 (https://github.com/advisories/GHSA-2jwv-jmq4-4j3r). ([#7008](https://togithub.com/cert-manager/cert-manager/issues/7008), [@inteon](https://togithub.com/inteon))
- Helm: the cainjector ConfigMap was not mounted in the cainjector deployment. ([#7053](https://togithub.com/cert-manager/cert-manager/issues/7053), [@cert-manager-bot](https://togithub.com/cert-manager-bot))
- Updated Go to 1.21.11 bringing in security fixes for archive/zip and net/netip. ([#7076](https://togithub.com/cert-manager/cert-manager/issues/7076), [@ThatsMrTalbot](https://togithub.com/ThatsMrTalbot))
hashicorp/terraform-provider-google (google)
### [`v4.85.0`](https://togithub.com/hashicorp/terraform-provider-google/blob/HEAD/CHANGELOG.md#4850-June-12-2024)
[Compare Source](https://togithub.com/hashicorp/terraform-provider-google/compare/v4.84.0...v4.85.0)
NOTES:
- The `4.85.0` release backports configuration for the retention period for Cloud Storage soft delete (https://cloud.google.com/resources/storage/soft-delete-announce) so that customers who have not yet upgraded to `5.22.0`+ are able to configure the retention period of objects in their buckets. By upgrading to this version and configuring or otherwise interacting with the `google_storage_bucket.soft_delete_policy` values, you will need to upgrade directly to `5.22.0`+ from `4.85.0` when upgrading to `5.X` in the future.
IMPROVEMENTS:
- storage: added `soft_delete_policy` to `google_storage_bucket` resource ([#17624](https://togithub.com/hashicorp/terraform-provider-google/pull/17624))
hashicorp/terraform-provider-google-beta (google-beta)
### [`v4.85.0`](https://togithub.com/hashicorp/terraform-provider-google-beta/releases/tag/v4.85.0)
[Compare Source](https://togithub.com/hashicorp/terraform-provider-google-beta/compare/v4.84.0...v4.85.0)
OTES:
- The `4.85.0` release backports configuration for the retention period for Cloud Storage soft delete (https://cloud.google.com/resources/storage/soft-delete-announce) so that customers who have not yet upgraded to `5.22.0`+ are able to configure the retention period of objects in their buckets. By upgrading to this version and configuring or otherwise interacting with the `google_storage_bucket.soft_delete_policy` values, you will need to upgrade directly to `5.22.0`+ from `4.85.0` when upgrading to `5.X` in the future.
IMPROVEMENTS:
- storage: added 'soft_delete_policy' to 'google_storage_bucket' resource ([#7119](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/7119))
#### 4.84.0 (September 26, 2023)
DEPRECATIONS:
- alloydb: deprecated `network` field in favor of `network_config` on `google_alloydb_cluster`. ([#6297](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6297))
- identityplayform: deprecated `google_identity_platform_project_default_config` resource. Use `google_identity_platform_config` resource instead ([#6293](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6293))
FEATURES:
- **New Data Source:** `google_certificate_manager_certificate_map` ([#6316](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6316))
- **New Resource:** `google_artifact_registry_vpcsc_config` ([#6265](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6265))
- **New Resource:** `google_dialogflow_cx_security_settings` ([#6300](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6300))
- **New Resource:** `google_gke_backup_restore_plan` ([#6278](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6278))
- **New Resource:** `google_scc_project_custom_module` ([#6315](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6315))
- **New Resource:** `google_tpu_v2_vm` ([#6264](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6264))
- **New Resource:** `google_edgenetwork_network` ([#6305](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6305))
- **New Resource:** `google_edgenetwork_subnet` ([#6305](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6305))
IMPROVEMENTS:
- alloydb: added `network_config` field to support named IP ranges on `google_alloydb_cluster`. ([#6297](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6297))
- cloudrunv2: added fields `network_interfaces` to resource `google_cloud_run_v2_job` to support Direct VPC egress. ([#6287](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6287))
- cloudrunv2: added fields `network_interfaces` to resource `google_cloud_run_v2_service` to support Direct VPC egress. ([#6287](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6287))
- compute: updated the `autoscaling_policy.mode` to accept `ONLY_SCALE_OUT` on `google_compute_autoscaler` ([#6304](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6304))
- compute: added `server_tls_policy` argument to `google_compute_target_https_proxy` resource ([#6269](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6269))
- compute: added `member` attribute to `google_compute_default_service_account` datasource ([#6311](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6311))
- compute: added output field `internal_ipv6_prefix` to `google_compute_subnetwork` resource ([#6306](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6306))
- container: added `node_config.fast_socket` field to `google_container_node_pool` ([#6289](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6289))
- containeraws: added support for `auto_repair` in `google_container_aws_node_pool` ([#6282](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6282))
- containerazure: added support for `auto_repair` in `google_container_azure_node_pool` ([#6282](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6282))
- filestore: added support for the `"ZONAL"` value to `tier` in `google_filestore_instance` ([#6303](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6303))
- firestore: added `delete_protection_state` field to `google_firestore_database` resource. ([#6295](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6295))
- identityplatform: added `sign-in` field to `google_identity_platform_config` resource ([#6293](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6293))
- networkconnectivity: added support for `linked_vpc_network` in `google_network_connectivity_spoke` ([#6282](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6282))
- networkservices: increased default timeout for `google_network_services_edge_cache_origin` to 120m from 60m ([#6275](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6275))
- networkservices: increased default timeout for `google_network_services_edge_cache_service` to 60m from 30m ([#6281](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6281))
- secretmanager: added `is_secret_data_base64` field to `google_secret_manager_secret_version` resource ([#6273](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6273))
- workstations: added `env` field to `google_workstations_workstation` resource ([#6258](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6258))
BUG FIXES:
- bigquery: updated documentation for `google_bigquery_table.time_partitioning.expiration_ms` ([#6290](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6290))
- bigtable: added a read timeout to `google_bigtable_instance` ([#6276](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6276))
- bigtable: improved regional reliability when instance overlaps a downed region in the resource `google_bigtable_instance` ([#6313](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6313))
- eventarc: resolved permadiff on `google_eventarc_trigger.event_data_content_type` by defaulting to the value returned by the API if not set in the configuration. ([#6282](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6282))
- identityplatform: fixed a potential perma-diff for `sign_in` in `google_identity_platform_config` resource ([#6317](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6317))
- monitoring: fixed scaling issues when deploying terraform changes with many `google_monitoring_monitored_project` ([#6259](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6259))
- monitoring: fixed validation of `service_id` on `google_monitoring_custom_service` and `slo_id` on `google_monitoring_slo` ([#6266](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6266))
- osconfig: fixed no more than one setting is allowed under `patch_config.windows_update` on `google_os_config_patch_deployment` ([#6314](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6314))
- provider: addressed a bug where configuring the provider with unknown values did not behave as expected ([#6312](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6312))
- provider: fixed the provider so it resumes ignoring empty strings set in the `provider` block ([#6268](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6268))
- secretmanager: replaced the panic block with an error in import function of `google_secret_manager_secret_version` resource ([#6296](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6296))
- secretmanager: fixed an issue in `google_secretmanager_secret` where replacing `replication.automatic` with `replication.auto` would destroy and recreate the resource ([#6325](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6325))
#### 4.83.0 (September 18, 2023)
DEPRECATIONS:
- secretmanager: deprecated `automatic` field on `google_secret_manager_secret`. Use `auto` instead. ([#6237](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6237))
FEATURES:
- **New Resource:** `google_biglake_table` ([#6205](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6205))
- **New Resource:** `google_data_pipeline_pipeline` ([#6236](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6236))
- **New Resource:** `google_dialogflow_cx_test_case` ([#6249](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6249))
- **New Resource:** `google_storage_insights_report_config` ([#6253](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6253))
- **New Resource:** `google_apigee_target_server` ([#6215](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6215))
IMPROVEMENTS:
- bigquery: added `allow_non_incremental_definition` to `google_bigquery_table` resource ([#6248](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6248))
- bigquery: added `table_constraints` field to `google_bigquery_table` resource ([#6250](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6250))
- compute: added internal IPV6 support for `google_compute_address` and `google_compute_instance` resources ([#6232](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6232))
- containerattached: added `binary_authorization` field to `google_container_attached_cluster` resource ([#6256](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6256))
- containeraws: added update support for `config.instance_type` in `container_aws_node_pool` ([#6282](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6282))
- firestore: added `point_in_time_recovery_enablement` field to `google_firestore_database` resource ([#6239](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6239))
- firestore: added `update_time` and `uid` fields to `google_firestore_database` resource ([#6257](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6257))
- gkehub2: added `labels`, `namespace_labels` fields to `google_gke_hub_namespace` resource ([#6202](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6202))
- gkehub: added `labels` fields to `google_gke_hub_membership_binding` resource ([#6216](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6216))
- gkehub: added `labels` fields to `google_gke_hub_scope` resource ([#6243](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6243))
- gkeonprem: added `upgrade_policy` and `binary_authorization` fields in `google_gkeonprem_bare_metal_cluster` resource (beta) ([#6224](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6224))
- gkeonprem: added `upgrade_policy` field in `google_gkeonprem_vmware_cluster` resource (beta) ([#6224](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6224))
- secretmanager: added `auto` field to `google_secret_manager_secret` resource ([#6237](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6237))
- secretmanager: added `deletion_policy` field to `google_secret_manager_secret_version` resource ([#6252](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6252))
- storage: supported in-place update for `autoclass` field in `google_storage_bucket` resource ([#6233](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6233))
- vertexai: added `public_endpoint_enabled` to `google_vertex_ai_index_endpoint` ([#6208](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6208))
- workstations: added `env` field to `google_workstations_workstation` resource (beta) ([#6258](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6258))
BUG FIXES:
- bigquerydatatransfer: fixed a bug when importing `location` of `google_bigquery_data_transfer_config` ([#6203](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6203))
- container: fixed a bug where `additional_pod_network_configs` was not sent correctly in `google_container_node_pool` ([#6211](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6211))
