Zum Inhalt springen

Hashicorp Release Notes

54 Einträge aus 2 Quellen. Zuletzt aktualisiert:

Folge Hashicorp, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.17.0-rc1: Variablen in Provider-Anforderungen, Terraform Policy GA

Terraform 1.17.0-rc1 erlaubt Variablen und Locals in Provider-Anforderungen, bringt die Planungsoption -minimal-refresh, macht Terraform Policy (-policies) allgemein verfügbar, unterstützt mock_provider für Ephemeral Resources und behebt Panics bei pow und log.

1.17.0-rc1 (October 07, 2026)

NEW FEATURES:

  • Terraform now supports variables and locals in provider requirements (#39153)

  • A new -minimal-refresh planning option has been added, which will only refresh resources that have proposed changes. (#35290)

  • policy: Terraform Policy is now generally available. The -policies flag for plan, apply, and query no longer requires an experimental build or the -allow-experimental-features flag. Query policies evaluate resources discovered by list blocks and report human-readable or JSON results. See https://developer.hashicorp.com/terraform/policy for more information. (#38970)

ENHANCEMENTS:

  • command/init: Enrich log messages with provider versions (#38918)

  • test: Add mock_provider support for ephemeral resources (#38928)

  • command/login: display warning after successful login if user is subject to an organization's TTL policy

BUG FIXES:

  • funcs: pow and log no longer panic when result is not a number (#38912) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.5

Terraform 1.16.5 behebt einen Absturz bei einem als tainted markierten Instanzstatus ohne gültigen Status sowie ein Problem, bei dem die Resource Identity beim Löschen nil sein konnte.

1.16.5 (September 30, 2026)

BUG FIXES:

  • Fixed a crash that happens when a tainted instance state is seen without a valid status (#39287)

  • resource-identity: fixed an issue where resource identity could be nil during delete (#39285)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.17.0-beta2

Terraform 1.17.0-beta2 unterstützt Variablen und Locals in Provider-Anforderungen, bringt die Planungsoption -minimal-refresh, macht Terraform Policy allgemein verfügbar (inklusive Query-Policies) und enthält weitere Verbesserungen und Fehlerbehebungen.

1.17.0-beta2 (September 23, 2026)

NEW FEATURES:

  • Terraform now supports variables and locals in provider requirements (#39153)

  • A new -minimal-refresh planning option has been added, which will only refresh resources that have proposed changes. (#35290)

  • policy: Terraform Policy is now generally available. The -policies flag for plan, apply, and query no longer requires an experimental build or the -allow-experimental-features flag. Query policies evaluate resources discovered by list blocks and report human-readable or JSON results. See https://developer.hashicorp.com/terraform/policy for more information. (#38970)

ENHANCEMENTS:

  • command/init: Enrich log messages with provider versions (#38918)

  • test: Add mock_provider support for ephemeral resources (#38928)

  • command/login: display warning after successful login if user is subject to an organization's TTL policy

BUG FIXES:

  • funcs: pow and log no longer panic when result is not a number (#38912) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.4

Terraform 1.16.4 behebt einen Fehler beim Darstellen von Policy-Evaluierungsergebnissen älterer Terraform-Enterprise-Versionen und einen ungültigen Deferred-Fehler in Stacks bei unbekanntem count/for_each.

1.16.4 (September 23, 2026)

BUG FIXES:

  • Fixed an issue where Terraform fails when rendering policy evaluation outcomes for older versions of Terraform Enterprise (#39095)

  • stacks: Fix invalid deferred error triggered by provider returning a deferral when a resource also has an unknown count/for_each. (#39237)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hashicorp Vault von Hashicorp

Vault 2.1.1

Vault 2.1.1 behebt Sicherheitslücken durch Updates von apache/thrift, golang.org/x/crypto und google.golang.org/grpc, ergänzt einen Okta-Provider für auth/jwt mit Gruppenabruf über die Admin API, begrenzt gleichzeitige Raft-Retry-Join-Worker auf 20 und enthält Verbesserungen bei Secrets Import und PKI-Widerruf sowie Fehlerbehebungen.

2.1.1

September 16, 2026

SECURITY:

  • core: Update github.com/apache/thrift to v0.24.0 to fix security vulnerability ghsa-8wv5-x4w7-5gww.
  • core: Update golang.org/x/crypto to v0.56.0 to fix security vulnerabilities GO-2026-6354 and GO-2026-6355.
  • core: Update google.golang.org/grpc to v1.83.2 to fix security vulnerability GHSA-2v4p-qf9q-27wj.

CHANGES:

  • auth/jwt: Added Okta provider with group fetching from Admin API when fetch_groups=true and truncation is detected.
  • auth/jwt: Update plugin to v0.26.4
  • core/raft: Limited concurrent retry-join workers to 20. Any further retry-join attempts while 20 are in progress will result in an error (too many concurrent raft retry joins in progress).
  • core: Bump Go version to 1.26.8

IMPROVEMENTS:

  • secrets import: Add allowed_ipv4_cidrs to source_aws and source_azure Secrets Import blocks to allow private CIDR exemptions for SSRF-safe connectivity.
  • secrets/pki: add an additional field to include an RFC 5280 revocation reason for (/pki/revoke) and (/pki/revoke-with-key).
  • ui: Bump dompurify to 3.4.15 to address SECVULN advisories

BUG FIXES:

  • Secrets Recovery (enterprise): Fixing Vault panic in cli when running vault recover without a path.
  • auth/jwt: Fixed incorrect HTTP status codes returned during agent ceiling policy evaluation. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.3: Fixes für create_before_destroy, Marks und Import

Terraform 1.16.3 behebt Probleme mit destroy=false bei create_before_destroy-Instanzen, mit mehreren Marks bei Funktionsergebnissen und Validierungen sowie mit der Provider-Auflösung beim Import.

1.16.3 (September 16, 2026)

BUG FIXES:

  • Fix handling of destroy=false around create_before_destroy instances (#39169)

  • Fix function result comparison when there are multiple marks (#39170)

  • Filter logic for marks could cause values with multiple marks to erroneously fail validations (#39171)

  • Fix issue with import provider resolution (#39185)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.17.0-beta1 mit -minimal-refresh und Terraform Policy

Terraform 1.17.0-beta1 unterstützt Variablen und Locals in Provider-Anforderungen, bringt die Planungsoption -minimal-refresh, macht Terraform Policy allgemein verfügbar und enthält weitere Verbesserungen und Fehlerbehebungen.

1.17.0-beta1 (September 09, 2026)

NEW FEATURES:

  • Terraform now supports variables and locals in provider requirements (#39153)

  • A new -minimal-refresh planning option has been added, which will only refresh resources that have proposed changes. (#35290)

  • policy: Terraform Policy is now generally available. The -policies flag for plan, apply, and init no longer requires the -allow-experimental-features flag. See https://developer.hashicorp.com/terraform/policy for more information. (#38970)

ENHANCEMENTS:

  • command/init: Enrich log messages with provider versions (#38918)

  • test: Add mock_provider support for ephemeral resources (#38928)

  • command/login: display warning after successful login if user is subject to an organization's TTL policy

BUG FIXES:

  • funcs: pow and log no longer panic when result is not a number (#38912) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.2: Absturz bei Modulinstallation behoben

Terraform 1.16.2 behebt einen Absturz bei der Modulinstallation, wenn ungültige Modulaufrufe auftreten.

1.16.2 (September 9, 2026)

BUG FIXES:

  • Fix panic in module installation when encoutering invalid module calls (#39129)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.1: Fehlerbehebungen bei CLI, import und state show

Terraform 1.16.1 behebt mehrere Fehler, darunter ein endloses Hängen der CLI nach Run-Task-Fehlern, ignorierte import-Blöcke bei for_each/count, Abstürze bei state show und Import-Identity sowie die create_before_destroy-Reihenfolge.

1.16.1 (September 2, 2026)

BUG FIXES:

  • cloud: Fixed a bug causing the CLI to pause indefinitely after a run task failure with pending policy evaluations (#38751)

  • Support referencing modules containing dynamic sources in Terraform Test (#38950)

  • stacks: Fixed validation to ensure the provider versions in the lock file and configuration are compatible. (#38829)

  • Fix panic when import identity references sensitive value (#39013)

  • import: Fixed a bug where import blocks would be ignored when multiple imports targeted different instances of a resource config using for_each or count. (#39068)

  • state show: Fix a panic when given an attribute path instead of a resource instance address (#39087)

  • Fix create_before_destroy ordering in some combinations of changes (#39091)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hashicorp Vault von Hashicorp

Vault 2.1.0

Vault 2.1.0 aktualisiert etcd client und go-pkcs12 zur Behebung von Sicherheitslücken, ergänzt die Lizenzbedingungen um Agentic IAM und macht issuer_id sowie unique_id_claim von OAuth-Resource-Server-Profilen (Enterprise) nach der Erstellung unveränderbar, wobei die Funktion keine Aktivierung über den Endpunkt sys/activation-flags/oauth-resource-server/activate mehr benötigt.

