UNCLASSIFIED - NO CUI

Skip to content

hgj

Cody Williams requested to merge renovate/major-github into main

This MR contains the following updates:

Package Type Update Change
cypress/included final major 9.7.0 -> 13.1.0
terraform-aws-modules/iam/aws (source) module major 4.7.0 -> 5.30.0

Release Notes

terraform-aws-modules/terraform-aws-iam

v5.30.0

Compare Source

Features
  • Add create_custom_role_trust_policy to control when a custom_role_trust_policy should be used (#​321) (481095e)
5.29.2 (2023-08-30)
Bug Fixes
  • Expand Permissions for external-secrets IRSA Policy towards AWS Secrets Manager (#​416) (fa74a18)
5.29.1 (2023-08-30)
Bug Fixes
  • Add missing condition role_session_name when assuming a role (#​418) (89d011e)

v5.29.2

Compare Source

v5.29.1

Compare Source

v5.29.0

Compare Source

Features
  • Add variable for adding statement for secretsmanager:CreateSecret (#​414) (24996cd)

v5.28.0

Compare Source

Features
  • Added direct policy attachment in iam-user module (#​387) (9fa481f)

v5.27.0

Compare Source

Features

v5.26.0

Compare Source

Features

v5.25.0

Compare Source

Features
  • Added variable load_balancer_controller_targetgroup_arns in iam-role-for-service-accounts-eks module (#​402) (61a5dbe)

v5.24.0

Compare Source

Features
5.23.1 (2023-06-29)
Bug Fixes

v5.23.1

Compare Source

v5.23.0

Compare Source

Features
  • Added variable trusted_role_actions to sub modules as a "Action of STS" (#​393) (5702679)

v5.22.0

Compare Source

Features

v5.21.0

Compare Source

Features
  • Added permissions to list zone tags in iam-role-for-service-accounts-eks module (#​394) (740945f)

v5.20.0

Compare Source

Features
  • Add support for AWS Gateway controller (VPC Lattice) to IRSA module (#​378) (fdee003)

v5.19.0

Compare Source

Features
  • Add support for condition role_session_name when assuming a role (#​379) (5aabe67)

v5.18.0

Compare Source

Features
  • iam-eks-role: Add variable to allow change of IAM assume role condition test operator (#​367) (542fc5a)
5.17.1 (2023-05-05)
Bug Fixes
  • Remove "autoscaling:UpdateAutoScalingGroup" permission from cluster-autoscaler IRSA (#​357) (aeb5d7f)

v5.17.1

Compare Source

v5.17.0

Compare Source

Features
  • Add name_prefix to iam-policy and iam-read-only-policy modules (#​369) (5bf5f6f)

v5.16.0

Compare Source

Features
  • Add elasticloadbalancing:AddTags permissions to AWS Load Balancer Controller policy required for version 2.4.7+ (#​358) (e1403c1)

v5.15.0

Compare Source

Features
  • Add permissions for instance requirements support for cluster autoscaler IRSA policy (#​356) (fac0cdc)
5.14.4 (2023-03-24)
Bug Fixes
5.14.3 (2023-03-23)
Bug Fixes
  • Do not attach force MFA statement for iam-groups-with-policies by default (#​333) (b9f3409)
5.14.2 (2023-03-21)
Bug Fixes
  • Add ssm:DescribeParameters permission to external-secrets IAM role for service account (IRSA) (#​348) (fe8d73b)
5.14.1 (2023-03-21)
Bug Fixes
  • Update self manage policy to support users with path (#​335) (9a8d5cb)

v5.14.4

Compare Source

v5.14.3

Compare Source

v5.14.2

Compare Source

v5.14.1

Compare Source

v5.14.0

Compare Source

Features
  • Update efs_csi policy to support resource tagging (#​352) (47cb7a2)

v5.13.0

Compare Source

Features
  • Add support for path in iam-group-with-assumable-roles-policy (#​345) (761368e)