- container: fixed concurrent ops' quota-error to be retriable in ` google_container_node_pool ` ([#6254](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6254))
- eventarc: resolved permadiff on `event_content_type` in `eventarc_trigger`, the field will now default to a value returned by the API when not set in configuration ([#6282](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6282))
- pipeline: fixed issue where certain `google_dataflow_job` instances would crash the provider ([#6255](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6255))
- provider: fixed a bug where `user_project_override` would not be not used correctly when provisioning resources implemented using the plugin framework. Currently there are no resources implemented this way, so no-one should have been impacted. ([#6230](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6230))
- pubsub: fixed issue where setting `no_wrapper.write_metadata` to false wasn't passed to the API for `google_pubsub_subscription` ([#6219](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6219))
- serviceaccount: added retries for reads after `google_service_account` creation if 403 Forbidden is returned. ([#6221](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6221))
- storage: fixed the failure in building a plan when a `content` value is expected on `google_storage_bucket_object_content` ([#6204](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6204)
#### 4.82.0 (September 11, 2023)
IMPROVEMENTS:
- compute: added in-place update support for field `enable_proxy_protocol` in `google_compute_service_attachment` resource ([#6192](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6192))
- compute: added in-place update support for field `reconcile_connections` in `google_compute_service_attachment` resource ([#6187](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6187))
- compute: added in-place update support for field `allowPscGlobalAccess` in `google_compute_forwarding_rule` resource ([#6179](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6179))
- container: added additional options for field `monitoring_config.enable_components` in `google_container_cluster` resource ([#6198](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6198))
- gkehub: added `labels` field to `google_gke_hub_scope_rbac_role_binding` resource ([#6200](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6200))
- logging: added in-place update support for field `unique_writer_identity` in `google_logging_project_sink` resource ([#6193](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6193))
- networkconnectivity: added `psc_connections.error.details` field to `google_network_connectivity_service_connection_policy` resource ([#6197](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6197))
- secretmanager: added in-place update support for field `replication.user_managed.replicas.customer_managed_encryption` in `google_secret_manager_secret` resource ([#6177](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6177))
BUG FIXES:
- bigquery: made `params.destination_table_name_template` and `params.data_path` immutable as updating these fields if value of `data_source_id` is `amazon_s3` in `google_bigquery_data_transfer_config` resource ([#6195](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6195))
- compute: fixed a crash when empty is given to `all_instances_config` in `google_compute_region_instance_group_manager` resource ([#6191](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6191))
- dns: fixed hash function for `network_url` in `google_dns_managed_zone` and `google_dns_policy` resources to make sure that the private DNS zone or DNS policy can be attatched to all of the networks in different projects, even though the network name is the same across of those projects ([#6199](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6199))
- servicedirectory: made `location` immutable as updating this field in `google_service_directory_namespace` resource ([#6182](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6182))
#### 4.81.0 (September 05, 2023)
FEATURES:
- **New Resource:** `google_biglake_catalog` ([#6152](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6152))
- **New Resource:** `google_redis_cluster` ([#6158](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6158))
- **New Resource:** `google_biglake_database` ([#6161](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6161))
- **New Resource:** `google_compute_network_attachment` ([#6159](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6159))
- **New Resource:** `google_gke_hub_membership_binding` ([#6170](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6170))
- **New Resource:** `google_gke_hub_namespace` ([#6170](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6170))
- **New Resource:** `google_gke_hub_scope` ([#6170](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6170))
- **New Resource:** `google_gke_hub_scope_iam_member` ([#6170](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6170))
- **New Resource:** `google_gke_hub_scope_iam_policy` ([#6170](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6170))
- **New Resource:** `google_gke_hub_membership_binding` ([#6170](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6170))
- **New Resource:** `google_gke_hub_scope_rbac_role_binding` ([#6170](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6170))
IMPROVEMENTS:
- compute: made the field `distribution_policy_target_shape` of `google_compute_region_instance_group_manager` not cause recreation of the resource. ([#6156](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6156))
- container: added `enable_fqdn_network_policy` field to `google_container_cluster` ([#6157](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6157))
- container: added `node_config.confidential_compute` field to `google_container_node_pool` resource ([#6166](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6166))
- datastream: allowed `password` of `google_datastream_connection_profile` to be mutable. ([#6140](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6140))
- dialogflowcx: added `response_type`, `channel`, `payload`, `conversation_success`, `output_audio_text`, `live_agent_handoff`, `play_audo`, `telephony_transfer_call`, `reprompt_event_handlers`, `set_parameter_actions`, and `conditional_cases` fields to `google_dialogflow_cx_page` resource ([#6168](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6168))
- dialogflowcx: added `response_type`, `channel`, `payload`, `conversation_success`, `output_audio_text`, `live_agent_handoff`, `play_audo`, `telephony_transfer_call`, `set_parameter_actions`, and `conditional_cases` fields to `google_dialogflow_cx_flow` resource ([#6168](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6168))
- iam: added `web_sso_config.additional_scopes` field to `google_iam_workforce_pool_provider` resource. ([#6145](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6145))
- iamworkforcepool: added `jwksJson` field to `WorkforcePoolProvider` resource ([#6153](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6153))
- monitoring: added `synthetic_monitor` to `google_monitoring_uptime_check_config` resource ([#6148](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6148))
- provider: improved error message when resource creation fails to to invalid API response ([#6149](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6149))
BUG FIXES:
- cloudrunv2: changed `template.volumes.secret.items.mode` field in `google_cloud_run_v2_job` resource to a non-required field. ([#6154](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6154))
- cloudrunv2: changed `template.volumes.secret.items.mode` field in `google_cloud_run_v2_service` resource to a non-required field. ([#6154](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6154))
- filestore: fixed a bug causing permadiff on `reserved_ip_range` field in `google_filestore_instance` ([#6143](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6143))
- identityplatform: fixed a permadiff on `authorized_domains` in `google_identity_platform_config` resource ([#6137](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6137))
#### 4.80.0 (August 28, 2023)
DEPRECATIONS:
- dataplex: deprecated the following `google_dataplex_datascan` fields: `dataProfileResult` and `dataQualityResult` ([#6090](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6090))
- firebase: deprecated `google_firebase_project_location` in favor of `google_firebase_storage_bucket` and `google_firestore_database` ([#6087](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6087))
FEATURES:
- **New Data Source:** `google_sql_database_instance_latest_recovery_time` ([#6109](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6109))
- **New Resource:** `google_certificate_manager_trust_config` ([#6118](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6118))
- **New Resource:** `google_compute_region_security_policy_rule` ([#6086](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6086))
- **New Resource:** `google_gke_hub_membership_rbac_role_binding` ([#6103](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6103))
- **New Resource:** `google_iam_deny_policy` (ga only) ([#6125](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6125))
- **New Resource:** dataform_repository_workflow_config (beta) ([#6102](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6102))
- **New Resource:** google_bigquery_bi_reservation ([#6088](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6088))
IMPROVEMENTS:
- alloydb: added `restore_backup_source` and `restore_continuous_backup_source` fields to support restore feature in `google_alloydb_cluster` resource. ([#6129](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6129))
- artifactregistry: added `cleanup_policies` and `cleanup_policy_dry_run` fields to resource `google_artifact_registry_repository` ([#6117](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6117))
- compute: added `security_policy` field to `google_compute_target_instance` resource ([#6122](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6122))
- compute: added support for `security_policy` field to `google_compute_target_pool` ([#6124](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6124))
- compute: added support for `user_defined_fields` to `google_compute_region_security_policy` ([#6086](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6086))
- compute: added support for specifying regional disks for `google_compute_instance` `boot_disk.source` ([#6132](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6132))
- container: added `additional_pod_ranges_config` field to `google_container_cluster` resource ([#6133](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6133))
- dataplex: added fields `data_profile_spec.post_scan_actions`, `data_profile_spec.include_fields` and `data_profile_spec.exclude_fields` ([#6104](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6104))
- dns: added support for removing the networks block from the configuration in resource `google_dns_response_policy` ([#6111](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6111))
- firebase: added `api_key_id` field to `google_firebase_web_app`, `google_firebase_android_app`, and `google_firebase_apple_app`. ([#6127](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6127))
- gkeonprem: automatically set `ignore_errors` to true in `google_gkeonprem_bare_metal_admin_cluster` delete calls ([#6095](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6095))
- sql: added `psc_config` , `psc_service_attachment_link`, and `dns_name` fields to `google_sql_database_instance` ([#6119](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6119))
- workstations: added `enable_nested_virtualization` field to `google_workstations_workstation_config` resource ([#6123](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6123))
BUG FIXES:
- bigquery: added support to unset policy tags in table schema ([#6106](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6106))
- bigtable: fixed permadiff in `google_bigtable_gc_policy.gc_rules` when `max_age` is specified using increments larger than hours ([#6131](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6131))
- bigtable: fixed permadiff in `google_bigtable_gc_policy.gc_rules` when `mode` is specified ([#6131](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6131))
- container: updated `resource_container_cluster` to ignore `dns_config` diff when `enable_autopilot = true` ([#6108](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6108))
- containeraws: allowed `config.labels` to be updatable in `google_container_aws_node_pool` ([#6120](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6120))
- containerazure: added diff suppression for case changes of enum values in `google_container_azure_cluster` ([#6096](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6096))
#### 4.79.0 (August 21, 2023)
FEATURES:
- **New Resource:** `google_backup_dr_management_server` ([#6054](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6054))
