NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1707 most downloaded on PyPI
Version 2 of the AWS Cloud Development Kit library
Last release today
17 Sep 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
6 years old
401 releases · first in 2021
One column per quarter.
compilation failure in Go (#35871) (4379f66), closes aws/aws-cdk#35770 #35862
L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
batch: ec2 Managed Compute Environment support default instance classes, deprecate useOptimalInstanceClasses (#35537) (9d59dd8), closes #35515
L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormation. Sometimes these updates can contain changes that are incompatible with previous types, but more accurately reflect reality. In this release we have changed:
Co-authored-by: aws-cdk-automation aws-cdk-automation@users.noreply.github.com
useOptimalInstanceClasses (#35537) (9d59dd8), closes #35515L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormati
aws-servicecatalog: AWS::ServiceCatalog::PortfolioPrincipalAssociation: PortfolioId property is now required. aws-servicecatalog: AWS::ServiceCatalog::PortfolioPrincipalAssociation: PrincipalARN property is now required. aws-servicecatalog: AWS::ServiceCatalog::PortfolioProductAssociation: Id attribute removed.
Co-authored-by: aws-cdk-automation aws-cdk-automation@users.noreply.github.com
cloudfront-origins: ip address type for http origin (#35445) (196c7ae), closes #35427
CodeBuildFactory support Docker server (#35584) (c62d996)from<Resource>Arn and from<Resource><Prop> in every L1 (#35470) (c588061)update L1 CloudFormation resource definitions
Function ARN reference changed from GetAtt to Ref (#35547) (8a26869), closes #35531Alias reference incorrectly resolves to underlying Key (#35545) (43ffcff), closes #35543kinesisanalytics: deprecate using KinesisAnalyticsV2 from aws-kinesisanalytics, use aws-kinesisanalyticsv2 instead
EmrCreateClusterOptions support ebsRootVolumeIops, ebsRootVolumeThroughput and managedScalingPolicy (#34677) (b3ad6f9), closes #33431aws-kinesisanalytics, use aws-kinesisanalyticsv2 instead (#35519) (4255b23)SecretRotationApplication creates lambda on python 3.9 which is EOL (#35528) (756b683), closes #3416833270: support new bun lock file (#34873) (0a55ed1), closes #33270
TarballImageAsset respects CDK_DOCKER environment variable (#35344) (8bf6b00), closes #35336introduce reference interfaces, but don't require them yet
stop passing the deprecated property to Cfn construct (#35080) (a20afcd), closes #34895
L1 resources are automatically generated from public CloudFormation Resource Schemas. They are build to closely reflect the real state of CloudFormation. Sometimes these updates can contain changes that are incompatible with previous types, but more accurately reflect reality. In this release we have changed:
DockerBuildOptions support network param (#34725) (bc333e2), closes #34514AlarmRule.concat cover empty operands (#34757) (a01aa38), closes #34662L1 resources are automatically generated from public CloudFormation Resource Schemas. They are build to closely reflect the real state of CloudFormati
StatusInfos property is removed.SingleSignOnApplicationArn property is removed.Name property is now set as immutable.aws-opsworkscm: CfnServer resource is no longer provisionable (AWS::OpsWorksCM::Server). Service is on deprecation path
cloudformation: L1 resources are automatically generated from public CloudFormation Resource Schemas. They are build to closely reflect the real state of CloudFormation. Sometimes these updates can contain changes that are incompatible with previous types, but more accurately reflect reality. In this release we have changed:
DataDestinationConfigs,
SignalsToCollect and SignalsToFetch in resource CfnCampaign are
now marked as immutable (they will cause a replacement of the resource
if updated)ServiceRegion property for AWS::EC2::VPCEndpoint (#35025) (fee0638), closes #32785 #33959ecs: add support for native blue/green deployments in ECS L2 (#35061) (#35170) (88696e9), closes #35167
eks: fix helm commands not running ecr public login
deprecating delete existing field in ARecord (#35039) (49b2627), closes #34230
custom-resources: use loggingFormat instead of deprecated logFormat (#35015) (81fe660), closes #35002
Tag must have a value error is impossible to attribute to a specific tag (#35091) (6c4181b)core: allow validation report multi-write based on context keys
custom-resource: Added async custom resource provider framework logging off by default
kinesisfirehose: support custom time zone settings for S3 destination (#34738) (2bbe762), closes #34737
arnForPolicy attribute for api destination (#34315) (e0ac9f8)fromLookup method for Amazon Aurora Database Cluster (#34849) (23ca6fc), closes #34848 #33258maxRetries prop to configure automatic retries on canary runs (#34541) (54d8a84), closes #34511L1 resources are automatically generated from public CloudFormation Resource Schemas. They are build to closely reflect the real state of CloudFormation. Sometimes these updates can contain changes that are incompatible with previous types, but more accurately reflect reality. In this release we have changed:
Id attribute was removedId attribute was removedId attribute was removedapigatewayv2: add stage variables support for HTTP and WebSocket API
"Invalid Assembly Manifest" when used with CLI 2.1017.0 and 2.1018.0 (#34880) (32ee050), closes aws/aws-cdk#34798
cloudformation: Some L1 resources experienced breaking changes due to updated CloudFormation resources. Please check the notes for each specific modul…
template property here has changed from string to jsonlambda: support for schema registry for kafka
lambda.Version and apigateway.Deployment from refactoring (#34710) (dd14a17)Asset actions when publishAssetsInParallel is false (#34049) (754ad50), closes #34042 #33844opensearch: update default TLS security policy to TLS 1.2 for OpenSearch domains (#34660) (3cc2dc2), closes #34658
bootstrapSelfManagedAddons (#33597) (cedc1b0), closes #30792DatabaseInstanceFromSnapshot support clusterSnapshotIdentifier (#33982) (48d30b6), closes #33889JsonSchema.additionalItems property type (#33879) (464d521), closes #33878 #33878IDeliveryStream as flow log destination (#34596) (cdfe6e7), closes #33883 #33757IDeliveryStream as flow log destination (#34665) (b77bd0e), closes aws/aws-cdk#34596lambda: disable aws-lambda:useCdkManagedLogGroup feature flag when not set (#34613) (b4cab7f), closes #34612 #34612
update L1 CloudFormation resource definitions
ValidationError instead of untyped Errors (#33392) (1dacaa3), closes #32569IPeer to PrefixList to be usable as a connection peer (#33617) (c277419), closes #33607OidcProviderNative construct utilizing the native CloudFormation resource (#28634) (d8e6c09), closes #21197ValidationErrors instead of untyped errors (#34579) (bd5caba), closes #32569ValidationErrors instead of untyped errors (#34577) (6ccdd81), closes #32569ValidationError instead of untyped Errors (#33384) (303daf2), closes #32569grantReplicationPermission for IAM Role permissions (#34138) (bfa6490), closes #34119ValidationErrors instead of untyped errors (#34580) (4d591ef), closes #32569ValidationErrors instead of untyped errors (#34581) (3895d76), closes #32569cloudformation: Some L1 resources experienced breaking changes due to updated CloudFormation resources. Please check the notes for each specific modul…
name and resourceConfigurationType property in CfnResourceConfigurationProps has changed from optional to required. Also, the name, subnetIds and vpcIdentifier properties in CfnResourceGatewayProps have changed from optional to mandatory.Addon support configurationValues (#34061) (b420033), closes #34001update L1 CloudFormation resource definitions
tree.json exceeds 512MB (#34478) (ff2f4af)platform is Platform.WEB_COMPUTE or Platform.WEB_DYNAMIC.update L1 CloudFormation resource definitions
platform is ignored during asset bundling (#33865) (91bec88), closes #30239NodejsFunction without the entry property fails (#34498) (36ce84d)lambda-nodejs: instantiating NodejsFunction without the entry property fails
cloudformation: Some L1 resources experienced breaking changes due to updated CloudFormation resources. Please check the notes for each specific modul…
DeliveryDestinationPolicy of resource AWS::Logs::DeliveryDestination changed to be DestinationPolicy instead of JSON.ValidationErrors instead of untyped errors (#34427) (5cfea39), closes #32569ValidationErrors instead of untyped errors (#34428) (2e7c55b), closes #32569ValidationErrors instead of untyped errors (#34429) (13d9645), closes #32569ValidationErrors instead of untyped errors (#34430) (e493cc8), closes #32569ValidationErrors instead of untyped errors (#34426) (5ee092a), closes #32569ValidationErrors instead of untyped errors (#34431) (10756c1), closes #32569ValidationErrors instead of untyped errors (#34432) (5509923), closes #32569ValidationErrors instead of untyped errors (#34434) (bc7c4e8), closes #32569ValidationErrors instead of untyped errors (#34435) (28048b3), closes #32569ValidationErrors instead of untyped errors (#34436) (98e352d), closes #32569ResultWriter support JSONPath/JSONata bucket (#33793) (8a5aecb), closes #32687ValidationErrors instead of untyped errors (#34438) (e828389), closes #32569publish 'app-staging-synthesizer-alpha' for Go
pullRequestFilter and pushFilter (#34267) (1cac5a0), closes #34253hostedZoneId to support token endpoint with default value derived from stack region or endpointUrl (#34122) (9e52752), closes #31843deviceDertificateAgeCheck is automatically enabled.appsync: add support for data source integrations (#34248) (2fac64e), closes #34264
ValidationErrors instead of untyped Errors (#34239) (7f378b6), closes #32569apigateway: add mode property for SpecRestApi
mode property for SpecRestApi (#34198) (feadd8c)Rule support role (#33779) (9e4c9a9), closes #33722Role.fromLookup() method (#33603) (9e3cbf6), closes #33602cloudformation: Some L1 resources experienced breaking changes due to updated CloudFormation resources. Please check the notes for each specific modul…
Id attribute is being removed from the
AWS::Neptune::DBClusterParameterGroup and AWS::Neptune::DBParameterGroup
resourcesspecifications prop moved from required to
optional in CfnDeploymentattribute attribute moved from required to optional in
RuleBooleanToEvaluatePropertycloudformation: Some L1 resources experienced breaking changes due to updated CloudFormation resources. Please check the notes for each specific modul…
ScheduleStatus property has been removed from AWS::Backup::RestoreTestingPlan.DisableSessionTags and TargetRoleArn properties and ExternalId attribute have been removed from AWS::EKS::PodIdentityAssociation.Id attribute has been removed from AWS::Neptune::DBSubnetGroup.CertificateDetails and Endpoint properties have been removed from AWS::RDS::DBInstance.Workgroup.BaseCapacity attribute has been removed from AWS::RedshiftServerless::Workgroup.escape parameter in Source.jsonData(). Users who were relying on the automatic JSON escaping for handling special characters in JSON files will need to explicitly enable this behavior by passing { escape: true } as the third parameter.HttpStage access logging (#33977) (d04e40f), closes #11100ValidationErrors instead of untyped Errors (#34120) (271e439), closes #32569DatabaseInstance.fromLookup (#33258) (eb97d2d)FluentdLogDriver add async replacing deprecated asyncConnect (#34059) (c993d34), closes #34055addNatGateways method, will be changed, resulting in the NAT Gateway being recreated. Additionally, the domain for the Elastic IP (EIP) will be set to vpc, which will also trigger its recreation in the account.core: implicit Aspect applications do not override custom Aspect applications
apigatewayv2: dualstack HTTP and WebSocket API
V2 pipeline type support in L3 construct (#34005) (994e952), closes #33995AwsCustomResource assumed role session name may contain invalid characters (#34016) (32b6b4d), closes #23260 #34011lambda: deprecate default feature flag @aws-cdk/aws-lambda:createNewPoliciesWithAddToRolePolicy (#34010) (242091a), closes #33688
ECRBuildAndPublish action (#33375) (c5cd679), closes #33376InspectorEcrImageScanAction and InspectorSourceCodeScanAction actions (#33378) (2dc8cc7), closes #33377cx-api: declare support for CDK_TOOLKIT_VERSION env var
Nodegroup support nodeRepairConfig (#32626) (b9cb47c), closes #32562ValidationErrors instead of untyped Errors (#33912) (8b23b5d), closes #32569placementGroup to LaunchTemplateProps and LaunchTemplate (#33726) (e5f71db), closes #33721SupportedRegions property for AWS::EC2::VPCEndpointService (#33959) (0c77cb6)redshiftserverless: The CfnWorkgroup.attrWorkgroupMaxCapacity attribute has been removed.
CfnWorkgroup.attrWorkgroupMaxCapacity attribute has been removed.CfnAnalysis.SheetTextBoxProperty.interactions, CfnDashboard.SheetTextBoxProperty.interactions, and CfnTemplate.SheetTextBoxProperty.interactions properties have been removed.CfnDistributionConfiguration.DistributionProperty.ssmParameterConfigurations property has been removed.ValidationErrors instead of untyped Errors (#33854) (f28eae2), closes #32569ValidationErrors instead of untyped Errors (#33853) (b6b91dd), closes #32569ValidationErrors instead of untyped Errors (#33855) (3ff5501), closes #32569ValidationErrors instead of untyped Errors (#33869) (5bc9292), closes #32569ValidationErrors instead of untyped Errors (#33870) (2dc5d70), closes #32569ValidationErrors instead of untyped Errors (#33871) (a9bae27), closes #32569ValidationErrors instead of untyped Errors (#33899) (0787840)ValidationErrors instead of untyped Errors (#33885) (6bf8095)ignoreErrorOnMissingContext parameter is misleading (#33875) (b3187b9)EventBus.grantPutEventsTo correctly handles service principals (under feature flag) (#33729) (38d82c4), closes #22080 #22080PrefixList.fromLookup() (#33619) (b6a15f3), closes aws/aws-cdk#33606 aws/aws-cdk#15115s3-deployment: backfill missing enums for s3-deployment (#33819) (2623e00), closes /docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-propert
ValidationError instead of untyped Errors (#33753) (1fea9f1)KinesisDataFirehosePutRecord has been renamed to FirehosePutRecord.iam: fix(iam): adding organization id pattern verification (#33773) (f7ed316), closes aws/aws-cdk#33768
ecr: throw ValidationError instead of untyped Errors
workflow.addconditionalTrigger to workflow.addConditionalTrigger.scheduler-alpha: deprecate Group in favour of ScheduleGroup
ValidationError instead of untyped Errors (#33700) (d12854a), closes #32569RemovalPolicies.of(scope) (#32283) (34c547c)transitionToArchivePolicy is specified and throughputMode is undefined (#33713) (842201c)InspectorStartAssessmentRun target's constructor now accepts IAssessmentTemplate instead of CfnAssessmentTemplate as its parameter type. To migrate existing code, use the AssessmentTemplate.fromCfnAssessmentTemplate() method to convert your CfnAssessmentTemplate instances to IAssessmentTemplate.assertions: added getResourceId method to Template
HealthChecks for multiple health check types, including EBS and VPC_LATTICE types (#31286) (b3edd0d), closes #31289 /github.com/aws/aws-cdk/blob/main/packages/aws-cdk-lib/aws-autoscaling/lib/auto-scaling-group.ts#L233 /github.com/aws/aws-cdk/blob/main/packages/aws-cdk-lib/aws-autoscaling/lib/auto-scaling-group.ts#L2232-L2258 /github.com/aws/aws-cdk/pull/31286#discussion_r1740763781DatabaseCluster support replicationSourceIdentifier (#33471) (878ad54), closes #33280cognito-identitypool-alpha: Any IdentityPool resources deployed in versions >=2.179.0 will now fail to deploy. You will need to delete the IdentityPoo
IdentityPool resources deployed in versions >=2.179.0 will now fail to deploy. You will need to delete the IdentityPoolRoleAttachment from your stack via the console before redeploying.msk: support for Kafka version 3.8.x and add deprecated labels to legacy versions
serviceTimeout for CustomResource does not work with token (#33541) (bc91c70), closes #33513 /github.com/go-to-k/aws-cdk/blob/75e52619cd09f363882ff62561a53cd5cd79ab30/packages/aws-cdk-lib/core/lib/custom-resource.ts#L169 /github.com/go-to-k/aws-cdk/blob/75e52619cd09f363882ff62561a53cd5cd79ab30/packages/aws-cdk-lib/core/lib/duration.ts#L332monitoringInterval in DatabaseClusterProps does not work with token (#33516) (f9b28b9), closes #33504SageMakerCreateTrainingJob add sagemaker:AddTags permission (#32536) (3b07346), closes #32294cloudfront-origins: read versioned access level (#33038) (315be88), closes #33034
ValidationErrors instead of untyped Errors (#33456) (6098816), closes #32569timeout for ManualApprovalAction (#33472) (7901f07), closes #33473DataProtectionPolicy template key must be PascalCase (#33462) (0379878), closes #33408 #26728eks: kubectlLayer property is now required in EKS Cluster and FargateCluster constructs. The default value for kubectlLayer is outdated and hence bein
kubectlLayer property is now required in EKS Cluster and FargateCluster constructs. The default value for kubectlLayer is outdated and hence being removed. You can specify your own kubectlLayer version based on your Kubernetes version.ValidationErrors instead of untyped Errors (#33455) (11a75b2), closes #32569detailedMetricsEnabled property (#33267) (0abcacf), closes #33222ValidationError instead of untyped Errors (#33386) (b4efb1e), closes #32569ValidationError instead of untyped Errors (#33383) (19cf902), closes #32569ValidationError instead of untyped Errors (#33388) (d3f3309), closes #32569ValidationError instead of untyped Errors (#33387) (48f2bf7), closes #32569ValidationError instead of untyped Errors (#33389) (c83ca82), closes #32569ValidationErrors instead of untyped Errors (#33440) (76848e4), closes #32569ValidationError instead of untyped Error (#33439) (ede5842), closes #32569ValidationError instead of untyped Errors (#33391) (92a9a73), closes #32569ValidationErrors instead of untyped Errors (#33438) (c08c7f0), closes #32569CloudAssemblyError instead of untyped Errors (#33390) (ae95d95), closes #32569ValidationError instead of untyped Errors (#33385) (14b1098), closes #32569cluster.addHelmChart ignores skipCrds (#31832) (ee63467), closes #31831SelfManagedKafkaEventSource cannot be used in NPM symlinked workspaces (#32937) (fe656af)CallAwsServiceCrossRegion doesn't work with WAIT_FOR_TASK_TOKEN (#32807) (800b775), closes #32746 /github.com/aws/aws-cdk/blob/bbdd42c8f45916d5c6945f3429916f6199d2ec66/packages/aws-cdk-lib/aws-stepfunctions-tasks/lib/lambda/invoke.ts#L146-L165IdentityPoolRoleAttachment construct and IdentityPool.addRoleMappings() function will no longer exist. This is to disambiguate that only one role attachment can exist per Identity Pool. If you are using the IdentityPool construct, this change will trigger a redeployment. If you need to add role mappings, please do so when the IdentityPool is created.cli: do not print credentials refreshed by plugins (#33398) (727d42f), closes #33394 #33394
cli: sdk logging is always present even when not turned on (#33324) (29a9a6d), closes #33320
dynamodb: add pointintimerecoveryspecification and deprecate old (#33059) (aec64f0), closes #32786
ValidationError instead of untyped errors (#33075) (04efe6c), closes #32569ValidationError instead of untyped errors (#33172) (abd4a3e), closes #32569ValidationError istead of untyped Errors (#33245) (ba2f5c8), closes #32569ValidationError instead of untyped errors (#33206) (ab9dd0a), closes #32569ValidationError instead of untyped errors (#33170) (ecbe1bf)ExternalService support daemon scheduling strategy (#32630) (361c7d3), closes #32538tls property to a ServiceConnectService (#32605) (d32baf6), closes #32583containerCpu and containerMemoryLimitMiB property to ApplicationLoadBalancedFargateService (#30920) (4dd97bc), closes #20638 #20638ValidationError instead of untyped errors in L1s (#33032) (1b666db), closes #32569operatingRegion property under IPAM class is now renamed to operatingRegions.TaskDefinitionProps.inferenceAccelerators attribute and TaskDefinition.addInferenceAccelerator() method will be marked as deprecated.ec2-alpha module is now in Developer Preview (#33230) (a06f91a)bedrock: deprecate Claude 2, 2.1, Instant
ValidationError instead of untyped errors (#33072) (8b472fc), closes #32569ValidationError instead of untyped errors (#33082) (5377586), closes #32569ValidationError instead of untyped errors (#33076) (dd34d2e), closes #32569ValidationError intsead of untyped errors (#33111) (cc1988a), closes #32569ValidationError instead of untyped errors (#33033) (a928748), closes #32569ValidationError instead of untyped errors (#33042) (0b2db62), closes #32569ValidationError instead of untyped errors (#33110) (5e0f16d), closes #32569ValidationError instead of untyped errors (#33031) (61e876b), closes #32569ValidationError instead of untyped errors (#33109) (aea8f3b), closes #32569ValidationError instead of untyped errors (#33045) (7452462), closes #32569ValidationError instead of untyped errors (#33046) (6469412), closes #32569ValidationError instead of untyped errors (#33067) (6677b33), closes #32569ValidationError instead of untyped errors (#33079) (e4703c1), closes #32569Increased unit test coverage to > 90%, consulted with Glue service team on best practices and sane defaults, updated integration tests.
apigatewayv2-integrations: WebSocketMockIntegration props (#30622) (a5a0168), closes #29661
WebSocketMockIntegration props (#30622) (a5a0168), closes #29661aws-cdk (#32817) (97af31b), closes #32237cli: "no stack found in the main cloud assembly" (#32839) (7b68908), closes aws/aws-cdk#32636 #32836 #32836
ecs: outdated linux commands for canContainersAccessInstanceRole=false and also deprecate property (#32763) (bbdd42c), closes #28518
cdk destroy (#32636) (c199378), closes #32545 #27179 40aws-cdk-testing/cli-integ/tests/cli-integ-tests/cli.integtest.ts#L190 aws-cdk-testing/cli-integ/tests/cli-integ-tests/cli.integtest.ts#L286-L291CI=false (#32749) (26b361d)canContainersAccessInstanceRole=false and also deprecate property (#32763) (bbdd42c), closes #28518Your coding agent can read these notes before it upgrades. Set up the MCP server →