2.1.0

September 01, 2026

SECURITY:

  • core: Update go.etcd.io/etcd/client/pkg/v3 to v3.7.1 to fix security vulnerability GO-2026-6107.
  • core: Update software.sslmate.com/src/go-pkcs12 to v0.7.2 to fix security vulnerability GO-2026-5052.

CHANGES:

  • License: Add Agentic IAM terms to client licensing model and update terms for Vault Platform licensing model.
  • core: Bump Go version to 1.26.7.
  • oauth-resource-server (enterprise): Prevent issuer_id from being mutated after OAuth Resource Server profile creation. Operators must delete and recreate profiles to change the issuer_id.
  • oauth-resource-server (enterprise): Prevent unique_id_claim from being mutated after OAuth Resource Server profile creation. Operators must delete and recreate profiles to change the unique_id_claim.
  • oauth-resource-server (enterprise): The OAuth Resource Server feature no longer requires activation via the sys/activation-flags/oauth-resource-server/activate endpoint.
  • oauth-resource-server (enterprise): Update OAuth Resource Server config to include custom claim options for the token's unique identifier and actor.
  • secrets/openldap (enterprise): Update plugin to v0.18.4+ent

FEATURES: …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.17.0-alpha20260827 mit -minimal-refresh

Terraform 1.17.0-alpha20260827 führt die Planungsoption -minimal-refresh ein, zeigt Diagnosen beim Erneuern ephemerer Ressourcen an und enthält kleinere Verbesserungen und Fehlerbehebungen.

1.17.0-alpha20260827 (August 27, 2026)

NEW FEATURES:

  • A new -minimal-refresh planning option has been added, which will only refresh resources that have proposed changes. (#35290)

ENHANCEMENTS:

  • command/init: Enrich log messages with provider versions (#38918)

  • command/login: display warning after successful login if user is subject to an organization's TTL policy

BUG FIXES:

  • funcs: pow and log no longer panic when result is not a number (#38912)

  • ephemeral: Terraform will now use and display diagnostics raised when renewing an ephemeral resource. This may cause warnings to appear that previously were lost. We expect that any error diagnostics that were previously lost would have caused confusing downstream errors, so we do not anticipate this change to be breaking. (#38989)

  • Fix panic when import identity references sensitive value (#39013)

NOTES: …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.0: store-Block, import in Modulen, s390x

Terraform 1.16.0 speichert geplante private Provider-Daten, ergänzt einen store-Block in terraform_data, erlaubt import-Blöcke in Modulen, bietet Binaries für Linux s390x und -json-Ausgabe für state show und workspace list.

1.16.0 (August 26, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.0-rc2 als Release Candidate

Terraform 1.16.0-rc2 ist ein Release Candidate mit u. a. gespeicherten privaten Provider-Daten, dem store-Block in terraform_data, import-Blöcken in Modulen und -json-Ausgabe für state show und workspace list.

1.16.0-rc2 (August 19, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.15.9: Modulvalidierung und go-slug-Update gegen CVE

Terraform 1.15.9 korrigiert die Validierung von Child-Modulen für ungültige Blöcke und aktualisiert go-slug auf v0.18.3 gegen CVE-2026-14978, damit Dateien per .terraformignore korrekt vom Upload ausgeschlossen werden.

1.15.9 (August 19, 2026)

BUG FIXES:

  • validate: Child module validation has been fixed and will now raise errors or warning diagnostics for invalid blocks. (list, import, backend, and cloud) (#38994)

NOTES:

  • Update go-slug to v0.18.3 to mitigate CVE-2026-14978, which is a Unicode normalization issue that could lead to files not being correctly excluded via .terraformignore from upload to a Terraform Enterprise or HCP Terraform during a run (#39036)

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.17.0-alpha20260812: Init-Logs und format_version

Terraform 1.17.0-alpha20260812 reichert Init-Logmeldungen mit Provider-Versionen an, zeigt Diagnosen beim Erneuern ephemerer Ressourcen an und ergänzt die JSON-Ausgabe von version um das Feld format_version.