- **New Resource:** `google_compute_region_security_policy_rule` ([#6086](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6086))
IMPROVEMENTS:
- cloudbuild: added `git_file_source.bitbucket_server_config` and `source_to_build.bitbucket_server_config` fields to `google_cloudbuild_trigger` resource ([#6051](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6051))
- cloudrunv2: added the following output only fields to `google_cloud_run_v2_job` and `google_cloud_run_v2_service` resources: `create_time`, `update_time`, `delete_time`, `expire_time`, `creator` and `last_modifier` ([#6067](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6067))
- composer: added `config.private_environment_config.connection_type` field to `google_composer_environment` resource ([#6043](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6043))
- compute: added `disk.provisioned_iops` field to `google_compute_instance_template` and `google_compute_region_instance_template` resources ([#6071](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6071))
- compute: added `advanced_options_config.user_ip_request_headers` field to `google_compute_security_policy` resource ([#6048](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6048))
- compute: added `user_defined_fields` field to `google_compute_region_security_policy` resource ([#6086](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6086))
- databasemigrationservice: added `edition` field to `google_database_migration_service_connection_profile` resource ([#6074](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6074))
- dns: allowed `globalL7ilb` value for the `routing_policy.load_balancer_type` field in `google_dns_record_set` resource ([#6084](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6084))
- gkeonprem: added `control_plane_node.vsphere_config.storage_policy_name` and `vcenter.storage_policy_name` fields to `google_gkeonprem_vmware_cluster` resource ([#6072](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6072))
- healthcare: added `default_search_handling_strict` field to `google_healthcare_fhir_store` resource ([#6078](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6078))
- metastore: added `scaling_config` field to `google_dataproc_metastore_service` resource ([#6052](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6052))
- secretmanager: added `version_aliases` field to `google_secret_manager_secret` resource ([#6058](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6058))
BUG FIXES:
- alloydb: fixed a permadiff on `google_alloydb_cluster` when `backup_window`, `enabled` or `location` fields are unset ([#6036](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6036))
- containeraws: fixed permadiffs on `google_container_aws_cluster` and `google_container_aws_node_pool` resources ([#6060](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6060))
- dataplex: fixed a bug when importing `google_dataplex_datascan` after running a job ([#6047](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6047))
- dns: changed `private_visibility_config.networks` from `required` to requiring at least one of `private_visibility_config.networks` or `private_visibility_config.gke_clusters` in `google_dns_managed_zone` resource ([#6035](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6035))
#### 4.78.0 (August 15, 2023)
FEATURES:
- **New Resource:** `google_billing_project_info` ([#6015](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6015))
- **New Resource:** `google_dataform_repository_release_config` ([#6009](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6009))
- **New Resource:** `google_network_connectivity_service_connection_policy` ([#6000](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6000))
IMPROVEMENTS:
- alloydb: added `continuous_backup_config` and `continuous_backup_info` fields to `cluster` resource ([#5996](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5996))
- bigquery: added `external_data_configuration.file_set_spec_type` to `google_bigquery_table` ([#6017](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6017))
- bigquery: added `max_staleness` to `google_bigquery_table` ([#6010](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6010))
- billingbudget: added `resource_ancestors` field to `google_billing_budget` resource ([#6008](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6008))
- cloudfunctions2: added support for GCF Gen2 CMEK ([#6004](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6004))
- cloudidentity: added field `type` to `google_cloud_identity_group_memberships` ([#6013](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6013))
- compute: added `subnetwork` field to the resource `google_compute_global_forwarding_rule` ([#6026](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6026))
- compute: added support for `INTERNAL_MANAGED` to the field `load_balancing_scheme` in the resource `google_compute_backend_service` ([#6026](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6026))
- compute: added support for `INTERNAL_MANAGED` to the field `load_balancing_scheme` in the resource `google_compute_global_forwarding_rule` ([#6026](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6026))
- compute: added support for `ip_version` to `google_compute_forwarding_rule` ([#6006](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6006))
- container: marked `master_ipv4_cidr_block` as not required when `private_endpoint_subnetwork` is provided for `google_container_cluster` ([#6025](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6025))
- container: added support for `advanced_datapath_observability_config` to `google_container_cluster` ([#6027](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6027))
- eventarc: added field `event_data_content_type` to `google_eventarc_trigger` ([#6032](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6032))
- healthcare: added `send_previous_resource_on_delete` field to `notification_configs` of `google_healthcare_fhir_store` ([#5999](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5999))
- pubsub: added `cloud_storage_config` field to `google_pubsub_subscription` resource ([#6024](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6024))
- secretmanager: added `annotations` field to `google_secret_manager_secret` resource ([#6007](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6007))
- workstations: added `private_cluster_config.allowed_projects` arguments to `google_workstations_workstation_cluster` ([#6021](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6021))
BUG FIXES:
- certificatemanager: added recreation behavior to the `google_certificate_manager_certificate` resource when its location changes ([#6031](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6031))
- cloudfunctions2: fixed creation failure state inconsistency in `google_cloudfunctions2_function` ([#6023](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6023))
- monitoring: updated `evaluation_interval` on `condition_prometheus_query_language` to be optional ([#6028](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6028))
#### 4.77.0 (August 7, 2023)
NOTES:
- vpcaccess: reverted the ability to update the number of instances for resource `google_vpc_access_connector` ([#5957](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5957))
FEATURES:
- **New Resource:** `google_document_ai_warehouse_document_schema` ([#5965](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5965))
- **New Resource:** `google_document_ai_warehouse_location` ([#5965](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5965))
IMPROVEMENTS:
- alloydb: added `continuous_backup_config` and `continuous_backup_info` fields to `cluster` resource ([#5996](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5996))
- cloudbuild: removed the validation function for the values of `machine_type` field on the `google_cloudbuild_trigger` resource ([#5985](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5985))
- compute: added future_limit in quota exceeded error details for compute resources. ([#5982](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5982))
- compute: added `enable_strong_affinity` field to `google_compute_region_backend_service` (beta) ([#5962](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5962))
- compute: added `ipv6_endpoint_type` and `ip_version` to `google_compute_address` ([#5986](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5986))
- compute: added `network_interface.ipv6_access_config.external_ipv6_prefix_length` to `google_compute_instance` ([#5986](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5986))
- compute: added `network_interface.ipv6_access_config.name` to `google_compute_instance` ([#5986](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5986))
- compute: added a new type `GLOBAL_MANAGED_PROXY` for the field `purpose` in the resource `google_compute_subnetwork` ([#5981](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5981))
- compute: added protocol type: UNSPECIFIED in `google_compute_backend_service` as per [release note](https://cloud.google.com/load-balancing/docs/release-notes#July\_24\_2023) ([#5967](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5967))
- compute: added `local_ssd_recovery_timeout` field to `google_compute_instance` resource ([#5968](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5968))
- compute: added `local_ssd_recovery_timeout` field to `google_compute_instance_template` resource ([#5968](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5968))
- compute: added `local_ssd_recovery_timeout` field to `google_compute_regional_instance_template` resource ([#5968](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5968))
- compute: made `network_interface.ipv6_access_config.external_ipv6` configurable in `google_compute_instance` ([#5986](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5986))
- container: added `enable_k8s_beta_apis.enabled_apis` field to `google_container_cluster` ([#5961](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5961))
- container: added `node_config.host_maintenance_policy` field to `google_container_cluster` and `google_container_node_pool` ([#5983](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5983))
- container: added `placement_policy.policy_name` field to `google_container_node_pool` resource ([#5994](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5994))
- container: unsuppressed `private_cluster_config` when `master_global_access_config` is set in `google_container_cluster` ([#5995](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5995))
- container: allowed `enabled_private_endpoint` to be settable on creation for PSC-based clusters ([#5989](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5989))
- gkeonprem: added taint on failed resource creation for `google_gkeonprem_bare_metal_admin_cluster` ([#5990](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5990))
- gkeonprem: increased timeout for resources `google_gkeonprem_bare_metal_cluster` and `google_gkeonprem_bare_metal_admin_cluster` ([#5990](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5990))
- identityplayform: added support for `blocking_functions` `quota` and `authorized_domains` in `google_identity_platform_config` ([#5964](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5964))
- monitoring: added update support for `period` in `google_monitoring_uptime_check_config` ([#5959](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5959))
- pubsub: added `no_wrapper` field to `google_pubsub_subscription` resource ([#5972](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5972))
- workstations: added `accelerators` field to `google_workstations_workstation_config` resource ([#5991](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5991))
BUG FIXES:
- bigquery: fixed a bug in update support for several fields in `google_bigquery_data_transfer_config` ([#5987](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5987))
- cloudfunctions2: fixed an issue where `google_cloudfunctions2_function.build_config.source.storage_source.generation` created a diff when not set in config ([#5992](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5992))
- firebasedatabase: fixed empty `database_url` output attribute ([#5988](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5988))
- monitoring: fixed an issue in `google_monitoring_monitored_project` where project numbers were not accepted for `name` ([#5955](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5955))
- vpcaccess: reverted new behaviour introduced by resource `google_vpc_access_connector` in `4.75.0`. `min_throughput` and `max_throughput` fields lost their default value, and customers could not make deployment due to that change. ([#5957](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5957))
#### 4.76.0 (July 31, 2023)
FEATURES:
- **New Resource:** `google_dataplex_task` ([#5914](https://togit
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
[ ] If you want to rebase/retry this PR, check this box
This PR has been generated by Mend Renovate. View repository job log here.
