Skip to content

Update Terraform azurerm to v5 - #586

Draft
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/azurerm-5.x
Draft

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/azurerm-5.x

Conversation

@renovate

@renovate renovate Bot commented Jul 29, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
azurerm (source) required_provider major 4.81.0 → 5.9.0

Release Notes

hashicorp/terraform-provider-azurerm (azurerm)

v5.9.0

Compare Source

FEATURES:

  • New List Resource: azurerm_app_service_custom_hostname_binding (#​33423)
  • New List Resource: azurerm_eventhub (#​33376)
  • New List Resource: azurerm_kubernetes_cluster_node_pool (#​33399)
  • New List Resource: azurerm_kubernetes_cluster_node_pool (#​33399)

ENHANCEMENTS:

  • dependencies: github.com/Azure/go-autorest/autorest/to - update to v0.4.1 (#​33548)
  • dependencies: github.com/Azure/go-autorest/autorest/validation - update to v0.3.2 (#​33548)
  • dependencies: github.com/hashicorp/go-uuid - update to v1.0.4 (#​33548)
  • dependencies: github.com/hashicorp/terraform-json - update to v0.28.0 (#​33548)
  • dependencies: github.com/hashicorp/terraform-plugin-framework-timeouts - update to v0.7.0 (#​33548)
  • dependencies: go-azure-sdk - update to v0.20261005.1221110 (#​33574)
  • dependencies: golang.org/x/crypto - update to v0.57.0 (#​33548)
  • dependencies: golang.org/x/mod - update to v0.41.0 (#​33548)
  • dependencies: golang.org/x/net - update to v0.59.0 (#​33548)
  • dependencies: golang.org/x/sync - update to v0.23.0 (#​33548)
  • dependencies: golang.org/x/sys - update to v0.48.0 (#​33548)
  • dependencies: golang.org/x/text - update to v0.42.0 (#​33548)
  • dependencies: golang.org/x/tools - update to v0.50.0 (#​33548)
  • dependencies: mssqlmanagedinstance - update API version to 2025-01-01 (#​33559)
  • Data Source: azurerm_application_gateway - export the ssl_profile.client_authentication_mode property (#​33536)
  • azurerm_application_gateway - add support for the ssl_profile.client_authentication_mode property (#​33536)
  • azurerm_monitor_data_collection_rule - add support for the logs_ingestion_endpoint and metrics_ingestion_endpoint properties (#​31317)
  • azurerm_storage_blob_inventory_policy - add support for the filter.created_within_days property (#​30675)
  • azurerm_data_protection_backup_policy_kubernetes_cluster - add support for VaultStore to the default_retention_rule.life_cycle.data_store_type property (#​32356)
  • azurerm_data_protection_backup_policy_kubernetes_cluster - add support for VaultStore to the retention_rule.life_cycle.data_store_type property (#​32356)
  • azurerm_machine_learning_workspace_network_outbound_rule_private_endpoint - add support for account to the sub_resource_target property (#​28568)
  • azurerm_monitor_data_collection_rule - add support for the Direct kind (#​31317)
  • azurerm_network_watcher_flow_log - support the value 5 for the version property (#​33589)
  • azurerm_orchestrated_virtual_machine_scale_set - os_disk.0.diff_disk_settings.0.placement supports NvmeDisk (#​33578)
  • azurerm_virtual_desktop_application - expand validation for the name property to allow spaces, periods, underscores, and @ (#​33522)
  • azurerm_virtual_desktop_host_pool - add support for MultiplePersistent to the load_balancer_type property (#​32744)
  • azurerm_virtual_network_gateway_connection - skip unnecessary update request when only shared_key has changed (#​33392)

BUG FIXES:

  • azurerm_app_configuration_feature - fix a serialization issue for the timewindow_filter.start and timewindow_filter.end properties which caused a broken config in Azure (#​32969)
  • azurerm_dashboard_grafana - fix an issue that prevented updates when smtp was set but not changed (#​32720)
  • azurerm_kubernetes_cluster_node_pool - add additional locking on the pod and node virtual network IDs to prevent conflicts when creating multiple node pools on the same virtual network (#​32682)
  • azurerm_vpn_server_configuration - fix a persistent diff on the radius property (#​33212)

v5.8.0

Compare Source

FEATURES:

  • New Action: azurerm_data_protection_resource_guard_unlock_delete (#​28306)
  • New Data Source: azurerm_oracle_autonomous_database_cross_region_disaster_recovery (#​30167)
  • New List Resource: azurerm_dns_a_record (#​33263)
  • New List Resource: azurerm_dns_cname_record (#​33264)
  • New List Resource: azurerm_dns_txt_record (#​33269)
  • New List Resource: azurerm_lb_probe (#​33459)
  • New List Resource: azurerm_monitor_workspace (#​33375)
  • New List Resource: azurerm_postgresql_flexible_server_firewall_rule (#​33377)
  • New List Resource: azurerm_storage_account_network_rules (#​33447)
  • New List Resource: azurerm_storage_container (#​33523)
  • New Resource: azurerm_oracle_autonomous_database_cross_region_disaster_recovery (#​30167)

ENHANCEMENTS:

  • dependencies: communication - update API version to 2026-03-18 (#​32802)
  • dependencies: go-azure-sdk - update to v0.20260928.1201942 (#​33524)
  • azurerm_linux_function_app_slot - add support for 7.6 to the site_config.application_stack.powershell_core_version property (#​33520)
  • azurerm_linux_function_app - add support for 7.6 to the site_config.application_stack.powershell_core_version property (#​33520)
  • azurerm_mysql_flexible_database - suppress persistent diffs on charset and collation when using the utf8 aliases as the API now returns utf8mb3 prefixed values (#​33138)
  • azurerm_netapp_volume_group_oracle - allow volume.storage_quota_in_gb minimum of 50 (previously 100) (#​33518)
  • azurerm_netapp_volume_group_sap_hana - allow volume.storage_quota_in_gb minimum of 50 (previously 100) (#​33518)
  • azurerm_postgresql_flexible_server - improve validation for storage_mb to allow increments of 1024 for storage_type of PremiumV22_LRS (#​33197)
  • azurerm_public_ip_prefix - support updating sku in-place. (#​33480)
  • azurerm_storage_account - prevent replacement of resource when account_kind changes from StorageV2 to Storage as Storage is deprecated and can no longer be used to create accounts (#​33531)
  • azurerm_storage_container - add Resource Identity support (#​33523)

BUG FIXES:

  • azurerm_container_app_job - the event_stream_endpoint and outbound_ip_addresses properties are now set into state (#​33513)

v5.7.0

Compare Source

FEATURES:

  • New List Resource: azurerm_private_dns_resolver_forwarding_rule (#​33313)
  • New List Resource: azurerm_windows_virtual_machine (#​33332)

ENHANCEMENTS:

  • dependencies: go-azure-sdk - update to v0.20260917.1142820 (#​33495)
  • dependencies: network - update API version to 2025-07-01 (#​33441)
  • Data Source: azurerm_linux_web_app - export the virtual_network_image_pull_enabled property (#​33316)
  • Data Source: azurerm_network_interface - export the auxiliary_mode, auxiliary_sku, edge_zone, and internal_domain_name_suffix properties (#​33204)
  • Data Source: azurerm_public_ip - export the domain_name_label_scope, edge_zone, public_ip_prefix_id, and sku_tier properties (#​33193)
  • Data Source: azurerm_service_plan - export the premium_plan_auto_scale_enabled property (#​33300)
  • Data Source: azurerm_storage_blob - export the cache_control and source_uri properties (#​33318)
  • Data Source: azurerm_traffic_manager_profile - export the maximum_return property (#​33346)
  • Data Source: azurerm_web_pubsub - export the live_trace and identity properties (#​33373)
  • azurerm_kubernetes_cluster_node_pool - add Windows2025 as a valid value for the os_sku property (#​33463)
  • azurerm_kubernetes_cluster - add Windows2025 as a valid value for the os_sku property (#​33463)

BUG FIXES:

  • Data Source: azurerm_kubernetes_cluster - fix a panic caused by a nil pointer dereference while flattening agent_pool_profile (#​33488)
  • azurerm_postgresql_flexible_server - fix cluster block read for replica create_mode (#​33082)

v5.6.0

Compare Source

FEATURES:

  • New List Resource: azurerm_batch_account (#​33252)
  • New List Resource: azurerm_cdn_frontdoor_origin_group (#​33334)
  • New Resource: azurerm_storage_discovery_workspace (#​31479)

ENHANCEMENTS:

  • dependencies: containers - update API version to 2026-05-01 (#​32688)
  • dependencies: go-azure-sdk - update to v0.20260910.1141000 (#​33413)
  • dependencies: qumulo - update API version to 2026-04-16 (#​33421)
  • dependencies: servicebus - update to API version 2026-01-01 (#​33450)
  • azurerm_iothub_device_update_instance - add support for the connection_string_wo and connection_string_wo_version properties (#​33448)
  • azurerm_linux_function_app - add support for the end_to_end_tls_encryption_enabled property (#​31135)
  • azurerm_linux_function_app_slot - add support for the end_to_end_tls_encryption_enabled property (#​31135)
  • azurerm_linux_web_app - add support for the end_to_end_tls_encryption_enabled property (#​31135)
  • azurerm_linux_web_app_slot - add support for the end_to_end_tls_encryption_enabled property (#​31135)
  • azurerm_mongo_cluster - Support new property network_bypass_mode (#​33168)
  • azurerm_servicebus_namespace - add support for the 1.3 value to the minimum_tls_version property (#​33457)
  • azurerm_windows_function_app - add support for the end_to_end_tls_encryption_enabled property (#​31135)
  • azurerm_windows_function_app_slot - add support for the end_to_end_tls_encryption_enabled property (#​31135)
  • azurerm_windows_web_app - add support for the end_to_end_tls_encryption_enabled property (#​31135)
  • azurerm_windows_web_app_slot - add support for the end_to_end_tls_encryption_enabled property (#​31135)

BUG FIXES:

  • azurerm_site_recovery_replicated_vm - select managed_disk properties compared case insensitive (#​33424)

v5.5.0

Compare Source

FEATURES:

  • New List Resource: azurerm_analysis_services_server (#​33250)
  • New List Resource: azurerm_application_insights_workbook (#​33244)
  • New List Resource: azurerm_attestation_provider (#​33251)
  • New List Resource: azurerm_cdn_frontdoor_origin (#​33307)
  • New List Resource: azurerm_eventhub_consumer_group (#​33335)
  • New List Resource: azurerm_linux_virtual_machine (#​33333)
  • New List Resource: azurerm_virtual_hub_connection (#​33311)

ENHANCEMENTS:

  • dependencies: go-azure-sdk - update to v0.20260901.1173158 (#​33274)
  • azurerm_private_endpoint - lock on private service connection resource ids (#​33298)
  • azurerm_storage_account - add support for the public_network_access property (#​33292)

BUG FIXES:

  • azurerm_resource_group - the managed_by property now forces recreation when changed as the API does not support changing this value (#​33339)
  • go-azure-sdk - Delete operations now poll on asynchronous operation URLs if returned by the API instead of only checking for a 404 on the resource URL, ensuring deletion errors are reported to the user (#​33274)

v5.4.0

Compare Source

FEATURES:

  • New List Resource: azurerm_application_insights_standard_web_test (#​33243)
  • New List Resource: azurerm_application_insights_workbook_template (#​33245)
  • New List Resource: azurerm_arc_kubernetes_provisioned_cluster (#​33247)
  • New List Resource: azurerm_availability_set (#​33241)
  • New List Resource: azurerm_batch_application (#​33254)
  • New List Resource: azurerm_dedicated_host_group (#​33257)
  • New List Resource: azurerm_log_analytics_workspace (#​33259)

ENHANCEMENTS:

  • dependencies: azurerm_mongo_cluster - update API version to 2026-06-01 (#​33195)
  • dependencies: azurerm_mongo_cluster_firewall_rule - update API version to 2026-06-01 (#​33195)
  • dependencies: azurerm_mongo_cluster_user - update API version to 2026-06-01 (#​33195)
  • dependencies: netapp - update API version to 2026-05-01 (#​33215)
  • Data Source: azurerm_api_management_workspace - export the description property (#​33205)
  • Data Source: azurerm_attestation_provider - export the sev_snp_policy_base64, open_enclave_policy_base64, sgx_enclave_policy_base64, and tpm_policy_base64 properties (#​33125)
  • Data Source: azurerm_automation_account - export the dsc_primary_access_key, dsc_server_endpoint, dsc_secondary_access_key, public_network_access_enabled, sku_name, and tags properties (#​33135)
  • Data Source: azurerm_automation_account - export the encryption block (#​33135)
  • Data Source: azurerm_ip_group - export the firewall_ids and firewall_policy_ids properties (#​33190)
  • Data Source: azurerm_private_link_service - export the fqdns and destination_ip_address properties (#​33191)
  • azurerm_key_vault_managed_hardware_security_module_key - allow the key_size property to be set when key_type is oct-HSM (#​32690)
  • azurerm_lb_probe - add support for the no_healthy_backends_behavior property (#​32645)
  • azurerm_linux_virtual_machine_scale_set - add support for the NvmeDisk value to the os_disk.diff_disk_settings.placement property (#​30328)
  • azurerm_linux_web_app - add support for the 8.5 value in the site_config.application_stack.php_version property (#​33308)
  • azurerm_linux_web_app_slot - add support for the 8.5 value in the site_config.application_stack.php_version property (#​33308)
  • azurerm_netapp_volume - support for the breakthrough_mode_enabled property (#​33215)
  • azurerm_postgresql_flexible_server - add support for the storage_type, storage_iops, and storage_throughput properties which allows choice of the new "Premium V2 LRS" storage type (#​32121)
  • azurerm_storage_account - add support for an in-place migration of account_replication_type between matching non-zonal and zonal types instead of resource recreation (#​33236)
  • azurerm_storage_table - add support for AAD authentication (#​32997)
  • azurerm_synapse_spark_pool - migrate to go-azure-sdk (#​33258)
  • azurerm_windows_virtual_machine_scale_set - add support for the NvmeDisk value to the os_disk.diff_disk_settings.placement property (#​30328)

BUG FIXES:

  • azurerm_synapse_spark_pool - fix lifecycle.ignore_changes support (#​33258)

v5.3.0

Compare Source

FEATURES:

  • New Data Source: azurerm_playwright_workspace (#​31954)
  • New List Resource: azurerm_cognitive_deployment (#​33149)
  • New List Resource: azurerm_playwright_workspace (#​31954)
  • New Resource: azurerm_playwright_workspace (#​31954)

ENHANCEMENTS:

  • dependencies: go-azure-helpers - update version to 0.82.0 (#​33142)
  • dependencies: sql - update API version to 2025-01-01 (#​33201)
  • Data Source: azurerm_role_definition - export the role_definition_resource_id property (#​33126)
  • azurerm_cognitive_deployment - add Resource Identity support (#​33149)
  • azurerm_federated_identity_credential - add additional polling to account for Azure's eventual consistency (#​32935)
  • azurerm_kubernetes_cluster - add support for the oms_agent.retina_flow_logs_enabled property (#​33222)
  • azurerm_managed_application - add support for the identity block (#​30725)
  • azurerm_private_endpoint - extend validation for the private_service_connection.subresource_names property to allow names containing spaces (#​32887)
  • azurerm_search_service - allow in-place downgrades of the sku property between Basic and Standard tiers (#​33069)
  • azurerm_site_recovery_replicated_vm - add update support to the managed_disk block without requiring resource recreation (#​33140)
  • azurerm_user_assigned_identity - add additional polling to account for Azure's eventual consistency (#​33142)

BUG FIXES:

  • Data Source: azurerm_app_configuration_key - now correctly sets tags into state (#​33182)
  • azurerm_eventhub_namespace - prevent network_rulesets.x.default_action being set to Deny if ip_rule or virtual_network_rule is not specified (#​33216)

v5.2.0

Compare Source

FEATURES:

  • New List Resource: azurerm_user_assigned_identity (#​32667)

ENHANCEMENTS:

  • dependencies: go - update to 1.26.6 (#​33141)
  • dependencies: go-azure-sdk - update to v0.20260811.1225050 (#​33079)
  • azurerm_cdn_frontdoor_batch_rule_set - allow / as an input to rule.conditions.request_path.values (#​33023)
  • azurerm_databricks_workspace - remove a redundant key vault existence check (#​33136)
  • azurerm_databricks_workspace_root_dbfs_customer_managed_key - remove a redundant key vault existence check (#​33136)
  • azurerm_logic_app_standard - add support for v10.0 to site_config.dotnet_framework_version (#​33116)
  • azurerm_mongo_cluster - administrator_password is no longer required when create_mode is Default to support Entra ID-only authentication (#​32092)
  • azurerm_redhat_openshift_cluster - add support for the network_profile.load_balancer_profile block (#​32473)
  • azurerm_redhat_openshift_cluster - add support for the platform_workload_identity_profile block (#​32473)
  • azurerm_role_assignment - the condition, condition_version, and description properties can now be updated in-place (#​32714)
  • azurerm_snapshot - create_option now supports CopyStart (#​32834)

BUG FIXES:

  • azurerm_cognitive_account_project - added create/update/delete lock on parent AccountID to make sure operations on parent account are processed in serial (required by Cognitive service) (#​33151)
  • azurerm_databricks_workspace - fix a persistent diff on removal of managed_disk_cmk_key_vault_key_id or managed_services_cmk_key_vault_key_id (#​33136)
  • azurerm_oracle_exadata_infrastructure - fix an issue that prevented users from deploying with no zones set (#​33011)

v5.1.0

Compare Source

ENHANCEMENTS:

  • dependencies: azurerm_linux_virtual_machine_scale_set - update to API version 2025-04-01 (#​31586)
  • dependencies: azurerm_orchestrated_virtual_machine_scale_set - update to API version 2025-04-01 (#​31586)
  • dependencies: azurerm_virtual_machine_scale_set - update to API version 2025-04-01 (#​31586)
  • dependencies: azurerm_virtual_machine_scale_set_extension - update to API version 2025-04-01 (#​31586)
  • dependencies: azurerm_windows_virtual_machine_scale_set - update to API version 2025-04-01 (#​31586)
  • dependencies: codesigning - update to API version 2025-10-13 (#​31714)
  • azurerm_linux_virtual_machine - encryption_at_host_enabled can now be set to true when os_disk.security_encryption_type is set to DiskWithVMGuestState (#​32885)
  • azurerm_linux_virtual_machine_scale_set - encryption_at_host_enabled can now be set to true when os_disk.security_encryption_type is set to DiskWithVMGuestState (#​32885)
  • azurerm_managed_devops_pool - add support for the CreatorOnly value to azure_devops_organization.permission.kind property (#​32753)
  • azurerm_windows_virtual_machine - encryption_at_host_enabled can now be set to true when os_disk.security_encryption_type is set to DiskWithVMGuestState (#​32885)
  • azurerm_windows_virtual_machine_scale_set - encryption_at_host_enabled can now be set to true when os_disk.security_encryption_type is set to DiskWithVMGuestState (#​32885)

BUG FIXES:

  • azurerm_cdn_frontdoor_batch_ruleset - parse rule.actions.route_configuration_override.origin_group.cdn_frontdoor_origin_group_id case-insensitively and normalize the resulting value to prevent diffs (#​32980)
  • azurerm_cdn_frontdoor_route - parse cdn_frontdoor_origin_group_id case-insensitively and normalize the resulting value to prevent diffs (#​32980)
  • azurerm_cdn_frontdoor_secret - fix an incorrect type assertion (#​32982)
  • azurerm_dev_center_project - parse dev_center_id case-insensitively and normalize the resulting value to prevent diffs (#​32798)
  • azurerm_eventhub - now prevents the status property from being set to SendDisabled on create (#​33071)
  • azurerm_storage_container - add a state migration for the id field, fixing the upgrade path from 4.x to 5.x (#​32978)
  • azurerm_storage_queue - extend state migration to handle a malformed resource_manager_id (#​32979)
  • azurerm_storage_share - add a state migration for the id field, fixing the upgrade path from 4.x to 5.x (#​33075)

v5.0.1

Compare Source

NOTES:

In addition to the bug fixes below, a number of resource documentation pages and the 5.0-upgrade-guide have been updated.

BUG FIXES:

  • azurerm_cdn_frontdoor_origin - fix a regression that prevented valid values as input to private_link.private_link_target_id (#​32912)
  • azurerm_storage_queue - add a state migration for the id field, fixing the upgrade path from 4.x to 5.x (#​32914)
  • azurerm_storage_table_entity - add a state migration for the storage_table_id field, fixing the upgrade path from 4.x to 5.x (#​32929)

v5.0.0

Compare Source

NOTES:

  • Major Version: Version 5.0 of the Azure Provider is a major version - some behaviours have changed and some deprecated fields/resources have been removed - please refer to the 5.0 upgrade guide for more information.
  • When upgrading to v5.0 of the AzureRM Provider, we recommend upgrading to the latest version of Terraform Core (which can be found here).

FEATURES:

  • New Action: azurerm_web_app_set_slot_distribution (#​32364)
  • New Datasource adds azurerm_kubernetes_automatic_cluster_datasource (#​32881)

ENHANCEMENTS:

  • dependencies: grpc update to 1.82.1 (#​32852)
  • dependencies: loadbalancers - update to API version 2025-01-01 (#​32644)
  • azurerm_cognitive_account_rai_policy - the content_filter.severity_threshold property is now optional (#​32100)
  • azurerm_container_registry - the trust_policy_enabled property has been deprecated and removed from the provider (#​32752)
  • azurerm_dashboard_grafana - the 11 value for the grafana_major_version property has been deprecated and the property now supports 13 (#​32777)
  • azurerm_log_analytics_workspace - add support for the internet_ingestion_access_type and internet_query_access_type properties (#​32562)
  • azurerm_subnet - add support for the network_security_group_id_wo and network_security_group_id_wo_version properties (#​32847)
  • azurerm_subnet - add support for the route_table_id_wo and route_table_id_wo_version properties (#​32847)
  • azurerm_subnet - export the network_security_group_id property (#​32847)
  • azurerm_subnet - export the route_table_id property (#​32847)
  • azurerm_windows_web_app - add support for ~24 to site_config.application_stack.node_version (#​32840)
  • azurerm_windows_web_app_slot - add support for ~24 to site_config.application_stack.node_version (#​32840)
  • cdn - migrate to go-azure-sdk (#​32849)
  • sentinel - migrate to go-azure-sdk (#​32759)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@melanie-exygy

Copy link
Copy Markdown
Contributor

Here's the issue to track this update: civiform/civiform#13772

@renovate
renovate Bot force-pushed the renovate/azurerm-5.x branch 2 times, most recently from a6c41ba to 9e2c940 Compare August 20, 2026 20:01
@renovate
renovate Bot force-pushed the renovate/azurerm-5.x branch 3 times, most recently from 56c8511 to 0f6dd58 Compare September 3, 2026 23:39
@renovate
renovate Bot force-pushed the renovate/azurerm-5.x branch 3 times, most recently from a88f119 to 1dbdf6a Compare September 16, 2026 11:41
@renovate
renovate Bot force-pushed the renovate/azurerm-5.x branch 2 times, most recently from add4934 to 3b206b3 Compare September 23, 2026 17:09
@renovate
renovate Bot force-pushed the renovate/azurerm-5.x branch 2 times, most recently from 064e66f to 38287b6 Compare October 1, 2026 23:38
@renovate
renovate Bot force-pushed the renovate/azurerm-5.x branch from 38287b6 to 06ad965 Compare October 8, 2026 18:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant