Repository navigation
chore(release): 2.264.0 - #38527
Merged
Merged
chore(release): 2.264.0#38527
Conversation
### Issue # (if applicable) Closes #37811 ### Reason for this change RDS Oracle `19.0.0.0.ru-2025-10.rur-2025-10.r1` is supported by Amazon RDS ([Oracle 19c Release Notes](https://docs.aws.amazon.com/AmazonRDS/latest/OracleReleaseNotes/oracle-version-19-0.html)) but was missing from the CDK `OracleEngineVersion` static properties. ### Description of changes Added `OracleEngineVersion.VER_19_0_0_0_2025_10_R1` static property for the October 2025 Release Update. ### Description of how you validated changes Follows the existing pattern of all other Oracle engine version entries. No logic change, only a new static constant. ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
### Issue # (if applicable) Closes #<issue number here>. ### Description of changes Moves the schedule run for pending-maintainer-action workflow from 08:00 UTC to 21:00 UTC ### Describe any new or updated permissions being added ### Description of how you validated changes ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…oup across 1 directory (#38466) Bumps the npm_and_yarn group with 1 update in the / directory: [nx](https://github.com/nrwl/nx/tree/HEAD/packages/nx). Updates `nx` from 20.8.4 to 22.7.2 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/nrwl/nx/releases">nx's releases</a>.</em></p> <blockquote> <h2>22.7.2 (2026-05-14)</h2> <h3>🚀 Features</h3> <ul> <li><strong>gradle:</strong> stream batch task results to nx as they finish (<a href="https://redirect.github.com/nrwl/nx/pull/35487">#35487</a>)</li> <li><strong>nx-dev:</strong> track docs analytics for code copy, LLM prompt, YouTube (<a href="https://redirect.github.com/nrwl/nx/pull/35526">#35526</a>)</li> <li><strong>testing:</strong> add migration for Jest 30 snapshot guide link (<a href="https://redirect.github.com/nrwl/nx/pull/35629">#35629</a>)</li> </ul> <h3>🩹 Fixes</h3> <ul> <li><strong>angular:</strong> disable vitest watch by default (<a href="https://redirect.github.com/nrwl/nx/pull/35493">#35493</a>)</li> <li><strong>angular-rspack:</strong> keep root-scoped assets out of per-locale i18n emit (<a href="https://redirect.github.com/nrwl/nx/pull/35621">#35621</a>)</li> <li><strong>bundling:</strong> include tsconfig solution input for rollup (<a href="https://redirect.github.com/nrwl/nx/pull/35476">#35476</a>)</li> <li><strong>bundling:</strong> include tsconfig solution input for webpack (<a href="https://redirect.github.com/nrwl/nx/pull/35477">#35477</a>, <a href="https://redirect.github.com/nrwl/nx/issues/35476">#35476</a>)</li> <li><strong>core:</strong> bump axios to 1.16.0 for all packages (<a href="https://redirect.github.com/nrwl/nx/pull/35568">#35568</a>)</li> <li><strong>core:</strong> add provenance check in nx console status path (<a href="https://redirect.github.com/nrwl/nx/pull/35485">#35485</a>)</li> <li><strong>core:</strong> remove access control header from graph app (<a href="https://redirect.github.com/nrwl/nx/pull/35494">#35494</a>)</li> <li><strong>core:</strong> ensure verbose logs go to stderr and daemon logs are properly decorated (<a href="https://redirect.github.com/nrwl/nx/pull/34358">#34358</a>)</li> <li><strong>core:</strong> show flaky-task count in run summary (<a href="https://redirect.github.com/nrwl/nx/pull/35491">#35491</a>)</li> <li><strong>core:</strong> unique telemetry user_id; expose workspace_id dimension (<a href="https://redirect.github.com/nrwl/nx/pull/35553">#35553</a>)</li> <li><strong>core:</strong> update minimatch to 10.2.5 (<a href="https://redirect.github.com/nrwl/nx/pull/35569">#35569</a>, <a href="https://redirect.github.com/nrwl/nx/issues/34660">#34660</a>)</li> <li><strong>core:</strong> restore use-legacy-versioning shim for <code>@nx/js</code><a href="https://github.com/21"><code>@21</code></a> ensurePackage path (<a href="https://redirect.github.com/nrwl/nx/pull/35574">#35574</a>)</li> <li><strong>core:</strong> isolate NX_PARALLEL env var in parallel-related specs (<a href="https://redirect.github.com/nrwl/nx/pull/35579">#35579</a>)</li> <li><strong>core:</strong> skip handleimport miss path when nx key packages are absent (<a href="https://redirect.github.com/nrwl/nx/pull/35596">#35596</a>)</li> <li><strong>core:</strong> use gethostuuid(3) instead of ioreg on macOS (<a href="https://redirect.github.com/nrwl/nx/pull/35599">#35599</a>)</li> <li><strong>core:</strong> isolate cache env vars in splitArgs spec (<a href="https://redirect.github.com/nrwl/nx/pull/35584">#35584</a>)</li> <li><strong>core:</strong> enable node's native v8 compile cache support (<a href="https://redirect.github.com/nrwl/nx/pull/35415">#35415</a>, <a href="https://redirect.github.com/nrwl/nx/issues/20454">#20454</a>)</li> <li><strong>core:</strong> support skipped batch tasks end-to-end and fix TUI double logs (<a href="https://redirect.github.com/nrwl/nx/pull/35617">#35617</a>)</li> <li><strong>core:</strong> keep TUI task selection on the in-progress section (<a href="https://redirect.github.com/nrwl/nx/pull/35640">#35640</a>)</li> <li><strong>core:</strong> allow <code>nx mcp</code> to run outside of an Nx workspace (<a href="https://redirect.github.com/nrwl/nx/pull/35655">#35655</a>)</li> <li><strong>core:</strong> cast perf entries to PerformanceMeasure for detail access (<a href="https://github.com/nrwl/nx/commit/43c0c821ba">43c0c821ba</a>)</li> <li><strong>devkit:</strong> exclude dist from jest module path scan (<a href="https://redirect.github.com/nrwl/nx/pull/35615">#35615</a>)</li> <li><strong>devkit:</strong> expand <code>@nx/devkit/</code>internal re-exports for cherry-picked v23 deep-import migration (<a href="https://redirect.github.com/nrwl/nx/issues/35541">#35541</a>)</li> <li><strong>dotnet:</strong> correct output paths for Web SDK and centralized dist setups (<a href="https://redirect.github.com/nrwl/nx/pull/35398">#35398</a>)</li> <li><strong>gradle:</strong> exclude batch-runner from jest haste-map crawl (<a href="https://redirect.github.com/nrwl/nx/pull/35501">#35501</a>)</li> <li><strong>gradle:</strong> exclude project-graph from jest module path scan (<a href="https://redirect.github.com/nrwl/nx/pull/35609">#35609</a>)</li> <li><strong>gradle:</strong> support Windows file paths (<a href="https://redirect.github.com/nrwl/nx/pull/35184">#35184</a>, <a href="https://redirect.github.com/nrwl/nx/issues/34987">#34987</a>)</li> <li><strong>js:</strong> strip glob from inferred outputs before resolving as path (<a href="https://redirect.github.com/nrwl/nx/pull/35463">#35463</a>, <a href="https://redirect.github.com/nrwl/nx/issues/35452">#35452</a>)</li> <li><strong>js:</strong> reference vitest.config in eslint dep-checks for vitest libs (<a href="https://redirect.github.com/nrwl/nx/pull/35460">#35460</a>, <a href="https://redirect.github.com/nrwl/nx/issues/33670">#33670</a>, <a href="https://redirect.github.com/nrwl/nx/issues/35450">#35450</a>)</li> <li><strong>js:</strong> include transitive workspace deps in pruned pnpm lockfile (<a href="https://redirect.github.com/nrwl/nx/pull/35532">#35532</a>, <a href="https://redirect.github.com/nrwl/nx/issues/35347">#35347</a>, <a href="https://redirect.github.com/nrwl/nx/issues/34655">#34655</a>)</li> <li><strong>linter:</strong> prevent ENOENT crash in getRelativeImportPath for unresolvable paths (<a href="https://redirect.github.com/nrwl/nx/pull/35007">#35007</a>, <a href="https://redirect.github.com/nrwl/nx/issues/13872">#13872</a>, <a href="https://redirect.github.com/nrwl/nx/issues/34066">#34066</a>, <a href="https://redirect.github.com/nrwl/nx/issues/30491">#30491</a>, <a href="https://redirect.github.com/nrwl/nx/issues/16716">#16716</a>, <a href="https://redirect.github.com/nrwl/nx/issues/35006">#35006</a>, <a href="https://redirect.github.com/nrwl/nx/issues/21889">#21889</a>, <a href="https://redirect.github.com/nrwl/nx/issues/32190">#32190</a>)</li> <li><strong>maven:</strong> skip attached artifacts that fail to materialize in batch record (<a href="https://redirect.github.com/nrwl/nx/pull/35473">#35473</a>)</li> <li><strong>maven:</strong> serialize Maven 4 build state recording (<a href="https://redirect.github.com/nrwl/nx/pull/35555">#35555</a>)</li> <li><strong>maven:</strong> widen runCLI timeout for --no-batch maven.test.ts cases (<a href="https://redirect.github.com/nrwl/nx/pull/35589">#35589</a>)</li> <li><strong>nx-dev:</strong> document nested CLI subcommands beyond two levels (<a href="https://redirect.github.com/nrwl/nx/pull/35519">#35519</a>)</li> <li><strong>nx-dev:</strong> short-circuit bot probes in framer rewrite edge function (<a href="https://redirect.github.com/nrwl/nx/pull/35527">#35527</a>)</li> <li><strong>react:</strong> withSvgr migration preserves other properties (<a href="https://redirect.github.com/nrwl/nx/pull/35484">#35484</a>)</li> <li><strong>repo:</strong> clear NX_INVOCATION_ROOT_PID in run-native-target to avoid recursion false-positive (<a href="https://github.com/nrwl/nx/commit/443dee0b22">443dee0b22</a>)</li> <li><strong>repo:</strong> revert deep-import rewrites that targeted v23-only <code>@nx/devkit/</code>internal entry (<a href="https://github.com/nrwl/nx/commit/ac8187963d">ac8187963d</a>)</li> <li><strong>repo:</strong> unblock 22.7.x cargo tests and nx-build e2e (<a href="https://redirect.github.com/nrwl/nx/issues/34285">#34285</a>)</li> </ul> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/nrwl/nx/commit/4e9ea1bc3f44fb90f4ef242bf248dbc903aebef8"><code>4e9ea1b</code></a> chore(core): refresh stale TUI snapshots on 22.7.x</li> <li><a href="https://github.com/nrwl/nx/commit/d02dc54141a1c523fabae7f1462a1e03c16179d4"><code>d02dc54</code></a> fix(repo): unblock 22.7.x cargo tests and nx-build e2e</li> <li><a href="https://github.com/nrwl/nx/commit/7e4bce91788c942c214ca59261b130d940faac61"><code>7e4bce9</code></a> feat(testing): add migration for Jest 30 snapshot guide link (<a href="https://github.com/nrwl/nx/tree/HEAD/packages/nx/issues/35629">#35629</a>)</li> <li><a href="https://github.com/nrwl/nx/commit/43c0c821ba355b910e638438df28ec7e320dce60"><code>43c0c82</code></a> fix(core): cast perf entries to PerformanceMeasure for detail access</li> <li><a href="https://github.com/nrwl/nx/commit/0cfc6bcd3685bb1c60a78d460474fcd88a208246"><code>0cfc6bc</code></a> fix(core): allow <code>nx mcp</code> to run outside of an Nx workspace (<a href="https://github.com/nrwl/nx/tree/HEAD/packages/nx/issues/35655">#35655</a>)</li> <li><a href="https://github.com/nrwl/nx/commit/df0e414420913730ff514e1d9c61f29182a3aa1a"><code>df0e414</code></a> chore(core): remove dead TUI selection lifecycle helpers (<a href="https://github.com/nrwl/nx/tree/HEAD/packages/nx/issues/35649">#35649</a>)</li> <li><a href="https://github.com/nrwl/nx/commit/a0f7a52bcbee27946654c95fa3b2c0bff9cc2d09"><code>a0f7a52</code></a> fix(core): keep TUI task selection on the in-progress section (<a href="https://github.com/nrwl/nx/tree/HEAD/packages/nx/issues/35640">#35640</a>)</li> <li><a href="https://github.com/nrwl/nx/commit/93813e9ef2fb87e51f3f8f19cb39633333759b13"><code>93813e9</code></a> fix(core): support skipped batch tasks end-to-end and fix TUI double logs (<a href="https://github.com/nrwl/nx/tree/HEAD/packages/nx/issues/3">#3</a>...</li> <li><a href="https://github.com/nrwl/nx/commit/c514039729050d4718b3446da32773f982f68625"><code>c514039</code></a> fix(core): enable node's native v8 compile cache support (<a href="https://github.com/nrwl/nx/tree/HEAD/packages/nx/issues/35415">#35415</a>)</li> <li><a href="https://github.com/nrwl/nx/commit/75e349822cfa8437c6d693449abfe4099a2919ce"><code>75e3498</code></a> fix(core): isolate cache env vars in splitArgs spec (<a href="https://github.com/nrwl/nx/tree/HEAD/packages/nx/issues/35584">#35584</a>)</li> <li>Additional commits viewable in <a href="https://github.com/nrwl/nx/commits/22.7.2/packages/nx">compare view</a></li> </ul> </details> <details> <summary>Install script changes</summary> <p>This version modifies <code>postinstall</code> script that runs during installation. Review the package contents before updating.</p> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/aws/aws-cdk/network/alerts). </details>
Automated changes by [create-pull-request](https://github.com/peter-evans/create-pull-request) GitHub action
### Issue # (if applicable) Closes #<issue number here>. ### Description of changes Fixed related-issues-bot-name in the project-sync workflow ### Describe any new or updated permissions being added ### Description of how you validated changes ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
### Issue # (if applicable) Closes #<issue number here>. ### Reason for this change Correct and simplify documentation held on jsdocs for MediaConnect. More appropriate description to help developers weigh up fields for their configuration. ### Description of changes ### Describe any new or updated permissions being added ### Description of how you validated changes ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
Updates the L1 CloudFormation resource definitions with the latest changes from `@aws-cdk/aws-service-spec`
**L1 CloudFormation resource definition changes:**
```
├[~] service aws-amazonmq
│ └ resources
│ └[~] resource AWS::AmazonMQ::Broker
│ └ properties
│ └[+] StorageSize: integer
├[~] service aws-apigatewayv2
│ └ resources
│ └[~] resource AWS::ApiGatewayV2::Api
│ └ attributes
│ └[+] ExecuteApiArn: string
├[+] service aws-artifact
│ ├ capitalized: Artifact
│ │ cloudFormationNamespace: AWS::Artifact
│ │ name: aws-artifact
│ │ shortName: artifact
│ └ resources
│ └ resource AWS::Artifact::Report
│ ├ name: Report
│ │ cloudFormationType: AWS::Artifact::Report
│ │ documentation: Resource schema for AWS Artifact Report
│ │ primaryIdentifier: ["Arn"]
│ └ attributes
│ ├ Arn: string
│ ├ ReportId: string
│ ├ Name: string
│ ├ Description: string
│ ├ PeriodStart: string
│ ├ PeriodEnd: string
│ ├ CreatedAt: string
│ ├ State: string<PUBLISHED|UNPUBLISHED>
│ ├ Series: string
│ ├ Category: string
│ ├ CompanyName: string
│ ├ ProductName: string
│ ├ TermArn: string
│ ├ Version: string
│ ├ AcceptanceType: string<PASSTHROUGH|EXPLICIT>
│ └ SequenceNumber: integer
├[~] service aws-athena
│ └ resources
│ └[+] resource AWS::Athena::Session
│ ├ name: Session
│ │ cloudFormationType: AWS::Athena::Session
│ │ documentation: An Athena session is a Spark-based interactive environment for running calculations within a workgroup.
