Gruntwork release 2026-09
Guides / Update Guides / Releases / 2026-09
This page lists all the updates to the Gruntwork Infrastructure as Code Library that were released in 2026-09.
For instructions on how to use these updates in your code, check out the updating documentation.
Here are the repos that were updated:
Published: 9/11/2026 | Release notes
Published: 9/29/2026 | Release notes
Details on user-facing changes will be documented in the release notes for:
Published: 9/29/2026 | Release notes
Details on user-facing changes will be documented in the release notes for:
Published: 9/24/2026 | Release notes
Details on user-facing changes will be documented in the release notes for:
Published: 9/18/2026 | Release notes
Details on user-facing changes will be documented in the release notes for:
Published: 9/16/2026 | Release notes
Details on user-facing changes will be documented in the release notes for:
Published: 9/9/2026 | Release notes
Details on user-facing changes will be documented in the release notes for:
Published: 9/4/2026 | Release notes
Details on user-facing changes will be documented in the release notes for:
Published: 9/24/2026 | Release notes
Previously, the ignore_list attribute only supported a comma-delimited list of globs as a string.
repository &
deploy_branch_name = "main"
ignore_list = "README.md,.github
As of this release, you can also use an HCL list to enumerate the globs you want Pipelines to ignore in your repository.
repository &
deploy_branch_name = "main"
ignore_list = ["README.md", ".github
As a consequence, you can also now use brace alternation to match on multiple paths in one glob when using the list form.
repository &
deploy_branch_name = "main"
ignore_list = ["README.md", "&
&
For backwards compatibility, the existing comma-delimited string form is still supported.
Full Changelog: https://github.com/gruntwork-io/pipelines-workflows/compare/v4.28.0...v4.29.0
Published: 9/21/2026 | Release notes
Fixed a bug affecting access control pull requests in Enterprise Account Factory.
The initial IAM trust policies now use immutable OIDC subject claims from delegated repositories.
Files read by stacks (e.g., by mark_as_read in a stack's locals) now trigger stack generation so that IaC changes can be detected.
Additionally, removing a file read by a stack will now trigger deletion protection if PIPELINES_FEATURE_VALIDATE_DAG_ON_DELETE is enabled.
Pipelines Hooks now receive a PIPELINES_HOOK_CTX_API_VERSION environment variable, initially set to v1.0.0. As more hook inputs are added over time, hook authors can check this variable against a minimum API version before their hooks attempt to run.
Full Changelog: https://github.com/gruntwork-io/pipelines-workflows/compare/v4.27.0...v4.28.0
Published: 9/18/2026 | Release notes
Published: 9/16/2026 | Release notes
Published: 9/11/2026 | Release notes
Published: 9/10/2026 | Release notes
Published: 9/4/2026 | Release notes
Published: 9/10/2026 | Release notes
Published: 9/9/2026 | Release notes
Published: 9/29/2026 | Modules affected: aws-sso, landingzone | Release notes
- fix: Use partition aware ARNs
- add variable to customize log group name
Published: 9/18/2026 | Release notes
Published: 9/15/2026 | Release notes
Published: 9/4/2026 | Modules affected: - api-gateway-account-settings, - api-gateway-proxy, - keep-warm, - lambda | Release notes
- fix: Stabilize
TestLambdaKeepWarm5 by relaxing exact-count assertions (#290)
- chore: Scope cloud-nuke cleanup to repo resource types and bump to v0.51.0 (#292)
- chore: Bump cloud-nuke cleanup to v0.52.0 (parallel scan) (#293)
- feat: Add timezone support to
scheduled-lambda-job through an opt-in EventBridge Scheduler (#294)
- fix: Raise the
TestLambdaDLQ SQS wait timeout to 300s to avoid async-delivery flakes (#295)
- chore: Migrate the lambda terratests to Terratest v2 beta (#296)
- feat!: Require AWS provider v6 across all modules, replacing the deprecated
id attribute on the aws_region data source with region (#299)
Published: 9/3/2026 | Release notes
Published: 9/15/2026 | Modules affected: all | Release notes
- added IPv6 support for the private subnet tiers, including DNS64/NAT64
- required AWS provider 6.x