Luke Heath
2f09a68085
Bump Fleet version to v4.90.0 ( #273 )
2026-08-05 21:09:57 -05:00
Robert Fairburn
97954e1551
Initial blue-green cutover for rds aurora ( #266 )
2026-07-23 10:23:52 -05:00
Jorge Falcon
1ce4979133
Document Restore/Rollback Process and Tooling for Fleet deploy on AWS ( #236 )
...
- Adds `tools/rds-db-restore/README.md` - Documentation for the restore
process.
- Adds `tools/rds-db-restore/db-restore.sh` - Script to restore and
rollback Fleet to an earlier state.
2026-07-21 12:02:49 -04:00
George Karr
2837d1621f
bumping version ( #270 )
2026-07-16 12:02:40 -07:00
Luke Heath
5c22e0388a
Bump Fleet version to v4.89.0 ( #269 )
2026-07-15 12:07:17 -07:00
Robert Fairburn
35ad999822
S3 bucket tagging ( #268 )
2026-07-15 07:45:23 -05:00
Robert Fairburn
d2cae029db
Improve validdate ( #267 )
2026-07-15 00:37:35 -05:00
George Karr
c09d3aa68c
bumping version ( #265 )
2026-07-10 18:33:56 -05:00
Robert Fairburn
a4813b4242
Cloudfront blue green ( #263 )
2026-07-10 02:41:57 -05:00
George Karr
f4a67ec750
bumping version ( #259 )
2026-07-07 13:09:32 -05:00
Robert Fairburn
151b7f745c
Monitoring 1.14.0 docs ( #255 )
2026-07-05 09:39:19 -05:00
George Karr
60436c5569
bumping version ( #258 )
2026-07-01 10:05:51 -05:00
Robert Fairburn
b099b04e08
tf-mod-addon-migrations-v2.3.0 examples ( #257 )
2026-06-22 07:56:28 -05:00
Robert Fairburn
02a5a25e61
Make migration timeouts configurable ( #253 )
2026-06-22 07:22:13 -05:00
Luke Heath
4e16c99b1c
Bump Fleet version to 4.87.0 ( #256 )
2026-06-19 18:21:04 -07:00
Robert Fairburn
ba70e93f65
Add alerting thresholds to monitoring. ( #254 )
2026-06-19 12:17:55 -05:00
Jorge Falcon
98cd54a428
Increase soft and hard ulimits for osquery-perf ( #252 )
2026-06-12 10:58:33 -04:00
Jorge Falcon
40751d25c3
Updating documentation and examples ( #251 )
2026-06-09 10:08:51 -04:00
Jorge Falcon
7b381e0bbb
Enforce DENY non-HTTPS requests to s3 buckets ( #250 )
...
- Enforces access over HTTPS to all Fleet-terraform created buckets.
- Fixes vpc-flow-logs log retention; now allows configuring the
retention in days.
2026-06-08 18:37:48 -04:00
Jorge Falcon
a276eb6a98
Updating Fleet terraform examples ( #249 )
2026-06-05 15:02:17 -04:00
Jorge Falcon
b6bf32755b
Support for managing default ACLs ( #248 )
2026-06-05 14:37:13 -04:00
George Karr
802881fcf2
bumping version ( #247 )
2026-06-03 11:55:14 -05:00
Luke Heath
3b21e8d9fa
Bump Fleet version references to v4.86.0 ( #246 )
2026-05-29 18:37:50 -05:00
George Karr
716d24be0e
bumping version ( #237 )
2026-05-27 10:42:39 -05:00
Robert Fairburn
70e1e1b800
Examples db fix ( #241 )
2026-05-26 14:56:16 -05:00
Robert Fairburn
b4f2ffbf98
Support custom database user and database names properly ( #240 )
2026-05-26 14:23:56 -05:00
Robert Fairburn
1bfc9a14be
update tagged module versions to latest ( #239 )
2026-05-26 10:35:09 -05:00
Robert Fairburn
95ead0f16d
Govcloud partition refactor ( #235 )
2026-05-26 05:18:51 -05:00
Luke Heath
4763e68d85
Bump Fleet version references to v4.85.0 ( #233 )
2026-05-14 10:40:08 -05:00
George Karr
653ad24c5c
bumping version ( #232 )
2026-05-07 14:01:00 -05:00
Jorge Falcon
10aebc2b8a
Example and README updates ( #224 )
...
Example Updates:
- `../example/main.tf`
README Updates:
- `byo-cloudwatch-log-sharing/target-account-firehose/.header.md`
- `byo-cloudwatch-log-sharing/target-account-firehose/README.md`
- `byo-file-carving/target-account/README.md`
- `byo-firehose-logging-destination/target-account/README.md`
- `logging-destination-datadog/.header.md`
- `logging-destination-datadog/README.md`
- `logging-destination-firehose/README.md`
- `logging-destination-snowflake/.header.md`
- `logging-destination-snowflake/README.md`
- `logging-destination-splunk/.header.md`
- `logging-destination-splunk/README.md`
- `okta-conditional-access/.header.md`
- `okta-conditional-access/README.md`
- `osquery-carve/README.md`
- `../byo-vpc/example/README.md`
- `../byo-vpc/example/main.tf`
- `../example/README.md`
2026-05-05 13:01:21 -04:00
George Karr
44bd43b643
bumping version ( #230 )
2026-04-30 23:43:43 -05:00
Robert Fairburn
2924052a86
Fix typos in monitoring module ( #227 )
2026-04-29 08:20:24 -05:00
Luke Heath
e92fccffcb
Bump Fleet to v4.84.0 ( #226 )
2026-04-24 20:45:43 -05:00
George Karr
3455439b15
bumping version ( #222 )
2026-04-21 13:32:29 -05:00
Jorge Falcon
1aabfc3316
Fix resource iam_role_name length limitations in logging-alb module ( #221 )
...
- Adds `var.enable_reencrypt_sweep` to control when lambda functions and
permission resources should be created.
- Adds `var.iam_role_name_prefix` to allow overriding the prefix used
for iam_role naming, when `var.enable_reencrypt_sweep = true`
2026-04-10 09:46:55 -04:00
dependabot[bot] and Robert Fairburn
cdab8be4c7
Bump github.com/aws/aws-sdk-go-v2/service/lambda from 1.88.0 to 1.88.5 in /addons/byo-cloudwatch-log-sharing/pubsub-bridge/lambda ( #210 )
...
[//]: # (dependabot-start)
⚠️ **Dependabot is rebasing this PR** ⚠️
Rebasing might not happen immediately, so don't worry if this takes some
time.
Note: if you make any changes to this PR yourself, they will take
precedence over the rebase.
---
[//]: # (dependabot-end)
Bumps
[github.com/aws/aws-sdk-go-v2/service/lambda](https://github.com/aws/aws-sdk-go-v2 )
from 1.88.0 to 1.88.5.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/b9b0c6553b80f99603b4f8356b88f5baf1328deb "><code>b9b0c65</code></a>
Release 2025-10-16</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/e2bc8a0ec6f430876fc7de4432ea9cc89c9568f8 "><code>e2bc8a0</code></a>
Regenerated Clients</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/8691ee380a96c49351e4b5ab8a70bc5d4d100724 "><code>8691ee3</code></a>
Update API model</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/51e8a3fe032fc566d31b389f492ab58475a98398 "><code>51e8a3f</code></a>
bump to go1.23 (<a
href="https://redirect.github.com/aws/aws-sdk-go-v2/issues/3211 ">#3211</a>)</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/ad2d36cba7c5772b4e8e4caf96939dc41b95c65c "><code>ad2d36c</code></a>
Release 2025-10-15</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/19a35d639f969ee328553e632e8cf8b83d324106 "><code>19a35d6</code></a>
Regenerated Clients</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/35cb02fd50fb125601b9c3b33feb72f3a2bcaa56 "><code>35cb02f</code></a>
Update endpoints model</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/f673a1b0a80e666c0128ec606ff053dace9771f1 "><code>f673a1b</code></a>
Update API model</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/48421fd812d8592a4eb2b32d11ae07e228969012 "><code>48421fd</code></a>
Release 2025-10-14</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/fedcba778c21b451a91b4e4bcdd5d6c1554c6a5a "><code>fedcba7</code></a>
Regenerated Clients</li>
<li>Additional commits viewable in <a
href="https://github.com/aws/aws-sdk-go-v2/compare/service/s3/v1.88.0...service/s3/v1.88.5 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/fleetdm/fleet-terraform/network/alerts ).
</details>
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Robert Fairburn <8029478+rfairburn@users.noreply.github.com >
2026-04-09 11:21:04 -05:00
dependabot[bot]
c7d41e2411
Bump github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream from 1.7.4 to 1.7.8 in /addons/byo-cloudwatch-log-sharing/pubsub-bridge/lambda ( #212 )
...
Bumps
[github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream](https://github.com/aws/aws-sdk-go-v2 )
from 1.7.4 to 1.7.8.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/e3b97d2a02cd4e27c40224f05aa1a7deba24abe2 "><code>e3b97d2</code></a>
Release 2023-10-12</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/863010ddb23c242c2a5d49d9f40094a6a49b5525 "><code>863010d</code></a>
Regenerated Clients</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/6946ef8b9149fe75ac1b427ca2c7f57cdcb64549 "><code>6946ef8</code></a>
Update endpoints model</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/6d93ded4536184d38a664b4b75dadd36cbd79878 "><code>6d93ded</code></a>
Update API model</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/bebc232e7f65b02d0b519d11e73cf925c38e716f "><code>bebc232</code></a>
fix: fail to load config if configured profile doesn't exist (<a
href="https://redirect.github.com/aws/aws-sdk-go-v2/issues/2309 ">#2309</a>)</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/5de46742b7fb1b72d93d344ee81568800a707267 "><code>5de4674</code></a>
fix DNS timeout error not retried (<a
href="https://redirect.github.com/aws/aws-sdk-go-v2/issues/2300 ">#2300</a>)</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/e155bb72a2ec20ec61db50fc3d4568e373fa4b63 "><code>e155bb7</code></a>
Release 2023-10-06</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/9d342ba33937c562d215f317a37dea121ee9763d "><code>9d342ba</code></a>
Regenerated Clients</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/1df99141a143a38570d64a182ed972ce9e3dba65 "><code>1df9914</code></a>
Update SDK's smithy-go dependency to v1.15.0</li>
<li><a
href="https://github.com/aws/aws-sdk-go-v2/commit/32ada3a191ac770b1b24164b667692183fc77ed9 "><code>32ada3a</code></a>
Update API model</li>
<li>Additional commits viewable in <a
href="https://github.com/aws/aws-sdk-go-v2/compare/service/m2/v1.7.4...service/m2/v1.7.8 ">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores )
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/fleetdm/fleet-terraform/network/alerts ).
</details>
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-04-09 11:19:23 -05:00
Jorge Falcon
1deabca4c6
logging-destination-firehose bucket configurations ( #213 )
...
- Sets `blocked_encryption_types = ["NONE"]` in
logging-destination-firehose buckets
2026-04-08 16:43:06 -04:00
Jorge Falcon
bdc3e4e49c
logging-destination-datadog bucket configurations ( #214 )
...
- Sets `blocked_encryption_types = ["NONE"]` in
logging-destination-datadog buckets
2026-04-08 16:42:05 -04:00
Jorge Falcon
fc2e2c5aa6
logging-destination-splunk bucket configurations ( #215 )
...
- Sets `blocked_encryption_types = ["NONE"]` in
logging-destination-splunk buckets
2026-04-08 16:41:54 -04:00
Jorge Falcon
27b7e17b61
logging-destination-snowflake bucket configurations ( #216 )
...
- Sets `blocked_encryption_types = ["NONE"]` in
logging-destination-snowflake buckets
2026-04-08 16:41:44 -04:00
Jorge Falcon
86c82786f2
okta-conditional-access bucket configurations ( #217 )
...
- Sets `blocked_encryption_types = ["NONE"]` in okta-conditional-access
buckets
2026-04-08 16:41:34 -04:00
Jorge Falcon
86bf5d2ebc
byo-file-carving bucket configurations ( #218 )
...
- Sets `blocked_encryption_types = ["NONE"]` in byo-file-carving buckets
2026-04-08 16:41:24 -04:00
Jorge Falcon
27df76ee9c
byo-firehose-logging-destination bucket configurations ( #219 )
...
- Sets `blocked_encryption_types = ["NONE"]` in
byo-firehose-logging-destination buckets
2026-04-08 16:41:13 -04:00
Jorge Falcon
86574cd680
byo-cloudwatch-log-sharing bucket configurations ( #220 )
...
- Sets `blocked_encryption_types = ["NONE"]` in
byo-cloudwatch-log-sharing buckets
2026-04-08 16:40:59 -04:00
Jorge Falcon
628a757c8e
byo-ecs bucket configuration ( #208 )
...
- Sets `blocked_encryption_types = ["NONE"]` in byo-ecs, for
software_installers bucket.
2026-04-08 01:14:25 -04:00
Jorge Falcon
6cbdaaa31c
logging-alb bucket configurations ( #209 )
...
- Sets `blocked_encryption_types = ["NONE"]` in logging-alb buckets
2026-04-08 01:14:07 -04:00
Jorge Falcon
608057d41d
osquery-carve bucket configurations ( #211 )
...
- Sets `blocked_encryption_types = ["NONE"]` in osquery-carve buckets
2026-04-08 01:13:53 -04:00
Robert Fairburn
ed71e24bbe
documentation updates for latest tf modules ( #206 )
2026-04-07 17:33:30 -05:00