Skip to content

Update Terraform azurerm to v4#137

Open
renovate[bot] wants to merge 1 commit intodevelopfrom
renovate/azurerm-4.x
Open

Update Terraform azurerm to v4#137
renovate[bot] wants to merge 1 commit intodevelopfrom
renovate/azurerm-4.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Nov 11, 2025

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
azurerm (source) required_provider major =3.117.04.69.0

Release Notes

hashicorp/terraform-provider-azurerm (azurerm)

v4.69.0

Compare Source

FEATURES:

  • New List Resource: azurerm_traffic_manager_profile (#​31977)
  • New List Resource: azurerm_web_pubsub (#​32126)
  • New Resource: azurerm_automation_runtime_environment_package (#​32022)
  • New Resource: azurerm_container_app_environment_managed_certificate (#​31137)

ENHANCEMENTS:

  • dependencies: Go - update to 1.25.9 (#​32148)
  • dependencies: kubernetesconfiguration/fluxconfiguration - update to API version 2025-04-01 (#​32080)
  • Data Source: azurerm_kubernetes_cluster_node_pool - export the node_image_version property (#​32108)
  • Data Source: azurerm_storage_account_blob_container_sas - expand permissions block to include new fields (#​32149)
  • Data Source: azurerm_storage_account_sas - expand permissions block to include new fields (#​32149)
  • Data Source: azurerm_storage_share - export the rbac_scope_id property (#​31194)
  • azurerm_bot_channels_registration - add support for the microsoft_app_type, microsoft_app_tenant_id, and microsoft_app_user_assigned_identity_id properties (#​30457)
  • azurerm_cdn_frontdoor_route - the cdn_frontdoor_origin_ids property is now optional, allowing users to use the depends_on meta-argument instead (#​29350)
  • azurerm_cognitive_deployment - the rai_policy_name property is now Optional + Computed as Azure returns a value when not set in the creation request (#​32131)
  • azurerm_container_app - add support for identity_id property in custom_scale_rule block (#​29777)
  • azurerm_key_vault - added object-name max length validation for all key vault entries (keys, secrets, certs, etc) (#​30665)
  • azurerm_kubernetes_cluster_node_pool - export the node_image_version property (#​32108)
  • azurerm_kubernetes_flux_configuration - the git_repository.provider property now supports GitHub (#​32080)
  • azurerm_monitor_scheduled_query_rules_alert_v2 - add support for email_subject within action block (#​32132)
  • azurerm_storage_share - export the rbac_scope_id property (#​31194)

BUG FIXES:

  • azurerm_linux_virtual_machine - parse os_managed_disk_id insensitively as Azure returns static segments cased inconsistently (#​32145)
  • azurerm_private_dns_resolver_inbound_endpoint - the ip_configurations.private_ip_address, ip_configurations.private_ip_allocation_method, and ip_configurations.subnet_id properties are now ForceNew as the API does not allow updating these values (#​31088)

v4.68.0

Compare Source

FEATURES:

  • New Data Source: azurerm_managed_devops_pool (#​28325)
  • New List Resource: azurerm_private_dns_cname_record (#​31833)
  • New Resource: azurerm_data_protection_backup_instance_data_lake_storage (#​32044)
  • New Resource: azurerm_managed_devops_pool (#​28325)

ENHANCEMENTS:

  • dependencies: go-azure-sdk - upgrade to v0.20260407.1111603 (#​32112)
  • Data Source: azurerm_bastion_host - export private_only_enabled (#​32042)
  • Data Source: azurerm_key_vault - improve validation for the name field to prevent apply time errors (#​30453)
  • Data Source: azurerm_mssql_managed_instance - add support for the general_purpose_v2_enabled property (#​29303)
  • azurerm_app_configuration_feature - Add support for custom_filter (#​30160)
  • azurerm_bastion_host - add support for a "Private-only" deployment and export private_only_enabled (#​32042)
  • azurerm_cosmosdb_account - add support for the EnableFabricNetworkAclBypass capability (#​31836)
  • azurerm_key_vault - improve validation for the name field to prevent apply time errors (#​30453)
  • azurerm_kubernetes_cluster - changing oidc_issuer_enabled from true to false now forces resource recreation as the API does not support this (#​32117)
  • azurerm_kubernetes_cluster_node_pool - lock on subnet ID instead of subnet name to prevent unnecessary serialization (#​32001)
  • azurerm_mssql_managed_instance - export the general_purpose_v2_enabled property (#​29303)
  • azurerm_netapp_volume - add support for data_protection_advanced_ransomware (#​32099)
  • azurerm_private_endpoint - the request_message and is_manual_connection properties are now validated at plan time (#​31705)
  • azurerm_storage_account - the is_hns_enabled property is now validated at plan time (#​30536)

