Juju Terraform provider v2.4.1 was released!

Juju Terraform provider 2.4.1 release notes

8 October 2026

:puzzle_piece: Requirements and compatibility

  • This release requires a Juju controller of version 3.6 or higher. Support for Juju 2.9 controllers is not available in the v2 track; 2.9 continues to be supported on the v1 track for security updates and bug fixes.

  • If you are using JAAS, this release requires a Juju controller of version 3.6.5 or higher.

  • This release is compatible with both Juju 3 and Juju 4 controllers.

:rocket: New features

Allow omitted write-only secret values when the version is unchanged

You no longer need to supply write-only secret values for every plan. If the value_wo_version of an existing juju_secret resource is unchanged, its value_wo map can contain null values-for example, when an ephemeral variable or environment-provided secret is no longer available.

This is useful to avoid keeping your secret value anywhere except in the Juju controller.

Write-only values are still validated when creating the secret or changing value_wo_version. Null elements in the non-write-only value map continue to be rejected.

  • Validate null values only when the write-only secret version changes by @SimoneDutto in #1391 (partially addresses #1386).

:hammer_and_wrench: Bug fixes

  • Switching away from a charm channel branch now works correctly - changing a channel such as latest/edge/my-branch to latest/edge now clears the previous branch instead of retaining it and producing an inconsistent result after apply. Removing an explicit track also correctly clears the previous track. Correctly handle channel with branch by @kian99 in #1392 (addresses #1389).

  • Improved error handling and diagnostics - the provider now correctly identifies model-not-found and wrapped errors, reports certificate errors more accurately, and emits warnings when missing resources are removed from Terraform state. Fix model-not-found and wrapped error handling by @kian99 in #1383.

:books: Documentation

  • Correct the Ubuntu charm base in the application resource example so that it matches the specified charm revision. Fix the application example base reference by @ale8k in #1387.

—

Full changelog: Comparing v2.4.0
v2.4.1 · juju/terraform-provider-juju · GitHub

A note on this release to highlight an important fix done in #1383.

To reconciliate the state, the Terraform provider on Read is calling the ModelInfo API, and if the error is model-not-found it will remove the model from the state.

There was some legacy code, using errors.As instead of errors.Is, that was mistakenly matching all jujuerrors.ConstError instead of matching only the specific model-not-found, causing the model to be removed from the state also in case of other jujuerrors.ConstError (i.e. timeout errors). This is a problem in automated environment (for example Flux) because Terraform is applied in a loop and:

  • on an apply a timeout error could trigger a model deletion just from the Terraform state
  • the next apply will remove of the dependencies of said model

This has been fixed in this release, and we advice everybody to move to this release, especially if they are using tools like Flux.

Thanks a lot to IS support, especially @alexdlukens.

1 Like