│ │ primaryIdentifier: ["Arn"]
│ ├ properties
│ │ ├ WorkGroup: string (required, immutable)
│ │ ├ EngineConfiguration: EngineConfiguration (required, immutable)
│ │ └ ExecutionRole: string (immutable)
│ ├ attributes
│ │ ├ Arn: string
│ │ ├ SessionId: string
│ │ ├ EngineVersion: string
│ │ ├ EngineConfiguration.AdditionalConfigs: Map<string, string>
│ │ └ EngineConfiguration.SparkProperties: Map<string, string>
│ └ types
│ └ type EngineConfiguration
│ ├ documentation: Contains engine data processing unit (DPU) configuration settings.
│ │ name: EngineConfiguration
│ └ properties
│ ├ CoordinatorDpuSize: integer
│ ├ MaxConcurrentDpus: integer (required)
│ ├ DefaultExecutorDpuSize: integer
│ ├ AdditionalConfigs: Map<string, string>
│ └ SparkProperties: Map<string, string>
├[~] service aws-auditmanager
│ └ resources
│ └[+] resource AWS::AuditManager::AssessmentFramework
│ ├ name: AssessmentFramework
│ │ cloudFormationType: AWS::AuditManager::AssessmentFramework
│ │ documentation: Creates a custom framework in AWS Audit Manager.
│ │ tagInformation: {"tagPropertyName":"Tags","variant":"standard"}
│ │ arnTemplate: arn:${Partition}:auditmanager:${Region}:${Account}:assessmentFramework/${AssessmentFrameworkId}
│ │ primaryIdentifier: ["Arn"]
│ ├ properties
│ │ ├ Name: string (required)
│ │ ├ Description: string
│ │ ├ ComplianceType: string
│ │ ├ ControlSets: Array<ControlSet> (required)
│ │ └ Tags: Array<tag>
│ ├ attributes
│ │ ├ Arn: string
│ │ ├ FrameworkId: string
│ │ ├ Type: string<Standard|Custom>
│ │ ├ CreatedAt: string
│ │ ├ LastUpdatedAt: string
│ │ ├ CreatedBy: string
│ │ └ LastUpdatedBy: string
│ └ types
│ ├ type ControlSet
│ │ ├ documentation: A control set entity that represents a collection of controls in Audit Manager.
│ │ │ name: ControlSet
│ │ └ properties
│ │ ├ Name: string (required)
│ │ └ Controls: Array<ControlSetControl> (required)
│ └ type ControlSetControl
│ ├ documentation: A reference to an existing control by ID.
│ │ name: ControlSetControl
│ └ properties
│ └ Id: string (required)
├[~] service aws-backup
│ └ resources
│ └[+] resource AWS::Backup::LegalHold
│ ├ name: LegalHold
│ │ cloudFormationType: AWS::Backup::LegalHold
│ │ documentation: Creates a legal hold on recovery points (backups). A legal hold prevents backups from being deleted while under hold.
│ │ tagInformation: {"tagPropertyName":"Tags","variant":"standard"}
│ │ arnTemplate: arn:${Partition}:backup:${Region}:${Account}:legal-hold:${LegalHoldId}
│ │ primaryIdentifier: ["Arn"]
│ ├ properties
│ │ ├ Title: string (required, immutable)
│ │ ├ Description: string (required, immutable)
│ │ ├ RecoveryPointSelection: RecoveryPointSelection (required, immutable)
│ │ └ Tags: Array<TagsItems>
│ ├ attributes
│ │ ├ Arn: string
│ │ ├ LegalHoldId: string
│ │ ├ Status: string<CREATING|ACTIVE|CANCELING|CANCELED>
│ │ └ CreationDate: string
│ └ types
│ ├ type DateRange
│ │ ├ documentation: A date range for filtering recovery points.
│ │ │ name: DateRange
│ │ └ properties
│ │ ├ FromDate: string (required)
│ │ └ ToDate: string (required)
│ ├ type RecoveryPointSelection
│ │ ├ documentation: The criteria to assign a set of resources, such as resource types or backup vaults.
│ │ │ name: RecoveryPointSelection
│ │ └ properties
│ │ ├ VaultNames: Array<string>
│ │ ├ ResourceIdentifiers: Array<string>
│ │ └ DateRange: DateRange
│ └ type TagsItems
│ ├ name: TagsItems
│ └ properties
│ ├ Key: string (required)
│ └ Value: string (required)
├[+] service aws-backupsearch
│ ├ capitalized: BackupSearch
│ │ cloudFormationNamespace: AWS::BackupSearch
│ │ name: aws-backupsearch
│ │ shortName: backupsearch
│ └ resources
│ └ resource AWS::BackupSearch::SearchJob
│ ├ name: SearchJob
│ │ cloudFormationType: AWS::BackupSearch::SearchJob
│ │ documentation: Definition of AWS::BackupSearch::SearchJob Resource Type
│ │ tagInformation: {"tagPropertyName":"Tags","variant":"standard"}
│ │ arnTemplate: arn:${Partition}:backup-search:${Region}:${Account}:search-job/${ResourceId}
│ │ primaryIdentifier: ["SearchJobArn"]
│ ├ properties
│ │ ├ Name: string (immutable)
│ │ ├ SearchScope: SearchScope (required, immutable)
│ │ └ Tags: Array<TagsItems> (immutable)
│ ├ attributes
│ │ ├ SearchJobArn: string
│ │ ├ SearchJobIdentifier: string
│ │ ├ CreationTime: string
│ │ └ Status: string<RUNNING|COMPLETED|STOPPING|STOPPED|FAILED>
│ └ types
│ ├ type SearchScope
│ │ ├ documentation: The search scope for the search job.
│ │ │ name: SearchScope
│ │ └ properties
│ │ └ BackupResourceTypes: Array<string<S3|EBS>> (required)
│ └ type TagsItems
│ ├ name: TagsItems
│ └ properties
│ ├ Key: string (required)
│ └ Value: string (required)
├[~] service aws-bcmdataexports
│ └ resources
│ └[+] resource AWS::BCMDataExports::Table
│ ├ name: Table
│ │ cloudFormationType: AWS::BCMDataExports::Table
│ │ documentation: Returns the metadata for the specified table and table properties, including the list of columns in the table schema, their data types, and column descriptions.
│ │ arnTemplate: arn:${Partition}:bcm-data-exports:${Region}:${Account}:table/${Identifier}
│ │ primaryIdentifier: ["Arn"]
│ ├ properties
│ │ └ TableName: string (required, immutable)
│ ├ attributes
│ │ ├ Arn: string
│ │ ├ Description: string
│ │ └ Schema: Array<Column>
│ └ types
│ └ type Column
│ ├ documentation: Includes basic information for a data column such as its description, name, and type.
│ │ name: Column
│ └ properties
│ ├ Name: string
│ ├ Type: string
│ └ Description: string
├[~] service aws-bedrock
│ └ resources
│ ├[+] resource AWS::Bedrock::DefaultPromptRouter
│ │ ├ name: DefaultPromptRouter
│ │ │ cloudFormationType: AWS::Bedrock::DefaultPromptRouter
│ │ │ documentation: Definition of AWS::Bedrock::DefaultPromptRouter Resource Type
│ │ │ arnTemplate: arn:${Partition}:bedrock:${Region}:${Account}:default-prompt-router/${ResourceId}
│ │ │ primaryIdentifier: ["PromptRouterArn"]
│ │ ├ attributes
│ │ │ ├ PromptRouterArn: string
│ │ │ ├ PromptRouterId: string
│ │ │ ├ PromptRouterName: string
│ │ │ ├ Description: string
│ │ │ ├ RoutingCriteria: RoutingCriteria
│ │ │ ├ FallbackModel: PromptRouterTargetModel
│ │ │ ├ Models: Array<PromptRouterTargetModel>
│ │ │ ├ Status: string<AVAILABLE>
│ │ │ ├ Type: string<custom|default>
│ │ │ ├ CreatedAt: string
│ │ │ └ UpdatedAt: string
│ │ └ types
│ │ ├ type PromptRouterTargetModel
│ │ │ ├ documentation: A target model for the prompt router.
│ │ │ │ name: PromptRouterTargetModel
│ │ │ └ properties
│ │ │ └ ModelArn: string (required)
│ │ └ type RoutingCriteria
│ │ ├ documentation: Routing criteria for a prompt router.
│ │ │ name: RoutingCriteria
│ │ └ properties
│ │ └ ResponseQualityDifference: number (required)
│ ├[~] resource AWS::Bedrock::EnforcedGuardrailConfiguration
│ │ └ attributes
│ │ └ Owner: - string<ACCOUNT>
│ │ + string<ACCOUNT|ORGANIZATION>
│ ├[+] resource AWS::Bedrock::KnowledgeBasePolicy
│ │ ├ name: KnowledgeBasePolicy
│ │ │ cloudFormationType: AWS::Bedrock::KnowledgeBasePolicy
│ │ │ documentation: Definition of AWS::Bedrock::KnowledgeBasePolicy Resource Type
│ │ │ scrutinizable: ResourcePolicyResource
│ │ │ primaryIdentifier: ["KnowledgeBaseId"]
│ │ ├ properties
│ │ │ ├ KnowledgeBaseId: string (required, immutable)
│ │ │ └ PolicyDocument: json (required)
│ │ └ attributes
│ │ └ RevisionId: string
│ └[+] resource AWS::Bedrock::ModelInvocationJob
│ ├ name: ModelInvocationJob
│ │ cloudFormationType: AWS::Bedrock::ModelInvocationJob
│ │ documentation: Resource Type definition for AWS::Bedrock::ModelInvocationJob
│ │ tagInformation: {"tagPropertyName":"Tags","variant":"standard"}
│ │ arnTemplate: arn:${Partition}:bedrock:${Region}:${Account}:model-invocation-job/${JobIdentifier}
│ │ primaryIdentifier: ["JobArn"]
│ ├ attributes
│ │ ├ JobArn: string
│ │ ├ JobName: string
│ │ ├ ModelId: string
│ │ ├ RoleArn: string
│ │ ├ InputDataConfig: ModelInvocationJobInputDataConfig
│ │ ├ OutputDataConfig: ModelInvocationJobOutputDataConfig
│ │ ├ VpcConfig: VpcConfig
│ │ ├ TimeoutDurationInHours: integer
│ │ ├ Status: string<Submitted|InProgress|Completed|Failed|Stopping|Stopped|PartiallyCompleted|Expired|Validating|Scheduled>
│ │ ├ SubmitTime: string
│ │ ├ LastModifiedTime: string
│ │ ├ JobExpirationTime: string
│ │ └ Tags: Array<tag>
│ └ types
│ ├ type ModelInvocationJobInputDataConfig
│ │ ├ documentation: Details about the location of the input to the batch inference job.
│ │ │ name: ModelInvocationJobInputDataConfig
│ │ └ properties
│ │ └ S3InputDataConfig: ModelInvocationJobS3InputDataConfig (required)
│ ├ type ModelInvocationJobOutputDataConfig
│ │ ├ documentation: Details about the location of the output of the batch inference job.
│ │ │ name: ModelInvocationJobOutputDataConfig
│ │ └ properties
│ │ └ S3OutputDataConfig: ModelInvocationJobS3OutputDataConfig (required)
│ ├ type ModelInvocationJobS3InputDataConfig
│ │ ├ documentation: Contains the configuration of the S3 location of the input data.
│ │ │ name: ModelInvocationJobS3InputDataConfig
│ │ └ properties
│ │ ├ S3Uri: string (required)
│ │ └ S3BucketOwner: string
│ ├ type ModelInvocationJobS3OutputDataConfig
│ │ ├ documentation: Contains the configuration of the S3 location of the output data.
│ │ │ name: ModelInvocationJobS3OutputDataConfig
│ │ └ properties
│ │ ├ S3Uri: string (required)
│ │ ├ S3EncryptionKeyId: string
│ │ └ S3BucketOwner: string
│ └ type VpcConfig
│ ├ documentation: The configuration of a virtual private cloud (VPC).
│ │ name: VpcConfig
│ └ properties
│ ├ SubnetIds: Array<string> (required)
│ └ SecurityGroupIds: Array<string> (required)
├[~] service aws-bedrockagentcore
│ └ resources
│ ├[+] resource AWS::BedrockAgentCore::CodeInterpreter
│ │ ├ name: CodeInterpreter
│ │ │ cloudFormationType: AWS::BedrockAgentCore::CodeInterpreter
│ │ │ documentation: Definition of AWS::BedrockAgentCore::CodeInterpreter Resource Type. This is a read-only resource representing the AWS-managed default code interpreter (aws.codeinterpreter.v1).