This PR contains the following updates:
v1.14.5
->v1.15.0
4.84.0
->4.85.0
4.84.0
->4.85.0
v1.8.4
->v1.8.5
Release Notes
cert-manager/cert-manager (cert-manager/cert-manager)
### [`v1.15.0`](https://togithub.com/cert-manager/cert-manager/releases/tag/v1.15.0) [Compare Source](https://togithub.com/cert-manager/cert-manager/compare/v1.14.6...v1.15.0) cert-manager is the easiest way to automatically manage certificates in Kubernetes and OpenShift clusters. cert-manager 1.15 promotes several features to beta, including GatewayAPI support (`ExperimentalGatewayAPISupport`), the ability to provide a subject in the Certificate that will be used literally in the CertificateSigningRequest (`LiteralCertificateSubject`) and the outputting of additional certificate formats (`AdditionalCertificateOutputFormats`). > \[!NOTE] > > The `cmctl` binary have been moved to https://github.com/cert-manager/cmctl/releases. > For the startupapicheck Job you should update references to point at `quay.io/jetstack/cert-manager-startupapicheck` > \[!NOTE] > > From this release, the Helm chart will no longer uninstall the CRDs when the chart is uninstalled. If you want the CRDs to be removed on uninstall use `crds.keep=false` when installing the Helm chart. #### Community Thanks again to all open-source contributors with commits in this release, including: [@Pionerd](https://togithub.com/Pionerd), [@SgtCoDFish](https://togithub.com/SgtCoDFish), [@ThatsMrTalbot](https://togithub.com/ThatsMrTalbot), [@andrey-dubnik](https://togithub.com/andrey-dubnik), [@bwaldrep](https://togithub.com/bwaldrep), [@eplightning](https://togithub.com/eplightning), [@erikgb](https://togithub.com/erikgb), [@findnature](https://togithub.com/findnature), [@gplessis](https://togithub.com/gplessis), [@import-shiburin](https://togithub.com/import-shiburin), [@inteon](https://togithub.com/inteon), [@jkroepke](https://togithub.com/jkroepke), [@lunarwhite](https://togithub.com/lunarwhite), [@mangeshhambarde](https://togithub.com/mangeshhambarde), [@pwhitehead-splunk](https://togithub.com/pwhitehead-splunk) & [@rodrigorfk](https://togithub.com/rodrigorfk), [@wallrj](https://togithub.com/wallrj). Thanks also to the following cert-manager maintainers for their contributions during this release: [@SgtCoDFish](https://togithub.com/SgtCoDFish), [@SpectralHiss](https://togithub.com/SpectralHiss), [@ThatsMrTalbot](https://togithub.com/ThatsMrTalbot), [@hawksight](https://togithub.com/hawksight), [@inteon](https://togithub.com/inteon), [@maelvls](https://togithub.com/maelvls) & [@wallrj](https://togithub.com/wallrj). Equally thanks to everyone who provided feedback, helped users and raised issues on GitHub and Slack and joined our meetings! Thanks also to the CNCF, which provides resources and support, and to the AWS open source team for being good community members and for their maintenance of the PrivateCA Issuer. In addition, massive thanks to Venafi for contributing developer time and resources towards the continued maintenance of cert-manager projects. #### Changes by Kind ##### Feature - GatewayAPI support has graduated to Beta. Add the `--enable-gateway-api` flag to enable the integration. ([#6961](https://togithub.com/cert-manager/cert-manager/issues/6961), [@ThatsMrTalbot](https://togithub.com/ThatsMrTalbot)) - Add support to specify a custom key alias in a JKS Keystore ([#6807](https://togithub.com/cert-manager/cert-manager/issues/6807), [@bwaldrep](https://togithub.com/bwaldrep)) - Add the ability to communicate with Vault via mTLS when strict client certificates is enabled at Vault server side ([#6614](https://togithub.com/cert-manager/cert-manager/issues/6614), [@rodrigorfk](https://togithub.com/rodrigorfk)) - Added option to provide additional audiences in the service account auth section for vault ([#6718](https://togithub.com/cert-manager/cert-manager/issues/6718), [@andrey-dubnik](https://togithub.com/andrey-dubnik)) - Venafi Issuer now sends a cert-manager HTTP User-Agent header in all Venafi Rest API requests. For example: `cert-manager-certificaterequests-issuer-venafi/v1.15.0+(linux/amd64)+cert-manager/ef068a59008f6ed919b98a7177921ddc9e297200`. ([#6865](https://togithub.com/cert-manager/cert-manager/issues/6865), [@wallrj](https://togithub.com/wallrj)) - Add hint to validation error message to help users of external issuers more easily fix the issue if they specify a Kind but forget the Group ([#6913](https://togithub.com/cert-manager/cert-manager/issues/6913), [@SgtCoDFish](https://togithub.com/SgtCoDFish)) - Add support for numeric OID types in LiteralSubject. Eg. "1.2.3.4=String Value" ([#6775](https://togithub.com/cert-manager/cert-manager/issues/6775), [@inteon](https://togithub.com/inteon)) - Promote the `LiteralCertificateSubject` feature to Beta. ([#7030](https://togithub.com/cert-manager/cert-manager/issues/7030), [@inteon](https://togithub.com/inteon)) - Promoted the AdditionalCertificateOutputFormats feature gate to Beta (enabled by default). ([#6970](https://togithub.com/cert-manager/cert-manager/issues/6970), [@erikgb](https://togithub.com/erikgb)) - The Helm chart now allows you to supply `extraObjects`; a list of yaml manifests which will helm will install and uninstall with the cert-manager manifests. ([#6424](https://togithub.com/cert-manager/cert-manager/issues/6424), [@gplessis](https://togithub.com/gplessis)) - Update the Route53 provider to support fetching credentials using AssumeRoleWithWebIdentity ([#6878](https://togithub.com/cert-manager/cert-manager/issues/6878), [@pwhitehead-splunk](https://togithub.com/pwhitehead-splunk)) - Helm can now add optional hostAliases to cert-manager Pod to allow the DNS self-check to pass in custom scenarios. ([#6456](https://togithub.com/cert-manager/cert-manager/issues/6456), [@Pionerd](https://togithub.com/Pionerd)) - Added a new Ingress annotation for copying specific Ingress annotations to Certificate's secretTemplate ([#6839](https://togithub.com/cert-manager/cert-manager/issues/6839), [@mangeshhambarde](https://togithub.com/mangeshhambarde)) - Added option to define additional token audiences for the Vault Kubernetes auth ([#6744](https://togithub.com/cert-manager/cert-manager/issues/6744), [@andrey-dubnik](https://togithub.com/andrey-dubnik)) - Allow `cert-manager.io/allow-direct-injection` in annotations ([#6801](https://togithub.com/cert-manager/cert-manager/issues/6801), [@jkroepke](https://togithub.com/jkroepke)) ##### Design - Remove repetitive words ([#6949](https://togithub.com/cert-manager/cert-manager/issues/6949), [@findnature](https://togithub.com/findnature)) ##### Bug or Regression - BUGFIX: Fixes issue with JSON-logging, where only a subset of the log messages were output as JSON. ([#6779](https://togithub.com/cert-manager/cert-manager/issues/6779), [@inteon](https://togithub.com/inteon)) - BUGFIX: JKS and PKCS12 stores now contain the full set of CAs specified by an issuer ([#6806](https://togithub.com/cert-manager/cert-manager/issues/6806), [@bwaldrep](https://togithub.com/bwaldrep)) - BUGFIX: cainjector leaderelection flag/config option defaults are missing ([#6816](https://togithub.com/cert-manager/cert-manager/issues/6816), [@inteon](https://togithub.com/inteon)) - BUGFIX: cert-manager issuers incorrectly copied the critical flag from the CSR instead of re-calculating that field themselves. ([#6724](https://togithub.com/cert-manager/cert-manager/issues/6724), [@inteon](https://togithub.com/inteon)) - Breaking Change: Fixed unintended certificate chain is used if `preferredChain` is configured. ([#6755](https://togithub.com/cert-manager/cert-manager/issues/6755), [@import-shiburin](https://togithub.com/import-shiburin)) - Bugfix: LiteralSubjects with a #= value can result in memory issues due to faulty BER parser (github.com/go-asn1-ber/asn1-ber). ([#6770](https://togithub.com/cert-manager/cert-manager/issues/6770), [@inteon](https://togithub.com/inteon)) - DigitalOcean: Ensure that only TXT records are considered for deletion when cleaning up after an ACME challenge ([#6875](https://togithub.com/cert-manager/cert-manager/issues/6875), [@SgtCoDFish](https://togithub.com/SgtCoDFish)) - Fix backwards incompatible removal of default prometheus Service resource. ([#6699](https://togithub.com/cert-manager/cert-manager/issues/6699), [@inteon](https://togithub.com/inteon)) - Fix broken cainjector image value in Helm chart ([#6692](https://togithub.com/cert-manager/cert-manager/issues/6692), [@SgtCoDFish](https://togithub.com/SgtCoDFish)) - Helm: Fix a bug in the logic that differentiates between 0 and an empty value. ([#6713](https://togithub.com/cert-manager/cert-manager/issues/6713), [@inteon](https://togithub.com/inteon)) - Make sure the Azure SDK error messages are stable. ([#6676](https://togithub.com/cert-manager/cert-manager/issues/6676), [@inteon](https://togithub.com/inteon)) - When using the literalSubject on a Certificate, the webhook validation for the common name now also points to the literalSubject. ([#6767](https://togithub.com/cert-manager/cert-manager/issues/6767), [@lunarwhite](https://togithub.com/lunarwhite)) - Bump golang.org/x/net to fix CVE-2023-45288 ([#6929](https://togithub.com/cert-manager/cert-manager/issues/6929), [@SgtCoDFish](https://togithub.com/SgtCoDFish)) - Fix ACME issuer being stuck waiting for DNS propagation when using Azure DNS with multiple instances issuing for the same FQDN ([#6351](https://togithub.com/cert-manager/cert-manager/issues/6351), [@eplightning](https://togithub.com/eplightning)) - Fix cainjector ConfigMap not mounted in the cainjector deployment. ([#7055](https://togithub.com/cert-manager/cert-manager/issues/7055), [@inteon](https://togithub.com/inteon)) - Added `disableAutoApproval` and `approveSignerNames` Helm chart options. ([#7054](https://togithub.com/cert-manager/cert-manager/issues/7054), [@inteon](https://togithub.com/inteon)) ##### Other (Cleanup or Flake) - ⚠️ Possibly breaking: Helm will now keep the CRDs when you uninstall cert-manager by default to prevent accidental data loss. ([#6760](https://togithub.com/cert-manager/cert-manager/issues/6760), [@inteon](https://togithub.com/inteon)) - New `crds.keep` and `crds.enabled` Helm options can now be used instead of the `installCRDs` option. ([#6760](https://togithub.com/cert-manager/cert-manager/issues/6760), [@inteon](https://togithub.com/inteon)) - Bump base images ([#6840](https://togithub.com/cert-manager/cert-manager/issues/6840), [@inteon](https://togithub.com/inteon)) - Bump