Skip to content

chore(deps): bump the all-updates group across 1 directory with 2 updates - #753

Merged
frasermolyneux merged 3 commits into
mainfrom
dependabot/terraform/terraform/all-updates-b1df775457
Aug 31, 2026
Merged

frasermolyneux merged 3 commits into
mainfrom
dependabot/terraform/terraform/all-updates-b1df775457

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 30, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on hashicorp/azurerm and hashicorp/google to permit the latest version.
Updates hashicorp/azurerm to 5.2.0

Release notes

Sourced from hashicorp/azurerm's releases.

v5.2.0

5.2.0 (August 20, 2026)

FEATURES:

  • New List Resource: azurerm_user_assigned_identity (#32667)

ENHANCEMENTS:

  • dependencies: go - update to 1.26.6 (#33141)
  • dependencies: go-azure-sdk - update to v0.20260811.1225050 (#33079)
  • azurerm_cdn_frontdoor_batch_rule_set - allow / as an input to rule.conditions.request_path.values (#33023)
  • azurerm_databricks_workspace - remove a redundant key vault existence check (#33136)
  • azurerm_databricks_workspace_root_dbfs_customer_managed_key - remove a redundant key vault existence check (#33136)
  • azurerm_logic_app_standard - add support for v10.0 to site_config.dotnet_framework_version (#33116)
  • azurerm_mongo_cluster - administrator_password is no longer required when create_mode is Default to support Entra ID-only authentication (#32092)
  • azurerm_redhat_openshift_cluster - add support for the network_profile.load_balancer_profile block (#32473)
  • azurerm_redhat_openshift_cluster - add support for the platform_workload_identity_profile block (#32473)
  • azurerm_role_assignment - the condition, condition_version, and description properties can now be updated in-place (#32714)
  • azurerm_snapshot - create_option now supports CopyStart (#32834)

BUG FIXES:

  • azurerm_cognitive_account_project - added create/update/delete lock on parent AccountID to make sure operations on parent account are processed in serial (required by Cognitive service) (#33151)
  • azurerm_databricks_workspace - fix a persistent diff on removal of managed_disk_cmk_key_vault_key_id or managed_services_cmk_key_vault_key_id (#33136)
  • azurerm_oracle_exadata_infrastructure - fix an issue that prevented users from deploying with no zones set (#33011)
Changelog

Sourced from hashicorp/azurerm's changelog.

5.2.0 (August 20, 2026)

FEATURES:

  • New List Resource: azurerm_user_assigned_identity (#32667)

ENHANCEMENTS:

  • dependencies: go - update to 1.26.6 (#33141)
  • dependencies: go-azure-sdk - update to v0.20260811.1225050 (#33079)
  • azurerm_cdn_frontdoor_batch_rule_set - allow / as an input to rule.conditions.request_path.values (#33023)
  • azurerm_databricks_workspace - remove a redundant key vault existence check (#33136)
  • azurerm_databricks_workspace_root_dbfs_customer_managed_key - remove a redundant key vault existence check (#33136)
  • azurerm_logic_app_standard - add support for v10.0 to site_config.dotnet_framework_version (#33116)
  • azurerm_mongo_cluster - administrator_password is no longer required when create_mode is Default to support Entra ID-only authentication (#32092)
  • azurerm_redhat_openshift_cluster - add support for the network_profile.load_balancer_profile block (#32473)
  • azurerm_redhat_openshift_cluster - add support for the platform_workload_identity_profile block (#32473)
  • azurerm_role_assignment - the condition, condition_version, and description properties can now be updated in-place (#32714)
  • azurerm_snapshot - create_option now supports CopyStart (#32834)

BUG FIXES:

  • azurerm_cognitive_account_project - added create/update/delete lock on parent AccountID to make sure operations on parent account are processed in serial (required by Cognitive service) (#33151)
  • azurerm_databricks_workspace - fix a persistent diff on removal of managed_disk_cmk_key_vault_key_id or managed_services_cmk_key_vault_key_id (#33136)
  • azurerm_oracle_exadata_infrastructure - fix an issue that prevented users from deploying with no zones set (#33011)

5.1.0 (August 13, 2026)

ENHANCEMENTS:

  • dependencies: azurerm_linux_virtual_machine_scale_set - update to API version 2025-04-01 (#31586)
  • dependencies: azurerm_orchestrated_virtual_machine_scale_set - update to API version 2025-04-01 (#31586)
  • dependencies: azurerm_virtual_machine_scale_set - update to API version 2025-04-01 (#31586)
  • dependencies: azurerm_virtual_machine_scale_set_extension - update to API version 2025-04-01 (#31586)
  • dependencies: azurerm_windows_virtual_machine_scale_set - update to API version 2025-04-01 (#31586)
  • dependencies: codesigning - update to API version 2025-10-13 (#31714)
  • azurerm_linux_virtual_machine - encryption_at_host_enabled can now be set to true when os_disk.security_encryption_type is set to DiskWithVMGuestState (#32885)
  • azurerm_linux_virtual_machine_scale_set - encryption_at_host_enabled can now be set to true when os_disk.security_encryption_type is set to DiskWithVMGuestState (#32885)
  • azurerm_managed_devops_pool - add support for the CreatorOnly value to azure_devops_organization.permission.kind property (#32753)
  • azurerm_windows_virtual_machine - encryption_at_host_enabled can now be set to true when os_disk.security_encryption_type is set to DiskWithVMGuestState (#32885)
  • azurerm_windows_virtual_machine_scale_set - encryption_at_host_enabled can now be set to true when os_disk.security_encryption_type is set to DiskWithVMGuestState (#32885)

BUG FIXES:

  • azurerm_cdn_frontdoor_batch_ruleset - parse rule.actions.route_configuration_override.origin_group.cdn_frontdoor_origin_group_id case-insensitively and normalize the resulting value to prevent diffs (#32980)
  • azurerm_cdn_frontdoor_route - parse cdn_frontdoor_origin_group_id case-insensitively and normalize the resulting value to prevent diffs (#32980)
  • azurerm_cdn_frontdoor_secret - fix an incorrect type assertion (#32982)
  • azurerm_dev_center_project - parse dev_center_id case-insensitively and normalize the resulting value to prevent diffs (#32798)
  • azurerm_eventhub - now prevents the status property from being set to SendDisabled on create (#33071)
  • azurerm_storage_container - add a state migration for the id field, fixing the upgrade path from 4.x to 5.x (#32978)

... (truncated)

Commits
  • 8d8282e deps: bump golang.org/x/mod and related packages (#33174)
  • a1a4086 CHANGELOG.md for 5.2.0 (#33105)
  • 0bae6ca azurerm_cognitive_account_project - add lock on parent account_id to delete...
  • 1ae3652 linters: bump azproviderlint to v0.2.0 (#33145)
  • 5ae79ae Fix for oracle Exadata Infra to support a location with no zones (#33011)
  • bd6be10 azurerm_databricks_workspace[_root_dbfs_customer_managed_key] - deprecate `...
  • 0c4e065 azurerm_redhat_openshift_cluster - support managed identity mode (#32473)
  • e8b9d7a dependencies: go - update to 1.26.6 (#33141)
  • a587475 docs: azurerm_cdn_endpoint requires content_types_to_compress if `is_comp...
  • 392955b azurerm_role_assignment - Support update for description, condition and...
  • Additional commits viewable in compare view

Updates hashicorp/google to 8.0.0

Release notes

Sourced from hashicorp/google's releases.

v8.0.0

Terraform Google Provider 8.0.0 Upgrade Guide

BREAKING RESOURCE REMOVALS:

  • beyondcorp: removed google_beyondcorp_app_connection, google_beyondcorp_app_connector, and google_beyondcorp_app_gateway resources, and the google_beyondcorp_app_connection, google_beyondcorp_app_connector, and google_beyondcorp_app_gateway data sources. Use google_beyondcorp_security_gateway and google_beyondcorp_security_gateway_application instead. (#18675)
  • iap: removed google_iap_brand and google_iap_client resources, and the google_iap_client data source. (#18679)
  • mlengine: removed google_ml_engine_model resource. Migrate machine learning deployments to google_vertex_ai_endpoint or Vertex AI Model Garden resources. (#18681)
  • notebooks: removed google_notebooks_environment, google_notebooks_instance (and associated IAM resources), and google_notebooks_runtime (and associated IAM resources). Migrate to google_workbench_instance. (#18583)
  • vertexai: removed google_vertex_ai_schedule resource. Use google_colab_schedule instead. (#18673)