│ │ │ arnTemplate: arn:${Partition}:bedrock-agentcore:${Region}:aws:code-interpreter/${CodeInterpreterId}
│ │ │ vendedLogs: [{"permissionsVersion":"V2","logType":"APPLICATION_LOGS","destinations":[{"destinationType":"S3","outputFormats":["json","plain","w3c","parquet"]},{"destinationType":"CWL","outputFormats":["plain","json"]},{"destinationType":"FH","outputFormats":["json","plain","raw"]}],"mandatoryFields":["resource_arn","event_timestamp"],"optionalFields":["account_id","request_id","tool_session_id","span_id","trace_id","service_name","operation","request_payload","response_payload","resource","attributes","timeUnixNano","severityNumber","severityText","body","traceId","spanId"]},{"permissionsVersion":"V2","logType":"USAGE_LOGS","destinations":[{"destinationType":"S3","outputFormats":["json","plain","w3c","parquet"]},{"destinationType":"CWL","outputFormats":["plain","json"]},{"destinationType":"FH","outputFormats":["json","plain","raw"]}],"mandatoryFields":["resource_arn","event_timestamp","resource","attributes","metrics"]}]
│ │ │ primaryIdentifier: ["CodeInterpreterArn"]
│ │ └ attributes
│ │ ├ CodeInterpreterArn: string
│ │ ├ CodeInterpreterId: string
│ │ └ Status: string<CREATING|CREATE_FAILED|READY|DELETING|DELETE_FAILED|DELETED>
│ ├[~] resource AWS::BedrockAgentCore::Dataset
│ │ └ - arnTemplate: undefined
│ │ + arnTemplate: arn:${Partition}:bedrock-agentcore:${Region}:${Account}:dataset/${DatasetId}
│ ├[~] resource AWS::BedrockAgentCore::Gateway
│ │ └ types
│ │ ├[~] type CustomJWTAuthorizerConfiguration
│ │ │ └ properties
│ │ │ └[+] PrivateEndpoint: PrivateEndpoint
│ │ ├[+] type ManagedVpcResource
│ │ │ ├ name: ManagedVpcResource
│ │ │ └ properties
│ │ │ ├ VpcIdentifier: string (required)
│ │ │ ├ SubnetIds: Array<string> (required)
│ │ │ ├ EndpointIpAddressType: string<IPV4|IPV6> (required)
│ │ │ ├ SecurityGroupIds: Array<string>
│ │ │ └ RoutingDomain: string
│ │ ├[+] type PrivateEndpoint
│ │ │ ├ name: PrivateEndpoint
│ │ │ └ properties
│ │ │ ├ SelfManagedLatticeResource: SelfManagedLatticeResource
│ │ │ └ ManagedVpcResource: ManagedVpcResource
│ │ └[+] type SelfManagedLatticeResource
│ │ ├ name: SelfManagedLatticeResource
│ │ └ properties
│ │ └ ResourceConfigurationIdentifier: string (required)
│ ├[~] resource AWS::BedrockAgentCore::GatewayTarget
│ │ ├ attributes
│ │ │ └ ProtocolType: - string<MCP|HTTP>
│ │ │ + string<MCP|HTTP|INFERENCE>
│ │ └ types
│ │ ├[+] type InferenceConnectorSource
│ │ │ ├ name: InferenceConnectorSource
│ │ │ └ properties
│ │ │ └ ConnectorId: string (required)
│ │ ├[+] type InferenceConnectorTargetConfiguration
│ │ │ ├ name: InferenceConnectorTargetConfiguration
│ │ │ └ properties
│ │ │ └ Source: InferenceConnectorSource (required)
│ │ ├[+] type InferenceOperationConfiguration
│ │ │ ├ name: InferenceOperationConfiguration
│ │ │ └ properties
│ │ │ ├ Path: string (required)
│ │ │ ├ ProviderPath: string
│ │ │ └ Models: Array<ModelEntry>
│ │ ├[+] type InferenceProviderTargetConfiguration
│ │ │ ├ name: InferenceProviderTargetConfiguration
│ │ │ └ properties
│ │ │ ├ Endpoint: string (required)
│ │ │ ├ ModelMapping: ModelMapping
│ │ │ └ Operations: Array<InferenceOperationConfiguration>
│ │ ├[+] type InferenceTargetConfiguration
│ │ │ ├ name: InferenceTargetConfiguration
│ │ │ └ properties
│ │ │ ├ Connector: InferenceConnectorTargetConfiguration
│ │ │ └ Provider: InferenceProviderTargetConfiguration
│ │ ├[+] type ModelEntry
│ │ │ ├ name: ModelEntry
│ │ │ └ properties
│ │ │ └ Model: string (required)
│ │ ├[+] type ModelMapping
│ │ │ ├ name: ModelMapping
│ │ │ └ properties
│ │ │ └ ProviderPrefix: ProviderPrefix
│ │ ├[+] type ProviderPrefix
│ │ │ ├ name: ProviderPrefix
│ │ │ └ properties
│ │ │ ├ Strip: boolean (default=false)
│ │ │ └ Separator: string (default=".")
│ │ └[~] type TargetConfiguration
│ │ └ properties
│ │ └[+] Inference: InferenceTargetConfiguration
│ ├[~] resource AWS::BedrockAgentCore::Runtime
│ │ └ types
│ │ ├[+] type AllowedWorkloadConfiguration
│ │ │ ├ documentation: Allow-list of upstream workloads permitted to reach this resource via the workload identity chain. When set, the data plane enforces that the introspected workload chain's caller matches one of the configured hosting environments or workload identities; absent means no chain enforcement.
│ │ │ │ name: AllowedWorkloadConfiguration
│ │ │ └ properties
│ │ │ ├ HostingEnvironments: Array<HostingEnvironment>
│ │ │ └ WorkloadIdentities: Array<string>
│ │ ├[~] type CustomJWTAuthorizerConfiguration
│ │ │ └ properties
│ │ │ ├[+] AllowedWorkloadConfiguration: AllowedWorkloadConfiguration
│ │ │ ├[+] PrivateEndpoint: PrivateEndpoint
│ │ │ └[+] PrivateEndpointOverrides: Array<PrivateEndpointOverride>
│ │ ├[+] type HostingEnvironment
│ │ │ ├ documentation: An upstream workload identified by the ARN of its hosting environment (for example a Gateway or Runtime ARN)
│ │ │ │ name: HostingEnvironment
│ │ │ └ properties
│ │ │ └ Arn: string (required)
│ │ ├[+] type ManagedVpcResource
│ │ │ ├ documentation: Managed VPC resource configuration
│ │ │ │ name: ManagedVpcResource
│ │ │ └ properties
│ │ │ ├ VpcIdentifier: string (required)
│ │ │ ├ SubnetIds: Array<string> (required)
│ │ │ ├ EndpointIpAddressType: string<IPV4|IPV6> (required)
│ │ │ ├ SecurityGroupIds: Array<string>
│ │ │ ├ RoutingDomain: string
│ │ │ └ Tags: Map<string, string>
│ │ ├[+] type PrivateEndpoint
│ │ │ ├ name: PrivateEndpoint
│ │ │ └ properties
│ │ │ ├ SelfManagedLatticeResource: SelfManagedLatticeResource
│ │ │ └ ManagedVpcResource: ManagedVpcResource
│ │ ├[+] type PrivateEndpointOverride
│ │ │ ├ documentation: Override mapping of a domain to a private endpoint
│ │ │ │ name: PrivateEndpointOverride
│ │ │ └ properties
│ │ │ ├ Domain: string (required)
│ │ │ └ PrivateEndpoint: PrivateEndpoint (required)
│ │ └[+] type SelfManagedLatticeResource
│ │ ├ documentation: Self-managed VPC Lattice resource configuration
│ │ │ name: SelfManagedLatticeResource
│ │ └ properties
│ │ └ ResourceConfigurationIdentifier: string (required)
│ └[+] resource AWS::BedrockAgentCore::TokenVault
│ ├ name: TokenVault
│ │ cloudFormationType: AWS::BedrockAgentCore::TokenVault
│ │ documentation: Resource Type definition for AWS::BedrockAgentCore::TokenVault
│ │ arnTemplate: arn:${Partition}:bedrock-agentcore:${Region}:${Account}:token-vault/${TokenVaultId}
│ │ primaryIdentifier: ["Arn"]
│ ├ attributes
│ │ ├ Arn: string
│ │ ├ TokenVaultId: string
│ │ ├ KmsConfiguration: KmsConfiguration
│ │ └ LastModifiedDate: string
│ └ types
│ └ type KmsConfiguration
│ ├ documentation: Contains the KMS configuration for a resource.
│ │ name: KmsConfiguration
│ └ properties
│ ├ KeyType: string<CustomerManagedKey|ServiceManagedKey> (required)
│ └ KmsKeyArn: string
├[~] service aws-certificatemanager
│ └ resources
│ └[~] resource AWS::CertificateManager::Certificate
│ ├ - primaryIdentifier: ["Id"]
│ │ + primaryIdentifier: ["CertificateArn"]
│ ├ properties
│ │ ├ CertificateExport: - string
│ │ │ + string<ENABLED|DISABLED> (immutable)
│ │ └ CertificateTransparencyLoggingPreference: - string
│ │ + string<ENABLED|DISABLED>
│ ├ attributes
│ │ └[+] CertificateArn: string
│ └ types
│ └[~] type DomainValidationOption
│ └ properties
│ └ DomainName: - string (required)
│ + string
├[~] service aws-cleanrooms
│ └ resources
│ └[+] resource AWS::CleanRooms::IntermediateTable
│ ├ name: IntermediateTable
│ │ cloudFormationType: AWS::CleanRooms::IntermediateTable
│ │ documentation: Represents an intermediate table that stores cached query results within a collaboration
│ │ tagInformation: {"tagPropertyName":"Tags","variant":"standard"}
│ │ primaryIdentifier: ["IntermediateTableIdentifier","MembershipIdentifier"]
│ ├ properties
│ │ ├ MembershipIdentifier: string (required, immutable)
│ │ ├ Name: string (required, immutable)
│ │ ├ Description: string
│ │ ├ PopulationAnalysisConfiguration: PopulationAnalysisConfiguration (required, immutable)
│ │ ├ KmsKeyArn: string
│ │ ├ AnalysisRules: Array<IntermediateTableAnalysisRule>
│ │ └ Tags: Array<tag>
│ ├ attributes
│ │ ├ IntermediateTableIdentifier: string
│ │ ├ Arn: string
│ │ ├ MembershipArn: string
│ │ ├ CollaborationIdentifier: string
│ │ ├ CollaborationArn: string
│ │ └ Status: string<CREATED|POPULATE_STARTED|POPULATE_SUCCESS|POPULATE_FAILED|DISALLOWED_BY_DATA_PROVIDER|BASE_TABLE_REMOVED>
│ └ types
│ ├ type DifferentialPrivacy
│ │ ├ name: DifferentialPrivacy
│ │ └ properties
│ │ └ Columns: Array<DifferentialPrivacyColumn> (required)
│ ├ type DifferentialPrivacyColumn
│ │ ├ name: DifferentialPrivacyColumn
│ │ └ properties
│ │ └ Name: string (required)
│ ├ type IntermediateTableAnalysisRule
│ │ ├ name: IntermediateTableAnalysisRule
│ │ └ properties
│ │ ├ Type: string<CUSTOM> (required)
│ │ └ Policy: IntermediateTableAnalysisRulePolicy (required)
│ ├ type IntermediateTableAnalysisRuleCustom
│ │ ├ name: IntermediateTableAnalysisRuleCustom
│ │ └ properties
│ │ ├ AllowedAnalyses: Array<string> (required)
│ │ ├ AllowedAnalysisProviders: Array<string>
│ │ ├ AdditionalAnalyses: string<ALLOWED|REQUIRED|NOT_ALLOWED>
│ │ ├ AllowedResultReceivers: Array<string>
│ │ ├ DifferentialPrivacy: DifferentialPrivacy
│ │ └ DisallowedOutputColumns: Array<string>
│ ├ type IntermediateTableAnalysisRulePolicy
│ │ ├ name: IntermediateTableAnalysisRulePolicy
│ │ └ properties
│ │ └ V1: IntermediateTableAnalysisRulePolicyV1 (required)
│ ├ type IntermediateTableAnalysisRulePolicyV1
│ │ ├ name: IntermediateTableAnalysisRulePolicyV1
│ │ └ properties
│ │ └ Custom: IntermediateTableAnalysisRuleCustom (required)
│ ├ type PopulationAnalysisConfiguration
│ │ ├ name: PopulationAnalysisConfiguration
│ │ └ properties
│ │ └ SqlParameters: PopulationAnalysisSqlParameters
│ └ type PopulationAnalysisSqlParameters
│ ├ name: PopulationAnalysisSqlParameters
│ └ properties
│ ├ QueryString: string
│ └ AnalysisTemplateArn: string
├[~] service aws-cloudformation
│ └ resources
│ ├[+] resource AWS::CloudFormation::GeneratedTemplate
│ │ ├ name: GeneratedTemplate
│ │ │ cloudFormationType: AWS::CloudFormation::GeneratedTemplate
│ │ │ documentation: Creates a generated template from existing resources using the CloudFormation IaC Generator.
│ │ │ arnTemplate: arn:${Partition}:cloudformation:${Region}:${Account}:generatedTemplate/${Id}
│ │ │ primaryIdentifier: ["GeneratedTemplateId"]
│ │ ├ properties
│ │ │ ├ GeneratedTemplateName: string (required)
│ │ │ └ TemplateConfiguration: TemplateConfiguration
│ │ ├ attributes
│ │ │ ├ GeneratedTemplateId: string
│ │ │ ├ Status: string<CREATE_PENDING|UPDATE_PENDING|DELETE_PENDING|CREATE_IN_PROGRESS|UPDATE_IN_PROGRESS|DELETE_IN_PROGRESS|FAILED|COMPLETE>
│ │ │ ├ CreationTime: string
│ │ │ ├ LastUpdatedTime: string
│ │ │ ├ Progress: TemplateProgress
│ │ │ └ TotalWarnings: integer
│ │ └ types
│ │ ├ type TemplateConfiguration
│ │ │ ├ documentation: The configuration details of the generated template.
│ │ │ │ name: TemplateConfiguration
│ │ │ └ properties
│ │ │ ├ DeletionPolicy: string<DELETE|RETAIN>
│ │ │ └ UpdateReplacePolicy: string<DELETE|RETAIN>
│ │ └ type TemplateProgress
│ │ ├ documentation: A summary of the progress of the template generation.
│ │ │ name: TemplateProgress
│ │ └ properties
│ │ ├ ResourcesSucceeded: integer
│ │ ├ ResourcesFailed: integer
│ │ ├ ResourcesProcessing: integer
│ │ └ ResourcesPending: integer
│ ├[~] resource AWS::CloudFormation::LambdaHook
│ │ ├ properties
│ │ │ ├[+] AutoUpdate: boolean (default=true, immutable)
│ │ │ └[+] LoggingConfig: LoggingConfig (immutable)
│ │ └ types
│ │ └[+] type LoggingConfig
│ │ ├ documentation: Contains logging configuration information for an extension.
│ │ │ name: LoggingConfig
│ │ └ properties
│ │ ├ LogGroupName: string (required)
│ │ └ LogRoleArn: string (required)
│ └[+] resource AWS::CloudFormation::ResourceScan
│ ├ name: ResourceScan
│ │ cloudFormationType: AWS::CloudFormation::ResourceScan
│ │ documentation: Represents a CloudFormation resource scan that discovers existing AWS resources in an account and region.
│ │ arnTemplate: arn:${Partition}:cloudformation:${Region}:${Account}:resourceScan/${Id}
│ │ primaryIdentifier: ["ResourceScanId"]
│ ├ properties
│ │ └ ScanFilters: Array<ScanFilter> (immutable)
│ ├ attributes
│ │ ├ ResourceScanId: string
│ │ ├ ScanId: string
│ │ ├ Status: string<IN_PROGRESS|FAILED|COMPLETE|EXPIRED>
│ │ ├ StartTime: string
│ │ └ PercentageCompleted: number
│ └ types
│ └ type ScanFilter
│ ├ documentation: A filter that is used to specify which resource types to scan.
