⚠ BREAKING CHANGES
- ** L1 resources are automatically generated from public CloudFormation Resource Schemas. They are built to closely reflect the real state of CloudFormation. Sometimes these updates can contain changes that are incompatible with previous types, but more accurately reflect reality. In this release we have changed:
aws-appstream: AWS::AppStream::StackFleetAssociation: FleetName property is now immutable.
aws-appstream: AWS::AppStream::StackFleetAssociation: StackName property is now immutable.
aws-appsync: AWS::AppSync::ApiCache: AtRestEncryptionEnabled property is now immutable.
aws-appsync: AWS::AppSync::ApiCache: TransitEncryptionEnabled property is now immutable.
aws-bedrockagentcore: AWS::BedrockAgentCore::OnlineEvaluationConfig: OutputConfig attribute removed.
aws-cloud9: AWS::Cloud9::EnvironmentEC2: Id attribute removed.
aws-config: AWS::Config::ConfigurationRecorder: Id attribute removed.
aws-config: AWS::Config::OrganizationConfigRule: Id attribute removed.
aws-datazone: AWS::DataZone::PolicyGrant: Detail property is now required.
aws-datazone: AWS::DataZone::PolicyGrant: Principal property is now required.
aws-directoryservice: AWS::DirectoryService::MicrosoftAD: Id attribute removed.
aws-lambda: AWS::Lambda::NetworkConnector: VpcEgressConfiguration.NetworkProtocol property is now required.
aws-lambda: AWS::Lambda::NetworkConnector: VpcEgressConfiguration.SecurityGroupIds property is now required.
Features
- update L1 CloudFormation resource definitions (#38969) (ed0df78)
- batch: add ConsumableResource L2 construct (#36971) (a12f3a1)
- bedrockagentcore: support runtime platformVersion (#38924) (227423f)
- cloudfront: default Distribution behaviors to redirect HTTP to HTTPS (#38721) (6ede006), closes #38599
- opensearchservice: add useLatestServiceSoftwareForBlueGreen support (#38499) (6aa03e5), closes #38664 #38664
- pipelines: add
executionModesupport in CodePipeline L3 construct (#35022) (7283d38), closes #35014
Bug Fixes
- bump bundled brace-expansion to 5.0.12 (#38929) (ff25def), closes #38932
- applicationautoscaling: target tracking silently ignores custom metric account and region (#36503) (5d10288), closes #36401
- bedrockagentcore: accept aws-cn ECR image URIs in Runtime container URI validation (#38948) (49ac618), closes #38947
- cloudfront-origins: missing OAC permissions for Function URL (#35919) (d213cc7), closes #35872 /github.com/aws/aws-cdk/blob/75139b2145010bc74e8017b23450d7af95327f49/packages/aws-cdk-lib/aws-cloudfront-origins/lib/function-url-origin.ts#L144-L153 /github.com/aws/aws-cdk/blob/75139b2145010bc74e8017b23450d7af95327f49/packages/aws-cdk-lib/aws-cloudfront-origins/lib/function-url-origin.ts#L144-L153 /github.com/aws/aws-cdk/blob/75139b2145010bc74e8017b23450d7af95327f49/packages/aws-cdk-lib/aws-lambda/lib/function-base.ts#L577 #35725
- core: validation E2001 inadvertently not enabled (#38920) (0b763a7)
- eks: allow access policies on AccessEntryType.EC2 access entries (#38782) (e507e07), closes #37496
- s3-deployment:
Source.dataobjectKey can write outside the staging directory (#38921) (53439f9)
Alpha modules (2.273.0-alpha.0)
⚠ BREAKING CHANGES
- redshift-alpha: PUBLIC in any ASCII letter case is rejected as the name of a created user, or of an imported user that is granted table privileges. Existing PUBLIC grants are not removed, but narrowing one is rejected. Migrating to an ordinary name still works.
- redshift-alpha: The
loggingPropertiesprop onClusterProps(and theLoggingPropertiesinterface) has been removed from@aws-cdk/aws-redshift-alpha. Use the newloggingprop withClusterLogging.s3({ bucket, keyPrefix })orClusterLogging.cloudWatch({ logExports })instead.