[bugfix] aws_elasticache_cluster plan time validation for transit_encryption_enabled - #49114
Open
sukumaar wants to merge 4 commits into
Open
[bugfix] aws_elasticache_cluster plan time validation for transit_encryption_enabled#49114sukumaar wants to merge 4 commits into
sukumaar wants to merge 4 commits into
Conversation
Contributor
Community GuidelinesThis comment is added to every new Pull Request to provide quick reference to how the Terraform AWS Provider is maintained. Please review the information below, and thank you for contributing to the community that keeps the provider thriving! 🚀 Voting for Prioritization
Pull Request Authors
|
sukumaar
marked this pull request as ready for review
July 24, 2026 21:40
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Rollback Plan
If a change needs to be reverted, we will publish an updated version of the library.
Changes to Security Controls
Are there any changes to security controls (access controls, encryption, logging) in this pull request? If so, explain.
Description
Adds plan-time validation to
aws_elasticache_clusterthat rejectstransit_encryption_enabled = truewhen the engine is Redis or Valkey. The AWSCreateCacheClusterAPI does not support transit encryption for these engines; it's only supported viaCreateReplicationGroup(i.e.,aws_elasticache_replication_group).Previously, users would get a confusing API error during
terraform apply:Now they get a clear error at
terraform plantime:Why this PR over #49103
#49103 is docs-only. It fixes the wording but users can still pass the invalid config through
planand only fail atapply. This PR adds plan-time validation (the standard pattern in this provider for known API incompatibilities), covers Valkey, includes test coverage, and adds a changelog entry.Relations
Closes #49066
Relates #22123
References
Output from Acceptance Testing