BREAKING FIELD REMOVALS:

  • backupdr: removed resource_type argument from google_backup_dr_backup_plan_associations and google_backup_dr_data_source_references data sources. (#18688)
  • cloudrunv2: removed custom_audiences field from google_cloud_run_v2_worker_pool resource. (#18193)
  • cloudrunv2: removed http_get.http_headers.port probe field from google_cloud_run_v2_worker_pool resource. (#18290)
  • compute: removed attachment attribute within logical_structure.*.zones from google_compute_interconnect_attachment_group resource in favor of attachments. (#18676)
  • compute: removed reservation_block_count field from google_compute_reservation resource in favor of resource_status[0].reservation_block_count. (#18611)
  • datalossprevention: removed actions.publish_findings_to_cloud_data_catalog field from google_data_loss_prevention_job_trigger resource in favor of actions.publish_findings_to_dataplex_catalog. (#18530)
  • integrations: removed run_as_service_account argument from google_integrations_client resource. (#18680)

BREAKING INCREASED VALIDATION:

  • bigquerydatatransfer: changed constraint between sensitive_params.0.secret_access_key and sensitive_params.0.secret_access_key_wo from AtLeastOneOf to ExactlyOneOf in google_bigquery_data_transfer_config resource. (#18325)
  • cloudrunv2: made http_get.http_headers.name required when http_get.http_headers is set in google_cloud_run_v2_worker_pool resource. (#18290)
  • iamworkforcepool: made claim_mapping a required field on create in google_iam_workforce_pool_provider_scim_tenant resource. (#18348)
  • monitoring: changed constraint between http_check.0.auth_info.0.password and http_check.0.auth_info.0.password_wo to ExactlyOneOf in google_monitoring_uptime_check_config resource. (#18325)
  • secretmanager: made secret_data_wo_version required when secret_data_wo is set (RequiredWith) in google_secret_manager_secret_version resource. (#18325)
  • workflows: made source_contents a required argument in google_workflows_workflow resource. (#18411)

OTHER BREAKING CHANGES:

  • bigquerydatatransfer: converted sensitive_params.0.secret_access_key_wo_version from Integer to String data type with state migration in google_bigquery_data_transfer_config resource. (#18731)
  • bigquery: removed default_from_api for default_collation in google_bigquery_dataset resource; setting default_collation = "" now explicitly clears collation. (#18585)
  • cloudsecuritycompliance: converted cloud_control_details from list to set in google_cloud_security_compliance_framework resource. (#18596)
  • compute: added default empty strings ("") to project_id_or_num, network_url, and endpoint_url within consumer_accept_lists in google_compute_service_attachment resource to resolve permadiffs. (#18276)
  • compute: changed default value of load_balancing_scheme from EXTERNAL to EXTERNAL_MANAGED in google_compute_backend_service and google_compute_global_forwarding_rule resources. (#18557)
  • compute: updated guest_accelerator in google_compute_instance to plan and apply removal/replacement when count is explicitly set to 0 (or guest_accelerator = []). (#18426)
  • compute: converted nat_subnets and consumer_reject_lists from list to set in google_compute_service_attachment resource. (#18694)
  • container: extended name_prefix max length from 14 to 31 characters in google_container_node_pool and google_container_cluster resources. (#18477)
  • container: converted enable_components in logging_config and monitoring_config from list to set in google_container_cluster resource. (#18262)
  • secretmanager: converted secret_data_wo_version from Integer to String data type with state migration in google_secret_manager_secret_version resource. (#18325)
Changelog

Sourced from hashicorp/google's changelog.

8.0.0 (August 26, 2026)

Terraform Google Provider 8.0.0 Upgrade Guide

BREAKING RESOURCE REMOVALS:

  • beyondcorp: removed google_beyondcorp_app_connection, google_beyondcorp_app_connector, and google_beyondcorp_app_gateway resources, and the google_beyondcorp_app_connection, google_beyondcorp_app_connector, and google_beyondcorp_app_gateway data sources. Use google_beyondcorp_security_gateway and google_beyondcorp_security_gateway_application instead. (#18675)
  • iap: removed google_iap_brand and google_iap_client resources, and the google_iap_client data source. (#18679)
  • mlengine: removed google_ml_engine_model resource. Migrate machine learning deployments to google_vertex_ai_endpoint or Vertex AI Model Garden resources. (#18681)
  • notebooks: removed google_notebooks_environment, google_notebooks_instance (and associated IAM resources), and google_notebooks_runtime (and associated IAM resources). Migrate to google_workbench_instance. (#18583)
  • vertexai: removed google_vertex_ai_schedule resource. Use google_colab_schedule instead. (#18673)

BREAKING FIELD REMOVALS:

  • backupdr: removed resource_type argument from google_backup_dr_backup_plan_associations and google_backup_dr_data_source_references data sources. (#18688)
  • cloudrunv2: removed custom_audiences field from google_cloud_run_v2_worker_pool resource. (#18193)
  • cloudrunv2: removed http_get.http_headers.port probe field from google_cloud_run_v2_worker_pool resource. (#18290)
  • compute: removed attachment attribute within logical_structure.*.zones from google_compute_interconnect_attachment_group resource in favor of attachments. (#18676)
  • compute: removed reservation_block_count field from google_compute_reservation resource in favor of resource_status[0].reservation_block_count. (#18611)
  • datalossprevention: removed actions.publish_findings_to_cloud_data_catalog field from google_data_loss_prevention_job_trigger resource in favor of actions.publish_findings_to_dataplex_catalog. (#18530)
  • integrations: removed run_as_service_account argument from google_integrations_client resource. (#18680)

BREAKING INCREASED VALIDATION:

  • bigquerydatatransfer: changed constraint between sensitive_params.0.secret_access_key and sensitive_params.0.secret_access_key_wo from AtLeastOneOf to ExactlyOneOf in google_bigquery_data_transfer_config resource. (#18325)
  • cloudrunv2: made http_get.http_headers.name required when http_get.http_headers is set in google_cloud_run_v2_worker_pool resource. (#18290)
  • iamworkforcepool: made claim_mapping a required field on create in google_iam_workforce_pool_provider_scim_tenant resource. (#18348)
  • monitoring: changed constraint between http_check.0.auth_info.0.password and http_check.0.auth_info.0.password_wo to ExactlyOneOf in google_monitoring_uptime_check_config resource. (#18325)
  • secretmanager: made secret_data_wo_version required when secret_data_wo is set (RequiredWith) in google_secret_manager_secret_version resource. (#18325)
  • workflows: made source_contents a required argument in google_workflows_workflow resource. (#18411)

OTHER BREAKING CHANGES:

  • bigquerydatatransfer: converted sensitive_params.0.secret_access_key_wo_version from Integer to String data type with state migration in google_bigquery_data_transfer_config resource. (#18731)
  • bigquery: removed default_from_api for default_collation in google_bigquery_dataset resource; setting default_collation = "" now explicitly clears collation. (#18585)
  • cloudsecuritycompliance: converted cloud_control_details from list to set in google_cloud_security_compliance_framework resource. (#18596)
  • compute: added default empty strings ("") to project_id_or_num, network_url, and endpoint_url within consumer_accept_lists in google_compute_service_attachment resource to resolve permadiffs. (#18276)
  • compute: changed default value of load_balancing_scheme from EXTERNAL to EXTERNAL_MANAGED in google_compute_backend_service and google_compute_global_forwarding_rule resources. (#18557)
  • compute: updated guest_accelerator in google_compute_instance to plan and apply removal/replacement when count is explicitly set to 0 (or guest_accelerator = []). (#18426)
  • compute: converted nat_subnets and consumer_reject_lists from list to set in google_compute_service_attachment resource. (#18694)
  • container: extended name_prefix max length from 14 to 31 characters in google_container_node_pool and google_container_cluster resources. (#18477)
  • container: converted enable_components in logging_config and monitoring_config from list to set in google_container_cluster resource. (#18262)
  • secretmanager: converted secret_data_wo_version from Integer to String data type with state migration in google_secret_manager_secret_version resource. (#18325)

7.46.0 (August 25, 2026)

DEPRECATIONS:

  • beyondcorp: deprecated google_beyondcorp_app_connection, google_beyondcorp_app_connector, and google_beyondcorp_app_gateway resources and data sources. Use google_beyondcorp_security_gateway and google_beyondcorp_security_gateway_application instead. (#28976)

FEATURES:

  • New Data Source: google_memorystore_acl_policy (#28984)
  • New Data Source: google_redis_cluster_acl_policy (#28985)
  • New List Resource: google_migration_center_assets_export_job (#28904)
  • New List Resource: google_migration_center_discovery_client (#28904)

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…ates

Updates the requirements on [hashicorp/azurerm](https://github.com/hashicorp/terraform-provider-azurerm) and [hashicorp/google](https://github.com/hashicorp/terraform-provider-google) to permit the latest version.