github.com/go-jose/go-jose to v3.0.3 to fix CVE-2024-28180 ([#6854](https://togithub.com/cert-manager/cert-manager/issues/6854), [@wallrj](https://togithub.com/wallrj)) - Removed deprecated util functions that have been replaced by the `slices` and `k8s.io/apimachinery/pkg/util` packages. Removed deprecated CSR functions which have been replaced with other functions in the `pkg/util/pki` package. ([#6730](https://togithub.com/cert-manager/cert-manager/issues/6730), [@inteon](https://togithub.com/inteon)) - Upgrade go to 1.21.8: fixes CVE-2024-24783 ([#6823](https://togithub.com/cert-manager/cert-manager/issues/6823), [@inteon](https://togithub.com/inteon)) - Upgrade go to latest version 1.22.1 ([#6831](https://togithub.com/cert-manager/cert-manager/issues/6831), [@inteon](https://togithub.com/inteon)) - Upgrade google.golang.org/protobuf: fixing GO-2024-2611 ([#6827](https://togithub.com/cert-manager/cert-manager/issues/6827), [@inteon](https://togithub.com/inteon)) - `cmctl` and `kubectl cert-manger` have been moved to the https://github.com/cert-manager/cmctl repo and will be versioned separately starting with cmctl v2.0.0 ([#6663](https://togithub.com/cert-manager/cert-manager/issues/6663), [@inteon](https://togithub.com/inteon)) - Graduate the 'DisallowInsecureCSRUsageDefinition' feature gate to GA. (part 2) ([#6963](https://togithub.com/cert-manager/cert-manager/issues/6963), [@inteon](https://togithub.com/inteon)) - Remove deprecated `pkg/util/pki/ParseSubjectStringToRawDERBytes` function. ([#6994](https://togithub.com/cert-manager/cert-manager/issues/6994), [@inteon](https://togithub.com/inteon)) - Upgrade Kind to v0.23.0 and update supported node image digests ([#7020](https://togithub.com/cert-manager/cert-manager/issues/7020), [@github-actions](https://togithub.com/github-actions)\[bot]) - If the `--controllers` flag only specifies disabled controllers, the default controllers are now enabled implicitly. ([#7054](https://togithub.com/cert-manager/cert-manager/issues/7054), [@inteon](https://togithub.com/inteon)) - Upgrade to Go 1.22.3, fixing `GO-2024-2824`. ([#6996](https://togithub.com/cert-manager/cert-manager/issues/6996), [@github-actions](https://togithub.com/github-actions)\[bot]) ### [`v1.14.6`](https://togithub.com/cert-manager/cert-manager/releases/tag/v1.14.6) [Compare Source](https://togithub.com/cert-manager/cert-manager/compare/v1.14.5...v1.14.6) #### Changes by Kind ##### Other (Cleanup or Flake) - Upgrade Go to 1.21.10, fixing GO-2024-2824 (https://github.com/advisories/GHSA-2jwv-jmq4-4j3r). ([#7008](https://togithub.com/cert-manager/cert-manager/issues/7008), [@inteon](https://togithub.com/inteon)) - Helm: the cainjector ConfigMap was not mounted in the cainjector deployment. ([#7053](https://togithub.com/cert-manager/cert-manager/issues/7053), [@cert-manager-bot](https://togithub.com/cert-manager-bot)) - Updated Go to 1.21.11 bringing in security fixes for archive/zip and net/netip. ([#7076](https://togithub.com/cert-manager/cert-manager/issues/7076), [@ThatsMrTalbot](https://togithub.com/ThatsMrTalbot))hashicorp/terraform-provider-google (google)
### [`v4.85.0`](https://togithub.com/hashicorp/terraform-provider-google/blob/HEAD/CHANGELOG.md#4850-June-12-2024) [Compare Source](https://togithub.com/hashicorp/terraform-provider-google/compare/v4.84.0...v4.85.0) NOTES: - The `4.85.0` release backports configuration for the retention period for Cloud Storage soft delete (https://cloud.google.com/resources/storage/soft-delete-announce) so that customers who have not yet upgraded to `5.22.0`+ are able to configure the retention period of objects in their buckets. By upgrading to this version and configuring or otherwise interacting with the `google_storage_bucket.soft_delete_policy` values, you will need to upgrade directly to `5.22.0`+ from `4.85.0` when upgrading to `5.X` in the future. IMPROVEMENTS: - storage: added `soft_delete_policy` to `google_storage_bucket` resource ([#17624](https://togithub.com/hashicorp/terraform-provider-google/pull/17624))hashicorp/terraform-provider-google-beta (google-beta)
### [`v4.85.0`](https://togithub.com/hashicorp/terraform-provider-google-beta/releases/tag/v4.85.0) [Compare Source](https://togithub.com/hashicorp/terraform-provider-google-beta/compare/v4.84.0...v4.85.0) OTES: - The `4.85.0` release backports configuration for the retention period for Cloud Storage soft delete (https://cloud.google.com/resources/storage/soft-delete-announce) so that customers who have not yet upgraded to `5.22.0`+ are able to configure the retention period of objects in their buckets. By upgrading to this version and configuring or otherwise interacting with the `google_storage_bucket.soft_delete_policy` values, you will need to upgrade directly to `5.22.0`+ from `4.85.0` when upgrading to `5.X` in the future. IMPROVEMENTS: - storage: added 'soft_delete_policy' to 'google_storage_bucket' resource ([#7119](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/7119)) #### 4.84.0 (September 26, 2023) DEPRECATIONS: - alloydb: deprecated `network` field in favor of `network_config` on `google_alloydb_cluster`. ([#6297](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6297)) - identityplayform: deprecated `google_identity_platform_project_default_config` resource. Use `google_identity_platform_config` resource instead ([#6293](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6293)) FEATURES: - **New Data Source:** `google_certificate_manager_certificate_map` ([#6316](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6316)) - **New Resource:** `google_artifact_registry_vpcsc_config` ([#6265](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6265)) - **New Resource:** `google_dialogflow_cx_security_settings` ([#6300](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6300)) - **New Resource:** `google_gke_backup_restore_plan` ([#6278](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6278)) - **New Resource:** `google_scc_project_custom_module` ([#6315](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6315)) - **New Resource:** `google_tpu_v2_vm` ([#6264](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6264)) - **New Resource:** `google_edgenetwork_network` ([#6305](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6305)) - **New Resource:** `google_edgenetwork_subnet` ([#6305](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6305)) IMPROVEMENTS: - alloydb: added `network_config` field to support named IP ranges on `google_alloydb_cluster`. ([#6297](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6297)) - cloudrunv2: added fields `network_interfaces` to resource `google_cloud_run_v2_job` to support Direct VPC egress. ([#6287](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6287)) - cloudrunv2: added fields `network_interfaces` to resource `google_cloud_run_v2_service` to support Direct VPC egress. ([#6287](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6287)) - compute: updated the `autoscaling_policy.mode` to accept `ONLY_SCALE_OUT` on `google_compute_autoscaler` ([#6304](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6304)) - compute: added `server_tls_policy` argument to `google_compute_target_https_proxy` resource ([#6269](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6269)) - compute: added `member` attribute to `google_compute_default_service_account` datasource ([#6311](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6311)) - compute: added output field `internal_ipv6_prefix` to `google_compute_subnetwork` resource ([#6306](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6306)) - container: added `node_config.fast_socket` field to `google_container_node_pool` ([#6289](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6289)) - containeraws: added support for `auto_repair` in `google_container_aws_node_pool` ([#6282](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6282)) - containerazure: added support for `auto_repair` in `google_container_azure_node_pool` ([#6282](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6282)) - filestore: added support for the `"ZONAL"` value to `tier` in `google_filestore_instance` ([#6303](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6303)) - firestore: added `delete_protection_state` field to `google_firestore_database` resource. ([#6295](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6295)) - identityplatform: added `sign-in` field to `google_identity_platform_config` resource ([#6293](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6293)) - networkconnectivity: added support for `linked_vpc_network` in `google_network_connectivity_spoke` ([#6282](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6282)) - networkservices: increased default timeout for `google_network_services_edge_cache_origin` to 120m from 60m ([#6275](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6275)) - networkservices: increased default timeout for `google_network_services_edge_cache_service` to 60m from 30m ([#6281](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6281)) - secretmanager: added `is_secret_data_base64` field to `google_secret_manager_secret_version` resource ([#6273](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6273)) - workstations: added `env` field to `google_workstations_workstation` resource ([#6258](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6258)) BUG FIXES: - bigquery: updated documentation for `google_bigquery_table.time_partitioning.expiration_ms` ([#6290](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6290)) - bigtable: added a read timeout to `google_bigtable_instance` ([#6276](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6276)) - bigtable: improved regional reliability when instance overlaps a downed region in the resource `google_bigtable_instance` ([#6313](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6313)) - eventarc: resolved permadiff on `google_eventarc_trigger.event_data_content_type` by defaulting to the value returned by the API if not set in the configuration. ([#6282](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6282)) - identityplatform: fixed a potential perma-diff for `sign_in` in `google_identity_platform_config` resource ([#6317](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6317)) - monitoring: fixed scaling issues when deploying terraform changes with many `google_monitoring_monitored_project` ([#6259](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6259)) - monitoring: fixed validation of `service_id` on `google_monitoring_custom_service` and `slo_id` on `google_monitoring_slo` ([#6266](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6266)) - osconfig: fixed no more than one setting is allowed under `patch_config.windows_update` on `google_os_config_patch_deployment` ([#6314](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6314)) - provider: addressed a bug where configuring the provider with unknown values did not behave as expected ([#6312](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6312)) - provider: fixed the provider so it resumes ignoring empty strings set in the `provider` block ([#6268](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6268)) - secretmanager: replaced the panic block with an error in import function of `google_secret_manager_secret_version` resource ([#6296](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6296)) - secretmanager: fixed an issue in `google_secretmanager_secret` where replacing `replication.automatic` with `replication.auto` would destroy and recreate the resource ([#6325](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6325)) #### 4.83.0 (September 18, 2023) DEPRECATIONS: - secretmanager: deprecated `automatic` field on `google_secret_manager_secret`. Use `auto` instead. ([#6237](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6237)) FEATURES: - **New Resource:** `google_biglake_table` ([#6205](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6205)) - **New Resource:** `google_data_pipeline_pipeline` ([#6236](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6236)) - **New Resource:** `google_dialogflow_cx_test_case` ([#6249](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6249)) - **New Resource:** `google_storage_insights_report_config` ([#6253](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6253)) - **New Resource:** `google_apigee_target_server` ([#6215](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6215)) IMPROVEMENTS: - bigquery: added `allow_non_incremental_definition` to `google_bigquery_table` resource ([#6248](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6248)) - bigquery: added `table_constraints` field to `google_bigquery_table` resource ([#6250](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6250)) - compute: added internal IPV6 support for `google_compute_address` and `google_compute_instance` resources ([#6232](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6232)) - containerattached: added `binary_authorization` field to `google_container_attached_cluster` resource ([#6256](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6256)) - containeraws: added update support for `config.instance_type` in `container_aws_node_pool` ([#6282](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6282)) - firestore: added `point_in_time_recovery_enablement` field to `google_firestore_database` resource ([#6239](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6239)) - firestore: added `update_time` and `uid` fields to `google_firestore_database` resource ([#6257](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6257)) - gkehub2: added `labels`, `namespace_labels` fields to `google_gke_hub_namespace` resource ([#6202](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6202)) - gkehub: added `labels` fields to `google_gke_hub_membership_binding` resource ([#6216](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6216)) - gkehub: added `labels` fields to `google_gke_hub_scope` resource ([#6243](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6243)) - gkeonprem: added `upgrade_policy` and `binary_authorization` fields in `google_gkeonprem_bare_metal_cluster` resource (beta) ([#6224](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6224)) - gkeonprem: added `upgrade_policy` field in `google_gkeonprem_vmware_cluster` resource (beta) ([#6224](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6224)) - secretmanager: added `auto` field to `google_secret_manager_secret` resource ([#6237](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6237)) - secretmanager: added `deletion_policy` field to `google_secret_manager_secret_version` resource ([#6252](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6252)) - storage: supported in-place update for `autoclass` field in `google_storage_bucket` resource ([#6233](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6233)) - vertexai: added `public_endpoint_enabled` to `google_vertex_ai_index_endpoint` ([#6208](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6208)) - workstations: added `env` field to `google_workstations_workstation` resource (beta) ([#6258](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6258)) BUG FIXES: - bigquerydatatransfer: fixed a bug when importing `location` of `google_bigquery_data_transfer_config` ([#6203](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6203)) - container: fixed a bug where `additional_pod_network_configs` was not sent correctly in `google_container_node_pool` ([#6211](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6211)) - container: fixed concurrent ops' quota-error to be retriable in ` google_container_node_pool ` ([#6254](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6254)) - eventarc: resolved permadiff on `event_content_type` in `eventarc_trigger`, the field will now default to a value returned by the API when not set in configuration ([#6282](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6282)) - pipeline: fixed issue where certain `google_dataflow_job` instances would crash the provider ([#6255](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6255)) - provider: fixed a bug where `user_project_override` would not be not used correctly when provisioning resources implemented using the plugin framework. Currently there are no resources implemented this way, so no-one should have been impacted. ([#6230](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6230)) - pubsub: fixed issue where setting `no_wrapper.write_metadata` to false wasn't passed to the API for `google_pubsub_subscription` ([#6219](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6219)) - serviceaccount: added retries for reads after `google_service_account` creation if 403 Forbidden is returned. ([#6221](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6221)) - storage: fixed the failure in building a plan when a `content` value is expected on `google_storage_bucket_object_content` ([#6204](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6204) #### 4.82.0 (September 11, 2023) IMPROVEMENTS: - compute: added in-place update support for field `enable_proxy_protocol` in `google_compute_service_attachment` resource ([#6192](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6192)) - compute: added in-place update support for field `reconcile_connections` in `google_compute_service_attachment` resource ([#6187](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6187)) - compute: added in-place update support for field `allowPscGlobalAccess` in `google_compute_forwarding_rule` resource ([#6179](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6179)) - container: added additional options for field `monitoring_config.enable_components` in `google_container_cluster` resource ([#6198](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6198)) - gkehub: added `labels` field to `google_gke_hub_scope_rbac_role_binding` resource ([#6200](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6200)) - logging: added in-place update support for field `unique_writer_identity` in `google_logging_project_sink` resource ([#6193](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6193)) - networkconnectivity: added `psc_connections.error.details` field to `google_network_connectivity_service_connection_policy` resource ([#6197](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6197)) - secretmanager: added in-place update support for field `replication.user_managed.replicas.customer_managed_encryption` in `google_secret_manager_secret` resource ([#6177](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6177)) BUG FIXES: - bigquery: made `params.destination_table_name_template` and `params.data_path` immutable as updating these fields if value of `data_source_id` is `amazon_s3` in `google_bigquery_data_transfer_config` resource ([#6195](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6195)) - compute: fixed a crash when empty is given to `all_instances_config` in `google_compute_region_instance_group_manager` resource ([#6191](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6191)) - dns: fixed hash function for `network_url` in `google_dns_managed_zone` and `google_dns_policy` resources to make sure that the private DNS zone or DNS policy can be attatched to all of the networks in different projects, even though the network name is the same across of those projects ([#6199](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6199)) - servicedirectory: made `location` immutable as updating this field in `google_service_directory_namespace` resource ([#6182](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6182)) #### 4.81.0 (September 05, 2023) FEATURES: - **New Resource:** `google_biglake_catalog` ([#6152](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6152)) - **New Resource:** `google_redis_cluster` ([#6158](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6158)) - **New Resource:** `google_biglake_database` ([#6161](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6161)) - **New Resource:** `google_compute_network_attachment` ([#6159](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6159)) - **New Resource:** `google_gke_hub_membership_binding` ([#6170](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6170)) - **New Resource:** `google_gke_hub_namespace` ([#6170](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6170)) - **New Resource:** `google_gke_hub_scope` ([#6170](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6170)) - **New Resource:** `google_gke_hub_scope_iam_member` ([#6170](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6170)) - **New Resource:** `google_gke_hub_scope_iam_policy` ([#6170](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6170)) - **New Resource:** `google_gke_hub_membership_binding` ([#6170](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6170)) - **New