NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1502 most downloaded on PyPI
Version 2 of the AWS Cloud Development Kit library
Last release 4 days ago
30 Sep 2026
Ships on a steady schedule
a new release about every 2 weeks
Nearly every release is documented
notes for 60 of the last 60 stable releases
1 version withdrawn
withdrawn after publishing
6 years old
403 releases · first in 2021
One column per quarter.
cli: "no stack found in the main cloud assembly" (#32839) (7b68908), closes aws/aws-cdk#32636 #32836 #32836
ecs: outdated linux commands for canContainersAccessInstanceRole=false and also deprecate property (#32763) (bbdd42c), closes #28518
cdk destroy (#32636) (c199378), closes #32545 #27179 40aws-cdk-testing/cli-integ/tests/cli-integ-tests/cli.integtest.ts#L190 aws-cdk-testing/cli-integ/tests/cli-integ-tests/cli.integtest.ts#L286-L291CI=false (#32749) (26b361d)canContainersAccessInstanceRole=false and also deprecate property (#32763) (bbdd42c), closes #28518update L1 CloudFormation resource definitions
lambda: add @deprecated tag to python3.8
availabilityZoneDistribution property to an AutoScalingGroup (#32100) (ecfce7c)@aws-cdk/cloud-assembly-schema (#32704) (3b162fc)null for expiration (#32554) (d4f6946)3_7_X and 3_7_X_KRAFT (#32515) (cbacf4d)cli: cli still fails for some plugins returning expiration: null (#32668) (4da2f65), closes #32111
aspects: "localAspects is not iterable" error (#32647) (8948ecb), closes #32470
cli: allow credential plugins to return null for expiration
cli: getting credentials via SSO fails when the region is set in the profile
cognito: user pool feature plans (#32367) (39c22de), closes #32369
AutoScalingGroup requireImdsv2 with launchTemplate or mixedInstancesPolicy throws unclear error (#32220) (06cdaac), closes #27586 #27586period of each metric in usingMetrics for MathExpression is ignored (#30986) (59e96a3), closes /github.com/aws/aws-cdk/blob/main/packages/aws-cdk-lib/aws-cloudwatch/lib/metric.ts#L606-L608 /github.com/aws/aws-cdk/blob/main/packages/aws-cdk-lib/aws-cloudwatch/lib/metric.ts#L566apigateway: We will be removing deprecated APIGatewayV2 constructs from aws-apigateway module.
APIGatewayV2 constructs from aws-apigateway module.cloudFrontEndpoint method for user pool domain without custom resource (#31402) (deeb2ad), closes #31342AppSync route53 target (#31976) (dc7574a), closes #26109appsync.HttpDataSourceProps erroneously extends BaseDataSourceProps (#32065) (4e7f5c4), closes #29689lambda:GetFunctionConfiguration action is not allowed (#32301) (be000a2), closes #32219$AWS_PROFILE is used (#32313) (6458439), closes #32312--no-rollback flag that is present (#32309) (559d676), closes #32295originAccessControlId CloudFront Origin property to CloudFormation templates (#32020) (f9708a6), closes #32018Role.addManagedPolicy() does not work for imported roles IRole (#31212) (c78ef1b), closes #8307cli: lambda hotswap fails if lambda:GetFunctionConfiguration action is not allowed (#32301) (a073e93), closes /github.com/aws/aws-sdk-js-v3/blob/main/
lambda:GetFunctionConfiguration action is not allowed (#32301) (a073e93), closes /github.com/aws/aws-sdk-js-v3/blob/main/clients/client-lambda/src/waiters/waitForFunctionUpdatedV2.ts#L10 /github.com/aws/aws-sdk-js-v3/blob/main/clients/client-lambda/src/waiters/waitForFunctionUpdated.ts#L13rds: enhanced monitoring configuration at the cluster level (#32157) (01f2dcd), closes #32151
lambda: support for Provisioned Pollers
cloudfront: add attachWebAclId method for Distribution
attachWebAclId method for Distribution (#30567) (cbe2bec)scheduler and scheduler-targets modules are now in Developer Preview (#32207) (8776832), closes #31785cloudfront: function URL origin access control L2 construct (#31339) (b8f47c8), closes #31629
function URL origin access control L2 construct (#31339) (b8f47c8), closes #31629cdk diff always falls back to template only diff (#32165) (089e9d8)deploy (#32163) (9966f57)~/.aws/credentials is ignored (#32133) (d1b3c81), closes #32130cli: cdk diff always falls back to template only diff
cdk diff always falls back to template only diff (#32165) (3fd9699)deploy (#32163) (465da31)cli: failure to get credentials when session token is not set (#32134) (425efbc), closes #32120
cli: upgrade aws-sdk to sdkv3 (#31702) (5bc0662), closes #25870 #26292 #20956 #24744 #27265
cli: automatically roll back stacks if necessary (#31920) (2f9fb1e), closes #30546
autoMinorVersionUpgrade for a database cluster (#31962) (0fb6106)artifactS3Encryption property to the Canary Construct. (#30197) (1f39cb9), closes #30190bootstrap: add lifecycle rule to abort multipart uploads after 7 days (#31956) (b800da8), closes #29045
synth is called multiple times on mutated construct tree (#31865) (a261c9d), closes #24689fifo: false does not deploy (#31922) (a9d3b02), closes #8550VpcCidrBlock L2 construct replaces CfnVPCCidrBlock. This change alters the logical ID of AWS::EC2::VPCCidrBlock resources in CloudFormation templates. Existing deployments will see errors like CIDR range conflicts with x.xx.xx.xx/xx with association ID vpc-cidr-assoc-ABCD. To resolve this, you must recreate your existing stacks to use the new module.enable node-fips compatible body checksums for S3
cli: add ability to configure hotswap properties for ECS (#30511) (fee2cf8), closes #29618
'Need to perform AWS calls for account' when doing cross-account deployments (#31846) (5aa63d1), closes #31845
cli: garbage collect s3 assets (under --unstable flag)
--unstable flag) (#31611) (0a0e4ad)emailVerified for AttributeMapping interface (#31632) (5de7835), closes #30467 #30467fromLookup method to return dummy key if target key was not found (#31676) (34bdeca), closes #31574 /github.com/aws/aws-cdk/blob/v2.161.0/packages/aws-cdk-lib/aws-kms/lib/key.ts#L686 /github.com/aws/aws-cdk/issues/31574#issuecomment-2399080697transitionDefaultMinimumObjectSize for life cycle (#31778) (4aa117b), closes #31777 /docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-s3-bucket-lifecycleconfiguration.html#cfn-s3cdk import errors with 'S3 error: Access Denied' (#31727) (cd324d0), closes #31597 #31716cli: cdk import errors with 'S3 error: Access Denied' (#31727) (5c2787a), closes #31597 #31716
appsync: add ownerContact property to the GraphqlApi
ownerContact property to the GraphqlApi (#31585) (a8b2f01)grantDataApiAccess method for imported database cluster (#31280) (3c92012), closes #31116 /github.com/aws/aws-cdk/blob/main/packages/aws-cdk-lib/aws-rds/lib/cluster.ts#L983 /github.com/aws/aws-cdk/blob/main/packages/aws-cdk-lib/aws-rds/lib/cluster.ts#L523-L526cdk diff on large templates fails when passing in toolkitStackName and qualifier (#31636) (f603c97), closes #29179http2Enabled with true is ignored in ApplicationLoadBalancer (#31675) (c1b240e), closes #31609destinations property with destination (singular) and changed the type from array of Destinations to a single Destination. Old behaviour would only allow an array with a single Destination to be passed in anyway.### Reverts * feat(cli): cdk rollback (#31407) (#31657) (29bf223) --- ## Alpha modules (2.161.1-alpha.0)
update L1 CloudFormation resource definitions (#31640) (79d9c4d), closes /docs.aws.amazon.com/datasync/latest/userguide/create-locations-cli.html#crea
cdk rollback (#31407) (0755561), closes #30546cdk diff --quiet to print stack name when there is diffs (#30186) (bcf9209), closes #27128isTaggable function can return undefined instead of false (#31600) (be70c82), closes #26495cdk diff to upload large templates (#31597) (be1207b), closes #29936 /github.com/aws/aws-cdk/blob/main/packages/aws-cdk/lib/api/bootstrap/bootstrap-template.yaml#L275 /github.com/aws/aws-cdk/blob/4b00ffeb86b3ebb9a0190c2842bd36ebb4043f52/packages/aws-cdk/lib/api/deployments.ts#L605logging and logGroup properties in DestinationLoggingProps have been removed and replaced with a single optional property loggingConfig which accepts a class of type LoggingConfig.Combine the logging and logGroup properties into a single new optional property called loggingConfig which accepts a class of type LoggingConfig.
LoggingConfig is an abstract class which can be instantiated through either an instance of EnableLogging or DisableLogging which can be used in the following 3 ways:
import * as logs from 'aws-cdk-lib/aws-logs';
const logGroup = new logs.LogGroup(this, 'Log Group');
declare const bucket: s3.Bucket;
// 1. Enable logging with no parameters - a log group will be created for you
const destinationWithLogging = new destinations.S3Bucket(bucket, {
loggingConfig: new destinations.EnableLogging(),
});
// 2. Enable a logging and pass in a logGroup to be used
const destinationWithLoggingAndMyLogGroup = new destinations.S3Bucket(bucket, {
loggingConfig: new destinations.EnableLogging(logGroup),
});
// 3. Disable logging (does not accept any parameters so it is now impossible to provide a logGroup in this case)
const destinationWithoutLogging = new destinations.S3Bucket(bucket, {
loggingConfig: new destinations.DisableLogging(),
});
unit + integ test
allow all sts options for roles assumed by the cli (#31089) (5e95ba2), closes #26157 #22535
sts options for roles assumed by the cli (#31089) (5e95ba2), closes #26157 #22535fix(ec2): fixing vpc endpoint pattern for ecr and ecr docker
cognito: deprecate privateKey and add privateKeyValue as typed SecureValue (#31409) (7ee183d), closes /github.com/aws/aws-cdk/blob/1e203753519e10e19ef…
routeSelectionExpression for an HTTP API (#31373) (36baf51), closes #31104encryptionKey property is removed and encryption property type has changed from the StreamEncryption enum to the StreamEncryption class.To pass in a KMS key for the customer managed key case, use StreamEncryption.customerManagedKey(key)
Replaced encryption and encryptionKey properties with a single property encryption of type StreamEncryption and is used by calling one of the 3 methods:
SreamEncryption.unencrypted()
StreamEncryption.awsOwnedKey()
StreamEncryption.customerManagedKey(key?: IKey)
This makes it so it's not longer possible to pass in a key when the encryption type is AWS owned or unencrypted. The key is an optional parameter in StreamEncryption.customerManagedKey(key?: IKey) so following the previous behaviour, if a key is provided it will be used, otherwise a key will be created for the user.
Generated templates do not change so behaviour remains the same.
Updated integ/unit tests.
cloudformation-include: can't use CFN intrinsics in Tags (#30515) (af9e6ba), closes #27594
update L1 CloudFormation resource definitions
bedrock: add Stable Image Ultra, Stable Diffusion 3 Large, and Stable Image Core model identifiers
RedshiftDataParameters (#29462) (84c6442), closes #15712 #31017codebuild: macOS codebuild support (#31203) (823ff6e), closes #31170
preserveOnDelete for EKS addon (#30776) (23fba1c)multiRegion property to a Key (#31125) (3dc4c50)update L1 CloudFormation resource definitions
elasticloadbalancingv2-targets: add AlbListenerTarget for NLBs, deprecate AlbTarget due to ALB listener race conditions (#17208) (#30396) (1fca1e5), c…
lambda: support Recursive Loop Protection property
lambda: support filter criteria encryption
feat(ecs): add validation checks to memory cpu combinations of FARGATE compatible task definitions
apigatewayv2: add description property for stage
description property for stage (#30820) (8651bbe)versionDescription property for LaunchTemplate (#30837) (597228c)description property for eventBus (#30935) (28fbc82)displayName for topic (#30770) (da2ec75)update L1 CloudFormation resource definitions
codedeploy: zonal configuration for ServerDeploymentConfig (#30429) (da0dc57), closes #30430
ServerDeploymentConfig (#30429) (da0dc57), closes #30430createdBy property for notification rule (#30780) (a68b418)apigateway: authorization scope is not added when not explicitly defining authorization type in method or root api (#30822) (4bee768), closes #30444
lambda-nodejs: breaking change in esbuild causes import module error (#30726) (7f5ce4b), closes #30717
project.visibility (#30103) (1bacb69)delegatedZone (#30440)" (#30606) (95280a0), closes #30600lambda-nodejs: breaking change in esbuild causes import module error (#30726) (06c14b1), closes #30717
fix(core): overrideLogicalId validation
route53 CrossAccountZoneDelegationRecord fails at deployment time with imported delegatedZone (#30440)" (#30606) (69eb617), closes #30600
ec2: add nitro enclave and hibernation settings to the Instance Construct
appsync: add maxBatchSize property to the AppSyncFunction Construct
maxBatchSize property to the AppSyncFunction Construct (#30266) (f1dc142)config: proactive evaluation mode (#30174) (516ecef), closes #30172
userRoleRequired for the SlackChannelConfiguration (#30420) (5b84ca6), closes #30403Fleet L2 (#29754) (940e799), closes #29617 #29616logApiResponseData is added to custom resource event properties by default (#30418) (a899ac6), closes #30121 #29949 #29648delegatedZone (#30440) (a3d9b10), closes #28581appconfig: add grantReadConfig method to Environment Construct (#30180) (c8f2646), closes #28585
instanceInitiatedShutdownBehavior for EC2 instance (#30160) (c073617), closes #30164hour property set to 24 in the LustreMaintenanceTime class. (#30342) (6301a9a), closes #30341fix(ses-actions): permissions too wide for S3 action
codebuild: add deleteReports property to the ReportGroup Construct
fix(diff): properties from ChangeSet diff were ignored
asg: support keypair functionality for asg (#29679) (f6b649d), closes #29237
GitPullRequestFilter for pipeline trigger (#29128) (5ce1b64), closes #29126ProductStack memoryLimit prop (#30105) (4b6dc8c), closes #29862rds: implement setting parameter group name
update L1 CloudFormation resource definitions
autoPublish property to the Function (#30030) (5dd72b8), closes #30028kmsKey for repository (#29988) (5f8e52e)fromApiDestinationAttributes import method (#29943) (db155e1), closes #29942fix(lambda): version.fromVersionArn creates invalid Version object
appconfig: constrain environments to a single deployment at a time (#29500) (3dd834d), closes #29345
pidMode for FargateTaskDefinition (#29670) (ed75b16), closes #29619WorkMail rule action (#29854) (6fdc458)diff --template crashes (#29896) (466f170), closes #29890ApiGateway events target should accept IRestApi (#29397) (8e1fefd), closes #16423 /github.com/aws/aws-cdk/pull/16542#discussion_r713676896 /github.com/aws/aws-cdk/pull/16542#issuecomment-925051255Your coding agent can read these notes before it upgrades. Set up the MCP server →