BUG FIXES:

  • azurerm_databricks_workspace - fix the update behaviour for the access_connector_id property (#​32025)
  • azurerm_function_app_flex_consumption - add locking on virtual_network_subnet_id to prevent conflicts if the same subnet is used for multiple deployments (#​32091)
  • azurerm_kubernetes_cluster - fix an issue that prevented oidc_issuer_enabled = false from being set on create (#​32117)
  • azurerm_kubernetes_cluster - fix a diff caused by Azure's default value for oidc_issuer_enabled changing in AKS 1.34+ (#​32117)
  • azurerm_public_ip - domain_name_label, reverse_fqdn, domain_name_label_scope can now be set to empty (#​31699)
  • azurerm_resource_group - fix parallelism issue in create_poller (#​32123)
  • azurerm_storage_account - Remove TLS1_3 as a valid value for min_tls_version (#​32072)

v4.67.0

Compare Source

FEATURES:

  • New List Resource: azurerm_storage_sync (#​31995)
  • New Resource: azurerm_data_protection_backup_policy_data_lake_storage (#​31179)
  • New Resource: azurerm_eventgrid_namespace_topic (#​30104)
  • New Resource: azurerm_kubernetes_cluster_deployment_safeguard (#​31670)
  • New Resource: azurerm_resource_provider_feature_registration (#​28303)

ENHANCEMENTS:

  • dependencies: go-azure-sdk - upgrade to v0.20260326.1151219 (#​32047)
  • dependencies: storage - update to API version 2025-06-01 (#​32071)
  • Data Source: azurerm_application_gateway - export the backend, listener, and routing_rule properties (#​30376)
  • Data Source: azurerm_logic_app_standard - export the site_config.ip_restriction_default_action property (#​31816)
  • Data Source: azurerm_mssql_elasticpool - export the high_availability_replica_count property (#​31761)
  • azurerm_application_gateway - add support for the backend, listener, and routing_rule properties (#​30376)
  • azurerm_kubernetes_cluster - add support for the Ubuntu2404 OS SKU (#​32070)
  • azurerm_kubernetes_cluster - improve validation for network_profile.0.advanced_networking (#​31497)
  • azurerm_kubernetes_cluster_node_pool - add support for the Ubuntu2404 OS SKU (#​32070)
  • azurerm_kusto_attached_database_configuration - add support for the database_name_override, database_name_prefix, sharing.functions_to_exclude, and sharing.functions_to_include properties (#​31470)
  • azurerm_logic_app_standard - add support for the site_config.scm_ip_restriction_default_action property (#​32043)
  • azurerm_logic_app_standard - add support for the site_config.ip_restriction_default_action property (#​31816)
  • azurerm_mssql_elasticpool - add support for the high_availability_replica_count property (#​31761)
  • azurerm_nat_gateway - add support for the StandardV2 SKU (#​31197)
  • azurerm_public_ip - add support for the StandardV2 SKU (#​31197)
  • azurerm_public_ip_prefix - add support for the StandardV2 SKU (#​31197)

BUG FIXES:

  • azurerm_backup_policy_vm - fix the Update function to properly set all timestamps when any of backup.time, retention_daily, retention_weekly, retention_montly, or retention_yearly change (#​31969)
  • azurerm_cosmosdb_account - fix an API error caused by backup.interval_in_minutes and backup.retention_in_hours being set to 0 in the API payload when not defined in config (#​32037)
  • azurerm_machine_learning_compute_instance - fix setting node_public_ip_enabled into state (#​31725)
  • azurerm_search_service - mark query_keys.key value as sensitive (#​32053) (#​32053)

v4.66.0

Compare Source

FEATURES:

  • New Data Source: azurerm_container_app_environment_storage (#​32007)
  • New List Resource: azurerm_video_indexer_account (#​31978)

ENHANCEMENTS:

  • dependencies: Go - upgrade to version 1.25.8 (#​31907)
  • azurerm_bastion_host - Upgrade API to 2025-01-01 (#​32030)
  • azurerm_kubernetes_cluster - add support for migration from Azure or Kubenet CNI to Azure CNI Overlay (#​30959)
  • azurerm_search_service: add support for endpoint attribute (#​32010)
  • cognitive_account_rai_blocklist_resource - add support for the tags property (#​31871)

BUG FIXES:

  • azurerm_container_app - fix failure_count_threshold validation values for container app probes (#​31989)
  • azurerm_linux_function_app_slot - fix API error when removing auth_settings_v2 configuration from a previously deployed appservice slot (#​32008)
  • azurerm_linux_web_app_slot - fix API error when removing auth_settings_v2 configuration from a previously deployed appservice slot (#​32008)
  • azurerm_log_analytics_workspace - preserve default value of local_authentication_enabled (#​32004)
  • azurerm_windows_function_app_slot - fix API error when removing auth_settings_v2 configuration from a previously deployed appservice slot (#​32008)
  • azurerm_windows_web_app_slot - fix API error when removing auth_settings_v2 configuration from a previously deployed appservice slot (#​32008)

v4.65.0

Compare Source

ENHANCEMENTS:

  • dependencies: go-azure-sdk - update to v0.20260312.1165223
  • azurerm_federated_identity_credential - the parent_id property has been renamed to user_assigned_identity_id (#​31921)

BUG FIXES:

  • azurerm_kubernetes_cluster_node_pool - max_surge and max_unavailable are no longer required for spot node pools (#​31129)
  • azurerm_log_analytics_workspace_table - fix validation for basic plan (#​30925)
  • azurerm_managed_disk - fix nil pointer dereference when updating disk_access_id (#​31955)

v4.64.0

Compare Source

FEATURES:

ENHANCEMENTS:

  • dependencies: containerservice - partial upgrade to API version 2025-03-01 (#​31838)
  • dependencies: containerservice - partial upgrade to API version 2025-10-01 (#​31401)
  • dependencies: paloalto - update to API version 2025-10-08 (#​31570)
  • Data Source: azurerm_kubernetes_cluster - export the bootstrap_profile and network_profile.outbound_type attributes (#​30983)
  • azurerm_subnet - add support for the PureStorage.Block/storagePools value in the delegation.service_delegation.name property (#​31878)
  • azurerm_virtual_network - add support for the PureStorage.Block/storagePools value in the subnet.delegation.service_delegation.name property (#​31878)

BUG FIXES:

  • azurerm_purview_account - use correct API values for identity type (#​31905) (#​31905)
  • azurerm_recovery_services_vault - skip request to modify soft delete state for vaults that are currently set to AlwaysON due to Azure's new secure-by-default policy
  • azurerm_resource_provider_registration - add additional polling logic to prevent errors due to inconsistent API behaviour (#​31909)

v4.63.0

Compare Source

FEATURES:

  • provider: added the enhanced_validation block with the locations and resource_providers properties to replace the ARM_PROVIDER_ENHANCED_VALIDATION environment variable (#​31678)

ENHANCEMENTS:

  • azurerm_site_recovery_replicated_vm- add support for PremiumV2_LRS in the target_replica_disk_type property (#​31890)

BUG FIXES:

  • azurerm_analysis_services_server - fix an issue that prevented creation of the resource with power_bi_service_enabled set to false and one or more ipv4_firewall_rule blocks defined (#​31870)
  • azurerm_analysis_services_server - fix an issue that prevented adding or removing ipv4_firewall_rule blocks without also modifying power_bi_service_enabled (#​31870)
  • azurerm_linux_web_app, azurerm_windows_web_app, azurerm_windows_function_app, azurerm_linux_function_app, azurerm_function_app_flex_consumption - fix API error when removing auth_settings_v2 configuration from a previously deployed appservice (#​31821) (#​31821)
  • dependencies: dataprotection - downgrade to API version 2025-07-01 due to new validation introduced by Azure on 2025-09-01 that is blocking deployments (#​31877)

v4.62.1

Compare Source

BUG FIXES:

  • azurerm_data_factory - fix removal of customer_managed_key_identity_id to no longer send an empty string to Azure, instead sending an empty object (#​31858)
  • azurerm_data_factory_customer_managed_key - fix a persistent ID parsing error on user_assigned_identity_id when Azure returned an empty string (#​31858)
  • azurerm_data_factory_customer_managed_key - fix removal of user_assigned_identity_id to no longer send an empty string to Azure, instead sending an empty object (#​31858)
  • azurerm_linux_function_app_slot - fix an issue that prevented users from deploying a slot to a container-based function app (#​31842)

v4.62.0

Compare Source

FEATURES:

  • New List Resource: azurerm_network_ddos_protection_plan (#​31768)
  • New List Resource: azurerm_private_dns_a_record (#​31785)
  • New List Resource: azurerm_private_endpoint (#​31769)
  • New List Resource: azurerm_redis_cache (#​31770)
  • New List Resource: azurerm_redis_firewall_rule (#​31770)
  • New List Resource: azurerm_route (#​31760)
  • New List Resource: azurerm_mssql_elasticpool (#​31736)
  • New List Resource: azurerm_mssql_virtual_machine (#​31737)

ENHANCEMENTS:

  • dependencies: databricks - update to API version 2026-01-01 (#​31654)
  • dependencies: dataprotection - update to API version 2025-09-01 (#​31402)
  • azurerm_dashboard_grafana - add support for the 12 value in the grafana_major_version property and remove the deprecated 10 value (#​31653)
  • azurerm_linux_function_app - add support for 25 in the java_version property (#​31096)
  • azurerm_linux_web_app - add support for 3.14 in the python_version property (#​31826)
  • azurerm_linux_web_app - add support for 25 in the java_version property (#​31096)
  • azurerm_linux_web_app_slot - add support for 3.14 in the python_version property (#​31826)
  • azurerm_windows_function_app - add support for 25 in the java_version property (#​31096)
  • azurerm_windows_web_app - add support for 25 in the java_version property (#​31096)

BUG FIXES:

  • azurerm_container_app_job - fix an issue where template.container.startup_probe.initial_delay and template.container.readiness_probe.initial_delay were not set in the API request (#​31796)

v4.61.0

Compare Source

FEATURES:

  • New List Resource: azurerm_application_gateway (#​31749)
  • New List Resource: azurerm_application_security_group (#​31742)
  • New List Resource: azurerm_firewall and azurerm_firewall_policy (#​31734)
  • New List Resource: azurerm_firewall_policy_rule_collection_group (#​31741)
  • New List Resource: azurerm_ip_group (#​31740)
  • New List Resource: azurerm_mssql_database (#​31735)
  • New List Resource: azurerm_mssql_job_agent (#​31738)
  • New List Resource: azurerm_mssql_server (#​31650)
  • New List Resource: azurerm_nat_gatway (#​31764)
  • New List Resource: azurerm_network_security_rule (#​31748)
  • New List Resource: azurerm_public_ip (#​31762)
  • New List Resource: azurerm_web_application_firewall_policy (#​31758)

ENHANCEMENTS:

  • dependencies: go update to 1.25.5
  • dependencies: go-azure-sdk - update to v0.20260212.1143955
  • azurerm_managed_redis - sku_name can now be updated (#​31203)
  • azurerm_managed_redis - default_database must be specified when creating a new resource (#​31724)
  • azurerm_point_to_site_vpn_gateway - connection_configuration.x.internet_security_enabled can now be updated (#​31733)
  • azurerm_security_center_storage_defender - update to API version 2025-06-01 (#​31759)

