What changed in AWS CLI from 1 to 2

30 releases numbered after 1.45.64 up to and including 2.36.40, stable releases only. 1.45.64 and 2.36.40 are the newest stable releases of 1 and 2 we track; this page follows them as new ones ship.

274 changes across 30 releases

Added 228

2.36.40

  • New AWS REVIEW mode as supported data retention mode for Bedrock models
  • Support for ValidateSecurityGroupQuotasForInterface API for authorized AWS services to validate security group rule quotas before creating an elastic network interface
  • AdjustableAtLevel property to QuotaContext in Service Quotas, indicating whether a quota is adjustable at the account or resource level
  • Two new Monetization Functions lifecycle hooks in Elemental MediaTailor: Post Ads Response and Pre Manifest Insertion
  • VAST Request function type in Elemental MediaTailor that calls a VAST or VMAP ad server
  • Yield Optimization with demand from Amazon Publisher Services in Elemental MediaTailor

2.36.39

  • Add support for WhatsApp Flows with endpoints in socialmessaging
  • Enable TagOnCreate for Rule resource on CreateRule API in connect
  • Add PreEvaluationFilters field to Rule resource in connect affecting Create, Update, Describe and Search APIs
  • Add Consent Portal APIs to AgentCore Identity to manage portals for end users to grant OAuth authorization for agents to access resources
  • Add trace source selection by log group prefix, custom or source log group result destinations, and metrics namespace customization to AgentCore Evaluation
  • Enable AWS Transfer Family SFTP Connectors to support specifying an ordered list of AWS Secrets Manager version stages for secret retrieval
  • Add support for Sequence Activities in GuardDuty Findings
  • Include source server architecture in SourceProperties in AWS Elastic Disaster Recovery to identify x86 and ARM64 systems
  • Allow Amazon EVS users to set, update, and retrieve values for parameters that apply across all EVS Environments at a regional level such as VCF License portability core count
  • Enable Amazon Transcribe to support specifying up to 29 PII entity types in the ContentRedaction configuration of a StartTranscriptionJob request
  • Add critical parameter to Amazon ECS managed daemon APIs to control whether a daemon task failure drains the container instance
  • Add support for sending TCP resets for Gateway Load Balancer when a flow's idle timeout expires or when a target becomes unhealthy or is deregistered

2.36.38

  • sagemaker-featurestore-runtime now supports the UpdateRecord API for partial updates to individual feature values in an existing Online Store record
  • mgn now supports applying source security posture to existing VPCs by uploading a source network file with firewall rules and matching source subnets by CIDR
  • appintegrations adds a force parameter to DeleteApplication to delete applications with existing associations in one call
  • appintegrations adds ConflictException to UpdateApplication for clear error messaging when an update conflicts with the application's current state
  • ec2 now supports retaining interruptible Capacity Reservations in an active state when all capacity is reclaimed
  • medialive now supports AB forensic video watermarking
  • mwaa now allows clearing optional S3 paths by accepting empty strings for plugins, requirements, and startup script fields in UpdateEnvironment requests
  • bedrock-agentcore batch evaluation now supports up to 10 CloudWatch log groups per CloudWatchLogsSource
  • odb adds the ListFlexComponents API for listing flex components available for a given DB system shape
  • sagemaker now supports the Standard V2 online store type for feature-level writes to feature groups

2.36.37

  • Add support for the Amazon Lightsail GetProfile API, which returns the profile for the specified account
  • Add support for AAC passthrough in mediaconvert
  • Add ManifestCues option to mediaconvert to support HLS manifest Cue marker passthrough
  • Add playback device compatibility mode for DASH H.265 outputs in mediaconvert
  • Add TTML caption styling options in mediaconvert
  • Add interlace mode support for XAVC HD Intra CBG profile in mediaconvert
  • Add renewalTerm returns to GetOfferTerms in marketplace-discovery, exposing maxRenewals, lockoutPeriod, adjustmentDeadline, priceIncrease, and termTemplates
  • Add configurable control over S3 direct access for AWS Lambda, allowing explicit enable or disable of how functions stream file reads directly from S3 buckets
  • Add support for custom detection rules in Amazon GuardDuty, including APIs to manage rule associations and organization-level configurations
  • Add dry run feature for Amazon Kinesis Data Streams data-plane APIs to validate permissions and request parameters
  • Add renewal support for AWS Marketplace private offers in marketplace-agreement
  • Add SearchAgreements filters in marketplace-agreement
  • Add support for mounting Amazon S3 data directly into pipeline task containers via S3 Access Points in AWS IoT SiteWise Scenario Discovery
  • Add support for configuring additional ephemeral storage per task in AWS IoT SiteWise Scenario Discovery
  • Add support for managing SMIME signing certificates for email identities in sesv2, including associating, listing, and disassociating certificates
  • Add UpdateConfigurationSet operation to sesv2 to configure message security options such as signing scheme

2.36.36

  • Release HTTP and AGUI descriptors to the dataplane model for agent-registry

2.36.35

  • Support for up to 10 attachments (150 MB each) per case correspondence in AWS Support, increased from 3 at 5 MB
  • Global routing support on Amazon Connect Global Resiliency instances with new GetCrossRegionRouting and UpdateCrossRegionRouting APIs
  • AWS Agent Registry is now generally available
  • Support for Slack bidirectional communication configuration in AWS DevOps Agent agent spaces
  • ConditionalBehavior response on DescribeRegistrationFieldDefinitions in AWS End User Messaging SMS
  • Asynchronous RestartConnector API for Amazon MSK Connect to restart newly created connectors with option to restart all tasks or only failed tasks
  • Nested virtualization support for Amazon WorkSpaces Core managed instances via CpuOptions.NestedVirtualization in CreateWorkspaceInstance
  • App management APIs in Amazon QuickSight including ListApps, SearchApps, DescribeApp, DescribeAppPermissions, UpdateAppPermissions, and DeleteApp
  • New APIs for segment membership events in Customer Profiles allowing export to Kinesis streams
  • New calculated attribute statistic and 2 new segment dimension types in Customer Profiles
  • Support for data delivery to Amazon S3 Tables (Apache Iceberg) and general purpose Amazon S3 buckets in Amazon Kinesis Data Streams with CreateChannel, UpdateChannel, DeleteChannel, DescribeChannel, and ListChannels APIs
  • G6e instance support in Amazon SageMaker Batch Transform for deploying generative AI models

2.36.34

  • New HealthLake API RestoreFHIRDatastore providing capability to restore active datastores to a point in time within the last 30 days or recover a deleted datastore from the delete snapshot
  • Add GetClientToken operation to cognito-idp allowing M2M auth through the SDK
  • Add DescribeTermsByClient operation to cognito-idp to find which Terms are associated with a user-pool client without knowing the Terms resource id
  • Release partnercentral-selling API for PARC APN Program letting sellers add software revenue details to AWS opportunity summary
  • Add optional syncSchedule field to bedrock-agent CreateDataSource and UpdateDataSource for Managed Knowledge Bases data source connectors to sync automatically on a daily, weekly, or monthly schedule
  • Add support for early success criteria on ECS rolling deployments to let deployment complete once a configurable percentage of tasks are healthy with configurable BLOCKING or DEFERRED cleanup of previous service revisions
  • Add IngestData API to bedrock-agentcore Memory for direct ingestion into long-term memory

2.36.33

  • Added resultCount to QueryStatistics in GetQueryResults for logs service
  • Added deploymentMode parameter to CreateDeployment in codedeploy service
  • EC2 allows AMI owners to define compatible instance types on their AMIs
  • Added cascadeDelete to DeleteDomain in datazone service
  • Added InsufficientCapacityException to RunMicrovm in lambda-microvms service
  • Added lifecycle status field to ListManagedMicrovmImageVersions in lambda-microvms service
  • Added ConflictException to CreateMicrovmAuthToken and CreateMicrovmShellAuthToken in lambda-microvms service
  • Added AdminDeleteSoftwareToken API operation in cognito-idp service
  • Added support for full snapshot size in bytes of DB instance snapshots in rds service

2.36.32

  • Add deleting state to possible VPC States in ec2
  • Add new status enum for Firewalls in network-firewall
  • AWS DevOps Agent now supports trigger filter groups for Release Readiness Review to control when the capability auto-triggers based on webhook events and target branches
  • Support License Expiry field in ListProductSubscriptions API in license-manager-user-subscriptions
  • Amazon SageMaker AI now supports ml.g7 instances for model optimization in supported AWS Regions

2.36.31

  • Adds the UpdateApprovalAction API for resolving agent action approvals in AWS DevOps Agent agent spaces
  • Add ability to tune TerminatedPodGcThreshold configuration in an Amazon EKS cluster
  • Fleet feature to support Capacity Reservation Resource Groups with Amazon EC2 Capacity Blocks and interruptible Capacity Reservations
  • Extend AWS IoT Rules Engine to support IoT InfluxDB Action for sending messages from IoT sensors and applications to InfluxDB
  • Add support for Distribution Segments in mixed instances policies, providing ordered prioritization across On-Demand Capacity Reservations, Capacity Blocks, interruptible Capacity Reservations, and On-Demand capacity
  • Announce IAM access troubleshooter to debug access denied errors faster with detailed evaluations of policies considered
  • Add support for i7i.metal-48xl EC2 bare metal instance type in EVS

2.36.30

  • Add ExtractedInformation segment to the ListRealtimeContactAnalysisSegmentsV2 API in connect service
  • Add ExtractedInformation segment to the ListRealtimeContactAnalysisSegments API in connect-contact-lens service
  • Add accountConstraints and patternType to GetWorkload, ListWorkloads, GetWorkloadDeploymentPattern and ListWorkloadDeploymentPatterns in launch-wizard service
  • Add private and self-signed certificate configuration support for penetration tests in securityagent service
  • Add OAuth authentication support for Amazon MSK Replicator when connecting to external Apache Kafka clusters
  • Add effectiveDbParameterGroupIdentifier field to timestream-influxdb service to surface the parameter group actually applied
  • Add support for specifying an inference profile ID or ARN as the target model in bedrock CreateAdvancedPromptOptimizationJob
  • Add GetFixture API to elementalinference service to retrieve fixture details
  • Add access role ARN to CreateFeed, GetFeed, and UpdateFeed responses in elementalinference service

2.36.29

  • Added support to CreateRemoveAccessSession for selecting a server version on the mobile WebDriver endpoint in Device Farm
  • Allow customers to specify an initial warm up period to wait for metrics to arrive when creating metric or log alarms in CloudWatch

2.36.28

  • Amazon SES now supports per-message tracking overrides using the new ConfigurationOverrides parameter in SendEmail and SendBulkEmail to enable or disable open and click tracking for individual messages
  • Lambda adds support for full JSON resource-based policies, enabling customers to create, retrieve, update, and delete function resource policies as complete JSON documents
  • Direct Connect now supports custom route prefix pool allocations allowing you to set IPv4 and IPv6 route prefix counts on private and transit virtual interfaces
  • AWS Batch now supports a new compute environment type that provides fully managed EC2 capacity with broader compute flexibility than Fargate, including GPU instances, bare metal, and specific instance type selection
  • SageMaker added IAM Identity Center (IdC) support to CreatePartnerApp and UpdatePartnerApp APIs
  • SageMaker added Customer Managed Key (CMK) support to CreateMlflowApp and DescribeMlflowApp
  • CloudFront added SigV4a as a supported signing protocol for Origin Access Control (OAC), enabling CloudFront to sign requests to Amazon S3 Multi-Region Access Point origins

2.36.27

  • Amazon VPC Lattice now supports modification of private DNS options on Service Network VPC Associations
  • EKS now supports cluster certificate authorities (CA)
  • Amazon Redshift enhanced System Table retention allows storing system table data directly in S3 Tables instead of Redshift Managed Storage
  • Account Access now includes throttling exceptions in operation outputs
  • AgentCore Memory now supports Flexible Namespaces and Non-Conversational Payloads in CreateEvent API
  • AWS Elemental MediaLive now supports video cropping and output positioning with cropRectangle and outputPositionRectangle parameters
  • AgentCore Memory now supports Flexible Namespaces
  • AWS Batch now supports managing CloudWatch Container Insights on compute environments via CreateComputeEnvironment and UpdateComputeEnvironment
  • Amazon Redshift Serverless enhanced System Table Retention allows storing system table data directly in S3 Tables instead of Redshift Managed Storage

2.36.26

  • Amazon WorkSpaces now supports nested virtualization, allowing you to run hypervisors and virtualization-based workloads within your WorkSpaces
  • AWS Outposts now supports VPC Endpoint configuration in CreatePrivateConnectivityConfig, enabling scoped private connectivity with provisioning role creation for secure outpost installations
  • Introduce DescribeAssessment and ListAssessments APIs to expose validation issues on Marketplace resources via a newly created Assessment resource

2.36.25

  • AWS Elastic Disaster Recovery (AWS DRS) now offers Recovery Plans to recover multi-server applications in the right order in one action with ordered steps and wait times
  • Add implementations of third-party evaluators, both managed-as-a-service and as templates within custom evaluators for bedrock-agentcore-control
  • AgenticRetrieveStream API now supports Amazon Bedrock AgentCore Memory with new memoryConfiguration parameter to continue a session from short-term memory and retrieve from long-term memory
  • Add new APIs to create, describe, update, delete, and list extraction definitions for managing lifecycle of extraction definition resources in Connect
  • Add new event sources for Rules related to ACW and new action to Extract Information in Connect
  • Amazon Location Service now supports POI density and category filtering on dynamic maps with PoiDensity (Off to VeryDense) and PoiCategories parameters on GetStyleDescriptor API
  • Add new Transfer Responsibility error codes and document related CloudTrail events for accepting and terminating a Transfer Responsibility in Organizations

2.36.24

  • Added support for associating glossary terms with iterable form items, such as table columns in Glue
  • Added support for g7.2xlarge, g7.4xlarge, g7.8xlarge, g7.12xlarge, g7.24xlarge, and g7.48xlarge instance types for SageMaker HyperPod
  • CloudWatch Logs centralization rules now support tag propagation with configurable conflict resolution strategies
  • Added AgentCore Payments support for CMK, Marketplace Subscriptions and QuickCreate
  • Amazon Redshift now unlocks a locked admin user account and resets the failed-login counter when updating the admin password using the ModifyCluster API when account lockout security is enabled
  • Added support for Consuming code for MWAA Serverless
  • Amazon Redshift Serverless now unlocks a locked admin user account and resets the failed-login counter when updating the admin password using the UpdateNamespace API when account lockout security is enabled
  • Added support for the Machine Payments Protocol (MPP) and x402 upto scheme payments protocol in Amazon Bedrock AgentCore Payments
  • Added CheckIngestedDocumentAcl and GetIngestedDocumentAcl APIs to Amazon Bedrock Knowledge Bases to verify user access to documents based on ingested ACLs

2.36.23

  • Added the GetBlobDifferences API operation to codecommit, which returns line-level diffs between two blob versions without requiring a local clone with support for pagination
  • Added InstanceIds parameter to TerminateInstanceInAutoScalingGroup in autoscaling to terminate multiple instances in a single call and return an Activities list
  • Added LaunchInstances response in autoscaling to return IdempotentCallInProgressFault for duplicate client tokens
  • Added support in securityagent for setting a maximum task-hour budget cap on penetration tests and code reviews
  • Added REVALIDATION job type to securityagent for revalidating previously reported findings
  • Added support in acm to update existing email-validated certificates to use the DNS validation method
  • Added support in cleanrooms for minimum aggregation thresholds and comparison controls to the Custom analysis rule type
  • Added StartAssistantContact API to connect to start chat contacts handled by an AI agent
  • Added SegmentAttributes to StartWebRTCContact in connect

2.36.22

  • Introduced role manager for IAM, an automated capability that sets up IAM roles your AWS services need
  • Added Well-Architected Agent, a generative AI service that analyzes AWS environments and delivers personalized recommendations across cost, security, performance, and resilience
  • Added APIs for DLP with Microsoft Purview to manage configs with label enforcement across Spaces, Chat, and Knowledge Bases
  • Added Approval Workflows APIs for CRUD operations on policies for asset sharing for Agents, Knowledge Bases, and Spaces
  • Added Limits Management APIs for limit profiles for index storage and agent hours per user
  • Added support for Oracle Exadata on Exascale Infrastructure (ExaDB-XS) resources including storage vaults and VM clusters