v5.12.0

Compare Source

Features
  • Add eks:DescribeCluster for Karpenter cluster endpoint auto discovery (#​343) (3f2cdc8)
5.11.2 (2023-02-15)
Bug Fixes
5.11.1 (2023-01-19)
Bug Fixes

v5.11.2

Compare Source

v5.11.1

Compare Source

v5.11.0

Compare Source

Features
  • Allow multiple MFA devices and users to manage MFA devices (#​313) (57a5d70)

v5.10.0

Compare Source

Features
  • Added Extra STS actions param in assumable role with SAML (#​317) (a2ad4cd)
Bug Fixes
  • Use a version for to avoid GitHub API rate limiting on CI workflows (#​323) (90349fa)
5.9.2 (2022-12-10)
Bug Fixes
5.9.1 (2022-12-07)
Bug Fixes
  • Add ssm:GetParameters permission to external-secrets policy (#​316) (0e77849)

v5.9.2

Compare Source

v5.9.1

Compare Source

v5.9.0

Compare Source

Features

v5.8.0

Compare Source

Features
  • Add additional permissions to Karpenter EKS IRSA role for native node termination handling support (#​304) (d6865d2)

v5.7.0

Compare Source

Features
  • Ensure that GitHub OIDC subject prefixes are normalied for repo: (#​310) (b9873a0)

v5.6.0

Compare Source

Features
  • Add support for creating IAM GitHub OIDC provider and role(s) (#​308) (cc44693)
5.5.7 (2022-11-09)
Bug Fixes
  • Add secretsmanager:ListSecrets to external-secrets policy (#​305) (d3fb017)
5.5.6 (2022-11-07)
Bug Fixes
  • Update CI configuration files to use latest version (#​302) (4c1c958)
5.5.5 (2022-11-01)
Bug Fixes
5.5.4 (2022-10-26)
Bug Fixes
  • Insufficient permissions for karpenter policy when not using karpenter discovery tags on security group (#​294) (5ad496b)
5.5.3 (2022-10-26)
Bug Fixes
  • Correct tflint errors for latest version of tflint (#​296) (b40ade4)
5.5.2 (2022-10-13)
Bug Fixes
  • Explicitly assume with condition matching role arn (#​283) (470b6ff)
5.5.1 (2022-10-12)
Bug Fixes

v5.5.7

Compare Source

v5.5.6

Compare Source

v5.5.5

Compare Source

v5.5.4

Compare Source

v5.5.3

Compare Source

v5.5.2

Compare Source

v5.5.1

Compare Source

v5.5.0

Compare Source

Features
  • Add support for roles created to explicitly assume their own role if desired (#​281) (3d29d26)

v5.4.0

Compare Source

Features
  • Add support for spot request permissions with Karpenter IRSA role (#​277) (b3b99d9)
5.3.3 (2022-09-06)
Bug Fixes
  • Fixed iam-user module when encrypted_ses_smtp_password_v4 is null (#​275) (936d0f1)
5.3.2 (2022-09-05)
Bug Fixes
5.3.1 (2022-08-25)
Bug Fixes
  • Don't force users to reset passwords in modules/iam-user (#​271) (358f7d4)

v5.3.3

Compare Source

v5.3.2

Compare Source

v5.3.1

Compare Source

v5.3.0

Compare Source

Features
  • Add additional permission for karpenter IAM policy added in v0.14.0 release (#​264) (bce17b2)

v5.2.0

Compare Source

Features
  • Add additional Karpenter permissions for spot pricing improvements (#​258) (14cc1df)

v5.1.0

Compare Source

Features
  • Update cluster autoscaler policy for recent permission changes upstream (#​255) (2f1b2bf)

v5.0.0

Compare Source

BREAKING CHANGES
  • Replace use of toset() for policy attachment, bump min version of AWS provider to 4.0 and Terraform to 1.0 (#​250)
Features
  • Replace use of toset() for policy attachment, bump min version of AWS provider to 4.0 and Terraform to 1.0 (#​250) (835135b)
4.24.1 (2022-05-10)
Bug Fixes
  • Avoid restricting Karpenter RunInstances subnets by tag key (#​247) (bbbe0c0)

v4.24.1

Compare Source

v4.24.0

Compare Source

Features

v4.23.0

Compare Source

Features
  • Improved iam-eks-role module (simplified, removed provider_url_sa_pairs, updated docs) (#​236) (d014730)
4.22.1 (2022-04-25)
Bug Fixes

v4.22.1

Compare Source

v4.22.0

Compare Source

Features
4.21.1 (2022-04-22)
Bug Fixes
  • Correct aws arn partition for service account eks (#​235) (e51b6c3)

v4.21.1

Compare Source

v4.21.0

Compare Source

Features
  • Added appmesh controller support to iam-role-for-service-accounts-eks (#​231) (0492955)
4.20.3 (2022-04-20)
Bug Fixes
  • Correct policy attachment to cert_manager in example (#​234) (6a28193)
4.20.2 (2022-04-19)
Bug Fixes
4.20.1 (2022-04-15)
Bug Fixes
  • Fixed example where VPC CNI permissions should apply to the aws-node account (#​225) (1fb1cfc)

v4.20.3

Compare Source

v4.20.2

Compare Source

v4.20.1

Compare Source

v4.20.0

Compare Source

Features
  • Add support for AMP, cert-manager, and external-secrets to iam-role-for-service-accounts-eks (#​223) (f53d409)

v4.19.0

Compare Source

Features
  • Add variable to allow changing tag condition on Karpenter iam-role-for-service-accounts-eks policy (#​218) (3d7ea33)

v4.18.0

Compare Source

Features
  • Add support for EFS CSI driver to iam-role-for-service-accounts-eks (#​215) (5afe63f)
4.17.2 (2022-03-31)
Bug Fixes
  • Fixed output of iam_user_login_profile_password in iam-user submodule (#​214) (932a7d8)
4.17.1 (2022-03-29)
Bug Fixes
  • Backwards compatibility in 4.x.x series in iam-user submodule (#​212) (2c57668)

v4.17.2

Compare Source

v4.17.1

Compare Source

v4.17.0

Compare Source

Features

v4.16.0

Compare Source

Features
  • Add load_balancer_controller targetgroup binding only role (#​199) (e00526e)
4.15.1 (2022-03-23)
Bug Fixes
  • Permit RunInstances permission for Karpenter when request contains karpenter.sh/discovery tag key (#​209) (18081d1)

v4.15.1

Compare Source

v4.15.0

Compare Source

Features
  • Made it clear that we stand with Ukraine (8e2b836)
Bug Fixes
  • Policy generation when ebs_csi_kms_cmk_ids is set (#​203) (e2b4054)

v4.14.0

Compare Source

Features
  • Add variable to change IAM condition test operator to suite; defaults to StringEquals (#​201) (8469c03)
4.13.2 (2022-03-02)
Bug Fixes
4.13.1 (2022-02-18)
Bug Fixes
  • Correct permission on AWS load balancer controller (#​191) (a912557)

v4.13.2

Compare Source

v4.13.1

Compare Source

v4.13.0

Compare Source

Features
  • Add new addon policy for AWS load balancer controller to IRSA role (#​189) (e2ce5c9)

v4.12.0

Compare Source

Features
  • Add conditional policy statement attachments for EKS IAM role module (#​184) (e29b94f)

v4.11.0

Compare Source

Features
  • Include cost explorer to default console services in iam-read-only-policy module (#​186) (e701139)
4.10.1 (2022-01-21)
Bug Fixes

v4.10.1

Compare Source

v4.10.0

Compare Source

Features
  • Allow setting custom trust policy in iam-assumable-role (#​176) (095cb29)

v4.9.0

Compare Source

Features

v4.8.0

Compare Source

Bug Fixes
  • update CI/CD process to enable auto-release workflow (#​175) (9278e6f)
Features

v4.7.0 - 2021-10-14

  • feat: Added support for trusted_role_actions for MFA in iam-assumable-role (#​171)

v4.6.0 - 2021-09-20

  • feat: Added output group_arn to iam-group-with-policies (#​165)