BUG FIXES:

  • azurerm_managed_redis_geo_replication - fix an issue that prevented linking 3 or more clusters (#​31385)
  • azurerm_signalr_service - fix setting default values into state, preventing diffs on import for connectivity_logs_enabled, http_request_logs_enabled, and messaging_logs_enabled (#​31566)

v4.60.0

Compare Source

FEATURES:

  • New Data Source: azurerm_cognitive_account_project (#​31605)
  • New Data Source: azurerm_managed_redis_access_policy_assignment (#​30980)
  • New Data Source: azurerm_oracle_database_system_versions (#​31001)
  • New Resource: azurerm_api_management_workspace_named_value (#​31299)
  • New List Resource: azurerm_cognitive_account (#​31624)
  • New Resource: azurerm_data_factory_linked_service_sql_managed_instance (#​30896)
  • New Resource: azurerm_managed_redis_access_policy_assignment (#​30980)
  • New List Resource: azurerm_mysql_flexible_database, azurerm_mysql_flexible_server_firewall_rule, azurerm_mysql_flexible_server_configuration - includes addition of Identity (#​31646) (#​31646)
  • New List Resource: azurerm_service_plan (#​31610)

ENHANCEMENTS:

  • dependencies: containerinstance - update to API version 2025-09-01 (#​31640)
  • dependencies: storagemover - update to API version 2025-07-01 (#​31587)
  • Data Source: azurerm_container_app - add support for the read_secrets property allowing users to skip secret retrieval that may trigger authorization errors (#​31199)
  • azurerm_application_gateway - add support for 2.2 to waf_configuration.rule_set_version (#​31674)
  • azurerm_application_gateway - add support for MS-ThreatIntel-XSS to waf_configuration.disabled_rule_group.rule_group_name (#​31674)
  • azurerm_express_route_port - add support for GcmAesXpn128 and GcmAesXpn256 ciphers to link*.macsec_cipher (#​30240)
  • azurerm_postgresql_flexible_server - add support for cluster (#​31315)
  • azurerm_web_application_firewall_policy - add support for 2.2 to managed_rules.managed_rule_set.version and managed_rules.exclusion.excluded_rule_set.version (#​31674)
  • azurerm_web_application_firewall_policy - add support for MS-ThreatIntel-XSS to managed_rules.managed_rule_set.rule_group_override.rule_group_name and managed_rules.exclusion.excluded_rule_set.rule_group.rule_group_name (#​31674)
  • provider: the subscription_id property can now be populated based on the az CLI (#​30251)

BUG FIXES:

  • azurerm_express_route_port - fix an issue that caused identity to be removed when updating unrelated properties (#​30240)
  • azurerm_federated_identity_credential - the id is now built using the resource group name segment from the parent_id preventing unexpected 404 statuses (#​30860)
  • azurerm_kubernetes_cluster - fixed capacity_reservation_group_id loss during node pool cycling (#​30654)
  • azurerm_monitor_aad_diagnostic_setting - add polling as a workaround to an eventual consistency issue (#​31123)
  • list.azurerm_private_dns_zone - fix context handling resolving an issue where this list resources never returned results (#​31719)

v4.59.0

Compare Source

ENHANCEMENTS:

  • dependencies: go-azure-sdk - update to v0.20260129.1200123 (#​31621)
  • azurerm_automation_runbook - add support for the runtime_environment_name property (#​30992)
  • azurerm_kusto_eventgrid_data_connection - update validation for eventhub_consumer_group_name to allow $Default as input (#​31551)
  • azurerm_linux_function_app - add support for 3.14 to site_config.application_stack.python_version (#​31195)
  • azurerm_linux_function_app_slot - add support for 3.14 to site_config.application_stack.python_version (#​31195)
  • azurerm_netapp_volume_group_sap_hana_resource - add support for zone, encryption_key_source, key_vault_private_endpoint_id, and network_features (#​31603)
  • azurerm_user_assigned_identity - add support for the isolation_scope property (#​31216)

BUG FIXES:

