Skip to main content

Gruntwork release 2026-09

Guides / Update Guides / Releases / 2026-09

This page lists all the updates to the Gruntwork Infrastructure as Code Library that were released in 2026-09. For instructions on how to use these updates in your code, check out the updating documentation.

Here are the repos that were updated:

pipelines-actions​

v4.12.1​

Published: 9/11/2026 | Release notes

pipelines-cli​

v0.68.0​

Published: 9/29/2026 | Release notes

Details on user-facing changes will be documented in the release notes for:

v0.67.0​

Published: 9/29/2026 | Release notes

Details on user-facing changes will be documented in the release notes for:

v0.66.0​

Published: 9/24/2026 | Release notes

Details on user-facing changes will be documented in the release notes for:

v0.65.0​

Published: 9/18/2026 | Release notes

Details on user-facing changes will be documented in the release notes for:

v0.63.0​

Published: 9/16/2026 | Release notes

Details on user-facing changes will be documented in the release notes for:

v0.62.0​

Published: 9/9/2026 | Release notes

Details on user-facing changes will be documented in the release notes for:

v0.61.0​

Published: 9/4/2026 | Release notes

Details on user-facing changes will be documented in the release notes for:

pipelines-workflows​

v4.29.0​

Published: 9/24/2026 | Release notes

Previously, the ignore_list attribute only supported a comma-delimited list of globs as a string.

repository {
deploy_branch_name = "main"

ignore_list = "README.md,.github/**"
}

As of this release, you can also use an HCL list to enumerate the globs you want Pipelines to ignore in your repository.

repository {
deploy_branch_name = "main"

ignore_list = ["README.md", ".github/**"]
}

As a consequence, you can also now use brace alternation to match on multiple paths in one glob when using the list form.

repository {
deploy_branch_name = "main"

ignore_list = ["README.md", "{catalog, .github}/**"]
}

For backwards compatibility, the existing comma-delimited string form is still supported.

Full Changelog: https://github.com/gruntwork-io/pipelines-workflows/compare/v4.28.0...v4.29.0

v4.28.0​

Published: 9/21/2026 | Release notes

Fixed a bug affecting access control pull requests in Enterprise Account Factory.

The initial IAM trust policies now use immutable OIDC subject claims from delegated repositories.

Files read by stacks (e.g., by mark_as_read in a stack's locals) now trigger stack generation so that IaC changes can be detected.

Additionally, removing a file read by a stack will now trigger deletion protection if PIPELINES_FEATURE_VALIDATE_DAG_ON_DELETE is enabled.

Pipelines Hooks now receive a PIPELINES_HOOK_CTX_API_VERSION environment variable, initially set to v1.0.0. As more hook inputs are added over time, hook authors can check this variable against a minimum API version before their hooks attempt to run.

Full Changelog: https://github.com/gruntwork-io/pipelines-workflows/compare/v4.27.0...v4.28.0

v4.27.1​

Published: 9/18/2026 | Release notes

Full Changelog: https://github.com/gruntwork-io/pipelines-workflows/compare/v4.27.0...v4.27.1

v4.27.0​

Published: 9/16/2026 | Release notes

Fixed a bug in GCP authentication causing failures when the GitHub OIDC token had expired. GCP auth configuration now mints new tokens as required.

Fixed a bug preventing Drift Detected job types from being consolidated during pipelines Plan / Apply

Full Changelog: https://github.com/gruntwork-io/pipelines-workflows/compare/v4.26.1...v4.27.0

v4.26.1​

Published: 9/11/2026 | Release notes

v4.26.0​

Published: 9/10/2026 | Release notes

Added an experimental feature flag PIPELINES_FEATURE_EXPERIMENT_NO_TG_TF_PATH to disable pipelines setting TG_TF_PATH before executing Terragrunt.

Full Changelog: https://github.com/gruntwork-io/pipelines-workflows/compare/v4.25.1...v4.26.0

v4.25.1​

Published: 9/4/2026 | Release notes

This is a parity release updating the internal pipelines binary, but provides no new functionality.

Full Changelog: https://github.com/gruntwork-io/pipelines-workflows/compare/v4.25.0...v4.25.1

terraform-aws-architecture-catalog​

v6.1.6​

Published: 9/10/2026 | Release notes

v6.1.5​

Published: 9/9/2026 | Release notes

terraform-aws-control-tower​

v2.1.3​

Published: 9/29/2026 | Modules affected: aws-sso, landingzone | Release notes

  • fix: Use partition aware ARNs
  • add variable to customize log group name

v2.1.2​

Published: 9/18/2026 | Release notes

Full Changelog: https://github.com/gruntwork-io/terraform-aws-control-tower/compare/v2.1.1...v2.1.2

terraform-aws-data-storage​

v1.4.0​

Published: 9/15/2026 | Release notes

Full Changelog: https://github.com/gruntwork-io/terraform-aws-data-storage/compare/v1.3.1...v1.4.0

terraform-aws-lambda​

v1.4.0​

Published: 9/4/2026 | Modules affected: - api-gateway-account-settings, - api-gateway-proxy, - keep-warm, - lambda | Release notes

  • fix: Stabilize TestLambdaKeepWarm5 by relaxing exact-count assertions (#290)
  • chore: Scope cloud-nuke cleanup to repo resource types and bump to v0.51.0 (#292)
  • chore: Bump cloud-nuke cleanup to v0.52.0 (parallel scan) (#293)
  • feat: Add timezone support to scheduled-lambda-job through an opt-in EventBridge Scheduler (#294)
  • fix: Raise the TestLambdaDLQ SQS wait timeout to 300s to avoid async-delivery flakes (#295)
  • chore: Migrate the lambda terratests to Terratest v2 beta (#296)
  • feat!: Require AWS provider v6 across all modules, replacing the deprecated id attribute on the aws_region data source with region (#299)

terraform-aws-service-catalog​

v2.16.0​

Published: 9/3/2026 | Release notes

Full Changelog: https://github.com/gruntwork-io/terraform-aws-service-catalog/compare/v2.15.0...v2.16.0

terraform-aws-vpc​

v0.30.0​

Published: 9/15/2026 | Modules affected: all | Release notes

  • added IPv6 support for the private subnet tiers, including DNS64/NAT64
  • required AWS provider 6.x