1.17.0-alpha20260812 (August 12, 2026)

ENHANCEMENTS:

  • command/init: Enrich log messages with provider versions (#38918)

BUG FIXES:

  • funcs: pow and log no longer panic when result is not a number (#38912)

  • ephemeral: Terraform will now use and display diagnostics raised when renewing an ephemeral resource. This may cause warnings to appear that previously were lost. We expect that any error diagnostics that were previously lost would have caused confusing downstream errors, so we do not anticipate this change to be breaking. (#38989)

NOTES:

  • version: JSON output now includes a new format_version field, which will enable safer future changes of the command's JSON output format. It is assumed existing tooling ignores unknown fields and therefore this change should not be breaking in itself but we advice consumers to pay attention to format_version in future releases and/or use latest version of hashicorp/terraform-json & hashicorp/terraform-exec which does. (#38930)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.0-rc1 als Release Candidate

Terraform 1.16.0-rc1 ist ein Release Candidate mit u. a. gespeicherten privaten Provider-Daten, dem store-Block in terraform_data, import-Blöcken in Modulen und -json-Ausgabe für state show und workspace list.

1.16.0-rc1 (August 12, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.16.0-beta2 mit store-Block und Modul-Imports

Terraform 1.16.0-beta2 bringt u. a. gespeicherte private Provider-Daten, den store-Block in terraform_data, import-Blöcke in Modulen und -json-Ausgabe für state show und workspace list.

1.16.0-beta2 (August 05, 2026)

NEW FEATURES:

  • Terraform now stores planned private data for providers, allowing provider-specific state to be preserved across plan and apply. (#37986)

  • terraform_data: The new store block can hold ephemeral and sensitive values across plan and apply. (#38298)

  • Providers can now use nested blocks as computed values (#38305)

  • import: import blocks inside modules are now supported. (#38352)

  • Terraform is now available as a pre-built binary for Linux s390x (zLinux). (#38384)

  • Resource action triggers can now use on_failure modes of halt, taint, or continue. (#38722)

ENHANCEMENTS:

  • state show: The state show command can now produce machine-readable output when supplied with the -json flag (#23940)

  • workspace: The workspace list command can now produce machine-readable output when supplied with the -json flag (#38397)

  • test: Terraform now reports which resources were left behind when skip_cleanup is set. (#38449) …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Hashicorp Vault von Hashicorp

Vault 2.0.4

Vault 2.0.4 behebt mehrere Sicherheitslücken, darunter eine Rechteausweitung durch Groß-/Kleinschreibung bei Policy-Namen in denied_parameters, und entfernt gnupg, openssl und procps aus den UBI-basierten Container-Images.

2.0.4

August 04, 2026

BREAKING CHANGES:

  • containers: The following packages have been removed from UBI based container images: gnupg, openssl, procps.

SECURITY:

  • acl: Fix privilege-escalation vulnerability where a denied_parameters constraint on the policies request field could be bypassed by submitting a mixed-case policy name (e.g. "Super-Admin" instead of "super-admin"). Vault now normalizes the policies parameter to lowercase before evaluating allowed_parameters/denied_parameters constraints.
  • identity/scim (enterprise): The identity/entity/merge endpoint now rejects requests that involve any SCIM-managed entity, preventing privileged operators from bypassing SCIM ownership guardrails to transfer aliases, group memberships, or policies across SCIM boundaries.
  • identity: Prevent the entity batch-delete endpoint (identity/entity/batch-delete) from deleting the underlying storage of entities that belong to another namespace.
  • identity: entity/name updates now reject mismatched id or external_id selectors to prevent retargeting updates to a different entity

CHANGES:

  • auth/oci: Update plugin to v0.21.3
  • core: Bump Go version to 1.26.5.
  • core: remove support for duplicate attributes in HCL configuration files and policy definitions. Parsing HCL with …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Terraform von Hashicorp

Terraform 1.17.0-alpha20260729: Panics bei pow und log behoben

Terraform 1.17.0-alpha20260729 reichert Init-Logmeldungen mit Provider-Versionen an und verhindert Panics bei pow und log, wenn das Ergebnis keine Zahl ist.

1.17.0-alpha20260729 (July 29, 2026)

ENHANCEMENTS:

  • command/init: Enrich log messages with provider versions (#38918)

BUG FIXES:

  • funcs: pow and log no longer panic when result is not a number (#38912)

EXPERIMENTS:

Experiments are only enabled in alpha releases of Terraform CLI. The following features are not yet available in stable releases.

  • The experimental "deferred actions" feature, enabled by passing the -allow-deferral option to terraform plan, permits count and for_each arguments in module, resource, and data blocks to have unknown values and allows providers to react more flexibly to unknown values.
  • terraform test cleanup: The experimental test cleanup command. In experimental builds of Terraform, a manifest file and state files for each failed cleanup operation during test operations are saved within the .terraform local directory. The test cleanup command will attempt to clean up the local state files left behind automatically, without requiring manual intervention.
  • terraform test: backend blocks and skip_cleanup attributes: …

Originalquelle(öffnet in neuem Tab)Problem melden