v4.5.0 - 2021-09-16

  • feat: Added id of iam assumable role to outputs (#​164)

v4.4.0 - 2021-09-10

  • feat: Add ability for controlling whether or not to create a policy (#​163)
  • docs: Update version constraints (#​162)

v4.3.0 - 2021-08-18

  • feat: Add support for cross account access in iam-assumable-role-with-oidc (#​158)

v4.2.0 - 2021-06-29

  • feat: Support External ID with MFA in iam-assumable-role (#​159)

v4.1.0 - 2021-05-03

  • feat: Add support tags to additional IAM modules (#​144)
  • chore: update CI/CD to use stable terraform-docs release artifact and discoverable Apache2.0 license (#​151)

v4.0.0 - 2021-04-26

  • feat: Shorten outputs (removing this_) (#​150)

v3.16.0 - 2021-04-20

  • feat: Add iam role unique_id to outputs (#​149)

v3.15.0 - 2021-04-15

  • fix: Set sensitive=true for sensitive outputs and use tolist() (#​148)

v3.14.0 - 2021-04-07

  • feat: Add role unique_id output in iam-assumable-role module (#​143)
  • chore: update documentation and pin terraform_docs version to avoid future changes (#​142)

v3.13.0 - 2021-03-11

  • feat: Allows multiple STS External IDs to be provided to an assumable role (#​138)

v3.12.0 - 2021-03-05

  • feat: Add iam-assumable-role-with-saml module (#​127)

v3.11.0 - 2021-03-04

  • fix: handle unencrypted secrets (#​139)
  • chore: update ci-cd workflow to allow for pulling min version from each directory (#​137)

v3.10.0 - 2021-03-01

  • fix: Update syntax for Terraform 0.15 (#​135)
  • chore: Run pre-commit terraform_docs hook (#​133)
  • chore: add ci-cd workflow for pre-commit checks (#​132)

v3.9.0 - 2021-02-20

  • chore: update documentation based on latest terraform-docs which includes module and resource sections (#​131)

v3.8.0 - 2021-01-29

  • feat: Add arn of created group(s) to outputs (#​128)

v3.7.0 - 2021-01-14

  • fix: Multiple provider_urls not working with iam-assumable-role-with-oidc (#​115)

v3.6.0 - 2020-12-04

  • feat: Fixed number of policies everywhere (#​121)

v3.5.0 - 2020-12-04

  • fix: automatically determine the number of role policy arns (#​119)

v3.4.0 - 2020-11-13

  • feat: iam-assumable-roles-with-saml - Allow for multiple provider ids (#​110)

v3.3.0 - 2020-11-02

  • ci: Updated pre-commit hooks, added terraform_validate (#​106)

v3.2.0 - 2020-10-30

  • docs: Updated examples in README (#​105)

v3.1.0 - 2020-10-30

  • Bump new major release v3

v3.0.0 - 2020-10-30

  • feat: Added number_of_ variables for iam-assumable-role submodules (#​96)

v2.25.0 - 2020-10-30

  • fix: remove empty string elements from local.urls in iam-assumable-role-with-oidc submodule (#​99)

v2.24.0 - 2020-10-30

  • feat: Add role_name_prefix option for oidc roles (#​101)

v2.23.0 - 2020-10-30

  • feat: Updated to support Terraform 0.13 also (#​103)
  • ci: Update pre-commit-terraform (#​100)

v2.22.0 - 2020-10-16

  • feat: Add role description variable for assumable role with oidc (#​98)

v2.21.0 - 2020-09-22

  • fix: Fixed ses_smtp_password_v4 output name

v2.20.0 - 2020-09-08

  • fix: simplify count statements (#​93)

v2.19.0 - 2020-09-08

  • fix: Allow running on custom AWS partition (incl. govcloud) (#​94)

v2.18.0 - 2020-08-18

  • feat: modules/iam-assumable-role-with-oidc: Support multiple provider URLs (#​91)

v2.17.0 - 2020-08-17

v2.16.0 - 2020-08-17

  • fix: Allow modules/iam-assumable-role-with-oidc to work in govcloud (#​83)

v2.15.0 - 2020-08-17

  • feat: Added support for sts:ExternalId in modules/iam-assumable-role (#​90)

v2.14.0 - 2020-08-13

  • fix: Delete DEMRECATED ses_smtp_password in iam-user. (#​88)

v2.13.0 - 2020-08-13

  • feat: Support for Terraform v0.13 and AWS provider v3 (#​87)
  • docs: Updated example in README (#​52)

v2.12.0 - 2020-06-10

  • Updated formatting
  • fix: Fix conditions with multiple subjects in assume role with oidc policy (#​74)

v2.11.0 - 2020-06-10

  • feat: Allow to set force_detach_policies on roles (#​68)

v2.10.0 - 2020-05-26

  • fix: Allow customisation of trusted_role_actions in iam-assumable-role module (#​76)

v2.9.0 - 2020-04-23

  • feat: modules/iam-user - Output SMTP password generated with SigV4 algorithm (#​70)

v2.8.0 - 2020-04-22

  • docs: Add note about pgp_key when create_iam_login_profile is set (#​69)
  • fix: Fix module source and name in README (#​65)
  • fix typo (#​62)

v2.7.0 - 2020-02-22

  • Updated pre-commit-terraform with README
  • Add instance profile to role sub-module (#​46)

v2.6.0 - 2020-01-27

  • Rename module from "-iodc" to "-oidc" (#​48)

v2.5.0 - 2020-01-27

  • New sub-module for IAM assumable role with OIDC (#​37)

v2.4.0 - 2020-01-09

  • Updated pre-commit hooks
  • iam-assumable-role: add description support (#​45)
  • Removed link to missing complete example (fixed #​34)

v2.3.0 - 2019-08-21

  • Added description support for custom group policies using a lookup (#​33)

v2.2.0 - 2019-08-21

  • Added trusted_role_services to iam-assumable-roles, autoupdated docs
  • Add Trusted Services to iam-assumable-role (#​31)
  • Fix link to iam-assumable-role example in README (#​35)

v2.1.0 - 2019-06-11

  • Removed duplicated tags from variables in iam-user (#​30)

v2.0.0 - 2019-06-11

  • Upgraded module to support Terraform 0.12 (#​29)

v1.0.0 - 2019-06-11

  • Fixed styles after #​26
  • iam-user,iam-assumable-role,iam-assumable-roles,iam-assumable-roles-with-saml tags support (#​26)

v0.5.0 - 2019-05-15

  • Added support for list of policies to attach to roles (#​25)

v0.4.0 - 2019-03-16

  • Minor adjustments
  • assumable roles for Users with SAML Identity Provider (#​19)

v0.3.0 - 2019-02-20

  • Added iam-group-with-policies and iam-group-complete

v0.2.0 - 2019-02-19

  • Added iam-group-with-assumable-roles-policy and iam-assumable-role (#​18)

v0.1.0 - 2019-02-19

  • Updated examples for iam-policy and formatting
  • Added iam policy (#​15)
  • Permission boundary (#​16)

v0.0.7 - 2018-08-19

  • Follow-up after #​12, added possibility to upload IAM SSH public keys
  • Ssh key support (#​12)
  • fix descriptions of variables (#​10)

v0.0.6 - 2018-05-28

  • Custom Session Duration (#​9)

v0.0.5 - 2018-05-16

  • Added pre-commit hook to autogenerate terraform-docs
  • Implement conditional logic for role creation (#​7)

v0.0.4 - 2018-03-01

  • Add max_password_age for password policy (#​5)

v0.0.3 - 2018-02-28

  • Added iam-user module (#​4)

v0.0.2 - 2018-02-12

  • Added iam-assumable-roles (#​2)
  • Added iam-account (#​1)

v0.0.1 - 2018-02-05

  • Do pre-commit run on all code
  • Added iam-account
  • Initial commit

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This MR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this MR, check this box

This MR has been generated by Renovate Bot.

Merge request reports