Resource:** `google_gke_hub_scope_rbac_role_binding` ([#6170](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6170)) IMPROVEMENTS: - compute: made the field `distribution_policy_target_shape` of `google_compute_region_instance_group_manager` not cause recreation of the resource. ([#6156](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6156)) - container: added `enable_fqdn_network_policy` field to `google_container_cluster` ([#6157](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6157)) - container: added `node_config.confidential_compute` field to `google_container_node_pool` resource ([#6166](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6166)) - datastream: allowed `password` of `google_datastream_connection_profile` to be mutable. ([#6140](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6140)) - dialogflowcx: added `response_type`, `channel`, `payload`, `conversation_success`, `output_audio_text`, `live_agent_handoff`, `play_audo`, `telephony_transfer_call`, `reprompt_event_handlers`, `set_parameter_actions`, and `conditional_cases` fields to `google_dialogflow_cx_page` resource ([#6168](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6168)) - dialogflowcx: added `response_type`, `channel`, `payload`, `conversation_success`, `output_audio_text`, `live_agent_handoff`, `play_audo`, `telephony_transfer_call`, `set_parameter_actions`, and `conditional_cases` fields to `google_dialogflow_cx_flow` resource ([#6168](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6168)) - iam: added `web_sso_config.additional_scopes` field to `google_iam_workforce_pool_provider` resource. ([#6145](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6145)) - iamworkforcepool: added `jwksJson` field to `WorkforcePoolProvider` resource ([#6153](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6153)) - monitoring: added `synthetic_monitor` to `google_monitoring_uptime_check_config` resource ([#6148](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6148)) - provider: improved error message when resource creation fails to to invalid API response ([#6149](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6149)) BUG FIXES: - cloudrunv2: changed `template.volumes.secret.items.mode` field in `google_cloud_run_v2_job` resource to a non-required field. ([#6154](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6154)) - cloudrunv2: changed `template.volumes.secret.items.mode` field in `google_cloud_run_v2_service` resource to a non-required field. ([#6154](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6154)) - filestore: fixed a bug causing permadiff on `reserved_ip_range` field in `google_filestore_instance` ([#6143](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6143)) - identityplatform: fixed a permadiff on `authorized_domains` in `google_identity_platform_config` resource ([#6137](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6137)) #### 4.80.0 (August 28, 2023) DEPRECATIONS: - dataplex: deprecated the following `google_dataplex_datascan` fields: `dataProfileResult` and `dataQualityResult` ([#6090](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6090)) - firebase: deprecated `google_firebase_project_location` in favor of `google_firebase_storage_bucket` and `google_firestore_database` ([#6087](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6087)) FEATURES: - **New Data Source:** `google_sql_database_instance_latest_recovery_time` ([#6109](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6109)) - **New Resource:** `google_certificate_manager_trust_config` ([#6118](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6118)) - **New Resource:** `google_compute_region_security_policy_rule` ([#6086](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6086)) - **New Resource:** `google_gke_hub_membership_rbac_role_binding` ([#6103](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6103)) - **New Resource:** `google_iam_deny_policy` (ga only) ([#6125](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6125)) - **New Resource:** dataform_repository_workflow_config (beta) ([#6102](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6102)) - **New Resource:** google_bigquery_bi_reservation ([#6088](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6088)) IMPROVEMENTS: - alloydb: added `restore_backup_source` and `restore_continuous_backup_source` fields to support restore feature in `google_alloydb_cluster` resource. ([#6129](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6129)) - artifactregistry: added `cleanup_policies` and `cleanup_policy_dry_run` fields to resource `google_artifact_registry_repository` ([#6117](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6117)) - compute: added `security_policy` field to `google_compute_target_instance` resource ([#6122](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6122)) - compute: added support for `security_policy` field to `google_compute_target_pool` ([#6124](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6124)) - compute: added support for `user_defined_fields` to `google_compute_region_security_policy` ([#6086](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6086)) - compute: added support for specifying regional disks for `google_compute_instance` `boot_disk.source` ([#6132](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6132)) - container: added `additional_pod_ranges_config` field to `google_container_cluster` resource ([#6133](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6133)) - dataplex: added fields `data_profile_spec.post_scan_actions`, `data_profile_spec.include_fields` and `data_profile_spec.exclude_fields` ([#6104](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6104)) - dns: added support for removing the networks block from the configuration in resource `google_dns_response_policy` ([#6111](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6111)) - firebase: added `api_key_id` field to `google_firebase_web_app`, `google_firebase_android_app`, and `google_firebase_apple_app`. ([#6127](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6127)) - gkeonprem: automatically set `ignore_errors` to true in `google_gkeonprem_bare_metal_admin_cluster` delete calls ([#6095](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6095)) - sql: added `psc_config` , `psc_service_attachment_link`, and `dns_name` fields to `google_sql_database_instance` ([#6119](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6119)) - workstations: added `enable_nested_virtualization` field to `google_workstations_workstation_config` resource ([#6123](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6123)) BUG FIXES: - bigquery: added support to unset policy tags in table schema ([#6106](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6106)) - bigtable: fixed permadiff in `google_bigtable_gc_policy.gc_rules` when `max_age` is specified using increments larger than hours ([#6131](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6131)) - bigtable: fixed permadiff in `google_bigtable_gc_policy.gc_rules` when `mode` is specified ([#6131](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6131)) - container: updated `resource_container_cluster` to ignore `dns_config` diff when `enable_autopilot = true` ([#6108](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6108)) - containeraws: allowed `config.labels` to be updatable in `google_container_aws_node_pool` ([#6120](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6120)) - containerazure: added diff suppression for case changes of enum values in `google_container_azure_cluster` ([#6096](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6096)) #### 4.79.0 (August 21, 2023) FEATURES: - **New Resource:** `google_backup_dr_management_server` ([#6054](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6054)) - **New Resource:** `google_compute_region_security_policy_rule` ([#6086](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6086)) IMPROVEMENTS: - cloudbuild: added `git_file_source.bitbucket_server_config` and `source_to_build.bitbucket_server_config` fields to `google_cloudbuild_trigger` resource ([#6051](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6051)) - cloudrunv2: added the following output only fields to `google_cloud_run_v2_job` and `google_cloud_run_v2_service` resources: `create_time`, `update_time`, `delete_time`, `expire_time`, `creator` and `last_modifier` ([#6067](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6067)) - composer: added `config.private_environment_config.connection_type` field to `google_composer_environment` resource ([#6043](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6043)) - compute: added `disk.provisioned_iops` field to `google_compute_instance_template` and `google_compute_region_instance_template` resources ([#6071](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6071)) - compute: added `advanced_options_config.user_ip_request_headers` field to `google_compute_security_policy` resource ([#6048](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6048)) - compute: added `user_defined_fields` field to `google_compute_region_security_policy` resource ([#6086](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6086)) - databasemigrationservice: added `edition` field to `google_database_migration_service_connection_profile` resource ([#6074](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6074)) - dns: allowed `globalL7ilb` value for the `routing_policy.load_balancer_type` field in `google_dns_record_set` resource ([#6084](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6084)) - gkeonprem: added `control_plane_node.vsphere_config.storage_policy_name` and `vcenter.storage_policy_name` fields to `google_gkeonprem_vmware_cluster` resource ([#6072](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6072)) - healthcare: added `default_search_handling_strict` field to `google_healthcare_fhir_store` resource ([#6078](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6078)) - metastore: added `scaling_config` field to `google_dataproc_metastore_service` resource ([#6052](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6052)) - secretmanager: added `version_aliases` field to `google_secret_manager_secret` resource ([#6058](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6058)) BUG FIXES: - alloydb: fixed a permadiff on `google_alloydb_cluster` when `backup_window`, `enabled` or `location` fields