Last required release: v202207-2 (642)
Flexible Deployment Options
terraform-enterprise container manifest: amd64/linux
- Azure DevOps VCS-backed workspaces may be unable to connect to the VCS, execute plans or runs, or import modules. The error in the logs shows
no matching host key type found. Their offer: ssh-rsa","component":"atlas". There are several workarounds available depending on the deployment option of TFE. Refer to this knowledge base article for more information.
- Consolidated services mode is enabled by default as of v202309-1, but you can disable it using the
consolidated_services_enabledsetting until v202401-1, when we permanently remove it. This setting only applies to Replicated deployments.
- You can now exclude specific workspaces from global or project-scoped policy sets. Terraform Enterprise will not enforce a policy set’s policies on any runs in an excluded workspace.
- Workspace admins can now schedule automatic destroy runs to trigger the deletion of all infrastructure managed by a workspace at some point in the future.
- You can schedule an automatic destroy in Destruction and Deletion under Workspace Settings.
- Workspace Event notification triggers now include auto destroy notifications. For more details, refer to the Notification Configuration documentation.
- Organizations now specify a default execution mode, which their workspaces may inherit. By default, new workspaces will inherit the organization default execution mode (and default agent pool, if applicable), but can override this default with a different execution mode.
- Terraform Enterprise now includes an upgrade startup check that ensures that upgrades occur in a sequential manner and do not forego required Terraform Enterprise releases.
- Terraform Enterprise can now connect to an external Vault server using TLS v1.3.
- Added fallback mechanism for persisting Terraform state when backend errors occur during runs.
- Terraform Enterprise can now connect to Redis servers using a password containing certain special characters (e.g.,
- Terraform Enterprise can now connect to database servers using a password containing certain special characters (e.g.,
- Terraform Enterprise now respects the
redis_portconfiguration setting when consolidated services is enabled.
- A user without read access to a project can no longer assign it to a policy set or see if it’s already assigned.
- Fixed premature expiration of Terraform artifacts during runs.
- Fixed bug preventing repository publishing by ID when using ADO VCS provider.
- Fixed validation issue for creating GitLab.com providers in regards to new key format.
- Policy Checks will now error when attempting to queue if associated Policies or Policy Sets have been deleted, as the Policy Check is no longer valid.
- Instruct terraform CLI to save snapshot state versions on a 1 hour interval to compensate for a terraform CLI bug in 1.5.0 ~ 1.5.7 that is saving state versions every 20 seconds in the absence of the header.
- Container updates address reported vulnerabilities (CVEs) in underlying packages and dependencies.