chore(deps): update terraform minio to v3.43.0 - #1479
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/minio-3.x
branch
from
August 2, 2026 02:01
089f55e to
a6ca34d
Compare
renovate
Bot
force-pushed
the
renovate/minio-3.x
branch
from
August 3, 2026 21:47
a6ca34d to
ce625d6
Compare
renovate
Bot
force-pushed
the
renovate/minio-3.x
branch
from
August 4, 2026 13:41
ce625d6 to
022c417
Compare
renovate
Bot
force-pushed
the
renovate/minio-3.x
branch
from
August 26, 2026 18:42
022c417 to
5b6eeb7
Compare
renovate
Bot
force-pushed
the
renovate/minio-3.x
branch
from
September 3, 2026 22:48
5b6eeb7 to
3f1d5fa
Compare
renovate
Bot
force-pushed
the
renovate/minio-3.x
branch
from
September 12, 2026 01:13
3f1d5fa to
2ece48b
Compare
renovate
Bot
force-pushed
the
renovate/minio-3.x
branch
from
September 15, 2026 15:55
2ece48b to
8201f67
Compare
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.38.5→3.43.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
aminueza/terraform-provider-minio (minio)
v3.43.0Compare Source
Added
minio_access_keysdata source, which lists the access keys a server holdsgrouped by identity provider, with an optional
usersfilter. It reportsidentifiers and metadata only; the MinIO APIs behind it never return secret
material. The OpenID group covers both the credential a login mints and the
service accounts created under it, told apart by
kind, and it asks for everyconfigured OpenID provider rather than the default one alone.
identity_providersdefaults tobuiltin, because MinIO answers a listingrequest for an identity provider it does not run with an error rather than an
empty list
(#1144).
minio_kms_keysdata source, which lists the keys the configured KMS holdsand takes an optional
patternglob. Community MinIO serves key listingwhenever a KMS is configured, so this is not limited to AIStor
(#1145).
Changed
golang.org/x/syncfrom 0.22.0 to 0.23.0(#1165).
(#1167).
Fixed
minio_accesskeyno longer loses its attachedpolicywhen the secret isrotated. MinIO's
UpdateServiceAccountreads a request that omits the policyfield as "no session policy" and detaches whatever is attached, and the
provider sent status, secret and description changes as separate calls, none
of which carried the policy. Rotating a secret through
secret_key_wo_version, or changing only the status or the description, threwaway a policy the configuration never asked to remove. Clearing a policy on
purpose still works
(#1176).
v3.42.0Compare Source
Added
minio_sts_credentialsephemeral resource: mints temporary credentialsthrough STS AssumeRole without writing them to Terraform state. Use it to
configure another provider instance or to feed a write-only attribute.
duration_secondsaccepts 3600 or more, since the MinIO client libraryreplaces lower values with 3600. The resource requires a provider configured
with static credentials: it refuses to run when the provider uses
assume_role,assume_role_with_web_identityor a session token, because itwould otherwise issue credentials outside the scope those establish, and
MinIO rejects AssumeRole made with temporary credentials. Every Terraform
operation opens the resource and mints a new server-side session that lives
until it expires. Requires Terraform 1.10 or later
(#1146).
Changed
terraform-plugin-mux, combining theexisting SDKv2 resources and data sources with a plugin-framework half that
serves ephemeral resources. Every existing resource and data source is
unchanged; the provider now speaks protocol 6, which Terraform 1.0 and later
already negotiate.
Fixed
minio_sts_credentialsnow uses the provider TLS settings. The request wentout on the default HTTP client, so
minio_insecure,minio_cacert_file,minio_cert_file,minio_key_fileandrequest_timeout_secondswere allignored. Against a server with a private certificate authority the resource
failed with
x509: certificate signed by unknown authoritywhile every otherresource worked. The request now also stops when Terraform is interrupted
(#1151).
MINIO_REQUEST_TIMEOUT_SECONDS,MINIO_MAX_RETRIESandMINIO_RETRY_DELAY_MSnow set
request_timeout_seconds,max_retriesandretry_delay_ms. Thethree attributes declared a static default beside the environment lookup, and
the static default won, so the variables never took effect. A deployment that
already sets one of them gets the value it asked for after this upgrade, where
before it got 30, 6 and 1000
(#1149).
provider,
destroyincluded, instead of being ignored. The error names thevariable:
MINIO_MAX_RETRIES must be a whole number, got "abc".request_timeout_secondsof 0 or less falls back to 30. It used to reach theHTTP transport, where every call then failed with a misleading
i/o timeout.minio_health_statusfell back to 10 seconds in that case and now uses 30 too.retry_delay_msis not the base delay between retries, as its descriptionsaid. It caps the wait at 20 times its value in milliseconds, and the wait
itself is random and doubles with each attempt. The description and the
documentation now say so. The retry behaviour is unchanged.
v3.41.1Compare Source
Changed
github.com/minio/madmin-go/v4from 4.10.3 to 4.10.5(#1130).
golang.org/x/cryptofrom 0.55.0 to 0.56.0(#1137).
google.golang.org/grpcfrom 1.82.1 to 1.83.1(#1136).
Fixed
TestAccMinioIAMUser_importtrailing plans deterministic(#1129).
v3.41.0Compare Source
Changed
minio_iam_group: changingnamenow recreates the group (ForceNew).MinIO has no rename operation; before this change a rename was silently
ignored and Terraform state diverged from the server
(#1127).
Fixed
minio_iam_group:force_destroynow actually deletes a group that still hasmembers, and no longer fires during ordinary updates (previously an apply that
changed any other attribute on a group carrying the flag deleted the group and
failed with
Provider produced inconsistent result after apply) (#1113).minio_iam_group: deleting a group that still has members now waits for themembership to clear and then fails with a clear error pointing at
force_destroy, instead of silently leaving the group behind on the server(#1109).
error updating IAM Group %s: %s; twenty-one messages across IAM group,IAM user, service account and bucket policy resources now state the
operation plainly (#1121).
minio_config_historyandminio_license_inforeads against servers thatdo not serve those admin APIs (community MinIO) now return within seconds
instead of retrying for minutes before reporting the graceful fallback
(#1126).
v3.40.1Compare Source
Terraform Provider MinIO v3.40.1
To install this provider, copy and paste this code into your Terraform configuration:
What's Changed
🐛 Bug Fixes
📖 Documentation
🧪 Tests
Full Changelog: aminueza/terraform-provider-minio@v3.40.0...v3.40.1
v3.40.0Compare Source
Terraform Provider MinIO v3.40.0
To install this provider, copy and paste this code into your Terraform configuration:
What's Changed
Security
minio_s3_bucket_anonymous_accesswithaccess_type = "public"no longer grants anonymous clientss3:PutBucketPolicy,s3:DeleteBucketPolicy,s3:DeleteBucket,s3:CreateBucket,s3:GetBucketPolicyor the bucket notification actions. Before this fix, any unauthenticated client could rewrite the bucket policy or delete the bucket. Re-apply your configuration to replace the old policy; anonymous object read/write access is unchanged.Other Changes
Full Changelog: aminueza/terraform-provider-minio@v3.39.0...v3.40.0
v3.39.0Compare Source
Terraform Provider MinIO v3.39.0
To install this provider, copy and paste this code into your Terraform configuration:
What's Changed
🐛 Bug Fixes
madmin-go/v4for MinIO admin API v4 support by @aminueza in #1074Full Changelog: aminueza/terraform-provider-minio@v3.38.6...v3.39.0
v3.38.6Compare Source
Terraform Provider MinIO v3.38.6
To install this provider, copy and paste this code into your Terraform configuration:
What's Changed
🐛 Bug Fixes
📖 Documentation
🔧 Maintenance
🧪 Tests
Other Changes
Full Changelog: aminueza/terraform-provider-minio@v3.38.5...v3.38.6
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.