  • azurerm_kubernetes_cluster - thenetwork_policy property now allows updating from calico to cilium (#​31627)
  • azurerm_logic_app_trigger_http_request - fix an issue that prevented importing existing resources due to empty trigger inputs (#​31433)
  • azurerm_mssql_database - fix validation for min_capacity and auto_pause_delay_in_minutes (#​31690)

v4.58.0

Compare Source

FEATURES:

  • New Data Source: azurerm_network_security_perimeter (#​31356)
  • New Data Source: azurerm_network_security_perimeter_profile (#​31356)
  • New Resource: azurerm_network_security_perimeter (#​31356)
  • New Resource: azurerm_network_security_perimeter_access_rule (#​31356)
  • New Resource: azurerm_network_security_perimeter_association (#​31356)
  • New Resource: azurerm_network_security_perimeter_profile (#​31356)
  • New List Resource: azurerm_resource_group (#​31270)

ENHANCEMENTS:

  • dependencies: go-azure-sdk - update to v0.20251219.1184026 (#​31397)
  • azurerm_backup_policy_file_share - add support for backup_tier and snapshot_retention_in_days (#​29243)
  • azurerm_cosmosdb_cassandra_cluster - version now supports 4.1 and 5.0 (#​31424)
  • azurerm_function_app_flex_consumption - the maximum_instance_count property now allows values from 1 - 1000 (#​31392)
  • azurerm_kubernetes_cluster - network_data_plane and network_policy now support updating to cilium (#​30958)
  • azurerm_kusto_eventhub_data_connection - add support for retrieval_start_date (#​31445)
  • azurerm_kusto_iothub_data_connection - add support for retrieval_start_date (#​31413)
  • azurerm_kusto_script - add support for script_level and principal_permissions_action (#​31403)
  • azurerm_linux_function_app - add support for 24 to site_config.application_stack.node_version (#​31098)
  • azurerm_linux_function_app_slot - add support for 24 to site_config.application_stack.node_version (#​31098)
  • azurerm_linux_web_app - add support for 24-lts to site_config.application_stack.node_version (#​31098)
  • azurerm_linux_web_app_slot - add support for 24-lts to site_config.application_stack.node_version (#​31098)
  • azurerm_mssql_managed_instance - increase storage_size_in_gb maximum to 32768 (#​31387)
  • azurerm_netapp_volume_group_oracle - service_level now supports Flexible (#​31508)
  • azurerm_netapp_volume_group_sap_hana - service_level now supports Flexible (#​31508)
  • azurerm_network_manager_routing_configuration - add support for the route_table_usage_mode property (#​31463)
  • azurerm_windows_function_app - add support for ~24 to site_config.application_stack.node_version (#​31248)
  • azurerm_windows_function_app_slot - add support for ~24 to site_config.application_stack.node_version (#​31248)
  • data.azurerm_container_registry - admin_password is now sensitive (#​31428)

BUG FIXES:

  • azurerm_api_management - fix an issue that prevented updates to hostname_configuration.*.key_vault_certificate_id (#​31534)
  • azurerm_api_management_custom_domain - fix an issue that prevented updates to [management|portal|developer_portal|scm|gateway].key_vault_certificate_id (#​31534)
  • azurerm_container_app_custom_domain - no longer error during read when container app is deleted outside of Terraform (#​31523)
  • azurerm_databricks_workspace - removed a legacy workaround that prevented apply operations from succeeding when managed_disk_cmk_rotation_to_latest_version_enabled and tags were updated simultaneously (#​31509)
  • azurerm_storage_account - can now update a Storage Standard ZRS account (#​31431)
  • clients - fix correlation id across many clients (#​31368)

v4.57.0

Compare Source

NOTE: This release removes the Mobile Network (azurerm_mobile_network*) resources and data sources due to Azure having retired the service

FEATURES:

  • New Resource: azurerm_automation_runtime_environment (#​30991)

ENHANCEMENTS:

  • azurerm_data_protection_backup_vault_customer_managed_key - the key_vault_key_id property now supports keys from a Managed HSM vault (#​31365)
  • azurerm_kubernetes_cluster - support for the node_provisioning_profile block (#​30517)
  • azurerm_log_analytics_cluster_customer_managed_key - the key_vault_key_id property now supports keys from a Managed HSM vault (#​31375)
  • azurerm_mssql_database - the transparent_data_encryption_key_vault_key_id property now supports keys from a Managed HSM vault (#​31373)

BUG FIXES:

  • azurerm_data_factory - fix ID parsing errors when customer_managed_key_identity_id is an empty string (#​28621)
  • azurerm_eventhub - partition_count can now be updated for dedicated clusters (#​30993)
  • azurerm_linux_function_app - fix panic when deployed without all required permissions (#​31344)

v4.56.0

Compare Source

ENHANCEMENTS:

  • dependencies: healthbot - update to API version 2025-05-25 (#​31328)
  • dependencies: terraform-plugin-testing - update to v1.14.0 (#​31334)
  • Data Source: azurerm_cognitive_account - add support for new attributes (#​30778)
  • azurerm_cognitive_account - add support for the kind property to rollback or upgrade from OpenAI to AIServices (#​31063)
  • azurerm_databricks_workspace_root_dbfs_customer_managed_key - the key_vault_key_id property now supports keys from Managed HSM Vaults (#​31336)
  • azurerm_databricks_workspace_root_dbfs_customer_managed_key - the key_vault_key_id property now supports versionless keys (#​31336)
  • azurerm_healthbot - add support for the C1 and PES SKUs (#​31328)
  • azurerm_lb fix ignore_changes behaviour in updatable properties (#​31318)
  • azurerm_network_manager_network_group - add support for the member_type property [GH-30672
  • azurerm_network_manager_static_member - add support for using a subnet as the target resource (#​30672)
  • azurerm_virtual_network_gateway - add support for the ErGwScale SKU (#​31082)

BUG FIXES:

  • azurerm_container_app_environment_certificate - fix an issue that prevented creating the resource with an empty value for certificate_password (#​31335)
  • azurerm_databricks_workspace_root_dbfs_customer_managed_key - fix a panic that occurred when the customer managed key was removed from the workspace outside of Terraform (#​31336)
  • azurerm_databricks_workspace_root_dbfs_customer_managed_key - fix the timeout for the delete operation (#​31336)
  • azurerm_storage_blob_inventory_policy - fix setting Resource Identity data (#​31313)

v4.55.0

Compare Source

FEATURES:

  • New Data Source: azurerm_api_management_workspace (#​30241)
  • New Resource: azurerm_cognitive_account_project (#​30916)
  • New Resource: azurerm_log_analytics_workspace_table_custom_log (#​30800)
  • New Resource: azurerm_mongo_cluster_user (#​31205)
  • New Resource: azurerm_palo_alto_next_generation_firewall_virtual_hub_strata_cloud_manager (#​30613)
  • New Resource: azurerm_palo_alto_next_generation_firewall_virtual_network_strata_cloud_manager (#​30613)
  • New List Resource: azurerm_private_dns_zone (#​31157)

ENHANCEMENTS:

  • dependencies: containerregistry - update to API version 2025-04-01 (#​30205)
  • dependencies: go-azure-helpers - update to v0.75.1 (#​31148)
  • dependencies: go-azure-sdk - update to v0.20251202.1181053 (#​31253)
  • dependencies: managedidentity - upgrade API version to 2024-11-30 (#​30535)
  • dependencies: postgres - update to API version 2025-08-01 (#​31162)
  • azurerm_cognitive_account - update validation for customer_managed_key.key_vault_key_id to allow managed HSM keys as input (#​31147)
  • azurerm_container_app_environment - extend validation for workload_profile_type for additional supported SKUs (#​30738)
  • azurerm_container_app_environment_certificate - add support for the certificate_key_vault block (#​30510)
  • azurerm_data_factory - update validation for customer_managed_key_id to allow managed HSM keys as input (#​31146)
  • azurerm_mongo_cluster - support for new properties customer_managed_key, data_api_mode_enabled, identity, restore, authentication_methods and storage_type (#​31100)
  • azurerm_mysql_flexible_server - add support for MySQL version 8.4 (#​31099)
  • azurerm_oracle_autonomous_database - the admin_password property is no longer ForceNew (#​30966)
  • azurerm_postgresql_flexible_server - update validation for customer_managed_key.key_vault_key_id and customer_managed_key.geo_backup_key_vault_key_id to allow managed HSM keys as input (#​31148)
  • azurerm_postgresql_flexible_server - add support for PostgreSQL version 18 (#​31162)
  • azurerm_storage_encryption_scope - update validation for key_vault_key_id to allow managed HSM keys as input (#​31145)

BUG FIXES:

  • Data Source: azurerm_ssh_public_key - fix normalisation for public_key to avoid removing a literal EOT from the base64 encoded content (#​31249)
  • azurerm_data_protection_backup_vault - poll delete request for completion (#​31202)
  • azurerm_function_app_hybrid_connection - remove validation preventing resource import when using an elastic service plan SKU (#​31134)
  • azurerm_key_vault_key - not_before_date and expiration_date are now set into state when empty, fixing an issue where drift was not detected (#​31192)
  • azurerm_key_vault_secret - not_before_date and expiration_date are now set into state when empty, fixing an issue where drift was not detected (#​31192)
  • azurerm_kubernetes_cluster - fix drift on azure_policy_enabled when updating cluster (#​30917)
  • azurerm_kubernetes_fleet_update_run - fix a nil pointer dereference to prevent panics (#​31213)
  • azurerm_lb_nat_rule - fix an issue that prevented changing floating_ip_enabled and tcp_reset_enabled from true to false (#​31244)
  • azurerm_lb_outbound_rule - fix an issue that prevented changing tcp_reset_enabled from true to false (#​31244)
  • azurerm_lb_rule - fix an issue that prevent

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot force-pushed the renovate/azurerm-4.x branch 2 times, most recently from b8dd116 to bcfc34f Compare November 19, 2025 23:42
@renovate renovate Bot force-pushed the renovate/azurerm-4.x branch from bcfc34f to 25042fd Compare November 26, 2025 10:51
@renovate renovate Bot force-pushed the renovate/azurerm-4.x branch 2 times, most recently from ee36aa8 to 4078195 Compare December 12, 2025 07:21
@renovate renovate Bot force-pushed the renovate/azurerm-4.x branch from 4078195 to d38a068 Compare December 19, 2025 07:36
@renovate renovate Bot force-pushed the renovate/azurerm-4.x branch from d38a068 to 2552471 Compare January 23, 2026 08:52
@renovate renovate Bot force-pushed the renovate/azurerm-4.x branch 2 times, most recently from b03bd87 to a09a0ac Compare February 7, 2026 04:00
@renovate renovate Bot force-pushed the renovate/azurerm-4.x branch from a09a0ac to 0acaf77 Compare February 13, 2026 07:57
@renovate renovate Bot force-pushed the renovate/azurerm-4.x branch 2 times, most recently from 3a7acb6 to 0edacba Compare February 27, 2026 09:35
@renovate renovate Bot force-pushed the renovate/azurerm-4.x branch 3 times, most recently from 5b56ecf to b7e1595 Compare March 6, 2026 08:52
@renovate renovate Bot force-pushed the renovate/azurerm-4.x branch 2 times, most recently from 9f4f400 to b67ec06 Compare March 20, 2026 08:15
@renovate renovate Bot force-pushed the renovate/azurerm-4.x branch 2 times, most recently from 2d6f388 to 9ab0717 Compare April 5, 2026 07:13
@renovate renovate Bot changed the title chore(deps): update terraform azurerm to v4 Update Terraform azurerm to v4 Apr 8, 2026
@renovate renovate Bot force-pushed the renovate/azurerm-4.x branch from 9ab0717 to 7314f24 Compare April 15, 2026 18:33
@renovate renovate Bot force-pushed the renovate/azurerm-4.x branch from 7314f24 to 198aa8b Compare April 17, 2026 11:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants