This PR contains the following updates: | Package | Type | Update | Change | Pending | |---|---|---|---|---| | [azurerm](https://registry.terraform.io/providers/hashicorp/azurerm) ([source](https://github.com/hashicorp/terraform-provider-azurerm)) | required_provider | major | `~> 4.0` → `~> 5.0` | `5.8.0` | --- ### Release Notes <details> <summary>hashicorp/terraform-provider-azurerm (azurerm)</summary> ### [`v5.7.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#570-September-24-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.6.0...v5.7.0) FEATURES: - **New List Resource**: `azurerm_private_dns_resolver_forwarding_rule` ([#​33313](https://github.com/hashicorp/terraform-provider-azurerm/issues/33313)) - **New List Resource**: `azurerm_windows_virtual_machine` ([#​33332](https://github.com/hashicorp/terraform-provider-azurerm/issues/33332)) ENHANCEMENTS: - dependencies: `go-azure-sdk` - update to `v0.20260917.1142820` ([#​33495](https://github.com/hashicorp/terraform-provider-azurerm/issues/33495)) - dependencies: `network` - update API version to `2025-07-01` ([#​33441](https://github.com/hashicorp/terraform-provider-azurerm/issues/33441)) - Data Source: `azurerm_linux_web_app` - export the `virtual_network_image_pull_enabled` property ([#​33316](https://github.com/hashicorp/terraform-provider-azurerm/issues/33316)) - Data Source: `azurerm_network_interface` - export the `auxiliary_mode`, `auxiliary_sku`, `edge_zone`, and `internal_domain_name_suffix` properties ([#​33204](https://github.com/hashicorp/terraform-provider-azurerm/issues/33204)) - Data Source: `azurerm_public_ip` - export the `domain_name_label_scope`, `edge_zone`, `public_ip_prefix_id`, and `sku_tier` properties ([#​33193](https://github.com/hashicorp/terraform-provider-azurerm/issues/33193)) - Data Source: `azurerm_service_plan` - export the `premium_plan_auto_scale_enabled` property ([#​33300](https://github.com/hashicorp/terraform-provider-azurerm/issues/33300)) - Data Source: `azurerm_storage_blob` - export the `cache_control` and `source_uri` properties ([#​33318](https://github.com/hashicorp/terraform-provider-azurerm/issues/33318)) - Data Source: `azurerm_traffic_manager_profile` - export the `maximum_return` property ([#​33346](https://github.com/hashicorp/terraform-provider-azurerm/issues/33346)) - Data Source: `azurerm_web_pubsub` - export the `live_trace` and `identity` properties ([#​33373](https://github.com/hashicorp/terraform-provider-azurerm/issues/33373)) - `azurerm_kubernetes_cluster_node_pool` - add `Windows2025` as a valid value for the `os_sku` property ([#​33463](https://github.com/hashicorp/terraform-provider-azurerm/issues/33463)) - `azurerm_kubernetes_cluster` - add `Windows2025` as a valid value for the `os_sku` property ([#​33463](https://github.com/hashicorp/terraform-provider-azurerm/issues/33463)) BUG FIXES: - Data Source: `azurerm_kubernetes_cluster` - fix a panic caused by a nil pointer dereference while flattening `agent_pool_profile` ([#​33488](https://github.com/hashicorp/terraform-provider-azurerm/issues/33488)) - `azurerm_postgresql_flexible_server` - fix `cluster` block read for replica `create_mode` ([#​33082](https://github.com/hashicorp/terraform-provider-azurerm/issues/33082)) ### [`v5.6.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#560-September-17-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.5.0...v5.6.0) FEATURES: - **New List Resource**: `azurerm_batch_account` ([#​33252](https://github.com/hashicorp/terraform-provider-azurerm/issues/33252)) - **New List Resource**: `azurerm_cdn_frontdoor_origin_group` ([#​33334](https://github.com/hashicorp/terraform-provider-azurerm/issues/33334)) - **New Resource**: `azurerm_storage_discovery_workspace` ([#​31479](https://github.com/hashicorp/terraform-provider-azurerm/issues/31479)) ENHANCEMENTS: - dependencies: `containers` - update API version to `2026-05-01` ([#​32688](https://github.com/hashicorp/terraform-provider-azurerm/issues/32688)) - dependencies: `go-azure-sdk` - update to `v0.20260910.1141000` ([#​33413](https://github.com/hashicorp/terraform-provider-azurerm/issues/33413)) - dependencies: `qumulo` - update API version to `2026-04-16` ([#​33421](https://github.com/hashicorp/terraform-provider-azurerm/issues/33421)) - dependencies: `servicebus` - update to API version `2026-01-01` ([#​33450](https://github.com/hashicorp/terraform-provider-azurerm/issues/33450)) - `azurerm_iothub_device_update_instance` - add support for the `connection_string_wo` and `connection_string_wo_version` properties ([#​33448](https://github.com/hashicorp/terraform-provider-azurerm/issues/33448)) - `azurerm_linux_function_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_linux_function_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_linux_web_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_linux_web_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_mongo_cluster` - Support new property `network_bypass_mode` ([#​33168](https://github.com/hashicorp/terraform-provider-azurerm/issues/33168)) - `azurerm_servicebus_namespace` - add support for the `1.3` value to the `minimum_tls_version` property ([#​33457](https://github.com/hashicorp/terraform-provider-azurerm/issues/33457)) - `azurerm_windows_function_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_windows_function_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_windows_web_app` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) - `azurerm_windows_web_app_slot` - add support for the `end_to_end_tls_encryption_enabled` property ([#​31135](https://github.com/hashicorp/terraform-provider-azurerm/issues/31135)) BUG FIXES: - `azurerm_site_recovery_replicated_vm` - select `managed_disk` properties compared case insensitive ([#​33424](https://github.com/hashicorp/terraform-provider-azurerm/issues/33424)) ### [`v5.5.