│ │ name: ScanFilter
│ └ properties
│ └ Types: Array<string>
├[~] service aws-cloudfront
│ └ resources
│ └[~] resource AWS::CloudFront::VpcOrigin
│ └ types
│ └[~] type VpcOriginEndpointConfig
│ └ properties
│ └[+] IpAddressType: string<ipv4|dualstack> (default="ipv4")
├[~] service aws-cloudwatch
│ └ resources
│ ├[~] resource AWS::CloudWatch::Alarm
│ │ ├ properties
│ │ │ └[+] EvaluationWindow: EvaluationWindow
│ │ └ types
│ │ ├[+] type EvaluationWindow
│ │ │ ├ name: EvaluationWindow
│ │ │ └ properties
│ │ │ ├ WallClockWindow: WallClockWindow
│ │ │ └ SlidingWindow: json
│ │ └[+] type WallClockWindow
│ │ ├ name: WallClockWindow
│ │ └ properties
│ │ └ Timezone: string
│ └[~] resource AWS::CloudWatch::LogAlarm
│ └ types
│ ├[~] type ScheduleConfiguration
│ │ └ properties
│ │ ├ EndTimeOffset: (documentation changed)
│ │ └ StartTimeOffset: - integer
│ │ + integer (required)
│ │ (documentation changed)
│ └[~] type ScheduledQueryConfiguration
│ └ properties
│ ├ LogGroupIdentifiers: - Array<string> (required)
│ │ + Array<string>
│ └[+] Tags: Array<tag>
├[~] service aws-codeartifact
│ └ resources
│ └[+] resource AWS::CodeArtifact::Package
│ ├ name: Package
│ │ cloudFormationType: AWS::CodeArtifact::Package
│ │ documentation: Resource Type definition for AWS::CodeArtifact::Package
│ │ primaryIdentifier: ["Arn"]
│ ├ properties
│ │ ├ DomainName: string (required, immutable)
│ │ ├ Repository: string (required, immutable)
│ │ ├ Format: string<npm|pypi|maven|nuget|generic|ruby|swift|cargo> (required, immutable)
│ │ ├ Namespace: string (immutable)
│ │ └ Name: string (required, immutable)
│ ├ attributes
│ │ ├ Arn: string
│ │ └ OriginConfiguration: OriginConfiguration
│ └ types
│ ├ type OriginConfiguration
│ │ ├ documentation: The package origin configuration for the package.
│ │ │ name: OriginConfiguration
│ │ └ properties
│ │ └ Restrictions: Restrictions
│ └ type Restrictions
│ ├ documentation: The origin restrictions for the package.
│ │ name: Restrictions
│ └ properties
│ ├ Publish: string<ALLOW|BLOCK>
│ └ Upstream: string<ALLOW|BLOCK>
├[~] service aws-codebuild
│ └ resources
│ ├[-] resource AWS::CodeBuild::Build
│ │ ├ name: Build
│ │ │ cloudFormationType: AWS::CodeBuild::Build
│ │ │ documentation: Resource Type definition for AWS::CodeBuild::Build
│ │ │ arnTemplate: arn:${Partition}:codebuild:${Region}:${Account}:build/${BuildId}
│ │ │ primaryIdentifier: ["Id"]
│ │ ├ properties
│ │ │ └ ProjectName: string (immutable)
│ │ └ attributes
│ │ ├ BuildComplete: boolean
│ │ ├ TimeoutInMinutes: integer
│ │ ├ EndTime: string
│ │ ├ CurrentPhase: string
│ │ ├ StartTime: string
│ │ ├ ServiceRole: string
│ │ ├ BuildNumber: integer
│ │ ├ Id: string
│ │ ├ EncryptionKey: string
│ │ ├ QueuedTimeoutInMinutes: integer
│ │ ├ Arn: string
│ │ ├ Initiator: string
│ │ └ BuildStatus: string
│ ├[-] resource AWS::CodeBuild::BuildBatch
│ │ ├ name: BuildBatch
│ │ │ cloudFormationType: AWS::CodeBuild::BuildBatch
│ │ │ documentation: Resource Type definition for AWS::CodeBuild::BuildBatch
│ │ │ arnTemplate: arn:${Partition}:codebuild:${Region}:${Account}:build-batch/${BuildBatchId}
│ │ │ primaryIdentifier: ["Id"]
│ │ ├ properties
│ │ │ └ ProjectName: string (immutable)
│ │ └ attributes
│ │ ├ Id: string
│ │ ├ BuildBatchStatus: string
│ │ ├ BuildBatchNumber: integer
│ │ ├ CurrentPhase: string
│ │ ├ EncryptionKey: string
│ │ ├ QueuedTimeoutInMinutes: integer
│ │ ├ StartTime: string
│ │ ├ Arn: string
│ │ ├ BuildTimeoutInMinutes: integer
│ │ ├ Initiator: string
│ │ └ Complete: boolean
│ └[+] resource AWS::CodeBuild::Sandbox
│ ├ name: Sandbox
│ │ cloudFormationType: AWS::CodeBuild::Sandbox
│ │ documentation: Represents a CodeBuild sandbox, an ephemeral compute environment started from a CodeBuild project.
│ │ arnTemplate: arn:${Partition}:codebuild:${Region}:${Account}:sandbox/${SandboxId}
│ │ primaryIdentifier: ["Arn"]
│ ├ properties
│ │ └ ProjectName: string (immutable)
│ └ attributes
│ ├ Arn: string
│ ├ Id: string
│ ├ Status: string
│ ├ RequestTime: string
│ ├ StartTime: string
│ ├ EncryptionKey: string
│ ├ ServiceRole: string
│ ├ TimeoutInMinutes: integer
│ └ QueuedTimeoutInMinutes: integer
├[~] service aws-cognito
│ └ resources
│ ├[~] resource AWS::Cognito::UserPool
│ │ └ types
│ │ ├[+] type EumsSmsConfiguration
│ │ │ ├ name: EumsSmsConfiguration
│ │ │ └ properties
│ │ │ ├ CallerArn: string (required)
│ │ │ ├ ExternalId: string
│ │ │ ├ OriginationIdentity: string
│ │ │ ├ ConfigurationSetName: string
│ │ │ ├ InEntityId: string
│ │ │ ├ InTemplateId: string
│ │ │ └ Region: string
│ │ └[~] type SmsConfiguration
│ │ └ properties
│ │ └[+] EumsSms: EumsSmsConfiguration
│ ├[~] resource AWS::Cognito::UserPoolDomain
│ │ └ types
│ │ └[~] type CustomDomainConfigType
│ │ └ properties
│ │ └[+] SecurityPolicy: string
│ └[~] resource AWS::Cognito::UserPoolRegionalConfigurationAttachment
│ └ types
│ ├[+] type EumsSmsConfiguration
│ │ ├ name: EumsSmsConfiguration
│ │ └ properties
│ │ ├ CallerArn: string (required)
│ │ ├ ExternalId: string
│ │ ├ OriginationIdentity: string
│ │ ├ ConfigurationSetName: string
│ │ ├ InEntityId: string
│ │ ├ InTemplateId: string
│ │ └ Region: string
│ └[~] type SmsConfiguration
│ └ properties
│ └[+] EumsSms: EumsSmsConfiguration
├[+] service aws-cognitosync
│ ├ capitalized: CognitoSync
│ │ cloudFormationNamespace: AWS::CognitoSync
│ │ name: aws-cognitosync
│ │ shortName: cognitosync
│ └ resources
│ └ resource AWS::CognitoSync::Dataset
│ ├ name: Dataset
│ │ cloudFormationType: AWS::CognitoSync::Dataset
│ │ documentation: Resource type definition for a Cognito Sync Dataset. A dataset is a collection of key-value pairs per identity that can store up to 1 MB of data and sync across devices.
│ │ primaryIdentifier: ["Arn"]
│ ├ properties
│ │ ├ IdentityPoolId: string (immutable)
│ │ ├ IdentityId: string (immutable)
│ │ └ DatasetName: string (immutable)
│ └ attributes
│ ├ Arn: string
│ ├ CreationDate: string
│ ├ LastModifiedDate: string
│ ├ LastModifiedBy: string
│ ├ DataStorage: integer
│ └ NumRecords: integer
├[~] service aws-config
│ └ resources
│ ├[~] resource AWS::Config::ConformancePack
│ │ ├ - tagInformation: undefined
│ │ │ + tagInformation: {"tagPropertyName":"Tags","variant":"standard"}
│ │ ├ properties
│ │ │ └[+] Tags: Array<tag>
│ │ └ attributes
│ │ └[+] ConformancePackArn: string
│ └[~] resource AWS::Config::OrganizationConformancePack
│ ├ - tagInformation: undefined
│ │ + tagInformation: {"tagPropertyName":"Tags","variant":"standard"}
│ ├ properties
│ │ └[+] Tags: Array<tag>
│ └ attributes
│ └[+] OrganizationConformancePackArn: string
├[~] service aws-connect
│ └ resources
│ ├[+] resource AWS::Connect::DataLakeAssociation
│ │ ├ name: DataLakeAssociation
│ │ │ cloudFormationType: AWS::Connect::DataLakeAssociation
│ │ │ documentation: Resource schema for AWS::Connect::DataLakeAssociation
│ │ │ primaryIdentifier: ["InstanceId","DataSetId","TargetAccountId"]
│ │ ├ properties
│ │ │ ├ InstanceId: string (required, immutable)
│ │ │ ├ DataSetId: string (required, immutable)
│ │ │ └ TargetAccountId: string (immutable)
│ │ └ attributes
│ │ ├ ResourceShareId: string
│ │ └ ResourceShareArn: string
│ ├[~] resource AWS::Connect::DataTable
│ │ └ properties
│ │ ├ InstanceArn: - string (immutable)
│ │ │ + string (required, immutable)
│ │ ├ Name: - string
│ │ │ + string (required)
│ │ ├ Status: - string<PUBLISHED> (immutable)
│ │ │ + string<PUBLISHED> (required, immutable)
│ │ ├ TimeZone: - string
│ │ │ + string (required)
│ │ └ ValueLockLevel: - string<NONE|DATA_TABLE|PRIMARY_VALUE|ATTRIBUTE|VALUE>
│ │ + string<NONE|DATA_TABLE|PRIMARY_VALUE|ATTRIBUTE|VALUE> (required)
│ ├[~] resource AWS::Connect::DataTableAttribute
│ │ └ properties
│ │ ├ DataTableArn: - string (immutable)
│ │ │ + string (required, immutable)
│ │ ├ InstanceArn: - string (immutable)
│ │ │ + string (required, immutable)
│ │ ├ Name: - string
│ │ │ + string (required)
│ │ └ ValueType: - string<TEXT|NUMBER|BOOLEAN|TEXT_LIST|NUMBER_LIST>
│ │ + string<TEXT|NUMBER|BOOLEAN|TEXT_LIST|NUMBER_LIST> (required)
│ ├[~] resource AWS::Connect::DataTableRecord
│ │ └ properties
│ │ ├ DataTableArn: - string (immutable)
│ │ │ + string (required, immutable)
│ │ ├ DataTableRecord: - DataTableRecord
│ │ │ + DataTableRecord (required)
│ │ └ InstanceArn: - string (immutable)
│ │ + string (required, immutable)
│ ├[~] resource AWS::Connect::EvaluationForm
│ │ └ types
│ │ ├[~] type EvaluationFormMultiSelectQuestionOption
│ │ │ └ properties
│ │ │ ├ AutomaticFail: (documentation changed)
│ │ │ └ PointsConfiguration: (documentation changed)
│ │ ├[~] type EvaluationFormNumericQuestionOption
│ │ │ └ properties
│ │ │ └ PointsConfiguration: (documentation changed)
│ │ ├[~] type EvaluationFormQuestion
│ │ │ └ properties
│ │ │ └ ScoringConfiguration: (documentation changed)
│ │ ├[~] type EvaluationFormQuestionScoringConfiguration
│ │ │ ├ - documentation: undefined
│ │ │ │ + documentation: Scoring configuration for a question in an evaluation form.
│ │ │ └ properties
│ │ │ ├ IsExcludedFromScoring: (documentation changed)
│ │ │ ├ PointsConfiguration: (documentation changed)
│ │ │ └ ScoreThresholds: (documentation changed)
│ │ ├[~] type EvaluationFormScoreThreshold
│ │ │ ├ - documentation: undefined
│ │ │ │ + documentation: Information about a score threshold for a performance category.
│ │ │ └ properties
│ │ │ ├ MaxScorePercentage: (documentation changed)
│ │ │ └ MinScorePercentage: (documentation changed)
│ │ ├[~] type EvaluationFormSection
│ │ │ └ properties
│ │ │ ├ IsExcludedFromScoring: (documentation changed)
│ │ │ └ ScoreThresholds: (documentation changed)
│ │ ├[~] type EvaluationFormSingleSelectQuestionOption
│ │ │ └ properties
│ │ │ └ PointsConfiguration: (documentation changed)
│ │ ├[~] type QuestionOptionPointsConfiguration
│ │ │ ├ - documentation: undefined
│ │ │ │ + documentation: Information about the points configuration for an answer option.
│ │ │ └ properties
│ │ │ └ IsBonus: (documentation changed)
│ │ └[~] type QuestionPointsConfiguration
│ │ ├ - documentation: undefined
│ │ │ + documentation: Information about the points configuration for a question.
│ │ └ properties
│ │ └ IsBonus: (documentation changed)
│ ├[~] resource AWS::Connect::Rule
│ │ └ types
│ │ ├[~] type AssignSlaAction
│ │ │ └ properties
│ │ │ ├ CaseSlaConfiguration: (documentation changed)
│ │ │ └ SlaAssignmentType: (documentation changed)
│ │ ├[~] type CaseSlaConfiguration
│ │ │ └ - documentation: The SLA configuration for cases.
│ │ │ + documentation: undefined
│ │ └[~] type SlaTargetFieldValue
│ │ └ properties
│ │ └ StringValue: (documentation changed)
│ └[~] resource AWS::Connect::SecurityProfile
│ └ types
│ ├[~] type Application
│ │ └ properties
│ │ ├ ApplicationPermissions: - Array<string> (required)
│ │ │ + Array<string>
│ │ └ Namespace: - string (required)
│ │ + string
│ ├[~] type FlowModule
│ │ └ properties
│ │ ├ FlowModuleId: - string (required)
│ │ │ + string
│ │ └ Type: - string (required)
│ │ + string
│ ├[~] type PrimaryAttributeAccessControlConfigurationItem
│ │ └ properties
│ │ └ PrimaryAttributeValues: - Array<PrimaryAttributeValue> (required)
│ │ + Array<PrimaryAttributeValue>
│ └[~] type PrimaryAttributeValue
│ └ properties
│ ├ AccessType: - string<ALLOW> (required)
│ │ + string<ALLOW>
│ ├ AttributeName: - string (required)
│ │ + string
│ └ Values: - Array<string> (required)
│ + Array<string>
├[~] service aws-controlcatalog
│ └ resources
│ ├[-] resource AWS::ControlCatalog::CommonControl
│ │ ├ name: CommonControl
│ │ │ cloudFormationType: AWS::ControlCatalog::CommonControl
│ │ │ documentation: Resource Type definition for AWS::ControlCatalog::CommonControl
│ │ │ arnTemplate: arn:${Partition}:controlcatalog:::common-control/${CommonControlId}
│ │ │ primaryIdentifier: ["CommonControlId"]
│ │ ├ attributes
│ │ │ ├ Domain.Arn: string
│ │ │ ├ Objective.Arn: string
│ │ │ ├ CreateTime: string
│ │ │ ├ Name: string
│ │ │ ├ Objective: Objective
│ │ │ ├ CommonControlId: string
│ │ │ ├ LastUpdateTime: string
│ │ │ ├ Domain.Name: string
│ │ │ ├ Domain: Domain
│ │ │ ├ Description: string
│ │ │ ├ Arn: string
│ │ │ └ Objective.Name: string
│ │ └ types
│ │ ├ type Domain
│ │ │ ├ name: Domain
│ │ │ └ properties
│ │ │ ├ Arn: string
│ │ │ └ Name: string
│ │ └ type Objective
│ │ ├ name: Objective
│ │ └ properties
│ │ ├ Arn: string
│ │ └ Name: string
│ ├[-] resource AWS::ControlCatalog::Control
│ │ ├ name: Control
│ │ │ cloudFormationType: AWS::ControlCatalog::Control
│ │ │ documentation: Resource Type definition for AWS::ControlCatalog::Control
│ │ │ arnTemplate: arn:${Partition}:controlcatalog:::control/${ControlId}
│ │ │ primaryIdentifier: ["ControlId"]
│ │ ├ attributes
│ │ │ ├ GovernedResources: Array<string>
│ │ │ ├ Severity: string
│ │ │ ├ Implementation.Identifier: string
│ │ │ ├ ControlId: string
│ │ │ ├ Behavior: string
│ │ │ ├ CreateTime: string
│ │ │ ├ Name: string
│ │ │ ├ RegionConfiguration: RegionConfiguration
│ │ │ ├ Aliases: Array<string>
│ │ │ ├ Implementation.Type: string
│ │ │ ├ Description: string
│ │ │ ├ RegionConfiguration.Scope: string
│ │ │ ├ Arn: string
│ │ │ ├ RegionConfiguration.DeployableRegions: Array<string>
│ │ │ └ Implementation: ImplementationDetails
│ │ └ types
│ │ ├ type ImplementationDetails
│ │ │ ├ name: ImplementationDetails
│ │ │ └ properties
│ │ │ ├ Type: string (required)
│ │ │ └ Identifier: string
│ │ └ type RegionConfiguration
│ │ ├ name: RegionConfiguration
│ │ └ properties
│ │ ├ Scope: string (required)
│ │ └ DeployableRegions: Array<string>
│ └[+] resource AWS::ControlCatalog::Objective
│ ├ name: Objective
│ │ cloudFormationType: AWS::ControlCatalog::Objective
│ │ documentation: Returns information about an objective in the AWS Control Catalog.
│ │ arnTemplate: arn:${Partition}:controlcatalog:::objective/${ObjectiveId}
│ │ primaryIdentifier: ["Arn"]
│ ├ attributes
│ │ ├ Arn: string
│ │ ├ ObjectiveId: string
│ │ ├ Name: string
│ │ ├ Description: string
│ │ ├ Domain: Domain
│ │ ├ CreateTime: string
│ │ └ LastUpdateTime: string
│ └ types
│ └ type Domain
│ ├ documentation: The domain that the objective belongs to.
│ │ name: Domain
│ └ properties
│ ├ Arn: string
│ └ Name: string
├[-] service aws-dataexchange
│ ├ capitalized: DataExchange
│ │ cloudFormationNamespace: AWS::DataExchange
│ │ name: aws-dataexchange
│ │ shortName: dataexchange
│ ├ resources
│ │ └ resource AWS::DataExchange::EntitledDataSets
│ │ ├ name: EntitledDataSets
│ │ │ cloudFormationType: AWS::DataExchange::EntitledDataSets
│ │ │ documentation: Resource Type definition for AWS::DataExchange::EntitledDataSets
│ │ │ arnTemplate: arn:${Partition}:dataexchange:${Region}::data-sets/${DataSetId}
│ │ │ primaryIdentifier: ["Id"]
│ │ ├ properties
│ │ │ ├ AssetType: string (immutable)
│ │ │ ├ Description: string (immutable)
│ │ │ └ Name: string (immutable)
│ │ └ attributes
│ │ ├ CreatedAt: string
│ │ ├ Id: string
│ │ ├ UpdatedAt: string
│ │ ├ SourceId: string
│ │ ├ Origin: string
│ │ ├ Arn: string
│ │ └ DataSetId: string
│ └ metrics
│ ├ event aws.dataexchange@DataSetUpdateDelayed
│ │ ├ description: Schema for event type DataSetUpdateDelayed, published by AWS service aws.dataexchange
│ │ │ source: aws.dataexchange
│ │ │ detailType: Data Set Update Delayed
│ │ │ rootProperty: DataSetUpdateDelayed
│ │ └ types
│ │ ├ type DataSet
│ │ │ └ properties
│ │ │ ├ AssetType: string (required)
│ │ │ ├ Id: string (required)
│ │ │ └ Name: string (required)
│ │ ├ type DataSetUpdateDelayed
│ │ │ └ properties
│ │ │ ├ DataSet: DataSet (required)
│ │ │ ├ Notification: Notification (required)
│ │ │ └ Product: Product (required)
│ │ ├ type LakeFormationTagPolicyDetails
│ │ │ └ properties
│ │ │ ├ Database: string
│ │ │ └ Table: string
│ │ ├ type Notification
│ │ │ └ properties
│ │ │ ├ Scope: Scope
│ │ │ ├ Comment: string
│ │ │ └ Type: string (required)
│ │ ├ type Product
│ │ │ └ properties
│ │ │ ├ Id: string (required)
│ │ │ ├ Name: string (required)
│ │ │ └ ProviderContact: string (required)
│ │ ├ type RedshiftDataShareDetails
│ │ │ └ properties
│ │ │ ├ Arn: string (required)
│ │ │ ├ Database: string (required)
│ │ │ ├ Function: string
│ │ │ ├ Table: string
│ │ │ └ View: string
│ │ ├ type S3DataAccessDetails
│ │ │ └ properties
│ │ │ ├ KeyPrefixes: string[]
│ │ │ └ Keys: string[]
│ │ └ type Scope
│ │ └ properties
│ │ ├ LakeFormationTagPolicies: LakeFormationTagPolicyDetails[]
│ │ ├ RedshiftDataShares: RedshiftDataShareDetails[]
│ │ └ S3DataAccesses: S3DataAccessDetails[]
│ ├ event aws.dataexchange@DataUpdatedInDataSet
│ │ ├ description: Schema for event type DataUpdatedInDataSet, published by AWS service aws.dataexchange
│ │ │ source: aws.dataexchange
│ │ │ detailType: Data Updated in Data Set
│ │ │ rootProperty: DataUpdatedInDataSet
│ │ └ types
│ │ ├ type DataSet
│ │ │ └ properties
│ │ │ ├ AssetType: string (required)
│ │ │ ├ Id: string (required)
│ │ │ └ Name: string (required)
│ │ ├ type DataUpdate
│ │ │ └ properties
│ │ │ └ DataUpdatedAt: string
│ │ ├ type DataUpdatedInDataSet
│ │ │ └ properties
│ │ │ ├ DataSet: DataSet (required)
│ │ │ ├ Notification: Notification (required)
│ │ │ └ Product: Product (required)
│ │ ├ type Details
│ │ │ └ properties
│ │ │ └ DataUpdate: DataUpdate
│ │ ├ type LakeFormationTagPolicyDetails
│ │ │ └ properties
│ │ │ ├ Database: string
│ │ │ └ Table: string
│ │ ├ type Notification
│ │ │ └ properties
│ │ │ ├ Details: Details
│ │ │ ├ Scope: Scope
│ │ │ ├ Comment: string
│ │ │ └ Type: string (required)
│ │ ├ type Product
│ │ │ └ properties
│ │ │ ├ Id: string (required)
│ │ │ ├ Name: string (required)
│ │ │ └ ProviderContact: string (required)
│ │ ├ type RedshiftDataShareDetails
│ │ │ └ properties
│ │ │ ├ Arn: string (required)
│ │ │ ├ Database: string (required)
│ │ │ ├ Function: string
│ │ │ ├ Schema: string
│ │ │ └ View: string
│ │ ├ type S3DataAccessDetails
│ │ │ └ properties
│ │ │ ├ KeyPrefixes: string[]
│ │ │ └ Keys: string[]
│ │ └ type Scope
│ │ └ properties
│ │ ├ LakeFormationTagPolicies: LakeFormationTagPolicyDetails[]
│ │ ├ RedshiftDataShares: RedshiftDataShareDetails[]
│ │ └ S3DataAccesses: S3DataAccessDetails[]
│ ├ event aws.dataexchange@DeprecationPlannedForDataSet
│ │ ├ description: Schema for event type DeprecationPlannedForDataSet, published by AWS service aws.dataexchange
│ │ │ source: aws.dataexchange
│ │ │ detailType: Deprecation Planned for Data Set
│ │ │ rootProperty: DeprecationPlannedForDataSet
│ │ └ types
│ │ ├ type DataSet
│ │ │ └ properties
│ │ │ ├ AssetType: string (required)
│ │ │ ├ Id: string (required)
│ │ │ └ Name: string (required)
│ │ ├ type Deprecation
│ │ │ └ properties
│ │ │ └ DeprecationAt: string (required)
│ │ ├ type DeprecationPlannedForDataSet
│ │ │ └ properties
│ │ │ ├ DataSet: DataSet (required)
│ │ │ ├ Notification: Notification (required)
│ │ │ └ Product: Product (required)
│ │ ├ type Details
│ │ │ └ properties
│ │ │ └ Deprecation: Deprecation (required)
│ │ ├ type LakeFormationTagPolicyDetails
│ │ │ └ properties
│ │ │ ├ Database: string
│ │ │ └ Table: string
│ │ ├ type Notification
│ │ │ └ properties
│ │ │ ├ Details: Details (required)
│ │ │ ├ Scope: Scope
│ │ │ ├ Comment: string (required)
│ │ │ └ Type: string (required)
│ │ ├ type Product
│ │ │ └ properties
│ │ │ ├ Id: string (required)
│ │ │ ├ Name: string (required)
│ │ │ └ ProviderContact: string (required)
│ │ ├ type RedshiftDataShareDetails
│ │ │ └ properties
│ │ │ ├ Arn: string (required)
│ │ │ ├ Database: string (required)
│ │ │ ├ Function: string
│ │ │ ├ Schema: string
│ │ │ ├ Table: string
│ │ │ └ View: string
│ │ ├ type S3DataAccessDetails
│ │ │ └ properties
│ │ │ ├ KeyPrefixes: string[]
│ │ │ └ Keys: string[]
│ │ └ type Scope
│ │ └ properties
│ │ ├ LakeFormationTagPolicies: LakeFormationTagPolicyDetails[]
│ │ ├ RedshiftDataShares: RedshiftDataShareDetails[]
│ │ └ S3DataAccesses: S3DataAccessDetails[]
│ └ event aws.dataexchange@SchemaChangePlannedForDataSet
│ ├ description: Schema for event type SchemaChangePlannedForDataSet, published by AWS service aws.dataexchange
│ │ source: aws.dataexchange
│ │ detailType: Schema Change Planned for Data Set
│ │ rootProperty: SchemaChangePlannedForDataSet
│ └ types
│ ├ type DataSet
│ │ └ properties
│ │ ├ AssetType: string (required)
│ │ ├ Id: string (required)
│ │ └ Name: string (required)
│ ├ type Details
│ │ └ properties
│ │ └ SchemaChange: SchemaChange (required)
│ ├ type LakeFormationTagPolicyDetails
│ │ └ properties
│ │ ├ Database: string
│ │ └ Table: string
│ ├ type Notification
│ │ └ properties
│ │ ├ Details: Details (required)
│ │ ├ Scope: Scope
│ │ ├ Comment: string
│ │ └ Type: string (required)
│ ├ type Product
│ │ └ properties
│ │ ├ Id: string (required)
│ │ ├ Name: string (required)
│ │ └ ProviderContact: string (required)
│ ├ type RedshiftDataShareDetails
│ │ └ properties
│ │ ├ Arn: string (required)
│ │ ├ Database: string (required)
│ │ ├ Function: string
│ │ ├ Schema: string
│ │ ├ Table: string
│ │ └ View: string
│ ├ type S3DataAccessDetails
│ │ └ properties
│ │ ├ KeyPrefixes: string[]
│ │ └ Keys: string[]
│ ├ type SchemaChange
│ │ └ properties
│ │ ├ Changes: SchemaChangeItem[]
│ │ └ SchemaChangeAt: string (required)
│ ├ type SchemaChangeItem
│ │ └ properties
│ │ ├ Description: string
│ │ ├ Name: string (required)
│ │ └ Type: string (required)
│ ├ type SchemaChangePlannedForDataSet
│ │ └ properties
│ │ ├ DataSet: DataSet (required)
│ │ ├ Notification: Notification (required)
│ │ └ Product: Product (required)
│ └ type Scope
│ └ properties
│ ├ LakeFormationTagPolicies: LakeFormationTagPolicyDetails[]
│ ├ RedshiftDataShares: RedshiftDataShareDetails[]
│ └ S3DataAccesses: S3DataAccessDetails[]
├[~] service aws-devopsagent
│ └ resources
│ ├[~] resource AWS::DevOpsAgent::PrivateConnection
│ │ └ types
│ │ └[~] type ServiceManagedMode
│ │ └ properties
│ │ └[+] DnsResolution: string<PUBLIC|IN_VPC>
│ └[~] resource AWS::DevOpsAgent::Service
│ ├ properties
│ │ └ ServiceDetails: (documentation changed)
│ └ types
│ ├[~] type MCPServerAuthorizationConfig
│ │ └ properties
│ │ └[+] BearerToken: BearerTokenDetails
│ ├[~] type MCPServerSigV4AuthorizationConfig
│ │ └ properties
│ │ ├[+] McpRoleArn: string
│ │ └ RoleArn: - string (required)
│ │ + string
│ │ (documentation changed)
│ ├[~] type RegisteredMCPServerSigV4Details
│ │ └ properties
│ │ ├[+] McpRoleArn: string
│ │ └ RoleArn: (documentation changed)
│ └[~] type ServiceDetails
│ └ properties
│ ├ GitLab: - GitLabDetails (immutable)
│ │ + GitLabDetails
│ ├ MCPServer: - MCPServerDetails (immutable)
│ │ + MCPServerDetails
│ ├ MCPServerGrafana: - MCPServerGrafanaDetails (immutable)
│ │ + MCPServerGrafanaDetails
│ └ MCPServerNewRelic: - NewRelicServiceDetails (immutable)
│ + NewRelicServiceDetails
├[~] service aws-dms
│ └ resources
│ └[~] resource AWS::DMS::Certificate
│ ├ - primaryIdentifier: ["Id"]
│ │ + primaryIdentifier: ["CertificateArn"]
│ └ attributes
│ ├[+] CertificateArn: string
│ └[-] Id: string
├[~] service aws-docdb
│ └ resources
│ └[~] resource AWS::DocDB::EventSubscription
│ ├ - primaryIdentifier: ["Id"]
│ │ + primaryIdentifier: ["SubscriptionName"]
│ ├ properties
│ │ └ SourceType: - string
│ │ + string<db-instance|db-cluster|db-parameter-group|db-security-group|db-cluster-snapshot>
│ └ attributes
│ └[-] Id: string
├[~] service aws-dynamodb
│ └ resources
│ ├[+] resource AWS::DynamoDB::Export
│ │ ├ name: Export
│ │ │ cloudFormationType: AWS::DynamoDB::Export
│ │ …
…nts (#38098) Added 'Object Created' to the list of events for EventBridge notifications. ### Issue # (if applicable) N/A ### Reason for this change The `enableEventBridgeNotification` method was missing the "Object Created" S3 event type channeled to EventBridge in the method's documentation. > Ref: https://docs.aws.amazon.com/AmazonS3/latest/userguide/EventBridge.html *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…n group across 1 directory (#38491) Bumps the npm_and_yarn group with 1 update in the / directory: [ip-address](https://github.com/beaugunderson/ip-address). Updates `ip-address` from 10.2.0 to 10.4.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/beaugunderson/ip-address/releases">ip-address's releases</a>.</em></p> <blockquote> <h2>v10.4.0</h2> <h2>What's Changed</h2> <ul> <li>Add GitHub Actions CI by <a href="https://github.com/beaugunderson"><code>@beaugunderson</code></a> in <a href="https://redirect.github.com/beaugunderson/ip-address/pull/213">beaugunderson/ip-address#213</a></li> <li>Keep the package loadable on node 12, and enforce it by <a href="https://github.com/beaugunderson"><code>@beaugunderson</code></a> in <a href="https://redirect.github.com/beaugunderson/ip-address/pull/216">beaugunderson/ip-address#216</a></li> <li>Validate the byte arrays Address6 is given by <a href="https://github.com/beaugunderson"><code>@beaugunderson</code></a> in <a href="https://redirect.github.com/beaugunderson/ip-address/pull/217">beaugunderson/ip-address#217</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/beaugunderson/ip-address/compare/v10.3.1...v10.4.0">https://github.com/beaugunderson/ip-address/compare/v10.3.1...v10.4.0</a></p> <h2>v10.3.1</h2> <p><strong>Full Changelog</strong>: <a href="https://github.com/beaugunderson/ip-address/compare/v10.3.0...v10.3.1">https://github.com/beaugunderson/ip-address/compare/v10.3.0...v10.3.1</a></p> <h2>v10.3.0</h2> <p><strong>Full Changelog</strong>: <a href="https://github.com/beaugunderson/ip-address/compare/v10.2.2...v10.3.0">https://github.com/beaugunderson/ip-address/compare/v10.2.2...v10.3.0</a></p> <h2>v10.2.2</h2> <p><strong>Full Changelog</strong>: <a href="https://github.com/beaugunderson/ip-address/compare/v10.2.1...v10.2.2">https://github.com/beaugunderson/ip-address/compare/v10.2.1...v10.2.2</a></p> <h2>v10.2.1</h2> <p><strong>Full Changelog</strong>: <a href="https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.2.1">https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.2.1</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/beaugunderson/ip-address/commit/fbb8db28f1559842b7191cab7d8ea6408ed82f7b"><code>fbb8db2</code></a> 10.4.0</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/45a2b11ec254a2e5620de66e248adcb33d16e669"><code>45a2b11</code></a> Validate the byte arrays Address6 is given (<a href="https://redirect.github.com/beaugunderson/ip-address/issues/217">#217</a>)</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/bac8810b3935cab123316a4bc5ebaa22db140299"><code>bac8810</code></a> Keep the package loadable on node 12, and enforce it (<a href="https://redirect.github.com/beaugunderson/ip-address/issues/216">#216</a>)</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/9b3d8488d15e6bfe5f5503867b088ce056723e08"><code>9b3d848</code></a> Add a security policy and a README section on security posture</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/e84a7b381d02cb97ed114023e44133efae151254"><code>e84a7b3</code></a> Order the README API reference Address4, Address6, AddressError</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/015160b85ee60b39548219817a5de3c4e828a6d6"><code>015160b</code></a> Collapse each class in the README API reference</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/34061a897d526b7a063c3605402cd30a8363a035"><code>34061a8</code></a> Pin checkout and setup-node to commits in the release job</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/c5fae5d9bdfe8ded7f4ca01a3d3ea8d97f8f1277"><code>c5fae5d</code></a> Pin action-gh-release to a commit and move it to 3.0.2</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/e0ef0484193218b0d28cfbb53795bc44ddb3cc21"><code>e0ef048</code></a> Replace CircleCI with GitHub Actions</li> <li><a href="https://github.com/beaugunderson/ip-address/commit/5e3ceb779aee6ad3f33264e66225e8e7584ab612"><code>5e3ceb7</code></a> Add GitHub Actions CI across Node 20, 22, 24 and 25 (<a href="https://redirect.github.com/beaugunderson/ip-address/issues/213">#213</a>)</li> <li>Additional commits viewable in <a href="https://github.com/beaugunderson/ip-address/compare/v10.2.0...v10.4.0">compare view</a></li> </ul> </details> <details> <summary>Maintainer changes</summary> <p>This version was pushed to npm by <a href="https://www.npmjs.com/~GitHub%20Actions">GitHub Actions</a>, a new releaser for ip-address since your current version.</p> </details> <details> <summary>Install script changes</summary> <p>This version adds <code>prepare</code> script that runs during installation. Review the package contents before updating.</p> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/aws/aws-cdk/network/alerts). </details>
…t` does not support `JsonATA` for api_path (#37738) ### Issue # (if applicable) Closes #37728 . ### Reason for this change - `CallApiGatewayRestApiEndpoint` fails during synthesis when apiPath is provided as a JSONata expression. Error message during cdk synthesis : ``` (.venv) ➜ cdkAppPython git:(main) ✗ cdk synth jsii.errors.JavaScriptError: ValidationError: "path" must begin with a "/": '{% "/path/" & $states.input.path_suffix %}' ``` - This cdk synthesis failure prevents us from passing `JsonATA` expression in `api_path` & there is NO workaround . IAM policy must be resolved at synth time . JSONata expressions are evaluated at runtime by Step Functions . - This PR focuses on resolving the issue detailed below : #37728 . ### Description of changes 1. Detect when `apiPath` is a JSONata expression ({% ... %}). I've used the same `isValidJsonataExpression` logic to maintain consistency . https://github.com/aws/aws-cdk/blob/e207b76cc2503701b3c4e2c87023617b485b2fde/packages/aws-cdk-lib/aws-stepfunctions/lib/private/jsonata.ts#L1 2. When JSONata detected, use wildcard path `/*` as the IAM policy path ARN while keeping the original expression unchanged in the Step Functions definition . This `apiPath` behavior matches existing handling in CallApiGatewayHttpApiEndpoint ### Describe any new or updated permissions being added - No new permissions introduced . - Existing `execute-api:Invoke` permission now uses a wildcard path (/*) when apiPath is dynamic . - Scope still remains limited to ``` arn:partition:execute-api:<region>:<account>:<api-id>/<stage>/<method>/* ``` ### Description of how you validated changes 1. Unit tests added: - JSONata `apiPath` does not throw during synthesis - JSONata expression is passed through unchanged in state JSON 2. Integration test added (aws-stepfunctions-tasks): - IAM policy with wildcard path (/*) = ```.....<api-id>/<stage>/<method>/*``` - State machine definition preserving JSONata expression 3. I've also manually verified the correctness of IAM policy, Jsonata expression evaluation on the deployed resources. ( included in integ tests CFN ) ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…ions (#38486) ## Issue Closes #<ISSUE> ## Reason for this change The `Runtime` metric helpers in `aws-bedrockagentcore` emitted CloudWatch dimensions that do not match the metrics AgentCore actually publishes to the `AWS/Bedrock-AgentCore` namespace. As a result, any alarm built on these helpers never received data and stayed in `INSUFFICIENT_DATA`. - Per-resource helpers emitted only `{ Resource: <arn> }`. - Aggregated helpers emitted `{ Resource: 'All' }`, which matched no published metric at all. ## Description of changes Per-resource metrics (`metricInvocations`, `metricLatency`, `metricThrottles`, `metricSystemErrors`, `metricUserErrors`, `metricTotalErrors`, `metricSessionCount`) now emit the full dimension shape AgentCore publishes: ``` { Operation: 'InvokeAgentRuntime', Name: '<runtimeName>::DEFAULT', Resource: <arn> } ``` Aggregated metrics (`metricInvocationsAggregated`, `metricSessionsAggregated`) now emit `{ AggregateOperation: 'InvokeAgentRuntime' }` via a new private `metricAggregated()` helper that deliberately bypasses the per-resource seam (so the per-resource dimensions are not injected). The caller escape hatch (`props.dimensionsMap`) is preserved and merges over the defaults on both paths. No public signatures, helper names, or construct IDs changed. ## Describe any new or updated permissions being added None. ## Description of how you validated changes - **Unit tests**: added assertions against the synthesized CloudFormation template verifying the exact emitted dimensions for both per-resource and aggregated helpers, plus regression guards (no `Service` dimension on per resource; per-resource dimensions absent on aggregated), a caller-override merge test, and a token-path test confirming `Name` resolves to a concrete synth string ending `::DEFAULT` (not an `Fn::Join`). All metric tests pass. - **Live validation**: deployed a `Runtime` to a test account, invoked it, and probed CloudWatch `get-metric-data`. The new per-resource dimension set (`Operation` + `Name` + `Resource`) and the aggregated `AggregateOperation` dimension both returned populated datapoints (`Sum = 5.0`), while the old `{ Resource }`-only and `{ Resource: 'All' }` shapes returned no datapoints — confirming the corrected dimensions map to real, populated metric series. ## Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license* BREAKING CHANGE: `RuntimeBase` metric helpers now emit corrected CloudWatch dimensions per-resource metrics use `{ Operation, Name, Resource }` (was `{ Resource }`) and aggregated metrics use `{ AggregateOperation }` (was `{ Resource: 'All' }`). Alarms/dashboards built on the old dimensions must be updated.
…ion (#38487) ## Issue Closes #<ISSUE> ## Reason for this change The `Gateway` metric helpers in `aws-bedrockagentcore` emitted CloudWatch dimensions that do not match the metrics AgentCore actually publishes to the `AWS/Bedrock-AgentCore` namespace. As a result, any alarm built on these helpers never received data and stayed in `INSUFFICIENT_DATA`. The helpers emitted only `{ Resource: <gatewayArn> }`, omitting the `Operation` and `Protocol` dimensions AgentCore publishes for gateway invocation metrics. ## Description of changes Per-gateway metrics (`metricInvocations`, `metricThrottles`, `metricSystemErrors`, `metricUserErrors`, `metricLatency`, `metricDuration`, `metricTargetExecutionTime`, `metricTargetType`) now emit the shape AgentCore publishes: ``` { Operation: 'InvokeGateway', Protocol: <protocolType>, Resource: <gatewayArn> } ``` The `Protocol` dimension is sourced from the gateway's own protocol configuration (e.g. `MCP`). The caller escape hatch (`props.dimensionsMap`) is preserved and merges over the defaults. No public signatures, helper names, or construct IDs changed. ## Describe any new or updated permissions being added None. ## Description of how you validated changes Added/updated unit tests : - asserting the synthesized CloudFormation template emits `Operation=InvokeGateway`, `Protocol=MCP`, and `Resource=<gatewayArn>` for the per-gateway metrics (keeping the existing Namespace + Statistic assertions), - a caller-override merge test, `Match.objectLike({ Name: 'CustomDimension', Value: 'value' })` check in the unit tests - a `metricTargetType` test that also asserts the inherited `Operation`/`Protocol` dimensions, and a regression test for the imported-gateway (`fromGatewayAttributes`) metric path. All gateway metric tests pass (49/49). The dimension shape is documented at https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/observability-gateway-metrics.html. ## Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license* BREAKING CHANGE: `Gateway` metric helpers now emit corrected CloudWatch dimensions per-gateway metrics use `{ Operation, Protocol, Resource }` (was `{ Resource }`). Alarms/dashboards built on the old dimensions must be updated.
) ### Issue # (if applicable) Closes #38455 ### Reason for this change Fix spelling and documentation issues to improve clarity and consistency. ### Description of changes - Corrected occurrences of `nonexistant` to `nonexistent` throughout the codebase. - Renamed affected files containing `nonexistant` in their filenames. - Removed the duplicated word "evaluates" in `docs/release.md`. These changes do not affect functionality. ### Describe any new or updated permissions being added None. ### Description of how you validated changes - Searched the codebase to verify no remaining occurrences of `existant`. - Verified no filenames contain `existant`. - Reviewed the changes to ensure they do not affect functionality. ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
### Issue # (if applicable) N/A, no issue was open for 3.7. ### Reason for this change Amazon OpenSearch Service [added support for OpenSearch 3.7 in July 2026](https://aws.amazon.com/about-aws/whats-new/2026/07/amazon-opensearch-service/), in all regions where the service is available, but `EngineVersion` has no constant for it. The newest constant is `OPENSEARCH_3_5` (added in #37490). Users currently have to fall back to the `EngineVersion.openSearch('3.7')` escape hatch. That works fine, but it isn't discoverable and it doesn't match how every other supported version is exposed. ### Description of changes Adds `EngineVersion.OPENSEARCH_3_7`, following the same pattern as #37490 (3.5), #36186 (3.3) and #35477 (3.1): - `packages/aws-cdk-lib/aws-opensearchservice/lib/version.ts`, the new constant. - `packages/aws-cdk-lib/aws-opensearchservice/test/domain.test.ts`, added to `testedOpenSearchVersions`. Only 3.7 is added, not 3.6. OpenSearch Service ships every other minor in the 3.x line (3.1, 3.3, 3.5, 3.7), the same way the 2.x line went 2.9 / 2.11 / 2.13 / 2.15 / 2.17 / 2.19. There is no 3.6 engine version on the service even though an upstream OSS 3.6 release exists, so an `OPENSEARCH_3_6` constant would point at something you can't actually deploy. ### Describe any new or updated permissions being added None. ### Description of how you validated changes Added the new constant to `testedOpenSearchVersions` in `domain.test.ts`, so it runs through the existing unit test cases. Those pass. I originally also added 3.7 to `integ.opensearch.min.ts`, but that needs a regenerated snapshot and I can't run a real deployment to produce one. The [CONTRIBUTING guide](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) says not to work around that with `--dry-run` or by editing the snapshot by hand, so I've dropped the integ change instead and kept this PR to the constant plus unit test coverage. Happy to add 3.7 to `integ.opensearch.min.ts` as a follow-up if a maintainer can run `integ-runner --update-on-failed` for it. Note that test deploys one domain per entry in `versions`, so it would go from 6 domains to 7. ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
Two improvements to protect data stored in S3 buckets that back Glue tables: - Enforce SSL ([AWS Foundational Security Best Practices S3.5][1]). - Set encryption at rest as S3 managed when the table is configured with client side encryption. This is a fallback mechanism, since there is no way to enforce that the data was actually encrypted on the client side, so we use the baseline S3 managed encryption. [1]: https://docs.aws.amazon.com/securityhub/latest/userguide/s3-controls.html#s3-5 ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
The path of the root of the construct tree is, by definition, the ancestor of every other path. The current `isAncestorOf` returns false in this case. This was caught by accident when fact-check ran the tests with the seed -1286036690. ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
### Issue # (if applicable) Closes #37045. ### Reason for this change EBS volume size limits in AWS have been updated: **io2** supports 4 GiB–64 TiB and **gp3** supports 1 GiB–64 TiB ([EBS volume types](https://docs.aws.amazon.com/ebs/latest/userguide/ebs-volume-types.html); gp3 limit increased Sept 2025). The CDK was still enforcing a 16 TiB (16384 GiB) maximum for both, causing validation errors when creating io2 or gp3 volumes larger than 16 TiB (e.g. `Size.gibibytes(25000)`). This change aligns CDK validation with current AWS limits. ### Description of changes - **`packages/aws-cdk-lib/aws-ec2/lib/volume.ts`** Raised max size for `GENERAL_PURPOSE_SSD_GP3` (gp3) and `PROVISIONED_IOPS_SSD_IO2` (io2) from 16384 GiB to 65536 GiB (64 TiB). Left gp2, io1, st1, sc1, and magnetic limits unchanged per current AWS docs. - **`packages/aws-cdk-lib/aws-ecs/lib/base/service-managed-volume.ts`** Applied the same gp3 and io2 max size (65536 GiB) for ECS Service Managed EBS volumes so behavior matches the EC2 `Volume` construct. - **`packages/aws-cdk-lib/aws-ec2/test/volume.test.ts`** Updated the “validation size in range” test data so the expected max for gp3 and io2 is 65536 instead of 16384. No API or behavior changes for other volume types; only validation bounds were updated. Alternatives considered: updating all volume types to 64 TiB was rejected because AWS still documents 16 TiB max for gp2, io1, st1, and sc1. ### Describe any new or updated permissions being added None. This change only adjusts client-side validation limits; it does not introduce or change any IAM or resource permissions. ### Description of how you validated changes - **Unit tests:** Updated and ran the existing EC2 volume size validation tests in `packages/aws-cdk-lib/aws-ec2/test/volume.test.ts` (including “validation size in range”). Tests confirm that min/max (e.g. 1/65536 for gp3, 4/65536 for io2) are accepted and values outside the range are rejected. - **Build:** Verified `aws-cdk-lib` build and relevant tests pass (e.g. `yarn test aws-ec2`). - No new integration tests were added; this is a validation-only change that does not affect deployment or CloudFormation resource creation beyond allowing previously rejected sizes that AWS already supports. ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
AWS Glue allows the user to configure an encryption key (among other things) for a catalog. But if
one of the tables in an encrypted catalog has partition indexes, the custom resource that creates
the partition indexes fails. This happens because the custom resource handler does not have
permission to decrypt the data.
Currently there is no L2 for catalogs. Users configure the catalog via the L1:
```ts
new CfnDataCatalogEncryptionSettings(this, 'Settings', {
catalogId: this.account,
dataCatalogEncryptionSettings: {
connectionPasswordEncryption: {
kmsKeyId: kmsKey.keyId,
returnConnectionPasswordEncrypted: true,
}
},
});
```
One quick solution would be to add a new constructor property to the table constructs, and require
the user to pass the same configuration they used in the L1 via this new constructor property, But
this would be cumbersome and error-prone.
Instead, this change introduces a new `Catalog` L2, with minimal functionality to support
encryption, both of the data and the password:
```ts
const catalog = new glue.Catalog(stack, 'Catalog', {
catalogName: 'my-catalog',
encryptionAtRest: glue.DataCatalogEncryptionAtRest.kms(key),
connectionPasswordEncryption: { kmsKey: key, returnConnectionPasswordEncrypted: false },
});
```
Additionally, in AWS Glue, every account has an implicit catalog, whose ID is the account ID itself.
The L2 created here provides a type safe way to manipulate this default catalog as a regular
(singleton) resource, which can be obtained via:
```ts
const accountWideCatalog: ICatalog = Catalog.forAccount(scope);
```
A catalog's encryption is fixed when the catalog is created: a catalog either carries encryption
settings or it does not, so there are no mutation methods that change encryption after the fact. To
configure encryption for the account-wide catalog, use `Catalog.encryptAccount`:
```ts
Catalog.encryptAccount(scope, {
encryptionAtRest: DataCatalogEncryptionAtRest.kms(key),
});
```
Because encryption is fixed at construction, this must be called before the account catalog is first
used in the stack (before any `Catalog.forAccount(scope)` call, and before any `Database` that uses
the account catalog); calling it afterward throws. Configuring the same account catalog from
multiple stacks makes those stacks overwrite one another at deploy time, so this should be done in
exactly one stack.
Imported catalogs (`Catalog.fromCatalogArn` / `Catalog.fromCatalogId`) are pure identity handles:
they emit no resources and do not manage the imported catalog's encryption. To manage the encryption
of a catalog you did not create in this stack, add a `CfnDataCatalogEncryptionSettings` resource
targeting its id directly.
Closes #30364 and #35019.
BREAKING CHANGE: `IDatabase.catalogArn` and `IDatabase.catalogId` were removed in factor of a type
safe `ICatalog`, which has `catalogArn` and `catalogId`. Consumers and implementations were updated
accordingly.
----
*By submitting this pull request, I confirm that my contribution is made under the terms of the
Apache-2.0 license*
Editorial pass over `docs/DESIGN_GUIDELINES.md` (with a small companion fix in `AGENTS.md`) to make the guidance clearer, self-explanatory, and free of stale references. No behavioral or code changes. Highlights: - **Static type checks / `instanceof`**: explain *why* `instanceof` is unreliable in CDK (multiple copies of a package in `node_modules`, multiple versions in one tree, jsii cross-language boundaries) rather than just asserting the rule. `AGENTS.md` updated to match: L1 `Cfn*` checks are auto-generated via `spec2cdk`; core classes like `App`/`Stack`/`Stage` implement the pattern by hand. - **Versioning**: replaced the cryptic bullet "Semantic versioning Construct ID changes or scope hierarchy" with a full explanation — changing a construct's ID or scope position changes the derived logical ID, which replaces resources and causes data loss, so such changes are breaking and only allowed in `-alpha` modules. - **`Fn::Sub`**: replaced the bare "Do not use FnSub" with the rationale (it embeds logical IDs as literal strings, bypassing CDK's reference/dependency tracking) and the recommended alternatives. - **Removed stale content**: obsolete CDKv1→v2 note about removing pattern libraries, the deCDK prop-type restrictions, and dangling awslint rule tags (`[_awslint:...]`) that no longer correspond to active lint rules. - **Trait/Facade section**: trimmed duplicated explanation of Facades providing Trait implementations. - **Misc**: removed a leftover "Suggestion for alternative syntax?" author note (replaced with a proper explanation of static factory methods), de-duplicated the "be concise" props guidance, and minor wording/typo fixes. ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…ark existing helpers as legacy (#37209) ### Issue # (if applicable) Closes #37199. ### Reason for this change The ADOT project now recommends the optimized Lambda layers (`AWSOpenTelemetryDistro*` family) over the legacy embedded-collector layers. The current CDK README and JSDoc comments present the legacy `adotInstrumentation` helpers as the default/recommended approach, which no longer aligns with the [ADOT Lambda overview](https://aws-otel.github.io/docs/getting-started/lambda). ### Description of changes - Restructured the README "Lambda with AWS Distro for OpenTelemetry layer" section into two subsections: - **Optimized ADOT Lambda layers (recommended)** — new section showing how to use `AWSOpenTelemetryDistro*` layers via `LayerVersion.fromLayerVersionArn()` with `/opt/otel-instrument` and the `CloudWatchLambdaApplicationSignalsExecutionRolePolicy` IAM policy - **Legacy ADOT Lambda layers** — the existing `adotInstrumentation` example, now with a note explaining these use the legacy embedded-collector layers - Added legacy notes to JSDoc on `AdotInstrumentationConfig`, `AdotLayerVersion`, `AdotLambdaExecWrapper`, and all five version classes No behavioral or API changes — docs and JSDoc only. ### Describe any new or updated permissions being added N/A ### Description of how you validated changes Docs-only change. Verified TypeScript compiles without new errors. Reviewed the updated README for accuracy against the current [ADOT Lambda documentation](https://aws-otel.github.io/docs/getting-started/lambda). ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…ption (#38512) Per security best practices. ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…rtificate (#37250) ### Issue Closes #35404 ### Reason for this change Setting `minimumProtocolVersion` or `sslSupportMethod` on a `Distribution` without also providing a custom `certificate` has no effect — the distribution silently falls back to the CloudFront default certificate, which uses a fixed security policy. Users have no way of knowing their TLS configuration is being ignored. ### Description of changes Added `Annotations.of(this).addWarningV2()` warnings in the `Distribution` constructor for both `minimumProtocolVersion` and `sslSupportMethod` when they're set without a `certificate`. This follows the same pattern as the existing `emptyDomainNames` warning a few lines above. ### Description of how you validated changes Added three test cases: - Warning emitted when `minimumProtocolVersion` is set without a certificate - Warning emitted when `sslSupportMethod` is set without a certificate - No warning when `minimumProtocolVersion` is set with a certificate present All existing CloudFront tests pass (419 tests, 28 suites). ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md)
…input (#38162) ### Issue # (if applicable) Closes #38121. ### Reason for this change `RuleTargetInput.fromText('something')` synthesizes as `Input: '"something"'` (the string is wrapped in double quotes), which surprises users because the method name reads like "pass raw text". As explained in the issue thread (and previously in #18695), this is working as designed: the target `Input` field of an `AWS::Events::Rule` must be valid JSON, and a bare string is not valid JSON on its own, so the text is JSON-encoded at synthesis time. EventBridge decodes that JSON before delivering the input, so the target receives the unquoted value. The behavior is correct and required by EventBridge, but the docstring did not call out the JSON encoding, making the quoting non-obvious. The maintainer suggested a docstring clarification on the issue. ### Description of changes - `fromText`: document that the input is JSON-encoded, that a plain string therefore renders with surrounding double quotes, that EventBridge decodes it before delivery, and that the quotes cannot be removed because they are part of the required JSON encoding. - `fromMultilineText`: document that each line is JSON-encoded for the same reason. No behavior change; this is documentation only. ### Describe any new or updated permissions being added None. ### Description of how you validated changes Documentation-only change. `aws-cdk-lib` builds cleanly (the docstrings are part of the jsii assembly) and ESLint passes. No fenced code examples were added, so there is nothing for Rosetta to compile. ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) Credit to @TomasChmelik for the report and to the maintainer who diagnosed it on the issue. ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…#37468) Closes #37092 The HttpVersion enum JSDoc incorrectly stated 'Maximum HTTP version to support'. Per AWS documentation, this property specifies which HTTP versions are enabled. Notably, setting HTTP3 enables HTTP 3 only (not HTTP 2). Exemption Request: Documentation-only change, no code behavior change.
…urceArns` (#37425) ### Reason for this change Fix a typo in a local variable name. ### Description of changes Rename the local variable `resouceArns` to `resourceArns` in `FunctionBase.grantInvokeVersion()`. This is a local variable only — no public API surface is affected. ### Description of how you validated changes Local variable rename only. No behavioral change. Exemption Request: This is a trivial variable rename with no functional impact and no change to public API, so no integration test change is needed. ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…ce referencing (#38515) ### Issue # (if applicable) Closes #38517 ### Reason for this change ### Description of changes Fixes six issues in `@aws-cdk/aws-mediaconnect-alpha`: 1. **`addOutput()` options** — accepts `flowOutputName`, `description`, and `outputStatus` 2. **VPC interface simplified** — `vpcInterfaceAttachmentName: string` replaces `vpcInterfaceAttachment: VpcInterfaceConfig` (enables cross-stack usage) 3. **Availability zone support** — added optional `availabilityZone` to standard, failover, and merge router input/output configurations 4. **`publicNetwork()` CIDR optional** — supports outbound-only interfaces 5. **Maintenance naming consistency** — Flow now uses `maintenanceConfiguration: { day, time }` matching router input/output 6. **Exported base classes** — `FlowOutputBase`, `FlowEntitlementBase`, `FlowSourceBase`, `RouterNetworkInterfaceBase` were `@internal`, breaking TypeScript consumers 7. (found while fixing): Add missing token guards for regionName and availabilityZone string inputs ### How has this been tested? - Existing unit tests updated for new signatures - New integration test (`integ.mediaconnect-router-availability-zone`) verifying AZ + outbound-only deploys successfully - Existing integ tests pass with updated call sites ---- BREAKING CHANGE: `flow.addOutput(id, outputConfig)` signature changed to `flow.addOutput(id, options)` — wrap existing calls in `{ output: ... }`. `vpcInterfaceAttachment` prop on output configs replaced with `vpcInterfaceAttachmentName: string` — use `myVpcInterface.name` instead. `maintenance: { maintenanceDay, maintenanceStartHour }` → `maintenanceConfiguration: { day, time }` — prop and field names changed (more consistency) ### Describe any new or updated permissions being added ### Description of how you validated changes ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
…dates (#38521) Bumps the npm_and_yarn group with 2 updates in the / directory: [nx](https://github.com/nrwl/nx/tree/HEAD/packages/nx) and [postcss](https://github.com/postcss/postcss). Updates `nx` from 22.7.3 to 22.7.7 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/nrwl/nx/releases">nx's releases</a>.</em></p> <blockquote> <h2>22.7.7 (2026-07-10)</h2> <h3>🩹 Fixes</h3> <ul> <li><strong>core:</strong> prevent path traversal / zip-slip in self-hosted remote cache (<a href="https://redirect.github.com/nrwl/nx/pull/36116">#36116</a>)</li> <li><strong>core:</strong> warn when the self-hosted remote cache disables TLS verification (NXC-4593) (<a href="https://redirect.github.com/nrwl/nx/pull/36132">#36132</a>, <a href="https://redirect.github.com/nrwl/nx/issues/36116">#36116</a>)</li> <li><strong>dotnet:</strong> declare obj as a publish output to fix sandbox violation (<a href="https://redirect.github.com/nrwl/nx/issues/35858">#35858</a>)</li> <li><strong>dotnet:</strong> declare directory build props input for analyzer dotnet tasks (<a href="https://github.com/nrwl/nx/commit/df7540195a">df7540195a</a>)</li> <li><strong>dotnet:</strong> declare directory build props on the separate release build target (<a href="https://github.com/nrwl/nx/commit/6545ee2222">6545ee2222</a>)</li> <li><strong>dotnet:</strong> declare directory build props on the analyzer tests dotnet targets (<a href="https://github.com/nrwl/nx/commit/e72ee0dd79">e72ee0dd79</a>)</li> </ul> <h3>❤️ Thank You</h3> <ul> <li>FrozenPandaz <a href="https://github.com/FrozenPandaz"><code>@FrozenPandaz</code></a></li> <li>Jason Jean <a href="https://github.com/FrozenPandaz"><code>@FrozenPandaz</code></a></li> </ul> <h2>22.7.6 (2026-06-23)</h2> <h3>🩹 Fixes</h3> <ul> <li><strong>misc:</strong> bump happy-dom, tmp, and form-data to patched versions (<a href="https://redirect.github.com/nrwl/nx/pull/36013">#36013</a>)</li> </ul> <h3>❤️ Thank You</h3> <ul> <li>Jack Hsu <a href="https://github.com/jaysoo"><code>@jaysoo</code></a></li> </ul> <h2>22.7.5 (2026-05-27)</h2> <h3>🩹 Fixes</h3> <ul> <li><strong>core:</strong> update tmp to 0.2.6 due to CVE-2026-44705 (<a href="https://redirect.github.com/nrwl/nx/pull/35813">#35813</a>)</li> </ul> <h3>❤️ Thank You</h3> <ul> <li>Jack Hsu <a href="https://github.com/jaysoo"><code>@jaysoo</code></a></li> </ul> <h2>22.7.4 (2026-05-25)</h2> <h3>🩹 Fixes</h3> <ul> <li><strong>core:</strong> update brace-expansion and yaml (<a href="https://redirect.github.com/nrwl/nx/pull/35790">#35790</a>)</li> </ul> <h3>❤️ Thank You</h3> <ul> <li>Jack Hsu <a href="https://github.com/jaysoo"><code>@jaysoo</code></a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/nrwl/nx/commit/a328bf1d5eb3f32571500578867a18730e7f1db0"><code>a328bf1</code></a> fix(core): warn when the self-hosted remote cache disables TLS verification (...</li> <li><a href="https://github.com/nrwl/nx/commit/a82807621e4176e37909d2c1afede661b45cc30a"><code>a828076</code></a> fix(core): prevent path traversal / zip-slip in self-hosted remote cache (<a href="https://github.com/nrwl/nx/tree/HEAD/packages/nx/issues/36">#36</a>...</li> <li><a href="https://github.com/nrwl/nx/commit/dc849bbd9492d667f0162ca54c2f429f4cd27ed7"><code>dc849bb</code></a> fix(core): update brace-expansion and yaml (<a href="https://github.com/nrwl/nx/tree/HEAD/packages/nx/issues/35790">#35790</a>)</li> <li>See full diff in <a href="https://github.com/nrwl/nx/commits/22.7.7/packages/nx">compare view</a></li> </ul> </details> <br /> Updates `postcss` from 8.5.19 to 8.5.26 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/postcss/postcss/releases">postcss's releases</a>.</em></p> <blockquote> <h2>8.5.26</h2> <ul> <li>Fixed <code>list.split()</code> regression (by <a href="https://github.com/lazerg"><code>@lazerg</code></a>).</li> <li>Track symlinks in path protection in source map loading (by <a href="https://github.com/drengir1"><code>@drengir1</code></a>).</li> </ul> <h2>8.5.25</h2> <ul> <li>Fixed 8.5.17 visitor regression.</li> <li>Fixed <code>list.split()</code> for non-string values (by <a href="https://github.com/amir-rezaei"><code>@amir-rezaei</code></a>).</li> </ul> <h2>8.5.24</h2> <ul> <li>Preserve the BOM after the processing (by <a href="https://github.com/hdimer"><code>@hdimer</code></a>).</li> </ul> <h2>8.5.23</h2> <ul> <li>Do not load source map without <code>opts.from</code> for security reasons.</li> </ul> <h2>8.5.22</h2> <ul> <li>Fixed custom property losing semicolon before a comment (by <a href="https://github.com/sarathfrancis90"><code>@sarathfrancis90</code></a>).</li> </ul> <h2>8.5.21</h2> <ul> <li>Fixed childless at-rule losing semicolon before comment (by <a href="https://github.com/sarathfrancis90"><code>@sarathfrancis90</code></a>).</li> <li>Fixed docs (by <a href="https://github.com/isker"><code>@isker</code></a>).</li> </ul> <h2>8.5.20</h2> <ul> <li>Fixed missing space if <code>AtRule#params</code> is set after (by <a href="https://github.com/sarathfrancis90"><code>@sarathfrancis90</code></a>).</li> <li>Fixed mixing AST error on warnings (by <a href="https://github.com/MahinAnowar"><code>@MahinAnowar</code></a>).</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/postcss/postcss/blob/main/CHANGELOG.md">postcss's changelog</a>.</em></p> <blockquote> <h2>8.5.26</h2> <ul> <li>Fixed <code>list.split()</code> regression (by <a href="https://github.com/lazerg"><code>@lazerg</code></a>).</li> <li>Track symlinks in path protection in source map loading (by <a href="https://github.com/drengir1"><code>@drengir1</code></a>).</li> </ul> <h2>8.5.25</h2> <ul> <li>Fixed 8.5.17 visitor regression.</li> <li>Fixed <code>list.split()</code> for non-string values (by <a href="https://github.com/amir-rezaei"><code>@amir-rezaei</code></a>).</li> </ul> <h2>8.5.24</h2> <ul> <li>Preserve the BOM after the processing (by <a href="https://github.com/hdimer"><code>@hdimer</code></a>).</li> </ul> <h2>8.5.23</h2> <ul> <li>Do not load source map without <code>opts.from</code> for security reasons.</li> </ul> <h2>8.5.22</h2> <ul> <li>Fixed custom property losing semicolon before a comment (by <a href="https://github.com/sarathfrancis90"><code>@sarathfrancis90</code></a>).</li> </ul> <h2>8.5.21</h2> <ul> <li>Fixed childless at-rule losing semicolon before comment (by <a href="https://github.com/sarathfrancis90"><code>@sarathfrancis90</code></a>).</li> <li>Fixed docs (by <a href="https://github.com/isker"><code>@isker</code></a>).</li> </ul> <h2>8.5.20</h2> <ul> <li>Fixed missing space if <code>AtRule#params</code> is set after (by <a href="https://github.com/sarathfrancis90"><code>@sarathfrancis90</code></a>).</li> <li>Fixed mixing AST error on warnings (by <a href="https://github.com/MahinAnowar"><code>@MahinAnowar</code></a>).</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/postcss/postcss/commit/07b25773f38f77919f2af02ae3e8896b0deb5988"><code>07b2577</code></a> Release 8.5.26 version</li> <li><a href="https://github.com/postcss/postcss/commit/47de6b9d7c55674cb326c5de7a734a740916defc"><code>47de6b9</code></a> Update CI</li> <li><a href="https://github.com/postcss/postcss/commit/1493a83db7830912316512f55ab6064e7b7dd68e"><code>1493a83</code></a> Fix Rule#selectors losing the empty selector (<a href="https://redirect.github.com/postcss/postcss/issues/2129">#2129</a>)</li> <li><a href="https://github.com/postcss/postcss/commit/180db166e250d20e6761b224ae8d8134c9ba3e40"><code>180db16</code></a> Typo</li> <li><a href="https://github.com/postcss/postcss/commit/29e9e00f132c96e46e1de295b816fe88a05354e7"><code>29e9e00</code></a> Resolve symlinks before the previous-source-map containment check (<a href="https://redirect.github.com/postcss/postcss/issues/2125">#2125</a>)</li> <li><a href="https://github.com/postcss/postcss/commit/3ba8f84703a884329b58abea579c3615684e0b7e"><code>3ba8f84</code></a> Update dependencies</li> <li><a href="https://github.com/postcss/postcss/commit/87e72f671fd0d401c52822b5226c656632d92ec0"><code>87e72f6</code></a> Update lock file</li> <li><a href="https://github.com/postcss/postcss/commit/caaeeb907e4a816c44a23b00b151882bd02325a1"><code>caaeeb9</code></a> Upgrade nanoid to fix infinite loop on zero size (<a href="https://redirect.github.com/postcss/postcss/issues/2124">#2124</a>)</li> <li><a href="https://github.com/postcss/postcss/commit/3609b6f4296952d0b5b9ddae42c8d73ee460c041"><code>3609b6f</code></a> Explain how to type plugin options</li> <li><a href="https://github.com/postcss/postcss/commit/fbad419cbd01cd7a9a1a46413447f2cd9b3fce4a"><code>fbad419</code></a> docs: show ESM and TypeScript plugin declaration (<a href="https://redirect.github.com/postcss/postcss/issues/2118">#2118</a>)</li> <li>Additional commits viewable in <a href="https://github.com/postcss/postcss/compare/8.5.19...8.5.26">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/aws/aws-cdk/network/alerts). </details>
### Issue # (if applicable) Closes #37502. ### Reason for this change CloudWatch introduced Alarm Mute Rules, enabling us to temporarily mute alarm notifications during planned maintenance downtime, etc. https://aws.amazon.com/about-aws/whats-new/2026/02/amazon-cloudwatch-alarm-muting-rules/ For details https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/alarm-mute-rules.html ### Description of changes This PR includes: - A L2 construct `cloudwatch.AlarmMuteRule` and prop interface. - A convenient class `cloudwatch.ScheduleExpression` to generate alarm mute rule's schedule expression, inspired by `scheduler.ScheduleExpression`. - A convernient method `cloudwatch.Alarm.addAlarmMuteRule()`. #### Basic Usage ``` ts declare const alarm1: cloudwatch.IAlarm; declare const alarm2: cloudwatch.IAlarm; const alarmMuteRule = new cloudwatch.AlarmMuteRule(this, 'AlarmMuteRule', { // target alarms - optional alarms: [alarm1], // cron-style expression with optional time zone schedule: cloudwatch.ScheduleExpression.cron({ minute: '0', hour: '0', timeZone: cdk.TimeZone.ASIA_TOKYO }), // one-time schedule with optional time zone schedule: cloudwatch.ScheduleExpression.at(new Date(...), cdk.TimeZone.ASIA_TOKYO), // duration of mute period duration: cdk.Duration.minutes(30), }); // Alarms can be added after construction alarmMuteRule.addAlarm(alarm2); ``` ### Describe any new or updated permissions being added No permissions. ### Description of how you validated changes Added unit tests and an integ test. The integ test has no assertions because assertion cannot verify that nothing happens. ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
Updates the L1 CloudFormation resource definitions with the latest changes from `@aws-cdk/aws-service-spec`
**L1 CloudFormation resource definition changes:**
```
├[~] service aws-connectcampaignsv2
│ └ resources
│ └[~] resource AWS::ConnectCampaignsV2::Campaign
│ └ - arnTemplate: undefined
│ + arnTemplate: arn:${Partition}:connect-campaigns:${Region}:${Account}:campaign/${CampaignId}
├[~] service aws-devicefarm
│ └ resources
│ └[~] resource AWS::DeviceFarm::Project
│ └ - arnTemplate: arn:${Partition}:devicefarm:${Region}:${Account}:project:${ProjectId}
│ + arnTemplate: arn:${Partition}:devicefarm:${Region}:${Account}:project:${ResourceId}
├[~] service aws-directoryservice
│ └ resources
│ └[~] resource AWS::DirectoryService::MicrosoftAD
│ └ - arnTemplate: arn:${Partition}:ds:${Region}:${Account}:directory/${DirectoryId}
│ + arnTemplate: arn:${Partition}:ds:${Region}:${Account}:${DirectoryId}
├[~] service aws-globalaccelerator
│ └ resources
│ └[~] resource AWS::GlobalAccelerator::Accelerator
│ └ - arnTemplate: arn:${Partition}:globalaccelerator::${Account}:accelerator/${AcceleratorId}
│ + arnTemplate: arn:${Partition}:globalaccelerator::${Account}:accelerator/${ResourceId}
├[~] service aws-networkmanager
│ └ resources
│ └[~] resource AWS::NetworkManager::CoreNetwork
│ └ - arnTemplate: arn:${Partition}:networkmanager::${Account}:core-network/${CoreNetworkId}
│ + arnTemplate: arn:${Partition}:networkmanager::${Account}:core-network/${ResourceId}
├[~] service aws-personalize
│ └ resources
│ └[~] resource AWS::Personalize::DataDeletionJob
│ └ - arnTemplate: undefined
│ + arnTemplate: arn:${Partition}:personalize:${Region}:${Account}:data-deletion-job/${ResourceId}
├[~] service aws-pinpoint
│ └ resources
│ └[~] resource AWS::Pinpoint::InAppTemplate
│ └ - arnTemplate: arn:${Partition}:mobiletargeting:${Region}:${Account}:templates/${TemplateName}/EMAIL
│ + arnTemplate: arn:${Partition}:mobiletargeting:${Region}:${Account}:templates/${TemplateName}/PUSH
├[~] service aws-quicksight
│ └ resources
│ └[~] resource AWS::QuickSight::Space
│ └ - arnTemplate: undefined
│ + arnTemplate: arn:${Partition}:quicksight:${Region}:${Account}:space/${ResourceId}
├[~] service aws-rds
│ └ resources
│ └[~] resource AWS::RDS::DBParameterGroup
│ └ - arnTemplate: arn:${Partition}:rds:${Region}:${Account}:pg:${DBParameterGroupName}
│ + arnTemplate: arn:${Partition}:rds:${Region}:${Account}:pg:${ParameterGroupName}
├[~] service aws-rekognition
│ └ resources
│ └[~] resource AWS::Rekognition::StreamProcessor
│ └ - arnTemplate: arn:${Partition}:rekognition:${Region}:${Account}:streamprocessor/${Name}
│ + arnTemplate: arn:${Partition}:rekognition:${Region}:${Account}:streamprocessor/${StreamprocessorId}
└[~] service aws-resiliencehub
└ resources
└[~] resource AWS::ResilienceHub::ResiliencyPolicy
└ - arnTemplate: arn:${Partition}:resiliencehub:${Region}:${Account}:resiliency-policy/${PolicyId}
+ arnTemplate: arn:${Partition}:resiliencehub:${Region}:${Account}:resiliency-policy/${ResiliencyPolicyId}
```
aws-cdk-automation
temporarily deployed
to
automation
August 10, 2026 12:05 — with
GitHub Actions
Inactive
aws-cdk-automation
temporarily deployed
to
automation
August 10, 2026 12:06 — with
GitHub Actions
Inactive
aws-cdk-automation
temporarily deployed
to
automation
August 10, 2026 12:06 — with
GitHub Actions
Inactive
aws-cdk-automation
temporarily deployed
to
automation
August 10, 2026 12:06 — with
GitHub Actions
Inactive
aws-cdk-automation
temporarily deployed
to
automation
August 10, 2026 12:06 — with
GitHub Actions
Inactive
aws-cdk-automation
temporarily deployed
to
automation
August 10, 2026 12:06 — with
GitHub Actions
Inactive
aws-cdk-automation
temporarily deployed
to
automation
August 10, 2026 12:06 — with
GitHub Actions
Inactive
aws-cdk-automation
temporarily deployed
to
automation
August 10, 2026 12:06 — with
GitHub Actions
Inactive
Contributor
|
PRs without a linked issue will receive lower priority for review and merging. Please update the description to follow the PR template and include a line like |
Collaborator
|
@Mergifyio queue |
Contributor
Merge Queue Status
Waiting for
All conditions
|
Contributor
|
Comments on closed issues and PRs are hard for our team to see. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
See CHANGELOG