are unset ([#6036](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6036)) - containeraws: fixed permadiffs on `google_container_aws_cluster` and `google_container_aws_node_pool` resources ([#6060](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6060)) - dataplex: fixed a bug when importing `google_dataplex_datascan` after running a job ([#6047](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6047)) - dns: changed `private_visibility_config.networks` from `required` to requiring at least one of `private_visibility_config.networks` or `private_visibility_config.gke_clusters` in `google_dns_managed_zone` resource ([#6035](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6035)) #### 4.78.0 (August 15, 2023) FEATURES: - **New Resource:** `google_billing_project_info` ([#6015](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6015)) - **New Resource:** `google_dataform_repository_release_config` ([#6009](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6009)) - **New Resource:** `google_network_connectivity_service_connection_policy` ([#6000](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6000)) IMPROVEMENTS: - alloydb: added `continuous_backup_config` and `continuous_backup_info` fields to `cluster` resource ([#5996](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5996)) - bigquery: added `external_data_configuration.file_set_spec_type` to `google_bigquery_table` ([#6017](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6017)) - bigquery: added `max_staleness` to `google_bigquery_table` ([#6010](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6010)) - billingbudget: added `resource_ancestors` field to `google_billing_budget` resource ([#6008](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6008)) - cloudfunctions2: added support for GCF Gen2 CMEK ([#6004](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6004)) - cloudidentity: added field `type` to `google_cloud_identity_group_memberships` ([#6013](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6013)) - compute: added `subnetwork` field to the resource `google_compute_global_forwarding_rule` ([#6026](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6026)) - compute: added support for `INTERNAL_MANAGED` to the field `load_balancing_scheme` in the resource `google_compute_backend_service` ([#6026](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6026)) - compute: added support for `INTERNAL_MANAGED` to the field `load_balancing_scheme` in the resource `google_compute_global_forwarding_rule` ([#6026](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6026)) - compute: added support for `ip_version` to `google_compute_forwarding_rule` ([#6006](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6006)) - container: marked `master_ipv4_cidr_block` as not required when `private_endpoint_subnetwork` is provided for `google_container_cluster` ([#6025](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6025)) - container: added support for `advanced_datapath_observability_config` to `google_container_cluster` ([#6027](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6027)) - eventarc: added field `event_data_content_type` to `google_eventarc_trigger` ([#6032](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6032)) - healthcare: added `send_previous_resource_on_delete` field to `notification_configs` of `google_healthcare_fhir_store` ([#5999](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5999)) - pubsub: added `cloud_storage_config` field to `google_pubsub_subscription` resource ([#6024](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6024)) - secretmanager: added `annotations` field to `google_secret_manager_secret` resource ([#6007](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6007)) - workstations: added `private_cluster_config.allowed_projects` arguments to `google_workstations_workstation_cluster` ([#6021](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6021)) BUG FIXES: - certificatemanager: added recreation behavior to the `google_certificate_manager_certificate` resource when its location changes ([#6031](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6031)) - cloudfunctions2: fixed creation failure state inconsistency in `google_cloudfunctions2_function` ([#6023](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6023)) - monitoring: updated `evaluation_interval` on `condition_prometheus_query_language` to be optional ([#6028](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/6028)) #### 4.77.0 (August 7, 2023) NOTES: - vpcaccess: reverted the ability to update the number of instances for resource `google_vpc_access_connector` ([#5957](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5957)) FEATURES: - **New Resource:** `google_document_ai_warehouse_document_schema` ([#5965](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5965)) - **New Resource:** `google_document_ai_warehouse_location` ([#5965](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5965)) IMPROVEMENTS: - alloydb: added `continuous_backup_config` and `continuous_backup_info` fields to `cluster` resource ([#5996](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5996)) - cloudbuild: removed the validation function for the values of `machine_type` field on the `google_cloudbuild_trigger` resource ([#5985](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5985)) - compute: added future_limit in quota exceeded error details for compute resources. ([#5982](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5982)) - compute: added `enable_strong_affinity` field to `google_compute_region_backend_service` (beta) ([#5962](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5962)) - compute: added `ipv6_endpoint_type` and `ip_version` to `google_compute_address` ([#5986](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5986)) - compute: added `network_interface.ipv6_access_config.external_ipv6_prefix_length` to `google_compute_instance` ([#5986](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5986)) - compute: added `network_interface.ipv6_access_config.name` to `google_compute_instance` ([#5986](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5986)) - compute: added a new type `GLOBAL_MANAGED_PROXY` for the field `purpose` in the resource `google_compute_subnetwork` ([#5981](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5981)) - compute: added protocol type: UNSPECIFIED in `google_compute_backend_service` as per [release note](https://cloud.google.com/load-balancing/docs/release-notes#July\_24\_2023) ([#5967](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5967)) - compute: added `local_ssd_recovery_timeout` field to `google_compute_instance` resource ([#5968](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5968)) - compute: added `local_ssd_recovery_timeout` field to `google_compute_instance_template` resource ([#5968](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5968)) - compute: added `local_ssd_recovery_timeout` field to `google_compute_regional_instance_template` resource ([#5968](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5968)) - compute: made `network_interface.ipv6_access_config.external_ipv6` configurable in `google_compute_instance` ([#5986](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5986)) - container: added `enable_k8s_beta_apis.enabled_apis` field to `google_container_cluster` ([#5961](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5961)) - container: added `node_config.host_maintenance_policy` field to `google_container_cluster` and `google_container_node_pool` ([#5983](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5983)) - container: added `placement_policy.policy_name` field to `google_container_node_pool` resource ([#5994](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5994)) - container: unsuppressed `private_cluster_config` when `master_global_access_config` is set in `google_container_cluster` ([#5995](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5995)) - container: allowed `enabled_private_endpoint` to be settable on creation for PSC-based clusters ([#5989](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5989)) - gkeonprem: added taint on failed resource creation for `google_gkeonprem_bare_metal_admin_cluster` ([#5990](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5990)) - gkeonprem: increased timeout for resources `google_gkeonprem_bare_metal_cluster` and `google_gkeonprem_bare_metal_admin_cluster` ([#5990](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5990)) - identityplayform: added support for `blocking_functions` `quota` and `authorized_domains` in `google_identity_platform_config` ([#5964](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5964)) - monitoring: added update support for `period` in `google_monitoring_uptime_check_config` ([#5959](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5959)) - pubsub: added `no_wrapper` field to `google_pubsub_subscription` resource ([#5972](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5972)) - workstations: added `accelerators` field to `google_workstations_workstation_config` resource ([#5991](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5991)) BUG FIXES: - bigquery: fixed a bug in update support for several fields in `google_bigquery_data_transfer_config` ([#5987](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5987)) - cloudfunctions2: fixed an issue where `google_cloudfunctions2_function.build_config.source.storage_source.generation` created a diff when not set in config ([#5992](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5992)) - firebasedatabase: fixed empty `database_url` output attribute ([#5988](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5988)) - monitoring: fixed an issue in `google_monitoring_monitored_project` where project numbers were not accepted for `name` ([#5955](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5955)) - vpcaccess: reverted new behaviour introduced by resource `google_vpc_access_connector` in `4.75.0`. `min_throughput` and `max_throughput` fields lost their default value, and customers could not make deployment due to that change. ([#5957](https://togithub.com/hashicorp/terraform-provider-google-beta/pull/5957)) #### 4.76.0 (July 31, 2023) FEATURES: - **New Resource:** `google_dataplex_task` ([#5914](https://togitConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate. View repository job log here.