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#550-September-10-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.4.0...v5.5.0) FEATURES: - **New List Resource**: `azurerm_analysis_services_server` ([#​33250](https://github.com/hashicorp/terraform-provider-azurerm/issues/33250)) - **New List Resource**: `azurerm_application_insights_workbook` ([#​33244](https://github.com/hashicorp/terraform-provider-azurerm/issues/33244)) - **New List Resource**: `azurerm_attestation_provider` ([#​33251](https://github.com/hashicorp/terraform-provider-azurerm/issues/33251)) - **New List Resource**: `azurerm_cdn_frontdoor_origin` ([#​33307](https://github.com/hashicorp/terraform-provider-azurerm/issues/33307)) - **New List Resource**: `azurerm_eventhub_consumer_group` ([#​33335](https://github.com/hashicorp/terraform-provider-azurerm/issues/33335)) - **New List Resource**: `azurerm_linux_virtual_machine` ([#​33333](https://github.com/hashicorp/terraform-provider-azurerm/issues/33333)) - **New List Resource**: `azurerm_virtual_hub_connection` ([#​33311](https://github.com/hashicorp/terraform-provider-azurerm/issues/33311)) ENHANCEMENTS: - dependencies: `go-azure-sdk` - update to `v0.20260901.1173158` ([#​33274](https://github.com/hashicorp/terraform-provider-azurerm/issues/33274)) - `azurerm_private_endpoint` - lock on private service connection resource ids ([#​33298](https://github.com/hashicorp/terraform-provider-azurerm/issues/33298)) - `azurerm_storage_account` - add support for the `public_network_access` property ([#​33292](https://github.com/hashicorp/terraform-provider-azurerm/issues/33292)) BUG FIXES: - `azurerm_resource_group` - the `managed_by` property now forces recreation when changed as the API does not support changing this value ([#​33339](https://github.com/hashicorp/terraform-provider-azurerm/issues/33339)) - `go-azure-sdk` - `Delete` operations now poll on asynchronous operation URLs if returned by the API instead of only checking for a `404` on the resource URL, ensuring deletion errors are reported to the user ([#​33274](https://github.com/hashicorp/terraform-provider-azurerm/issues/33274)) ### [`v5.4.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#540-September-03-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.3.0...v5.4.0) FEATURES: - **New List Resource**: `azurerm_application_insights_standard_web_test` ([#​33243](https://github.com/hashicorp/terraform-provider-azurerm/issues/33243)) - **New List Resource**: `azurerm_application_insights_workbook_template` ([#​33245](https://github.com/hashicorp/terraform-provider-azurerm/issues/33245)) - **New List Resource**: `azurerm_arc_kubernetes_provisioned_cluster` ([#​33247](https://github.com/hashicorp/terraform-provider-azurerm/issues/33247)) - **New List Resource**: `azurerm_availability_set` ([#​33241](https://github.com/hashicorp/terraform-provider-azurerm/issues/33241)) - **New List Resource**: `azurerm_batch_application` ([#​33254](https://github.com/hashicorp/terraform-provider-azurerm/issues/33254)) - **New List Resource**: `azurerm_dedicated_host_group` ([#​33257](https://github.com/hashicorp/terraform-provider-azurerm/issues/33257)) - **New List Resource**: `azurerm_log_analytics_workspace` ([#​33259](https://github.com/hashicorp/terraform-provider-azurerm/issues/33259)) ENHANCEMENTS: - dependencies: `azurerm_mongo_cluster` - update API version to `2026-06-01` ([#​33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195)) - dependencies: `azurerm_mongo_cluster_firewall_rule` - update API version to `2026-06-01` ([#​33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195)) - dependencies: `azurerm_mongo_cluster_user` - update API version to `2026-06-01` ([#​33195](https://github.com/hashicorp/terraform-provider-azurerm/issues/33195)) - dependencies: `netapp` - update API version to `2026-05-01` ([#​33215](https://github.com/hashicorp/terraform-provider-azurerm/issues/33215)) - Data Source: `azurerm_api_management_workspace` - export the `description` property ([#​33205](https://github.com/hashicorp/terraform-provider-azurerm/issues/33205)) - Data Source: `azurerm_attestation_provider` - export the `sev_snp_policy_base64`, `open_enclave_policy_base64`, `sgx_enclave_policy_base64`, and `tpm_policy_base64` properties ([#​33125](https://github.com/hashicorp/terraform-provider-azurerm/issues/33125)) - Data Source: `azurerm_automation_account` - export the `dsc_primary_access_key`, `dsc_server_endpoint`, `dsc_secondary_access_key`, `public_network_access_enabled`, `sku_name`, and `tags` properties ([#​33135](https://github.com/hashicorp/terraform-provider-azurerm/issues/33135)) - Data Source: `azurerm_automation_account` - export the `encryption` block ([#​33135](https://github.com/hashicorp/terraform-provider-azurerm/issues/33135)) - Data Source: `azurerm_ip_group` - export the `firewall_ids` and `firewall_policy_ids` properties ([#​33190](https://github.com/hashicorp/terraform-provider-azurerm/issues/33190)) - Data Source: `azurerm_private_link_service` - export the `fqdns` and `destination_ip_address` properties ([#​33191](https://github.com/hashicorp/terraform-provider-azurerm/issues/33191)) - `azurerm_key_vault_managed_hardware_security_module_key` - allow the `key_size` property to be set when `key_type` is `oct-HSM` ([#​32690](https://github.com/hashicorp/terraform-provider-azurerm/issues/32690)) - `azurerm_lb_probe ` - add support for the `no_healthy_backends_behavior` property ([#​32645](https://github.com/hashicorp/terraform-provider-azurerm/issues/32645)) - `azurerm_linux_virtual_machine_scale_set` - add support for the `NvmeDisk` value to the `os_disk.diff_disk_settings.placement` property ([#​30328](https://github.com/hashicorp/terraform-provider-azurerm/issues/30328)) - `azurerm_linux_web_app` - add support for the `8.5` value in the `site_config.application_stack.php_version` property ([#​33308](https://github.com/hashicorp/terraform-provider-azurerm/issues/33308)) - `azurerm_linux_web_app_slot` - add support for the `8.5` value in the `site_config.application_stack.php_version` property ([#​33308](https://github.com/hashicorp/terraform-provider-azurerm/issues/33308)) - `azurerm_netapp_volume` - support for the `breakthrough_mode_enabled` property ([#​33215](https://github.com/hashicorp/terraform-provider-azurerm/issues/33215)) - `azurerm_postgresql_flexible_server` - add support for the `storage_type`, `storage_iops`, and `storage_throughput` properties which allows choice of the new "Premium V2 LRS" storage type ([#​32121](https://github.com/hashicorp/terraform-provider-azurerm/issues/32121)) - `azurerm_storage_account` - add support for an in-place migration of `account_replication_type` between matching non-zonal and zonal types instead of resource recreation ([#​33236](https://github.com/hashicorp/terraform-provider-azurerm/issues/33236)) - `azurerm_storage_table` - add support for AAD authentication ([#​32997](https://github.com/hashicorp/terraform-provider-azurerm/issues/32997)) - `azurerm_synapse_spark_pool` - migrate to `go-azure-sdk` ([#​33258](https://github.com/hashicorp/terraform-provider-azurerm/issues/33258)) - `azurerm_windows_virtual_machine_scale_set` - add support for the `NvmeDisk` value to the `os_disk.diff_disk_settings.placement` property ([#​30328](https://github.com/hashicorp/terraform-provider-azurerm/issues/30328)) BUG FIXES: - `azurerm_synapse_spark_pool` - fix `lifecycle.ignore_changes` support ([#​33258](https://github.com/hashicorp/terraform-provider-azurerm/issues/33258)) ### [`v5.3.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#530-August-27-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.2.0...v5.3.0) FEATURES: - **New Data Source**: `azurerm_playwright_workspace` ([#​31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954)) - **New List Resource**: `azurerm_cognitive_deployment` ([#​33149](https://github.com/hashicorp/terraform-provider-azurerm/issues/33149)) - **New List Resource**: `azurerm_playwright_workspace` ([#​31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954)) - **New Resource**: `azurerm_playwright_workspace` ([#​31954](https://github.com/hashicorp/terraform-provider-azurerm/issues/31954)) ENHANCEMENTS: - dependencies: `go-azure-helpers` - update version to `0.82.0` ([#​33142](https://github.com/hashicorp/terraform-provider-azurerm/issues/33142)) - dependencies: `sql` - update API version to `2025-01-01` ([#​33201](https://github.com/hashicorp/terraform-provider-azurerm/issues/33201)) - Data Source: `azurerm_role_definition` - export the `role_definition_resource_id` property ([#​33126](https://github.com/hashicorp/terraform-provider-azurerm/issues/33126)) - `azurerm_cognitive_deployment` - add Resource Identity support ([#​33149](https://github.com/hashicorp/terraform-provider-azurerm/issues/33149)) - `azurerm_federated_identity_credential` - add additional polling to account for Azure's eventual consistency ([#​32935](https://github.com/hashicorp/terraform-provider-azurerm/issues/32935)) - `azurerm_kubernetes_cluster` - add support for the `oms_agent.retina_flow_logs_enabled` property ([#​33222](https://github.com/hashicorp/terraform-provider-azurerm/issues/33222)) - `azurerm_managed_application` - add support for the `identity` block ([#​30725](https://github.com/hashicorp/terraform-provider-azurerm/issues/30725)) - `azurerm_private_endpoint` - extend validation for the `private_service_connection.subresource_names` property to allow names containing spaces ([#​32887](https://github.com/hashicorp/terraform-provider-azurerm/issues/32887)) - `azurerm_search_service` - allow in-place downgrades of the `sku` property between Basic and Standard tiers ([#​33069](https://github.com/hashicorp/terraform-provider-azurerm/issues/33069)) - `azurerm_site_recovery_replicated_vm` - add update support to the `managed_disk` block without requiring resource recreation ([#​33140](https://github.com/hashicorp/terraform-provider-azurerm/issues/33140)) - `azurerm_user_assigned_identity` - add additional polling to account for Azure's eventual consistency ([#​33142](https://github.com/hashicorp/terraform-provider-azurerm/issues/33142)) BUG FIXES: - Data Source: `azurerm_app_configuration_key` - now correctly sets `tags` into state ([#​33182](https://github.com/hashicorp/terraform-provider-azurerm/issues/33182)) - `azurerm_eventhub_namespace` - prevent `network_rulesets.x.default_action` being set to `Deny` if `ip_rule` or `virtual_network_rule` is not specified ([#​33216](https://github.com/hashicorp/terraform-provider-azurerm/issues/33216)) ### [`v5.2.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#520-August-20-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.1.0...v5.2.0) FEATURES: - **New List Resource**: `azurerm_user_assigned_identity` ([#​32667](https://github.com/hashicorp/terraform-provider-azurerm/issues/32667)) ENHANCEMENTS: - dependencies: `go` - update to `1.26.6` ([#​33141](https://github.com/hashicorp/terraform-provider-azurerm/issues/33141)) - dependencies: `go-azure-sdk` - update to `v0.20260811.1225050` ([#​33079](https://github.com/hashicorp/terraform-provider-azurerm/issues/33079)) - `azurerm_cdn_frontdoor_batch_rule_set` - allow `/` as an input to `rule.conditions.request_path.values` ([#​33023](https://github.com/hashicorp/terraform-provider-azurerm/issues/33023)) - `azurerm_databricks_workspace` - remove a redundant key vault existence check ([#​33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136)) - `azurerm_databricks_workspace_root_dbfs_customer_managed_key` - remove a redundant key vault existence check ([#​33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136)) - `azurerm_logic_app_standard` - add support for `v10.0` to `site_config.dotnet_framework_version` ([#​33116](https://github.com/hashicorp/terraform-provider-azurerm/issues/33116)) - `azurerm_mongo_cluster` - `administrator_password` is no longer required when `create_mode` is `Default` to support Entra ID-only authentication ([#​32092](https://github.com/hashicorp/terraform-provider-azurerm/issues/32092)) - `azurerm_redhat_openshift_cluster` - add support for the `network_profile.load_balancer_profile` block ([#​32473](https://github.com/hashicorp/terraform-provider-azurerm/issues/32473)) - `azurerm_redhat_openshift_cluster` - add support for the `platform_workload_identity_profile` block ([#​32473](https://github.com/hashicorp/terraform-provider-azurerm/issues/32473)) - `azurerm_role_assignment` - the `condition`, `condition_version`, and `description` properties can now be updated in-place ([#​32714](https://github.com/hashicorp/terraform-provider-azurerm/issues/32714)) - `azurerm_snapshot` - `create_option` now supports `CopyStart` ([#​32834](https://github.com/hashicorp/terraform-provider-azurerm/issues/32834)) BUG FIXES: - `azurerm_cognitive_account_project` - added create/update/delete lock on parent AccountID to make sure operations on parent account are processed in serial (required by Cognitive service) ([#​33151](https://github.com/hashicorp/terraform-provider-azurerm/issues/33151)) - `azurerm_databricks_workspace` - fix a persistent diff on removal of `managed_disk_cmk_key_vault_key_id` or `managed_services_cmk_key_vault_key_id` ([#​33136](https://github.com/hashicorp/terraform-provider-azurerm/issues/33136)) - `azurerm_oracle_exadata_infrastructure` - fix an issue that prevented users from deploying with no `zones` set ([#​33011](https://github.com/hashicorp/terraform-provider-azurerm/issues/33011)) ### [`v5.1.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#510-August-13-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.0.1...v5.1.0) ENHANCEMENTS: - dependencies: `azurerm_linux_virtual_machine_scale_set` - update to API version `2025-04-01` ([#​31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586)) - dependencies: `azurerm_orchestrated_virtual_machine_scale_set` - update to API version `2025-04-01` ([#​31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586)) - dependencies: `azurerm_virtual_machine_scale_set` - update to API version `2025-04-01` ([#​31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586)) - dependencies: `azurerm_virtual_machine_scale_set_extension` - update to API version `2025-04-01` ([#​31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586)) - dependencies: `azurerm_windows_virtual_machine_scale_set` - update to API version `2025-04-01` ([#​31586](https://github.com/hashicorp/terraform-provider-azurerm/issues/31586)) - dependencies: `codesigning` - update to API version `2025-10-13` ([#​31714](https://github.com/hashicorp/terraform-provider-azurerm/issues/31714)) - `azurerm_linux_virtual_machine` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#​32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885)) - `azurerm_linux_virtual_machine_scale_set` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#​32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885)) - `azurerm_managed_devops_pool` - add support for the `CreatorOnly` value to `azure_devops_organization.permission.kind` property ([#​32753](https://github.com/hashicorp/terraform-provider-azurerm/issues/32753)) - `azurerm_windows_virtual_machine` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#​32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885)) - `azurerm_windows_virtual_machine_scale_set` - `encryption_at_host_enabled` can now be set to `true` when `os_disk.security_encryption_type` is set to `DiskWithVMGuestState` ([#​32885](https://github.com/hashicorp/terraform-provider-azurerm/issues/32885)) BUG FIXES: - `azurerm_cdn_frontdoor_batch_ruleset` - parse `rule.actions.route_configuration_override.origin_group.cdn_frontdoor_origin_group_id` case-insensitively and normalize the resulting value to prevent diffs ([#​32980](https://github.com/hashicorp/terraform-provider-azurerm/issues/32980)) - `azurerm_cdn_frontdoor_route` - parse `cdn_frontdoor_origin_group_id` case-insensitively and normalize the resulting value to prevent diffs ([#​32980](https://github.com/hashicorp/terraform-provider-azurerm/issues/32980)) - `azurerm_cdn_frontdoor_secret` - fix an incorrect type assertion ([#​32982](https://github.com/hashicorp/terraform-provider-azurerm/issues/32982)) - `azurerm_dev_center_project` - parse `dev_center_id` case-insensitively and normalize the resulting value to prevent diffs ([#​32798](https://github.com/hashicorp/terraform-provider-azurerm/issues/32798)) - `azurerm_eventhub` - now prevents the `status` property from being set to `SendDisabled` on create ([#​33071](https://github.com/hashicorp/terraform-provider-azurerm/issues/33071)) - `azurerm_storage_container` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#​32978](https://github.com/hashicorp/terraform-provider-azurerm/issues/32978)) - `azurerm_storage_queue` - extend state migration to handle a malformed `resource_manager_id` ([#​32979](https://github.com/hashicorp/terraform-provider-azurerm/issues/32979)) - `azurerm_storage_share` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#​33075](https://github.com/hashicorp/terraform-provider-azurerm/issues/33075)) ### [`v5.0.1`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#501-July-30-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v5.0.0...v5.0.1) NOTES: In addition to the bug fixes below, a number of resource documentation pages and the 5.0-upgrade-guide have been updated. BUG FIXES: - `azurerm_cdn_frontdoor_origin` - fix a regression that prevented valid values as input to `private_link.private_link_target_id` ([#​32912](https://github.com/hashicorp/terraform-provider-azurerm/issues/32912)) - `azurerm_storage_queue` - add a state migration for the `id` field, fixing the upgrade path from 4.x to 5.x ([#​32914](https://github.com/hashicorp/terraform-provider-azurerm/issues/32914)) - `azurerm_storage_table_entity` - add a state migration for the `storage_table_id` field, fixing the upgrade path from 4.x to 5.x ([#​32929](https://github.com/hashicorp/terraform-provider-azurerm/issues/32929)) ### [`v5.0.0`](https://github.com/hashicorp/terraform-provider-azurerm/blob/HEAD/CHANGELOG.md#500-July-27-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-azurerm/compare/v4.81.0...v5.0.0) NOTES: - **Major Version**: Version 5.0 of the Azure Provider is a major version - some behaviours have changed and some deprecated fields/resources have been removed - please refer to [the 5.0 upgrade guide for more information](https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/guides/5.0-upgrade-guide). - When upgrading to v5.0 of the AzureRM Provider, we recommend upgrading to the latest version of Terraform Core ([which can be found here](https://developer.hashicorp.com/terraform/install)). FEATURES: - **New Action**: `azurerm_web_app_set_slot_distribution` ([#​32364](https://github.com/hashicorp/terraform-provider-azurerm/issues/32364)) - **New Datasource** adds `azurerm_kubernetes_automatic_cluster_datasource` ([#​32881](https://github.com/hashicorp/terraform-provider-azurerm/issues/32881)) ENHANCEMENTS: - dependencies: `grpc` update to `1.82.1` ([#​32852](https://github.com/hashicorp/terraform-provider-azurerm/issues/32852)) - dependencies: `loadbalancers` - update to API version `2025-01-01` ([#​32644](https://github.com/hashicorp/terraform-provider-azurerm/issues/32644)) - `azurerm_cognitive_account_rai_policy` - the `content_filter.severity_threshold` property is now optional ([#​32100](https://github.com/hashicorp/terraform-provider-azurerm/issues/32100)) - `azurerm_container_registry` - the `trust_policy_enabled` property has been deprecated and removed from the provider ([#​32752](https://github.com/hashicorp/terraform-provider-azurerm/issues/32752)) - `azurerm_dashboard_grafana` - the `11` value for the `grafana_major_version` property has been deprecated and the property now supports `13` ([#​32777](https://github.com/hashicorp/terraform-provider-azurerm/issues/32777)) - `azurerm_log_analytics_workspace` - add support for the `internet_ingestion_access_type` and `internet_query_access_type` properties ([#​32562](https://github.com/hashicorp/terraform-provider-azurerm/issues/32562)) - `azurerm_subnet` - add support for the `network_security_group_id_wo` and `network_security_group_id_wo_version` properties ([#​32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847)) - `azurerm_subnet` - add support for the `route_table_id_wo` and `route_table_id_wo_version` properties ([#​32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847)) - `azurerm_subnet` - export the `network_security_group_id` property ([#​32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847)) - `azurerm_subnet` - export the `route_table_id` property ([#​32847](https://github.com/hashicorp/terraform-provider-azurerm/issues/32847)) - `azurerm_windows_web_app` - add support for `~24` to `site_config.application_stack.node_version` ([#​32840](https://github.com/hashicorp/terraform-provider-azurerm/issues/32840)) - `azurerm_windows_web_app_slot` - add support for `~24` to `site_config.application_stack.node_version` ([#​32840](https://github.com/hashicorp/terraform-provider-azurerm/issues/32840)) - `cdn` - migrate to `go-azure-sdk` ([#​32849](https://github.com/hashicorp/terraform-provider-azurerm/issues/32849)) - `sentinel` - migrate to `go-azure-sdk` ([#​32759](https://github.com/hashicorp/terraform-provider-azurerm/issues/32759)) </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==--> --------- Co-authored-by: Renovate Bot <renovate@forteapps.net> Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/55 Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com> Co-authored-by: gitea_admin <admin@forteapps.net>
Kubernetes Cluster - GitOps Configuration
Kubernetes cluster bootstrapping and GitOps configuration repository using ArgoCD for multi-cloud Kubernetes (UpCloud, AWS EKS, Azure AKS, GCP GKE)
📚 Complete Documentation
New developers and operators: Please refer to our comprehensive documentation for detailed guides and references:
🎯 START HERE: Documentation Index
| Document | Description | Audience |
|---|---|---|
| GitOps Architecture | System architecture, repository structure, GitOps workflows, security model | Everyone (start here) |
| Developer Guide | Local setup, deploying apps, managing secrets, troubleshooting | Developers |
| Operations Runbook | Cluster bootstrap, day-to-day operations, incident response, maintenance | Platform Engineers, SREs |
| Technical Reference | Component specs, Helm charts, ArgoCD config, Kyverno policies, API docs | Everyone (reference) |
🚀 Quick Start
For New Developers
# 1. Clone repositories
git clone https://git.forteapps.net/Forte/launchpad.git
git clone ssh://git@git.forteapps.net:2222/Forte/helm-prod-values.git
# 2. Read the guides
# - Start: docs/GITOPS-ARCHITECTURE.md
# - Follow: docs/DEVELOPER-GUIDE.md
# 3. Deploy your first app (see Developer Guide)
For Operators
# 1. Bootstrap new cluster
./bootstrap.sh
# 2. Verify deployment
kubectl get applications -n argocd
kubectl get pods --all-namespaces
# 3. Read Operations Runbook for day-to-day tasks
📋 Overview
This repository contains the complete GitOps configuration for our Kubernetes cluster, using the App-of-Apps pattern with ArgoCD.
What's Inside
- Infrastructure Applications: Traefik, Cert-Manager, Kyverno, Prometheus, Grafana, Loki, Tempo, Sealed Secrets, Homepage (platform dashboard)
- Business Applications: MCP10X, MusicMan, Dot-AI Stack, ArgoCD MCP
- Policies: Kyverno security policies for secret management, namespace controls, pod verification
- Monitoring: Full observability stack with metrics, logs, traces, and alerting
- Secrets: Sealed Secrets for secure Git storage
Key Features
✅ GitOps-Native: Git is the single source of truth ✅ Auto-Sync: Changes automatically deployed (60s reconciliation) ✅ Self-Healing: Manual cluster changes are reverted ✅ Multi-Source: Separate chart templates from configuration ✅ Policy Enforcement: Kyverno ensures security and compliance ✅ Authentication: Automatic sidecar injection (token & OIDC support) ✅ TLS Everywhere: Automatic Let's Encrypt certificates ✅ Full Observability: Prometheus, Grafana, Loki, Tempo integration
🗂️ Repository Structure
.
├── bootstrap.sh # Cluster initialization (ArgoCD + GitOps)
├── _app-of-apps-{cluster}.yaml # Root ArgoCD Application (per cluster)
│
├── .tofu/ # Infrastructure provisioning (OpenTofu)
│ ├── platforms/ # Per-platform IaC (one dir per cloud)
│ │ ├── aks/ # Azure AKS (modules/ + dev/ + prod/ + workload/)
│ │ ├── eks/ # AWS EKS
│ │ ├── gke/ # GCP GKE
│ │ └── upc/ # UpCloud
│ ├── configs/ # Platform credentials (git-ignored)
│ │ └── *.env.example # Template for each platform
│ └── scripts/ # Cluster lifecycle scripts
│ ├── setup-cluster.sh # Create cluster: ./setup-cluster.sh aks-dev
│ ├── teardown-cluster.sh
│ └── get-kubeconfig.sh
│
├── clusters/ # Cluster metadata (domain, trustedIPs, etc.)
│
├── infra/ # Infrastructure ArgoCD Applications (Kustomize multi-cluster)
│ ├── base/ # Base ArgoCD Application manifests (one dir per component)
│ │ ├── kustomization.yaml # Aggregates all component subdirectories
│ │ ├── traefik-application/
│ │ │ ├── kustomization.yaml
│ │ │ └── traefik-application.yaml
│ │ ├── keycloak/
│ │ │ ├── kustomization.yaml
│ │ │ └── keycloak.yaml
│ │ ├── grafana/
│ │ ├── prometheus/
│ │ ├── ... # Each component in its own subdirectory
│ │ └── secrets/
│ ├── overlays/ # Per-cluster overrides (Kustomize)
│ │ ├── upc-dev/ # UpCloud Dev — includes all base components
│ │ ├── upc-prod/ # UpCloud Prod — all components + patches
│ │ ├── aks-dev/ # Azure AKS Dev — selective components only
│ │ ├── aks-prod/ # Azure AKS Prod
│ │ ├── eks-dev/ # AWS EKS Dev
│ │ ├── eks-prod/ # AWS EKS Prod
│ │ ├── gke-dev/ # GCP GKE Dev
│ │ └── gke-prod/ # GCP GKE Prod
│ ├── dashboards/ # Grafana dashboard ConfigMaps
│ └── values/ # Helm value overrides
│ ├── base/ # Shared cloud-agnostic values
│ ├── upc-dev/ # UpCloud Dev (storage, LB, pricing)
│ ├── upc-prod/ # UpCloud Prod
│ ├── eks-dev/ # AWS EKS Dev
│ ├── eks-prod/ # AWS EKS Prod
│ ├── aks-dev/ # Azure AKS Dev
│ ├── aks-prod/ # Azure AKS Prod
│ ├── gke-dev/ # GCP GKE Dev
│ └── gke-prod/ # GCP GKE Prod
│
├── apps/ # Business Applications (Kustomize, same pattern as infra)
│ ├── base/ # One subdirectory per app
│ │ ├── kustomization.yaml
│ │ ├── musicman/
│ │ ├── mcp10x/
│ │ ├── dot-ai-stack/
│ │ ├── ts-mcp/
│ │ └── argo-mcp/
│ └── overlays/ # Per-cluster: cherry-pick or include all
│ ├── upc-dev/ # All apps
│ ├── upc-prod/ # All apps + patches
│ └── aks-dev/ # Selective apps only
│
├── cluster-resources/ # Cluster-wide Kubernetes resources
│ ├── letsencrypt-issuer.yaml
│ ├── kyverno-config.yaml
│ ├── *-sealed.yaml # Sealed secrets
│ └── policies/ # Kyverno policies
│ ├── secret-cloner.yaml
│ ├── default-ns-blocker.yaml
│ ├── bare-pod-cleaner.yaml
│ └── auth-sidecar-injector.yaml
│
├── secrets/ # Application secrets (sealed)
│ └── *-credentials-sealed.yaml
│
├── private/ # Local-only files (Git-ignored)
│ └── *.yaml # Unsealed secrets (never committed)
│
└── docs/ # 📚 Comprehensive documentation
├── README.md # Documentation index
├── GITOPS-ARCHITECTURE.md # Architecture guide
├── DEVELOPER-GUIDE.md # Developer onboarding
├── OPERATIONS-RUNBOOK.md # Operations procedures
└── REFERENCE.md # Technical reference
See GitOps Architecture - Repository Structure for detailed explanation.
🏗️ Architecture
Three-Repository Pattern
| Repository | Purpose | Who Edits | How Often |
|---|---|---|---|
| launchpad (this repo) | ArgoCD Applications, cluster resources | Platform / DevOps engineers | ✅ Often |
| forte-helm | Generic Helm chart templates | Platform engineers | ❌ Rarely |
| helm-prod-values | App-specific configuration & versions | Developers / CI pipelines | ✅ Sometimes |
GitOps Workflow
Developer commits code → CI/CD builds image → Updates helm-prod-values → ArgoCD syncs → Deployed to cluster
Learn more: GitOps Architecture - GitOps Workflow
🔧 Common Tasks
Deploy a New Application
See detailed guide: Developer Guide - Deploying Your First Application
Quick version:
- Create
apps/myapp.yaml(ArgoCD Application manifest) - Create
helm-prod-values/myapp/values.yaml(configuration) - Create sealed secrets if needed
- Commit and push - ArgoCD auto-syncs!
Update an Existing Application
See detailed guide: Developer Guide - Updating an Existing Application
Quick version:
- Update code: Push to app repo → CI/CD updates image tag in helm-prod-values
- Update config: Edit
helm-prod-values/myapp/values.yaml→ commit → push
Manage Secrets
See detailed guide: Developer Guide - Working with Secrets
# Create plain secret
kubectl create secret generic myapp-creds \
--from-literal=KEY=value \
--dry-run=client -o yaml > private/myapp-creds.yaml
# Seal it
kubeseal --format=yaml --cert=pub-cert.pem \
< private/myapp-creds.yaml > secrets/myapp-creds-sealed.yaml
# Commit sealed version
git add secrets/myapp-creds-sealed.yaml
git commit -m "Add myapp credentials"
git push
Enable Authentication
See detailed guide: Developer Guide - Enabling Authentication
Quick version:
# In helm-prod-values/myapp/values.yaml
# Token-based auth (simple)
auth:
enabled: true
type: token
tokens:
- your-secret-token-here
# OIDC auth (SSO)
auth:
enabled: true
type: oidc
oidc:
authority: https://auth.example.com/realms/master
clientId: myapp
Then create OIDC secret (if using OIDC):
kubectl create secret generic auth-oidc \
--from-literal=client-secret=your-oidc-secret \
--from-literal=cookie-secret=$(openssl rand -hex 32) \
--namespace=myapp | \
kubeseal --format=yaml --cert=pub-cert.pem --namespace=myapp | \
kubectl apply -f -
Bootstrap Cluster
See detailed guide: Operations Runbook - Cluster Bootstrap
# Initialize new cluster
./bootstrap.sh
# Verify
kubectl get applications -n argocd
kubectl get pods --all-namespaces
🛠️ Quick Reference
Monitor Applications
# List all ArgoCD applications
kubectl get applications -n argocd
# Watch sync status
kubectl get applications -n argocd -w
# Check specific application
kubectl describe application myapp -n argocd
# View application logs
kubectl logs -n myapp <pod-name>
Access UIs
# ArgoCD UI
kubectl port-forward svc/argocd-server -n argocd 8080:443
# Access: https://localhost:8080 (no auth required)
# Grafana
kubectl port-forward -n monitoring svc/grafana 3000:80
# Access: http://localhost:3000
# Prometheus
kubectl port-forward -n monitoring svc/prometheus-server 9090:80
# Access: http://localhost:9090
Troubleshooting
# Check pod status
kubectl get pods -n myapp
# View pod logs
kubectl logs -n myapp <pod-name>
# Check pod events
kubectl describe pod -n myapp <pod-name>
# Check ArgoCD sync errors
kubectl describe application myapp -n argocd
# Force sync
kubectl patch application myapp -n argocd \
--type merge -p '{"metadata":{"annotations":{"argocd.argoproj.io/refresh":"hard"}}}'
Full troubleshooting guide: Developer Guide - Troubleshooting
🔐 Security
Secret Management
- ✅ Sealed Secrets for Git storage
- ✅ Kyverno auto-clones secrets to namespaces
- ❌ Never commit plain secrets
Network Security
- ✅ All traffic TLS-encrypted (Let's Encrypt)
- ✅ HTTP → HTTPS redirect
- ✅ Traefik IngressRoute per application
Policy Enforcement
- ✅ Kyverno policies for security
- ✅ Default namespace blocked
- ✅ Bare pods not allowed
- ✅ Optional authentication sidecar injection
Learn more: GitOps Architecture - Security Model
📊 Infrastructure Components
| Component | Purpose | Namespace | Replicas |
|---|---|---|---|
| ArgoCD | GitOps controller | argocd |
1 |
| Traefik | Ingress controller | traefik |
2 |
| Cert-Manager | TLS certificates | cert-manager |
1 |
| Kyverno | Policy engine | kyverno |
1 |
| Sealed Secrets | Secret encryption | kube-system |
1 |
| Prometheus | Metrics | monitoring |
1 |
| Grafana | Dashboards | monitoring |
1 |
| Loki | Logs | monitoring |
1 |
| Tempo | Distributed tracing | monitoring |
1 |
| Fluent-Bit | Log shipping | monitoring |
DaemonSet |
| OpenCost | Cost monitoring | monitoring |
1 |
| Renovate | Dependency updates | renovate |
CronJob |
Full specs: Technical Reference - Infrastructure Components
🌐 Domains & Networking
- Local development:
*.127.0.0.1.nip.io - Production:
*.forteapps.net - DNS: Manual configuration (contact platform team)
- TLS: Automatic via Let's Encrypt
📖 Key Concepts
App-of-Apps Pattern
_app-of-apps-{cluster}.yaml is the root Application that manages all other Applications in infra/. Each component in infra/base/ lives in its own subdirectory (e.g., infra/base/grafana/). Overlays can either include all components (via ../../base) or cherry-pick specific ones (via ../../base/grafana, ../../base/prometheus, etc.). Per-cluster patches swap Helm value file paths. Supported clusters: upc-dev, upc-prod, eks-dev, eks-prod, aks-dev, aks-prod, gke-dev, gke-prod.
Multi-Source Pattern
Applications reference both:
- Helm charts from
forte-helm(templates) - Values from
helm-prod-values(configuration)
This separates reusable templates from environment-specific config.
Sync Waves
Applications deploy in order using argocd.argoproj.io/sync-wave:
- Wave
-1: Namespaces - Wave
0: Kyverno (policies) - Wave
1: Infrastructure - Wave
2+: Applications
Auto-Sync & Self-Heal
- Auto-Sync: ArgoCD automatically deploys Git changes (60s polling)
- Self-Heal: Manual cluster changes are reverted to match Git
- Prune: Deleted resources in Git are removed from cluster
Learn more: GitOps Architecture - GitOps Workflow
⚙️ Configuration
ArgoCD Settings
- Reconciliation: Every 60 seconds
- Sync timeout: 5 minutes per application
- Retry policy: 5 attempts with exponential backoff
- Authentication: Disabled (internal use only)
Application Defaults
- Auto-sync: Enabled
- Self-heal: Enabled
- Prune: Enabled
- Validation: Server-side validation enabled
- Server-side apply: Enabled
Full configuration: Technical Reference - ArgoCD Configuration
🆘 Getting Help
Documentation
- Start here: Documentation Index
- For development: Developer Guide
- For operations: Operations Runbook
- For reference: Technical Reference
Support
- Slack: #platform-support
- Issues: Contact platform team
- Emergencies: Escalate via Slack
Common Questions
| Question | Answer |
|---|---|
| How do I deploy an app? | Developer Guide - Deploying Your First Application |
| How do I manage secrets? | Developer Guide - Working with Secrets |
| App won't sync? | Developer Guide - Troubleshooting |
| How do I bootstrap a cluster? | Operations Runbook - Cluster Bootstrap |
| Where are the logs? | Operations Runbook - Monitoring & Alerting |
🤝 Contributing
Adding a New Application
- Read Developer Guide - Deploying Your First Application
- Create ArgoCD Application manifest in
apps/ - Create Helm values in
helm-prod-values/ - Create sealed secrets if needed
- Commit and push - ArgoCD handles the rest!
Modifying Infrastructure
- Read Operations Runbook
- Update relevant files in
infra/orcluster-resources/ - Test changes in isolated namespace if possible
- Commit and push
- Monitor sync status in Slack/ArgoCD UI
Updating Documentation
Documentation lives in docs/. To update:
- Edit relevant markdown file
- Update "Last Updated" date
- Submit PR or push directly
- Notify team of significant changes
📝 Notes
Current Environment
- Provider: Multi-cloud (UpCloud, AWS EKS, Azure AKS, GCP GKE)
- Active clusters: UpCloud (upc-dev, upc-prod)
- Environment: Production (internal use only)
- Auth: Disabled for ArgoCD (internal access)
- Backup: Gitea daily backup to S3-compatible storage
Known Limitations
- Secret rotation not automated
- DNS management is manual
Future improvements: See Operations Runbook - Disaster Recovery
📚 Additional Resources
External Documentation
- ArgoCD Documentation
- Kyverno Documentation
- Traefik Documentation
- Cert-Manager Documentation
- Grafana Tempo Documentation
- Sealed Secrets
Related Repositories
- forte-helm - Helm chart templates
- helm-prod-values - Application values
📄 License
Internal use only. Not for public distribution.
👥 Maintainers
Platform Team
- Contact: #platform-support on Slack
- Issues: Create issue in repository or contact team directly
Last Updated: 2026-04-22 Documentation Version: 1.0.0
🚀 Ready to get started? Check out the Documentation Index!