Updates `hashicorp/azurerm` to 5.2.0
- [Release notes](https://github.com/hashicorp/terraform-provider-azurerm/releases)
- [Changelog](https://github.com/hashicorp/terraform-provider-azurerm/blob/main/CHANGELOG.md)
- [Commits](hashicorp/terraform-provider-azurerm@v4.81.0...v5.2.0)

Updates `hashicorp/google` to 8.0.0
- [Release notes](https://github.com/hashicorp/terraform-provider-google/releases)
- [Changelog](https://github.com/hashicorp/terraform-provider-google/blob/main/CHANGELOG.md)
- [Commits](hashicorp/terraform-provider-google@v7.25.0...v8.0.0)

---
updated-dependencies:
- dependency-name: hashicorp/azurerm
  dependency-version: 5.2.0
  dependency-type: direct:production
  dependency-group: all-updates
- dependency-name: hashicorp/google
  dependency-version: 8.0.0
  dependency-type: direct:production
  dependency-group: all-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file terraform Pull requests that update terraform code labels Aug 30, 2026
@github-actions

github-actions Bot commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Scanned Files

None

@github-actions

Copy link
Copy Markdown
Contributor

Dependabot Auto-Merge Policy

Auto-merge is currently blocked by policy for this pull request.

  • Reason: Dependabot metadata is unavailable, so auto-merge is blocked. Manual review required.
  • Policy code: metadata_unavailable
  • Update type: unknown
  • Dependencies: hashicorp/azurerm, hashicorp/google

Next action: manual review and merge is required.

This comment is maintained automatically by the dependabot-policy action.

@github-actions

github-actions Bot commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor
⛔ Superseded — A newer run has replaced this result.
⛔ Superseded — A newer run has replaced this result.

🏗️ Terraform Plan

🌍 Environment: dev

❌ Validate — Failed

❌ Validation failed. Check the workflow logs for details.

@github-actions

github-actions Bot commented Aug 30, 2026 •

Copy link
Copy Markdown
Contributor
⛔ Superseded — A newer run has replaced this result.

🏗️ Terraform Plan

🌍 Environment: dev

❌ Validate — Failed

❌ Validation failed. Check the workflow logs for details.

@frasermolyneux

Copy link
Copy Markdown
Owner

@copilot you will need to update the terraform to have this PR pass - review the terraform-plan-dev outputs and resolve.

Co-authored-by: frasermolyneux <34033625+frasermolyneux@users.noreply.github.com>

Copilot AI commented Aug 30, 2026

Copy link
Copy Markdown
Contributor

@copilot you will need to update the terraform to have this PR pass - review the terraform-plan-dev outputs and resolve.

Fixed in baead4a. The terraform-plan-dev failure was azurerm v5 breaking changes:

  • azurerm_application_insights.disable_ip_masking = true → ip_masking_enabled = false (property removed in v5)
  • azurerm_storage_table.storage_account_name → storage_account_id on geolocations, geolocationsv11 and proxycheck

Validated locally with Terraform 1.15.6 and azurerm 5.2.0 / google 8.0.0:

$ terraform init -backend=false
Terraform has been successfully initialized!
$ terraform validate
Success! The configuration is valid.
$ terraform fmt -check -recursive
(no output)

No config changes were needed for the google 8.0 bump — google_apikeys_key is unaffected.

@sonarqubecloud

Copy link
Copy Markdown

Copilot AI deployed to Development August 30, 2026 21:48 Active
@github-actions

Copy link
Copy Markdown
Contributor

🏗️ Terraform Plan

🌍 Environment: dev

✅ Validate — Passed

✅ Plan

Count
🔄 Change 1
📋 Resource Details
Action Resource
🔄 Update azurerm_api_management_subscription.web

This branch was successfully deployed

1 active deployment
Development — baead4a2 Deployed Aug 30, 2026 by Copilot via terraform-plan-dev #543
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file terraform Pull requests that update terraform code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants