NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1502 most downloaded on PyPI
Version 2 of the AWS Cloud Development Kit library
Last release 4 days ago
30 Sep 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
6 years old
403 releases · first in 2021
One column per quarter.
L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
** L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormation. Sometimes these updates can
contain changes that are incompatible with previous types, but more accurately reflect reality. In this release we have changed:
aws-servicediscovery: AWS::ServiceDiscovery::Instance: primary identifier is now ServiceId and InstanceId, so InstanceReference now requires serviceId.
codebuild: add hostKernel to build environment ( #38513 ) ( deec895 ), closes #38338 #38338 #38275 #38338
Invalid URL error (#38867) (6eb07dd)resolveReferences should only update references that require updates on its second pass in nested stacks (#38813) (6cf5313)L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
** L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormation. Sometimes these updates can
contain changes that are incompatible with previous types, but more accurately reflect reality. In this release we have changed:
aws-codecommit: AWS::CodeCommit::Repository: Id attribute removed.
aws-config: AWS::Config::DeliveryChannel: DeliveryFrequency property values narrowed to an enum.
aws-dms: AWS::DMS::ReplicationTask: Id attribute removed.
Bucket replication metrics cannot be enabled without replication time control (RTC) (#35929) (cd97d96), closes #35772 /github.com/aws/aws-cdk/issues/35772#issuecomment-3427574206dynamodb: TableV2 emits internal grants deprecation warnings ( #38806 ) ( 57b3043 ), closes #38709 #38399 #37892
TableV2 emits internal grants deprecation warnings (#38806) (57b3043), closes #38709 #38399 #37892defaultArguments. Previously, a managed argument set viadefaultArguments was silently honored in SparkJob and PythonShellJob (customerRayJob (constructdefaultArguments now throws a ValidationError at synthesis time:--enable-continuous-cloudwatch-log,--continuous-log-logGroup, --continuous-log-logStreamPrefix,--continuous-log-conversionPattern, --enable-continuous-log-filter,--enable-metrics, --enable-observability-metrics, --enable-spark-ui,--spark-event-logs-path, --job-language, --class, --extra-jars,--user-jars-first, --extra-py-files, --extra-files, library-set--debug, --mode, --JOB_NAME, --endpointA managed argument is rejected whether or not the current configuration emits it, so a
disabled feature (e.g. enableMetrics: false) cannot be re-enabled through
defaultArguments. Configure these through their dedicated props instead
(continuousLogging, enableMetrics, enableObservabilityMetrics, sparkUI,
className, extraJars, extraJarsFirst, extraPythonFiles, extraFiles). For
example, replace defaultArguments: { '--enable-continuous-cloudwatch-log': 'false' }
with continuousLogging: { enabled: false }. Arguments without a dedicated prop (e.g.
--enable-glue-datacatalog) are unaffected and remain settable via defaultArguments.
The checkNoReservedArgs(defaultArguments?) method on the Job base class was removed.
It is replaced by two protected members: setManagedArgument(key, value?), which each
job class calls to declare (and, when a value is present, emit) a managed argument, and
mergeDefaultArguments(defaultArguments?), which validates the caller-supplied
defaultArguments against the accumulated reserved set and returns the merged map.
FirewallRuleGroupAssociation now honors the previously-ignored mutationProtection and name props. Stacks that set mutationProtection: true will enable mutation protection on redeploy (which blocks further CloudFormation update/delete until it is set back to false); stacks that set name will write it to the template, which may replace the association.Action and Condition are no longer plain objects — use Action.job(...) / Action.crawler(...) and Condition.job(...) / Condition.crawler(...). Jobs are referenced via IJobRef and crawlers via ICrawlerRef (a CfnCrawler instance or CfnCrawler.fromCrawlerName(...)) instead of a CfnCrawler field or crawler-name string; IJob now extends the generated IJobRef. addDailyScheduledTrigger/addWeeklyScheduledTrigger/addCustomScheduledTrigger are replaced by addScheduledTrigger(id, { schedule, ... }) (use TriggerSchedule.daily()/weekly()/cron(...)). addNotifyEventTrigger is renamed addEventTrigger (NotifyEventTriggerOptions → EventTriggerOptions). All addXxxTrigger methods now return ITriggerRef instead of CfnTrigger.step: { interval, intervalUnit } instead of top-level interval/intervalUnit.subnet, vpc, or vpcSubnets; use network: ConnectionNetwork.subnet(...) or network: ConnectionNetwork.vpc(...) instead.s3-deployment: replace deprecated addDependency in integ test
L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormation. Sometimes these updates can contain changes that are incompatible with previous types, but more accurately reflect reality. In this release we have changed:
AWS::Athena::Session removed.AWS::BCMDataExports::Table removed.AWS::Bedrock::DefaultPromptRouter and AWS::Bedrock::ModelInvocationJob removed.AWS::BedrockAgentCore::Browser, AWS::BedrockAgentCore::CodeInterpreter, and AWS::BedrockAgentCore::TokenVault removed; AWS::BedrockAgentCore::PaymentConnector ConnectorType and AWS::BedrockAgentCore::PaymentCredentialProvider CredentialProviderVendor are now immutable; AWS::BedrockAgentCore::CapacityProvider OperatingSystem allowed values in the LaunchParameters type reduced from [LINUX_X86_64, LINUX_ARM64, MAC_ARM64, WINDOWS_X86_64] to [LINUX_X86_64, LINUX_ARM64].AWS::CertificateManager::Certificate Id attribute removed.AWS::Chime::AppInstance and AWS::Chime::AppInstanceBot, the CreatedTimestamp and LastUpdatedTimestamp attribute types changed from number to string.AWS::CloudFormation::ResourceScan removed.AWS::CodeArtifact::Package removed.AWS::CodeBuild::Sandbox removed; AWS::CodeBuild::SourceCredential Id attribute removed.AWS::DAX::ParameterGroup Id attribute removed; Description property is now immutable.Id attribute removed from AWS::DMS::Endpoint, AWS::DMS::EventSubscription, and AWS::DMS::ReplicationSubnetGroup; AWS::DMS::ReplicationTask MigrationType property is now immutable.Id attribute removed from AWS::DocDB::DBClusterParameterGroup and AWS::DocDB::DBSubnetGroup.AWS::DynamoDB::Export removed.AWS::ElastiCache::ReservedCacheNode removed.AWS::EMR::NotebookExecution removed.AWS::Events::Replay removed.AWS::FIS::SafetyLever removed.Id attribute removed from AWS::Glue::Classifier, AWS::Glue::Connection, AWS::Glue::CustomEntityType, AWS::Glue::DataQualityRuleset, AWS::Glue::MLTransform, AWS::Glue::SecurityConfiguration, AWS::Glue::TableOptimizer, and AWS::Glue::Workflow.AWS::Glue::Connection: complex-property types AuthenticationConfigurationInput and OAuth2PropertiesInput renamed to AuthenticationConfiguration and OAuth2Properties respectively.AWS::Glue::DataQualityRuleset: Name, TargetTable.DatabaseName, and TargetTable.TableName properties are now required; Name property is now immutable; Tags property type changed from json to map<string>.AWS::Glue::CustomEntityType: Name property is now immutable; Tags property is no longer recognised as resource tags.AWS::Glue::MLTransform: TransformEncryption property is now immutable.AWS::GreengrassV2::Component and AWS::GreengrassV2::CoreDevice removed.AWS::IdentityStore::AllGroupMemberships removed.AWS::ImageBuilder::AllImageBuildVersions, AWS::ImageBuilder::AllWorkflowBuildVersions, AWS::ImageBuilder::WorkflowExecution, and AWS::ImageBuilder::WorkflowStepExecution removed.AWS::MediaLive::Offering removed.AWS::MediaConvert::Preset Id attribute removed.AWS::MediaPackage::HarvestJob removed.AWS::MemoryDB::MultiRegionParameterGroup and AWS::MemoryDB::ReservedNode removed.AWS::Omics::Reference removed.AWS::OSIS::PipelineBlueprint removed.AWS::Personalize::DataDeletionJob and AWS::Personalize::Recipe removed.AWS::RedshiftServerless::RecoveryPoint removed.AWS::Route53::RecordSet GeoProximityLocation property removed, along with its supporting GeoProximityLocation and Coordinates complex-property types; Id attribute removed.AWS::SageMaker::ModelCardExportJob, AWS::SageMaker::MonitoringScheduleAlert, and AWS::SageMaker::TransformJob removed.AWS::SES::ReceiptRuleSet Id attribute removed.AWS::Signer::SigningJob removed.AWS::SSM::Session removed; AWS::SSM::Association InstanceId property is now immutable.AWS::SSO::ApplicationProvider removed.AWS::StepFunctions::MapRun removed.AWS::Transcribe::MedicalTranscriptionJob removed.AWS::VpcLattice::ServiceNetwork SharingConfig property is now immutable.DataQualityTargetTable's constructor is removed — use DataQualityTargetTable.fromTable(database, table) or fromTableName(database, tableName); IDatabase now extends IDatabaseRef.DataQualityRulesetProps.clientToken is removed; use the CfnDataQualityRuleset L1 for request-level idempotency.DataQualityRulesetProps.rulesetName is now required. AWS::Glue::DataQualityRuleset made Name a required property, so the name can no longer be left for CloudFormation to generate.dynamodb: avoid TableGrantsProps deprecation warnings for TableV2 ( #38399 ) ( fb5c25b ), closes #37221
timeZone on the Firehose S3Bucket destination now throws a ValidationError during synthesis instead of failing at CloudFormation deployment. Affected values: 3-letter IANA abbreviations (e.g. EST), Etc/UTC, Etc/GMT, Factory, and strings containing characters outside [a-zA-Z/_]+. Use a supported standard IANA identifier (e.g. America/New_York) or UTC for synth to pass.Size objects now properly stringify (#38662) (90fe151)SymlinkFollowMode.BLOCK_EXTERNAL will throw errors while bundling (#38506) (a11e451)TableV2.grants.*Data does not include index resources (#37892) (e48a97f), closes #37569TableV2MultiAccountReplica rejects imported tables with tokenized ARNs (#38365) (08f05e5), closes #38354NatInstanceProvider and NatInstanceProviderV2 always trigger the keyName deprecation warning (#38347) (47f2151), closes #30806Type is now an opaque class; construct column types via the Schema factories or Schema.custom(...) rather than { isPrimitive, inputString } literals. StorageParameter.custom(key, value) requires a string value, and StorageParameter.writeKmsKeyId takes a kms.IKey instead of a string.S3TableProps.bucket/encryption/encryptionKey are removed. Use storage: S3TableStorage.managedBucket(S3TableEncryption.kms(key?)) / S3TableStorage.fromBucket(bucket) and clientSideEncryption: TableClientSideEncryption.kms(key?). S3Table.encryption/encryptionKey are removed (clientSideEncryptionKey exposes the client-side key; read bucket.encryptionKey for server-side). The TableEncryption enum and the deprecated Table/TableProps are removed — use S3Table.Connection (#38561) (f9d7eac)glue-alpha: this is a corrective breaking change. Apps that leaned on the bug, and did things like InputFormat x = OutputFormat.AVRO; will get a compi…
DataQualityRulesetProps.rulesetDqdl: string is replaced bydqdl: Dqdl. Build it with Dqdl.fromString('Rules = [ ... ]').s3Encryption, cloudWatchEncryption, and jobBookmarksEncryption are no longer object literals. Use S3Encryption.s3Managed() / S3Encryption.kms(key?), CloudWatchEncryption.kms(key?), and JobBookmarksEncryption.clientSideKms(key?). The CloudWatchEncryptionMode and JobBookmarksEncryptionMode enums are removed (their mode is now implicit); S3EncryptionMode is retained.InputFormat x = OutputFormat.AVRO; will get a compilation error in other jsii languages. The intended usage, on the other hand, was broken before and works now.workerType and numberOfWorkers are no longer top-level job props. For Spark jobs, pass them together via workerConfiguration: { workerType, numberOfWorkers }. PythonShellJob no longer accepts them (it is sized by maxCapacity). RayJob no longer accepts workerType (it is fixed to Z.2X).SparkJobProps.enableMetrics removed, which will cause a compilation error for any app using it. But there is no behavior change, since this is a dead prop.has_encrypted_data supplied via parameters now throws.hasEncryptedData property (#38511) (c977e36)bump brace-expansion to 5.0.9 to address CVE-2026-69152 ( #38520 ) ( 8764b7b ), closes #38496 #38410
cdk validate can hang indefinitely (#38510) (0a238f3), closes #38498 #38425GlueVersion.V5_0 instead of V3_0. Set glueVersion explicitly to keep the previous behavior.Database resources will change to RETAIN.Database by default (#38535) (9669928)bedrockagentcore: Gateway metric helpers now emit corrected CloudWatch dimensions per-gateway metrics use { Operation, Protocol, Resource } (was { Res
Gateway metric helpers now emit corrected CloudWatch dimensions per-gateway{ Operation, Protocol, Resource } (was { Resource }). Alarms/dashboards built on theRuntimeBase metric helpers now emit corrected CloudWatch dimensions per-resource metrics use { Operation, Name, Resource } (was { Resource }) and aggregated metrics use { AggregateOperation } (was { Resource: 'All' }). Alarms/dashboards built on the old dimensions must be updated.CallApiGatewayRestApiEndpoint does not support JsonATA for api_path (#37738) (9f0afdc), closes #37728 /github.com/aws/aws-cdk/blob/e207b76cc2503701b3c4e2c87023617b485b2fde/packages/aws-cdk-lib/aws-stepfunctions/lib/private/jsonata.ts#L1IDatabase.catalogArn and IDatabase.catalogId were removed in factor of a typeICatalog, which has catalogArn and catalogId. Consumers and implementations were updatedCatalog L2 (#38443) (6a8ba8e)S3Table (#38501) (eb81d5e), closes /docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-5bump brace-expansion to 5.0.8 to address CVE-2026-14257 ( #38410 ) ( 5aaa395 ), closes #38409 #38063
removalPolicy prop removed from FlowProps, GatewayProps, and BridgeProps. These resources now follow CloudFormation's default deletion behaviour (Delete).revert "fix(core): stack.node.addDependency gets slower as stacks grow ( #38314 )" ( #38417 ) ( d97dd8d ), closes #38406 #38406
core: bump @aws/cloudformation-validate to 1.5.1-beta to fix install on Node != 22.x ( #38382 ) ( d409b96 ), closes #38380
ecs: add support ECS-optimized Amazon Linux 2023 (Neuron) AMI
dropInvalidHeaderFields in case of default or switching from true to false (#36483) (208b9db), closes #36409L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
update L1 CloudFormation resource definitions ( #38151 ) ( f266a47 ), closes /docs.aws.amazon.com/AmazonS3/latest/userguide/s3-files-prereq-policies.h
lambda: Runtime.NODEJS_LATEST now resolves to nodejs24.x in every region. Customers who pin to a concrete runtime ( Runtime.NODEJS_22_X , useLatestRun
lambda: Runtime.NODEJS_LATEST now resolves to nodejs24.x in every region. Customers who pin to a concrete runtime (Runtime.NODEJS_22_X, useLatestRuntimeVersion: false in aws-lambda-nodejs.NodejsFunction) are unaffected. Existing AWS::Lambda::Function resources synthesized with NODEJS_LATEST will see Runtime: nodejs22.x → Runtime: nodejs24.x on next deploy. Lambda accepts runtime updates in place.
Customer-code compatibility — IMPORTANT: Node.js 24 removes support for callback-style asynchronous handlers ((event, context, callback) => {...}) per the launch blog. Customers whose Lambda code still uses callback-based handlers will see runtime errors after the bump. Customers should migrate to async (event, context) => {...} or pin to Runtime.NODEJS_22_X explicitly.
"chore(bundling): check if docker image is cached before building" (#38116) (8ec236c), closes aws/aws-cdk#37951
L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
** L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormation. Sometimes these updates can contain changes that are incompatible with previous types, but more accurately reflect reality. In this release we have changed:
aws-cdk-lib: emits performance counters if synthesis is slow (#37919) (caa0f4c), closes #37843
any return types with specific interfaces in IPeer methods (#36637) (626e44d), closes #36636bucketNamePrefix and bucketNamespace properties (#37386) (997b003), closes #37760dynamodb: remove deprecated scope for stream grants (#36680) (570d552), closes #36289
PropertyMergeStrategys are now compatible with deferred Box values (#37844) (ca4b722)Lazys use the Box API internally (#37889) (464fa3d)L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
aws-elasticache: AWS::ElastiCache::CacheCluster: Id attribute removed. aws-sagemaker: AWS::SageMaker::Model: Id attribute removed. aws-vpclattice: AWS::VpcLattice::AuthPolicy: State attribute enum values changed from ACTIVE|INACTIVE to Active|Inactive.
PropertyMergeStrategy now supports array merge strategies (#37841) (701305d)core: "exports cannot be updated" for cross-region references
update L1 CloudFormation resource definitions
core: Validations class now supports addWarning, addError, and acknowledge (#37668) (5e8083c), closes aws/aws-cdk-rfcs#899
Validations class now supports addWarning, addError, and acknowledge (#37668) (5e8083c), closes aws/aws-cdk-rfcs#899bundledDependency (#37726) (6ba0598), closes #37717L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
aws-elasticloadbalancing: AWS::ElasticLoadBalancing::LoadBalancer: SourceSecurityGroup attribute removed. aws-elasticloadbalancing: AWS::ElasticLoadBalancing::LoadBalancer: PolicyItem type removed. aws-elasticloadbalancing: AWS::ElasticLoadBalancing::LoadBalancer: SourceSecurityGroup type removed.
Validations class is the new way to add validation plugins to CDK Apps (#37611) (95696b4), closes #37613policyValidationBeta1 interfaces to policyValidation (#37613) (8c613cf)Stage.policyValidationBeta1 is mutable (#37612) (3c1faf1)Token.isUnresolved checks to provisioned poller config validation (#37197) (667ed30)L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
aws-emr: AWS::EMR::Cluster: MonitoringConfiguration property removed. aws-emr: AWS::EMR::Cluster: CloudWatchLogConfiguration type removed. aws-emr: AWS::EMR::Cluster: EMRConfiguration type removed. aws-emr: AWS::EMR::Cluster: MonitoringConfiguration type removed.
L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
aws-appstream: AWS::AppStream::Stack: Id attribute removed. aws-appsync: AWS::AppSync::GraphQLApi: LogConfig.CloudWatchLogsRoleArn property is now required. aws-appsync: AWS::AppSync::GraphQLApi: LogConfig.FieldLogLevel property is now required. aws-kafkaconnect: AWS::KafkaConnect::Connector: ProvisionedCapacity.McuCount property is now required.
eks: downgrade isolated subnet validation from error to warning (#37500) (470856c), closes #37491
bump brace-expansion from 5.0.3 to 5.0.5 to address CVE-2026-33750
aws-bedrockagentcore: AWS::BedrockAgentCore::OnlineEvaluationConfig: ExecutionStatus attribute removed. aws-appstream: AWS::AppStream::ImageBuilder: Name property is now immutable. aws-eks: AWS::EKS::Capability: EKS_CAPABILITY_ACK_S3_LOGS vended log type removed.
core: noisy property deprecation warnings (#37415) (4fd0002), closes #37407
update L1 CloudFormation resource definitions
kinesisanalytics-flink-alpha: mark deprecated flink runtimes as deprecated
actions() method to Grants classes (#36987) (bbeaf5d)update L1 CloudFormation resource definitions
L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
** L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormation. Sometimes these updates can contain changes that are incompatible with previous types, but more accurately reflect reality. In this release we have changed:
PropertyMergeStrategy to merge arbitrary CFN property objects (#37206) (793ad97)s3 and ecs service mixins are now available in aws-cdk-lib (#37151) (52c99da)Asset uses a lot of memory (#37186) (70cae75)enableAutoSoftwareUpdate: false is not reflected in the CloudFormation template (#37152) (dec8e6f), closes #36382bump minimatch to ^10.2.3 to resolve ReDoS vulnerabilities (#37127) (c359329), closes #37100
aws-codedeploy: AWS::CodeDeploy::DeploymentGroup: Id attribute removed.
bump minimatch to ^10.2.1 to resolve ReDoS vulnerability (GHSA-3ppc-4f35-3m26)
rds: mark deprecated versions and add new engine versions
aws-licensemanager: AWS::LicenseManager::License: Beneficiary property is now required aws-licensemanager: AWS::LicenseManager::License: ProductSKU property is now required aws-sagemaker: AWS::SageMaker::Cluster: Orchestrator.Eks property is now immutable
ajv that triggers CVE scanners (#37022) (45662ba)redshift-alpha: update default node type from DC2_LARGE to RA3_LARGE
fromCodeAsset method to create runtime artifact with local code assets (#36472) (c5a87e6), closes #36473toDestination() (#36896) (48f1fe6)iam: undeprecate openIdConnectProviderArn and openIdConnectProviderIssuer in IOidcProvider
IDeliveryStreamRef as flow log destination (#36278) (cd73498), closes #33883 #34596 #33757Match.anyOf support for raw strings (#36908) (6804c7c), closes #36902 #36602 #36602MixinApplicator (#36877) (09db1c9), closes #36847core: intrinsic cfn function tokens are not detected as such in java
eks: add OidcProviderNative using L1 and deprecate OpenIdConnectProvider custom resource
IEncryptedResource objects now have fewer guarantees about the shape of the object. If you still require an IResource, change the type to IEncryptedResource & IResource and/or add a type guard check using Resource.isResource(). Implementations of IEncryptedResource no longer need to implement IResource but must continue to implement IEnvironmentAware. Since IResource extends IEnvironmentAware, there is no change for implementors. Calls to GrantableResources.isEncryptedResource() now require an IEnvironmentAware argument instead of IConstruct.trustAccountIdentities optional in KeyGrants (#36786) (06676ac)batch: undeprecate useOptimalInstanceClasses property (#36353) (3485d53), closes #36291 #36291
BucketPolicyStatementsMixin publicly (#36771) (458156d)apigatewayv2: use custom domain name instead of regional domain name when importing domain name via fromDomainNameAttributes
L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
securityGroups is now required in ManagedInstancesCapacityProviderProps. CloudFormation has always required this field, so any code that omitted it would have failed at deployment time with a validation error. This change catches the error at compile time instead, improving the developer experience. If your code previously omitted securityGroups, you must now explicitly provide at least one security group.JobQueue.computeEnvironments contains an computeEnvironment: IComputeEnvironment → IComputeEnvironmentRef. BackupPlanRule.props contains a backupVault: IBackupVault → IBackupVaultRef. ApiDestination.fromApiDestinationAttributes() return type ApiDestination → IApiDestination. This should never have returned a class but always an interface, as is the standard for referencing factories. EventDestination.bus changed IEventBus →IEventBusRef; FlowLogDestination.bind() now returns and ICluster.executeCommandConfiguration contains a member changing type ILogGroup → ILogGroupRef.ApiDestination.fromApiDestinationAttributes() now returns an IApiDestination. It used to return an ApiDestination but this was a mistake, referencing methods always return a type by interface, not by class.EventDestination.bus used to be an IEventBus but is now an IEventBusRef; it needs to be type tested to assert it is actually an IEventBus if that is necessary.FlowLogDestination.bind() and ICluster.executeCommandConfiguration now contain an ILogGroupRef instead of an ILogGroup, which guarantees less. These fields are for communication between constructs, and their values should not be used by application builders. If they do, they will need to add a cast or a type check.enableBatchConfig property is explicitly disabled by default. Even with this modification, the behavior of HttpAction remains unchanged from before, but only the Cfn template will be modified.RuntimeError: apiEndpoint is not configured on the imported HttpApi (revert of "chore(apigatewayv2): reference interfaces") (#36623) (fb17d39), closes aws/aws-cdk#36378RuntimeError: apiEndpoint is not configured on the imported HttpApi (revert of "chore(apigatewayv2): reference interfaces") (#36623) (1c10d49), closes
RuntimeError: apiEndpoint is not configured on the imported HttpApi (revert of "chore(apigatewayv2): reference interfaces") (#36623) (1c10d49), closes aws/aws-cdk#36378batch: unfortunately JobQueue exposes public readonly computeEnvironments: OrderedComputeEnvironment[]. The computeEnvironment member of that structur
JobQueue exposes public readonly computeEnvironments: OrderedComputeEnvironment[]. The computeEnvironment member of that structure now fewer guarantees, and needs casting. This should not have been exposed, and we assume the use of the exposed property here is rare.BackupPlanRule exposes public readonly props: BackupPlanRuleProps. The backupVault member of that structure now guarantees less, and needs casting. This should never have been exposed, and we assume the use of the exposed property here is rare.aws-securityhub: AWS::SecurityHub::ConnectorV2: Provider.JiraCloud.AuthStatus attribute removed.
aws-securityhub: AWS::SecurityHub::ConnectorV2: Provider.JiraCloud.AuthUrl attribute removed.
aws-securityhub: AWS::SecurityHub::ConnectorV2: Provider.JiraCloud.CloudId attribute removed.
aws-securityhub: AWS::SecurityHub::ConnectorV2: Provider.JiraCloud.Domain attribute removed.
aws-securityhub: AWS::SecurityHub::ConnectorV2: Provider.ServiceNow.AuthStatus attribute removed.
aws-securityhub: AWS::SecurityHub::ConnectorV2: JiraCloud type removed, replaced by JiraCloudProviderConfiguration.
aws-securityhub: AWS::SecurityHub::ConnectorV2: ServiceNow type removed, replaced by ServiceNowProviderConfiguration.
aws-ssm: AWS::SSM::MaintenanceWindowTarget: Id attribute removed.
App.of() returns incorrect values (#36475) (78034d3)arnForXxxx() helpers ignore environments from referenced resources (#36599) (4744c59){ Ref } incompatibility between schema and CFN (#36493) (3b06942)CHANGES TO L1 RESOURCES: L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the r
CHANGES TO L1 RESOURCES: L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormation. Sometimes these updates can contain changes that are incompatible with previous types, but more accurately reflect reality. In this release we have changed:
aws-ec2: AWS::EC2::EC2Fleet: DefaultTargetCapacityType property is now immutable.
aws-ec2: AWS::EC2::EC2Fleet: TargetCapacityUnitType property is now immutable.
HttpsRedirect use Distribution as the default CloudFront distribution (under feature flag) (#34312) (e2987eb), closes #31546canContainersAccessInstanceRole instance role (#36362) (7395b41)fleet and certificate (#35673) (71cfd60), closes #35664@aws-cdk/region-info throws an Cannot find module 'aws-cdk-lib/core/lib/errors' error (#36414) (01c7d2e), closes #36399ResourceEnvironment is not an alias (#36370) (ba8e194)engine property in NoPasswordUserProps has been removed.re-export of ResourceEnvironment is not an alias
core: TypeScript properties missing for types which extend internal interfaces (#36313) (3e7e17c), closes #36310
update L1 CloudFormation resource definitions
lambda: support for capacity providers
arnFor<ResourceName> for 47 more resources (#36231) (5a8be4f)isCfn<ResourceName> static helper to check if a value is this L1 resource (#36243) (dc9db9b)apigateway: support response streaming with response transfer mode (#36155) (f431021), closes #36156
EventPattern interfaces can be used with CfnRule (#36191) (efc135e)Cluster.grantTaskProtection method (#36207) (9b337df)ScheduleGroup.grant* methods (#36175) (eae8838)AutoDeleteObjects mixin fails with cannot find file error (#36188) (3ef337d), closes aws-cdk/mixins-preview/lib/custom-resource-handlers/aws-s3/auto-delete-objects-provider.ts#L21ResourcePolicy with this name already exists error when setting up LogDelivery (#36195) (f9aa31d)S3LogsDeliveryProps.permissionsVersion (#36197) (cc491df)scheduler: wrong ARN generated in ScheduleGroup.grant* methods
agentcore: add new properties for runtime, browser
HostedZoneGrants (#36109) (d24305c)lambda: add new lambda/kafka esm properties and on failure desitination
CHANGES TO L1 RESOURCES: L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the r
CHANGES TO L1 RESOURCES: L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormation. Sometimes these updates can contain changes that are incompatible with previous types, but more accurately reflect reality. In this release we have changed:
StateMachineGrants (#36094) (59ef00d)TableGrants and StreamGrants (#36093) (d0b074a)BucketGrants (#36102) (5891172)dynamodb: compound keys for global secondary indexes
L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
** L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormation. Sometimes these updates can contain changes that are incompatible with previous types, but more accurately reflect reality. In this release we have changed:
Source.jsonData() fails with null JSON values (#36054) (67b85f2), closes #36052aws-cdk-lib: Reference interfaces (such as IBucketRef, IRoleRef, etc.) were moved to a new aws-cdk-lib.interfaces submodule to prevent cyclic dependen
IBucketRef, IRoleRef, etc.) were moved to a new aws-cdk-lib.interfaces submodule to prevent cyclic dependencies between service modules. If you are importing reference interfaces, you have to update import statements accordingly. See #36060 for full details.using statements for these submodules. See #36037 for full details.aws-opensearchserverless: AWS::OpenSearchServerless::Collection: StandbyReplicas property is now immutable. aws-servicecatalog: AWS::ServiceCatalog::PortfolioPrincipalAssociation: Id attribute removed.
Your coding agent can read these notes before it upgrades. Set up the MCP server →