2.36.21

  • GetSubscriptionGrant now returns materialized asset scope name for mapping Lake Formation data cell filters or Redshift views to subscription grants in datazone
  • Add support for exporting redacted query execution logs in AWS Clean Rooms
  • Add online eval arn as input for recommendation API in bedrock-agentcore
  • Add seven new APIs for managing custom metrics in connect, including create, describe, update, and delete operations to tailor analytics dashboards
  • Add SDK support for AWS IAM account access manager in account-access, enabling mapping of IAM roles to users and groups in AWS IAM Identity Center
  • Give customers the ability to selectively tune certain configurations of Kubernetes control plane components in an Amazon EKS cluster

2.36.20

  • Added PREFIX AWARE routing strategy and PrefixAwareRoutingConfig to SageMaker CreateEndpointConfig with PrefixLength and ConcurrencyThreshold configuration
  • Added support for the SearchFixtures API and DataSourceConfiguration in ElementalInference to map fixture event data onto clipping outputs
  • Added the PrefixAwareId header to SageMaker Runtime InvokeEndpoint and InvokeEndpointWithResponseStream as a routing hint for prefix-aware routing
  • Added Malay language option to Connect for AI-powered automatic evaluation form filling
  • Added VirtualSourceAddress to MediaLive multicast output destinations for specifying source IP address for outbound multicast packets

2.36.19

  • Amazon SageMaker adds maintenance lifecycle statuses for Notebook Instances
  • Support for updating the task template associated with in-progress task contacts using the new UpdateContactTaskTemplate API in Amazon Connect
  • Support for inserting ads via the VAST Ad Buffet standard in MediaTailor with AdSequencingMode setting for sequential ad insertion
  • Support for BGP route protection in Amazon VPC IP Address Manager including route discovery, RPKI route protection findings, and delegated RPKI for BYOIP prefixes
  • provenanceEnabled parameter added to StartFHIRImportJob in HealthLake
  • enableEmailMfa input field on Actor to enable email-based MFA during penetration tests in Security Agent, with mfaForwardingAddress returned when enabled
  • StreamNameOutputMode field on MediaPackageV2 OriginEndpoints to choose whether egress manifests use numeric stream indices or encoder-assigned stream names

2.36.18

  • Add support for WhatsApp Conversions APIs in socialmessaging
  • Add support for capacity provider sessions in Amazon Bedrock AgentCore, allowing deletion of active sessions on runtime instances
  • Add support for C8a, C8i, C9g, M8a, M8i, and M9g EC2 instance type families for GameLift managed EC2 and container fleets
  • Add support for service generated insights across runs, jobs, and tests in Device Farm
  • Agent Registry Public Preview release
  • AWS Backup now lets you create read-only access points for Amazon S3 recovery points
  • MSK Clusters can now deliver authorizer logs to user-defined destinations
  • Add index category support to CloudWatch Logs DescribeFieldIndexes API to filter DEFAULT, CUSTOM, AUTO, and INACTIVE field indexes
  • Add new ListFreeTrialStatusesV2 API to Security Hub to describe free trial statuses
  • AWS Elemental MediaTailor now supports concurrent function execution with new Concurrent Executor function type
  • Add optional IncludeLocalZones parameter to EC2 Spot Placement Score API to consider Local Zones with Spot capacity
  • Add Model Customization SequenceLength parameter for SageMaker Training and g7 instance types for Training and Processing
  • EC2 Auto Scaling now supports being managed by other AWS services via the operator field
  • GetAgreementTerms now returns netPaymentTerm in AcceptedTerm with paymentDuePeriod field
  • Add support for Gateway rate limits and Runtime instances in Amazon Bedrock AgentCore
  • GetOfferTerms now returns netPaymentTerm in offerTerms with paymentDuePeriod field in ISO 8601 duration format

2.36.17

  • New enum values added for Agent Connectivity issues in ecs
  • PutDataCatalogExportConfiguration API to export Glue Data Catalog metadata to systems tables stored in S3 Tables in glue
  • RSASSA-PSS signing algorithm support in acm-pca
  • Persistent volume cost reporting in deadline service alongside compute and license costs
  • Fine-grained access control for AgentCore Memory through managed AgentCore Gateway HTTP Connectors in bedrock-agentcore-control

2.36.16

  • Add Azure SBOM export capability to Inspector2
  • AWS IAM Identity Center now lets you create organization-level instances without enabling multi-account permissions, with the ability to enable multi-account permissions during instance creation or later
  • Add ClientExperiencePolicy to ClientProperties object for ModifyClientProperties and DescribeClientProperties APIs in WorkSpaces
  • Add Vector indexes to Amazon DynamoDB for similarity search on vector embeddings using approximate nearest neighbor search
  • Amazon EC2 now supports Application Status Checks to monitor your application's health through configurable HTTP(S) paths and ports
  • Partners can now create leads in Partner Central Selling with only 5 required fields and free-text values for all other fields

2.36.15

  • Added eksNodeName, instanceId, and zone optional parameters to the AssumeRoleForPodIdentity API in eks-auth
  • Added ability to use Network Firewall as an explicit Proxy to protect workloads against data exfiltration
  • Added support for mediaconvert output to S3 Glacier Instant Retrieval
  • Added route visibility support for AWS Direct Connect with ListVirtualInterfaceRoutes to view BGP routes including AS path and BGP communities
  • Added support for customer-managed backup restore in timestream-influxdb
  • Added encryption of new DbInstances and DbClusters using customer-managed KMS keys in timestream-influxdb
  • Added CMK support for Telemetry Enablement Organization and Account Rules in observabilityadmin

2.36.14

  • Add StorageOperationStatus and StorageOperationPercentProgress to RDS DescribeDBInstances to monitor storage initialization and optimization progress
  • Add support for enhanced Git experience in Sagemaker Unified Studio in DataZone
  • Add ability to create and update CloudWatch Logs lookup tables directly from query results and configure lookup tables as scheduled query destinations
  • Add enum for sensitive property to CloudFormation DriftIgnoredReason
  • Add EKS value to Outposts AWSServiceName enum and mark Address field as sensitive
  • Add TargetAgreementId, TargetAgreementIntent, and CreatedBySource filters to Marketplace Catalog ListEntities API for Offer entity type
  • Add abandonment rate pacing control feature for outbound campaigns in Amazon Connect Campaigns V2
  • Add support for mid-conversation tool changes in Amazon Bedrock Converse and ConverseStream APIs
  • Add graphic composition support on cropped video outputs in AWS Elemental Inference
  • Add Amazon OpenSearch Service exporter for managed collectors in Amazon Managed Service for Prometheus
  • Add GetEnterpriseSupportChargeSummary, GetEnterpriseSupportContractDetails, and ListEnterpriseSupportLinkedAccountCharges APIs to AWS Billing for programmatic access to Enterprise Support billing data
  • Add support for new testing capability in AWS Resilience Hub
  • Add TopicV2 management APIs and enable using Topics in Analysis in Amazon QuickSight
  • Add AWS_CLI_SESSION_ID_DISABLED environment variable to opt out of session ID collection

2.36.12

  • Add support for providing a branch override when configured integrated repositories in securityagent
  • Add support for streaming tables for Apache Iceberg on Amazon MSK Express brokers, continuously materializing Apache Kafka topics as Iceberg tables in Amazon S3 Tables
  • Add support for data delivery to Amazon S3 general purpose buckets on Amazon MSK Express brokers
  • Add support for g7 family instance types for SageMaker Studio JupyterLab and CodeEditor apps in us-east-1, us-west-2, and us-east-2
  • Add UPDATING field to Container Association Status in network-firewall
  • Add Python3.15 and NodeJS 26 runtime support to AWS Lambda
  • Add support for configuring models through the OpenResponses API for custom evaluators in bedrock-agentcore-control
  • Add support for Public PricingPlanManager SDK

2.36.11

  • Add support for policy-based routing on AWS Transit Gateway with new policy table entry APIs to route traffic based on 5-tuple matching
  • Add pre-parse text transformations in AWS WAF to normalize raw query strings before parsing for SingleQueryArgument and AllQueryArguments
  • Add 10 new text transformations to AWS WAF including ModSecurity v3 parity options
  • Add Scenario Discover APIs to AWS IoT SiteWise
  • Add filtering, partitioning, and VPC support to AWS Glue REST API connector
  • Add ListApplicationShaderCaches API to retrieve shader cache metadata for applications in GameLift Streams
  • Add stream URLs to GameLift Streams for temporary unauthenticated access to stream sessions in browser
  • Add CreateStreamUrl, GetStreamUrl, ListStreamUrls, and RevokeStreamUrl operations to GameLift Streams
Changed 38

2.36.39

  • Update Step Functions API documentation around CloudTrail, Execution name reuse and sort order of ListExecutions API

2.36.37

  • Update taxsettings for France and Monaco Additional Info
  • Increase online evaluation configurations to support up to 25 evaluators in bedrock-agentcore-control
  • Increase CloudWatch Logs data sources for online evaluation to support up to 10 log groups in bedrock-agentcore-control

2.36.35

  • Updated descriptions for AWS Control Tower ListEnabledControls API parameters for clarity and accuracy

2.36.34

  • Updated AWS CLI v2 API reference for EC2 create-volume command to include AvailabilityZoneId in the output examples

2.36.33

  • Updated SDK and CLI documentation for AttachDataSource API in opensearch service

2.36.31

  • Speed up autocomplete index generation with a single SQLite transaction
  • Update documentation to clarify duplicate-billing prevention and BatchMeterUsage retry guidance

2.36.29

  • Updated CLI documentation for Backup Audit Manager List Job Summaries APIs
  • Updated DataProtectionConfig field key documentation in WAFv2
  • Increased spans count from 1k to 20k in bedrock-agentcore
  • Updated Dataset schema to THIRDPARTYEVALUATIONV1 in bedrock-agentcore-control
  • Generate account endpoint for Kinesis Data Streams requests when the account ID is available

2.36.28

  • EC2 marks UEFI instance metadata field as sensitive
  • Amplify increased the maximum allowed length for access tokens from 255 to 4,096 characters
  • Arc Region Switch adds support for RDS switchover read replica for Oracle databases in Region switch plans

2.36.26

  • EntityResolution DeleteSchemaMapping, DeleteMatchingWorkflow, DeleteIdMappingWorkflow, and DeleteIdNamespace operations now return 404 ResourceNotFoundException when the target resource does not exist instead of 200 Success
  • AWS Elemental MediaLive now supports SCTE-35 marker passthrough without IDR frame insertion for CMAF Ingest, MediaPackage V2, and transport stream outputs

2.36.25

  • Increase the replication rule limit from 10 to 25 for the ECR PutReplicationConfiguration API

2.36.23

  • SSM SessionManager now displays a warning message for outdated SessionManagerPlugin version

2.36.22

  • Improved validation of Kinesis stream ARN format in DSQL to ensure only valid ARN characters are accepted
  • Updated documentation for materialized views APIs in Glue
  • AWS MediaConnect now supports tuning internal recovery latency between Router Inputs and Outputs to prioritize stream quality versus end-to-end latency
  • Update awscrt to version 0.36.2

2.36.21

  • Amazon A2I in textract entered maintenance mode and now rejects StartHumanLoop requests from accounts that it does not recognize as existing customers
  • Clarify valid input values for the HandshakePartyType parameter in InviteAccountToOrganization in organizations, with API ORGANIZATION valid only in responses and ACCOUNT and EMAIL as valid input values
  • Add end-of-support notice to Amazon Cloud Directory public CLI reference documentation

2.36.19

  • Increased the maximum allowed length of the oauthToken parameter in the Amplify CreateApp and UpdateApp APIs

2.36.18

  • Updated CodeArtifact npm login to write configuration directly to .npmrc

2.36.16

  • Update endpoint generation logic for IAM
  • UpdateCluster in DSQL now checks the RemovePeerCluster permission on the specific cluster being removed instead of a wildcard, and documentation now clarifies how to set kmsEncryptionKey so the cluster uses the AWS-owned key
  • Improve accuracy of CloudTrail event documentation for AWS Organizations membership operations
  • Engagement invitations in Partner Central Selling now include enrichment data such as propensity scores and lead readiness directly in the response
  • Amazon Connect Customer now supports up to 50 attachments per email, increased from 10, with individual maximum attachment size limit of 20 MB and total email size limit of 25 MB

2.36.15

  • Updated Kantar server URL validation in mediaconvert to accept Fifty5Blue domain
  • Updated descriptions for number of PreParseTextTransformations allowed per rule statement in wafv2

2.36.12

  • Improve IAM Policy Simulator accuracy to evaluate SCP conditions and resource scoping, return explicitDeny for explicit SCP denials, and report accurate cross-account decisions
Fixed 5

2.36.34

  • Fixed an issue where reused HTTP connections could return a cached response status, dropping response headers

2.36.30

  • Fix source builds failing when the interpreter's bundled pip differs from the pip in the build environment
  • Correct the validation pattern on the ServiceName response field in dsql GetVpcEndpointServiceName API

2.36.23

  • Fixed StartWebRTCContact in connect to correctly return AccessDeniedException instead of an internal server error

2.36.21

  • Reset PSModulePath before launching new PowerShell console to avoid inheriting an incompatible PSModulePath
Removed 2

2.36.13

  • Removed Smithy RPC v2 CBOR support from bcm-recommended-actions service
  • Removed Smithy RPC v2 CBOR support from bcm-pricing-calculator service
Deprecated 1

2.36.39

  • Deprecate EncryptionConfig resources field in EKS as Amazon EKS encrypts all Kubernetes API data with envelope encryption by default for clusters running Kubernetes version 1.28 or higher

Original release notes, newest first

The list above is our reading of these notes; the originals from Amazon Web Services are here, one fold per release.

2.36.40
  • api-change:bedrock: New AWS REVIEW mode as supported data retention mode for Bedrock models
  • api-change:ec2: Adds support for ValidateSecurityGroupQuotasForInterface, an API that specifically authorized AWS services use to validate security group rule quotas before creating an elastic network interface.
  • api-change:service-quotas: Service Quotas adds the AdjustableAtLevel property to QuotaContext, indicating whether a quota is adjustable at the account or resource level.
  • api-change:mediatailor: Elemental MediaTailor now supports two new Monetization Functions lifecycle hooks, Post Ads Response and Pre Manifest Insertion, and a VAST Request function type that calls a VAST or VMAP ad server. This release also adds Yield Optimization with demand from Amazon Publisher Services.

View originalPermalink

2.36.39
  • api-change:eks: Deprecate EncryptionConfig resources field. Amazon EKS encrypts all Kubernetes API data with envelope encryption by default for clusters running Kubernetes version 1.28 or higher, so this field no longer affects which resources are encrypted.
  • api-change:socialmessaging: Adding support for WhatsApp Flows with endpoints.
  • api-change:connect: This release enables TagOnCreate for Rule resource on CreateRule API. It also introduces a new field called PreEvaluationFilters to Rule resource, thereby impacting all Create, Update, Describe and Search APIs for Rules
  • api-change:stepfunctions: Updates Step Functions API documentation around CloudTrail, Execution name reuse and sort order of ListExecutions API
  • api-change:bedrock-agentcore-control: AgentCore Identity adds Consent Portal APIs to manage portals that let end users grant OAuth authorization for agents to access resources. AgentCore Evaluation adds trace source selection by log group prefix, custom or source log group result destinations, and metrics namespace customization.
  • api-change:transfer: AWS Transfer Family SFTP Connectors now support specifying an ordered list of AWS Secrets Manager version stages for secret retrieval. This enables seamless credential rotation workflows where external partners may take time to update their systems with new credentials.
  • api-change:guardduty: Adding support for Sequence Activities in GuardDuty Findings
  • api-change:drs: AWS Elastic Disaster Recovery now includes source server architecture in SourceProperties to identify x86 and ARM64 systems.
  • api-change:evs: Amazon EVS now allows users to set, update, and retrieve values for parameters that apply across all EVS Environments in their account at a regional level, such as the VCF License portability core count.
  • api-change:transcribe: Amazon Transcribe now supports specifying up to 29 PII entity types in the ContentRedaction configuration of a StartTranscriptionJob request, allowing all supported entity types to be redacted in a single batch transcription job.
  • api-change:ecs: Adds a critical parameter to the Amazon ECS managed daemon APIs that controls whether a daemon task failure drains the container instance. Non-critical daemon failures no longer drain the instance or block instance registration.
  • api-change:bedrock-agentcore: Adds log group name prefix trace source selection, custom or source log group result destinations, and metrics namespace customization
  • api-change:elbv2: This release adds support for sending TCP resets for Gateway Load Balancer when a flow's idle timeout expires, or when a target becomes unhealthy or is deregistered. This adds updates the CLI documentation.

View originalPermalink

2.36.38
  • api-change:sagemaker-featurestore-runtime: Amazon SageMaker Feature Store now supports the UpdateRecord API, enabling partial updates to individual feature values in an existing Online Store record without rewriting the entire record. This reduces write payloads and latency for high-frequency feature-level writes .
  • api-change:mgn: AWS Transform for migrations adds a second network migration option - apply your source security posture to existing VPCs. Upload a source network file with firewall rules, tag the in-scope VPCs, and AWS Transform matches source subnets to them by CIDR and generates the security groups.
  • api-change:appintegrations: This release adds a force parameter to DeleteApplication and a ConflictException to UpdateApplication, letting customers delete applications with existing associations in one call and get a clear error when an update conflicts with the application's current state.
  • api-change:ec2: This release adds support to retain interruptible Capacity Reservations in an active state when all capacity is reclaimed.
  • api-change:medialive: AWS Elemental MediaLive now supports AB forensic video watermarking
  • api-change:mwaa: Enabled customers to clear optional S3 paths (plugins, requirements, and startup script) for their Amazon MWAA environments by accepting empty strings for the associated fields in UpdateEnvironment requests.
  • api-change:bedrock-agentcore: Batch evaluation now supports up to 10 CloudWatch log groups per CloudWatchLogsSource
  • api-change:odb: Adds the ListFlexComponents API for listing the flex components available for a given DB system shape.
  • api-change:sagemaker: Amazon SageMaker Feature Store now supports the Standard V2 online store type, which enables feature-level writes to feature groups. You can select Standard V2 when creating a feature group, and update the storage type of an existing feature group via UpdateFeatureGroup.

View originalPermalink

2.36.37
  • api-change:lightsail: This release adds support for the Amazon Lightsail GetProfile API, which returns the profile for the specified account.
  • api-change:mediaconvert: Adds support for AAC passthrough. Adds ManifestCues option to support HLS manifest Cue marker passthrough. Adds playback device compatibility mode for DASH H.265 outputs. Adds TTML caption styling options. Adds interlace mode support for XAVC HD Intra CBG profile.
  • api-change:marketplace-discovery: GetOfferTerms now returns renewalTerm for offers with pre-authorized renewals, exposing maxRenewals, lockoutPeriod, adjustmentDeadline, priceIncrease (fixed percentage or percentage range), and termTemplates (renewal payment schedules). Enables buyers to view renewal pricing and terms.
  • api-change:taxsettings: France and Monaco Additional Info changes
  • api-change:lambda: AWS Lambda now provides configurable control over S3 direct access, allowing you to explicitly enable or disable how functions stream file reads directly from S3 buckets. This gives you flexibility to tune data access behavior based on your workload requirements, independent of memory size.
  • api-change:guardduty: Amazon GuardDuty now supports custom detection rules, including APIs to manage rule associations and organization-level configurations.
  • api-change:kinesis: Amazon Kinesis Data Streams now supports a dry run feature for data-plane APIs to validate the permissions and request parameters. If all checks complete successfully, the API returns a 'DryRunOperationException', confirming the request would have succeeded without the 'DryRun' parameter.
  • api-change:marketplace-agreement: This release adds renewal support for AWS Marketplace private offers. Agreements report whether they renew and, if not, why. Renewal terms add price increases, renewal limits, renewal decision deadlines, and payment schedule templates. SearchAgreements adds filters.
  • api-change:iotsitewise: AWS IoT SiteWise Scenario Discovery now supports mounting Amazon S3 data directly into pipeline task containers via S3 Access Points, and configuring additional ephemeral storage per task. Mount configurations can be overridden at execution time. See the API guide for details.
  • api-change:bedrock-agentcore-control: Online evaluation configurations now support up to 25 evaluators. CloudWatch Logs data sources for online evaluation now support up to 10 log groups.
  • api-change:sesv2: Added support for managing SMIME signing certificates for email identities, including associating, listing, and disassociating certificates. Added the UpdateConfigurationSet operation to configure message security options such as signing scheme.

View originalPermalink

2.36.36
  • api-change:agent-registry: Release HTTP and AGUI descriptors to the dataplane model

View originalPermalink

2.36.35
  • api-change:support: AWS Support now allows up to 10 attachments (150 MB each) per case correspondence, up from 3 at 5 MB. Customers can share large diagnostic logs, heap dumps, and packet captures directly in cases to reduce back-and-forth and speed up resolution. Available in US East, US West, and Europe (Ireland).
  • api-change:connect: Added support for global routing on Amazon Connect Global Resiliency instances. New APIs GetCrossRegionRouting and UpdateCrossRegionRouting allow you to view and control cross-region contact routing between linked instances, so both Regions are active at all times.
  • api-change:agent-registry: AWS Agent Registry becomes Generally Available
  • api-change:devops-agent: Adds support for Slack bidirectional communication configuration in AWS DevOps Agent agent spaces.
  • api-change:pinpoint-sms-voice-v2: AWS End User Messaging SMS now returns ConditionalBehavior on DescribeRegistrationFieldDefinitions, allowing you to programmatically discover which registration fields are required, optional, or disallowed based on the values of other fields in the same form.
  • api-change:kafkaconnect: Amazon MSK Connect now supports restarting newly created connectors via the asynchronous RestartConnector API. Restart all tasks or only failed tasks, while preserving configuration and committed offsets. This returns a connector operation ARN that you can track with DescribeConnectorOperation.
  • api-change:workspaces-instances: Amazon WorkSpaces Core managed instances now support nested virtualization. Customers can enable nested virtualization with supported instance types at launch via CpuOptions.NestedVirtualization in CreateWorkspaceInstance to run hypervisors and virtual machines inside their WorkSpaces Instance.
  • api-change:quicksight: This release adds support for managing apps in Amazon QuickSight with ListApps, SearchApps, DescribeApp, DescribeAppPermissions, UpdateAppPermissions, and DeleteApp
  • api-change:controltower: Updated the descriptions for the AWS Control Tower ListEnabledControls API parameters to make them more accurate and intuitive.
  • api-change:customer-profiles: This release introduces new APIs for segment membership events allowing segment definition membership events to be exported to a kinesis stream for downstream processing. Additionally, includes new calculated attribute statistic and 2 new segment dimension types.
  • api-change:agent-registry-control: AWS Agent Registry becomes Generally Available
  • api-change:kinesis: Adds support for data delivery to Amazon S3 Tables (Apache Iceberg) and general purpose Amazon S3 buckets with new CreateChannel, UpdateChannel, DeleteChannel, DescribeChannel, and ListChannels APIs for Amazon Kinesis Data Streams.
  • api-change:sagemaker: Amazon SageMaker Batch Transform now supports G6e instances, powered by NVIDIA L40S Tensor Core GPUs. G6e instances are the most cost-efficient GPU instances for deploying generative AI models and the highest-performance GPU instances for spatial computing workloads.

View originalPermalink

2.36.34
  • api-change:healthlake: New HealthLake API, RestoreFHIRDatastore, providing the capability to restore active datastores to a point in time within the last 30 days or recover a deleted datastore from the delete snapshot.
  • api-change:cognito-idp: Adds two new operations - GetClientToken which allows M2M auth through the SDK, and DescribeTermsByClient to find which Terms are associated with a user-pool client without knowing the Terms resource id.
  • api-change:partnercentral-selling: Releasing PARC, new APN Program that lets sellers add solftware revenue details to aws opportunity summary
  • api-change:bedrock-agent: Adds an optional syncSchedule field to CreateDataSource and UpdateDataSource for Managed Knowledge Bases data source connectors, so a data source can sync automatically on a daily, weekly, or monthly schedule.
  • api-change:ecs: Amazon Elastic Container Service - This release adds support for early success criteria on ECS rolling deployments, letting deployment complete once a configurable percentage of tasks are healthy, with configurable BLOCKING (required) or DEFERRED (asynchronous) cleanup of previous service revisions.
  • api-change:bedrock-agentcore: AgentCore Memory now supports direct ingestion into long-term memory via IngestData API
  • bugfix:HTTP: Fixed an issue where reused connections could return a cached response status, dropping response headers.
  • enhancement:ec2: Updated AWS CLI v2 API reference for EC2 create-volume command so that the examples include AvailabilityZoneId in the output.

View originalPermalink

2.36.33
  • api-change:logs: Added resultCount to QueryStatistics in GetQueryResults. This field returns the total number of output rows in the final result set, helping customers programmatically determine whether a query produced results after all operations including post-aggregation filters.
  • api-change:opensearch: Updating SDK and CLI documentation for AttachDataSource API.
  • api-change:codedeploy: Added a deploymentMode parameter to CreateDeployment. Set it to RESTART to restart an EC2 and on-premises fleet, using the last successful revision, honoring Deployment Configuration.
  • api-change:ec2: EC2 allows AMI owners to define compatible instance types on their AMIs, blocking RunInstances calls automatically for launches on non-permitted instance types.
  • api-change:datazone: Add cascadeDelete to DeleteDomain. When specified, DataZone recursively deletes all projects, environments, subscriptions, and their underlying AWS resources before removing the domain. Deletion progress is reported via deleteProgress and resource failures via failureReasons on GetDomain.
  • api-change:lambda-microvms: Added InsufficientCapacityException to RunMicrovm for capacity-related failures. Added lifecycle status field (AVAILABLE, DEPRECATED) to ListManagedMicrovmImageVersions. Added ConflictException to CreateMicrovmAuthToken and CreateMicrovmShellAuthToken for unregistered MicroVMs.
  • api-change:cognito-idp: Adds the AdminDeleteSoftwareToken API operation, enabling administrators to remove a user's registered TOTP (software token) MFA configuration from a user pool.
  • api-change:rds: Adding support for the full snapshot size, in bytes, of DB instance snapshots.

View originalPermalink

2.36.32
  • api-change:ec2: Adds deleting state to possible VPC States.
  • api-change:network-firewall: Adding new status enum for Firewalls.
  • api-change:devops-agent: AWS DevOps Agent now supports trigger filter groups for Release Readiness Review, letting you control when the capability auto-triggers based on webhook events and target branches.
  • api-change:license-manager-user-subscriptions: Released support for License Expiry field in ListProductSubscriptions API
  • api-change:sagemaker: Amazon SageMaker AI now supports ml.g7 instances for model optimization. You can now run model optimization jobs on ml.g7 instances, in supported AWS Regions.

View originalPermalink

2.36.31
  • api-change:devops-agent: Adds the UpdateApprovalAction API for resolving agent action approvals in AWS DevOps Agent agent spaces.
  • enhancement:Source: Speed up autocomplete index generation with a single SQLite transaction
  • api-change:eks: This feature would give customers the ability to tune TerminatedPodGcThreshold configuration in an Amazon EKS cluster.
  • api-change:ec2: Fleet feature to support Capacity Reservation Resource Groups with Amazon EC2 Capacity Blocks and interruptible Capacity Reservations
  • api-change:iot: As part of this release, we are extending capability of AWS IoT Rules Engine to support IoT InfluxDB Action. The IoT InfluxDB action lets customers send messages from IoT sensors and applications to InfluxDB.
  • api-change:meteringmarketplace: Updated documentation to clarify duplicate-billing prevention and BatchMeterUsage retry guidance
  • api-change:autoscaling: Adds support for Distribution Segments in mixed instances policies, providing ordered prioritization across On-Demand Capacity Reservations, Capacity Blocks, interruptible Capacity Reservations, and On-Demand capacity.
  • api-change:iam-toolbox: AWS Identity and Access Management (IAM) announces access troubleshooter, helping you debug access denied errors faster. Supported error messages now include an identifier you can use to retrieve detailed evaluations of the policies considered and their results. Preview in US East (N. Virginia).
  • api-change:evs: EVS now supports i7i.metal-48xl EC2 bare metal instance type, delivering high random IOPS performance with real-time latency, ideal for IO intensive and latency-sensitive workloads such as transactional databases, real-time analytics, and AI ML pre-processing.

View originalPermalink

2.36.30
  • api-change:connect: This release adds the ExtractedInformation segment to the ListRealtimeContactAnalysisSegmentsV2 API, enabling customers to retrieve information extracted from real-time contact analysis.
  • bugfix:Source: Fix source builds failing when the interpreter's bundled pip differs from the pip in the build environment
  • api-change:connect-contact-lens: This release adds the ExtractedInformation segment to the ListRealtimeContactAnalysisSegments API, enabling customers to retrieve information extracted from real-time contact analysis.
  • api-change:launch-wizard: Added accountConstraints and patternType to GetWorkload, ListWorkloads, GetWorkloadDeploymentPattern and ListWorkloadDeploymentPatterns for Launch Wizard
  • api-change:dsql: Corrected the validation pattern on the ServiceName response field in the GetVpcEndpointServiceName API to match the values Amazon Aurora DSQL actually returns.
  • api-change:securityagent: Adding private and self-signed certificate configuration support for penetration tests
  • api-change:kafka: Amazon MSK Replicator now supports OAuth authentication when connecting to external Apache Kafka clusters, enabling customers to replicate data from clusters that require OAuth for client authentication. This new capability is supported in all AWS Regions where MSK Express brokers are available.
  • api-change:timestream-influxdb: Service-managed parameter groups now only apply optimized defaults to DB Clusters automatically. New field effectiveDbParameterGroupIdentifier surfaces the parameter group actually applied.
  • api-change:bedrock: Adds support for specifying an inference profile ID or ARN, or an application inference profile ARN as the target model in CreateAdvancedPromptOptimizationJob.
  • api-change:elementalinference: Added support for the GetFixture API, enabling customers to retrieve the details of a fixture from its fixture ID, and added the access role ARN to the CreateFeed, GetFeed, and UpdateFeed responses.
  • api-change:batch: Doc Update, Add note that UpdatePolicy applies only to EC2 managed compute environments

View originalPermalink

2.36.29
  • api-change:backup: Updating CLI Docs for Backup Audit Manager List Job Summaries APIs.
  • api-change:wafv2: DataProtectionConfig field Key Documentation Update
  • api-change:devicefarm: Added support to CreateRemoveAccessSession for selecting a server version on the mobile WebDriver endpoint.
  • api-change:bedrock-agentcore: Increase spans count from 1k to 20k
  • api-change:bedrock-agentcore-control: Update Dataset schema to THIRDPARTYEVALUATIONV1
  • api-change:kinesis: Generate account endpoint for Kinesis Data Streams requests when the account ID is available
  • api-change:cloudwatch: Allows customers to specify an initial warm up period to wait for metrics to arrive when creating metric or log alarms

View originalPermalink

2.36.28
  • api-change:sesv2: Amazon SES now supports per-message tracking overrides. You can use the new ConfigurationOverrides parameter in SendEmail and SendBulkEmail to enable or disable open and click tracking for individual messages without changing your account-level or configuration set settings.
  • api-change:ec2: EC2 marks UEFI instance metadata field as sensitive.
  • api-change:lambda: Adds support for full JSON resource-based policies, enabling customers to create, retrieve, update, and delete function resource policies as complete JSON documents.
  • api-change:directconnect: This release adds custom route prefix pool allocations for Direct Connect. You can set IPv4 and IPv6 route prefix counts on private and transit virtual interfaces, and view pool size and unallocated counts on connections and LAGs, plus direct connect gateway attachment prefix allocation totals.
  • api-change:amplify: Increased the maximum allowed length from 255 to 4,096 characters to support longer access tokens.
  • api-change:pricing-plan-manager: Documentation update for the CreateSubscription API to correct the default value of the approval mode parameter. The default value for paid subscriptions is MANUAL, not IMMEDIATE as previously documented. The default value remains IMMEDIATE for FREE tier subscriptions.
  • api-change:arc-region-switch: Adds support for Rds switchover read replica for Oracle databases in Region switch plans
  • api-change:batch: AWS Batch now supports a new compute environment type that provides fully managed EC2 capacity with broader compute flexibility than Fargate, including GPU instances, bare metal, and specific instance type selection, without infrastructure management overhead.
  • api-change:sagemaker: Added IAM Identity Center (IdC) support to CreatePartnerApp and UpdatePartnerApp APIs. Added Customer Managed Key (CMK) support to CreateMlflowApp and DescribeMlflowApp.
  • api-change:cloudfront: Added SigV4a as a supported signing protocol for Origin Access Control (OAC), enabling CloudFront to sign requests to Amazon S3 Multi-Region Access Point (S3-MRAP) origins.

View originalPermalink

2.36.27
  • api-change:vpc-lattice: Amazon VPC Lattice now supports modification of private DNS options on Service Network VPC Associations
  • api-change:eks: Adds support for EKS cluster certificate authorities (CA)
  • api-change:redshift: Amazon Redshift enhanced System Table retention that allows customers to store their system table data directly in S3 Tables in customer's account instead of Redshift Managed Storage
  • api-change:account-access: Adds throttling exceptions to operation outputs that were previously inconsistent with other operations.
  • api-change:bedrock-agentcore: AgentCore Memory now supports Flexible Namespaces and Non-Conversational Payloads in CreateEvent API
  • api-change:medialive: AWS Elemental MediaLive now supports video cropping and output positioning. Use cropRectangle and outputPositionRectangle to position the encoded video within the output frame, with the surrounding area filled with black.
  • api-change:bedrock-agentcore-control: AgentCore Memory now supports Flexible Namespaces
  • api-change:batch: AWS Batch now supports managing CloudWatch Container Insights on compute environments via CreateComputeEnvironment and UpdateComputeEnvironment.
  • api-change:redshift-serverless: Amazon Redshift Enhanced System Table Retention that allows customers to store their system table data directly in S3 Tables in customer's account instead of Redshift Managed Storage

View originalPermalink

2.36.26
  • api-change:workspaces: Amazon WorkSpaces now supports nested virtualization, allowing you to run hypervisors and virtualization-based workloads within your WorkSpaces. You can enable or disable nested virtualization when creating a WorkSpace or by modifying an existing WorkSpace's properties.
  • api-change:batch: Update AWS Batch documentation with newer Fargate Supported configurations, notes, and fix broken Docker link re-directs.
  • api-change:outposts: AWS Outposts now supports VPC Endpoint configuration in CreatePrivateConnectivityConfig, enabling scoped private connectivity with provisioning role creation for secure outpost installations
  • api-change:entityresolution: Added ResourceNotFoundException to DeleteSchemaMapping, DeleteMatchingWorkflow, DeleteIdMappingWorkflow, and DeleteIdNamespace. These operations now return a 404 ResourceNotFoundException (previously a 200 Success) when the target resource does not exist.
  • api-change:marketplace-catalog: Introducing two new APIs, DescribeAssessment and ListAssessments. These APIs expose validation issues on Marketplace resources. The validation issues are exposed via a newly created resource called Assessment.
  • api-change:ec2: Doc release for CreateImage support for instances with local snapshots in Outpost
  • api-change:medialive: AWS Elemental MediaLive now supports SCTE-35 marker passthrough without IDR frame insertion for CMAF Ingest, MediaPackage V2, and transport stream outputs.

View originalPermalink

2.36.25
  • api-change:ecr: Documentation update for the ECR PutReplicationConfiguration API to increase the replication rule limit from 10 to 25
  • api-change:drs: AWS Elastic Disaster Recovery (AWS DRS) now offers Recovery Plans to recover multi-server applications in the right order in one action. Define the launch sequence once, with ordered steps and wait times, and DRS runs it automatically. Validate with non-disruptive drills and monitor in real time.
  • api-change:bedrock-agentcore-control: Adds implementations of third-party evaluators, both managed-as-a-service and as templates within custom evaluators.
  • api-change:bedrock-agent-runtime: AgenticRetrieveStream API now supports Amazon Bedrock AgentCore Memory. Use the new memoryConfiguration parameter to continue a session from short-term memory and retrieve from long-term memory.
  • api-change:connect: This release adds new APIs to create, describe, update, delete, and list extraction definitions, enabling customers to manage lifecycle of extraction definition resources. Additionally, this release adds new event sources for Rules related to ACW and new action to Extract Information.
  • api-change:geo-maps: Amazon Location Service now supports POI density and category filtering on dynamic maps. The GetStyleDescriptor API adds two optional parameters. PoiDensity (Off to VeryDense) controls POI volume, and PoiCategories filters by up to nine categories. Available on HERE and Grab map styles.
  • api-change:organizations: Add new Transfer Responsibility error codes and document related CloudTrail events for accepting and terminating a Transfer Responsibility.

View originalPermalink

2.36.24
  • api-change:glue: Added support for associating glossary terms with iterable form items, such as table columns.
  • api-change:sagemaker: Release support for g7.2xlarge, g7.4xlarge, g7.8xlarge, g7.12xlarge, g7.24xlarge, and g7.48xlarge instance types for SageMaker HyperPod
  • api-change:observabilityadmin: CloudWatch Logs centralization rules now support tag propagation. You can configure a TagPropagationConfiguration on your centralization rule to automatically sync resource tags from source to destination log groups, with configurable conflict resolution strategies.
  • api-change:bedrock-agentcore-control: Adds AgentCore Payments support for CMK, Marketplace Subscriptions and QuickCreate
  • api-change:redshift: Amazon Redshift now unlocks a locked admin user account and resets the failed-login counter when you update the admin password using the ModifyCluster API. This option is available only when account lockout security is enabled.
  • api-change:mwaa-serverless: Adds support for Consuming code for MWAA Serverless
  • api-change:redshift-serverless: Amazon Redshift now unlocks a locked admin user account and resets the failed-login counter when you update the admin password using the UpdateNamespace API. This option is available only when account lockout security is enabled.
  • api-change:bedrock-agentcore: Add support for the Machine Payments Protocol (MPP) and x402 upto scheme payments protocol in Amazon Bedrock AgentCore Payments. Customers can now pay for MPP-gated resources and also pay services which requires upto scheme in x402
  • api-change:bedrock-agent-runtime: Adds CheckIngestedDocumentAcl and GetIngestedDocumentAcl APIs to Amazon Bedrock Knowledge Bases. Customers can verify user access to documents based on ingested ACLs and retrieve full ACL details including allow and deny entries, enabling validation of ACL ingestion without test retrievals.

View originalPermalink

2.36.23
  • api-change:codecommit: Added the GetBlobDifferences API operation, which returns line-level diffs between two blob versions without requiring a local clone. Returns structured hunks with context, additions, and deletions. Supports pagination for large diffs.
  • api-change:autoscaling: Amazon EC2 Auto Scaling now supports terminating multiple instances in a single TerminateInstanceInAutoScalingGroup call via the new InstanceIds parameter, returning an Activities list. LaunchInstances now returns IdempotentCallInProgressFault for duplicate client tokens.
  • api-change:securityagent: Add support for setting a maximum task-hour budget cap on penetration tests and code reviews, and for revalidating previously reported findings via a new REVALIDATION job type.
  • api-change:acm: This change allows customers to update their existing email-validated certificates to use the DNS validation method.
  • api-change:cleanrooms: This release adds support for minimum aggregation thresholds and comparison controls to the Custom analysis rule type.
  • enhancement:SSM SessionManager: Add warning message for outdated SessionManagerPlugin version
  • api-change:connect: Adds the StartAssistantContact API to start chat contacts handled by an AI agent. Adds SegmentAttributes to StartWebRTCContact, and corrects its error response to now receive AccessDeniedException (previously returned as an internal server error due to a missing error declaration).

View originalPermalink

2.36.22
  • api-change:iam: Introduced role manager, an IAM capability that automatically sets up the IAM roles your AWS services need. When you set up a supported service in the console, role manager creates a role for you or reuses an existing one from an AWS-managed template.
  • api-change:wellarchitected: This change releases the Well-Architected Agent, a generative AI service that analyzes a customer's AWS environment and delivers personalized, prioritized recommendations across cost, security, performance, and resilience.
  • api-change:quicksight: Added APIs for DLP with Microsoft Purview (manage configs with label enforcement across Spaces, Chat, Knowledge Bases), Approval Workflows (CRUD for policies on asset sharing for Agents, Knowledge Bases, Spaces), and Limits Management (limit profiles for index storage and agent hours per user).
  • api-change:dsql: Improved validation of Kinesis stream ARN format to ensure only valid ARN characters are accepted
  • api-change:glue: Documentation updates for materialized views APIs.
  • api-change:mediaconnect: AWS MediaConnect now supports tuning the internal recovery latency between Router Inputs and Outputs to prioritize stream quality versus end-to-end latency.
  • api-change:odb: Adds support for Oracle Exadata on Exascale Infrastructure (ExaDB-XS) resources including storage vaults and VM clusters.
  • enhancement:awscrt: Update awscrt to version 0.36.2

View originalPermalink

2.36.21
  • api-change:datazone: GetSubscriptionGrant now returns materialized asset scope name for mapping Lake Formation data cell filters or Redshift views to subscription grants.
  • api-change:textract: Amazon A2I entered maintenance mode in July 2026 and now rejects StartHumanLoop requests from accounts that it does not recognize as existing customers. This update adds a corresponding note to the HumanLoopConfig parameter documentation so that the API Reference and SDK docs explain this behavior.
  • api-change:cleanrooms: Adds support for exporting redacted query execution logs in AWS Clean Rooms
  • api-change:organizations: Documentation update for AWS Organizations that clarifies valid input values for the HandshakePartyType parameter in the InviteAccountToOrganization. API ORGANIZATION is valid in responses only. valid input values are ACCOUNT and EMAIL
  • api-change:bedrock-agentcore: Adding online eval arn as input for recommendation API
  • api-change:connect: Seven new APIs for managing custom metrics, including create, describe, update, and delete. Using Custom Metrics, customers of Amazon Connect Customer can tailor analytics dashboards to their needs by applying custom thresholds, filters, and calculations to one or more out of the box measurements.
  • api-change:clouddirectory: Added an end-of-support notice to Amazon Cloud Directory public CLI reference documentation.
  • api-change:account-access: Adds SDK support for AWS IAM account access manager, a feature that enables mapping of IAM roles to the users and groups in AWS IAM Identity Center.
  • bugfix:update: Reset PSModulePath before launching new PowerShell console to avoid inheriting an incompatible PSModulePath
  • api-change:eks: This feature would give customers the ability to selectively tune certain configurations of Kubernetes control plane components in an Amazon EKS cluster.

View originalPermalink

2.36.20
  • api-change:sagemaker: Added PREFIX AWARE routing strategy and PrefixAwareRoutingConfig to CreateEndpointConfig. Configure PrefixLength and ConcurrencyThreshold to route requests that share the same prompt prefix to the same instance.
  • api-change:elementalinference: Added support for the SearchFixtures API and DataSourceConfiguration, enabling customers to map fixture event data onto clipping outputs for improved feature accuracy.
  • api-change:sagemaker-runtime: Added the PrefixAwareId header to InvokeEndpoint and InvokeEndpointWithResponseStream. This optional parameter serves as a routing hint for endpoints configured with prefix-aware routing, differentiating routing decisions for requests that share the same prompt prefix.
  • api-change:connect: Added Malay language option to use AI to automatically fill evaluation forms in Malay
  • api-change:medialive: Added VirtualSourceAddress to multicast output destinations for MediaLive Anywhere channels. Specifies the source IP address for outbound multicast packets when downstream networks enforce source-IP filtering.

View originalPermalink

2.36.19
  • api-change:sagemaker: Amazon SageMaker adds maintenance lifecycle statuses for Notebook Instances
  • api-change:connect: Supports updating the task template associated with in-progress task contacts using the new UpdateContactTaskTemplate API. This enables supervisors and developers to dynamically reassign task templates without creating a new task.
  • api-change:mediatailor: Added support for inserting ads via the VAST Ad Buffet standard. You can now configure MediaTailor to insert ads in sequence order using the AdSequencingMode setting in your playback configuration. Standalone ads are used as fallbacks when a sequenced ad is unavailable.
  • api-change:ec2: This release adds support for BGP route protection in Amazon VPC IP Address Manager (IPAM), including route discovery, RPKI route protection findings, and delegated RPKI (Internet Registry Associations, routing policy registrations, and ROA management) for BYOIP prefixes.
  • api-change:amplify: Increased the maximum allowed length of the oauthToken parameter in the CreateApp and UpdateApp APIs to support longer OAuth tokens issued by third-party Git providers.
  • api-change:healthlake: Adds provenanceEnabled to StartFHIRImportJob
  • api-change:securityagent: Added enableEmailMfa input field on Actor to enable email-based MFA during penetration tests. When enabled, a server-generated mfaForwardingAddress is returned. Set up a forwarding rule in your email provider to forward MFA emails to this address so the agent can complete email-based MFA login flows
  • api-change:mediapackagev2: StreamNameOutputMode - a new optional field on MediaPackageV2 OriginEndpoints that lets customers choose whether egress manifests use numeric stream indices (default) or encoder-assigned stream names from the input

View originalPermalink

2.36.18
  • api-change:socialmessaging: Add support for WhatsApp Conversions APIs.
  • api-change:bedrock-agentcore: Add support for capacity provider sessions in Amazon Bedrock AgentCore. Customers can now delete an active session running on a runtime instance launched through their capacity provider.
  • api-change:gamelift: Adds support for C8a, C8i, C9g, M8a, M8i, and M9g EC2 instance type families for managed EC2 and container fleets. Also adds explicit anchors on most string regexes.
  • api-change:devicefarm: Adds support for service generated insights across runs, jobs, and tests.
  • api-change:agent-registry-control: Agent Registry's Public Preview release
  • api-change:s3: AWS Backup now lets you create read-only access points for Amazon S3 recovery points, enabling you to access backup data using S3 APIs without initiating a restore.
  • api-change:kafka: MSK Clusters can now deliver authorizer logs alongside broker logs to the destinations defined by you
  • api-change:logs: This release adds index category support to the CloudWatch Logs DescribeFieldIndexes API. Customers can filter and identify DEFAULT, CUSTOM, AUTO, and INACTIVE field indexes.
  • api-change:securityhub: Security Hub is adding a new public API, ListFreeTrialStatusesV2 to describe the free trial statuses of the Security Hub service and its opt-in features.
  • enhancement:CodeArtifact: Updated npm login to write configuration directly to .npmrc, consistent with how other package manager integrations handle their config files.
  • api-change:mediatailor: AWS Elemental MediaTailor now supports concurrent function execution. The new Concurrent Executor function type runs multiple independent child functions in parallel within a single lifecycle hook, reducing pipeline latency to the duration of the slowest call instead of the sum of all calls.
  • api-change:ec2: Adds a new optional IncludeLocalZones parameter to the Spot Placement Score API that defaults to false. When set to true, the Spot Placement Score API will consider the relevant Local Zones with Spot capacity when computing the Spot Placement Score.
  • api-change:sagemaker: Releases new Model Customization SequenceLength parameter for Training and g7 instance types for Training and Processing.
  • api-change:autoscaling: EC2 Auto Scaling now supports being managed by other AWS services via the operator field.
  • api-change:marketplace-agreement: GetAgreementTerms now returns a new term variant in AcceptedTerm, netPaymentTerm, with a paymentDuePeriod field (example "P30D").
  • api-change:bedrock-agentcore-control: Add support for Gateway rate limits and Runtime instances in Amazon Bedrock AgentCore. Customers can now configure rate limits scoped to control request rates, token consumption rates, and active connection rates. Customers can now create capacity providers to launch runtimes on their EC2 instances.
  • api-change:agent-registry: Agent Registry's Public Preview release
  • api-change:marketplace-discovery: GetOfferTerms now returns netPaymentTerm in offerTerms, specifying payment due period after invoice date. The paymentDuePeriod field uses ISO 8601 duration format (e.g., "P30D" for net 30 days). This is a backward-compatible addition. See API documentation for full structure and examples.
  • api-change:backup: AWS Backup now lets you create read-only access points for Amazon S3 recovery points, enabling you to access backup data using S3 APIs without initiating a restore.

View originalPermalink

2.36.17
  • api-change:ecs: New enum values added for Agent Connectivity issues
  • api-change:glue: Added the PutDataCatalogExportConfiguration to export Glue Data Catalog metadata to systems tables stored in S3 Tables.
  • api-change:acm-pca: Private Certificate Authority service now supports RSASSA-PSS signing algorithm.
  • api-change:deadline: AWS Deadline Cloud now reports persistent volume costs alongside compute and license costs. Customers can view per-fleet storage costs in Usage Explorer by selecting the Usage Type grouping, helping them better understand the costs of their infrastructure.
  • api-change:bedrock-agentcore-control: Adding support for fine-grained access control for AgentCore Memory through managed AgentCore Gateway HTTP Connectors.

View originalPermalink

2.36.16
  • api-change:iam: Updating endpoint generation logic
  • api-change:inspector2: Adding Azure SBOM export capability.
  • api-change:dsql: UpdateCluster now checks the RemovePeerCluster permission on the specific cluster being removed, not a wildcard and docs now clarify how to set kmsEncryptionKey so the cluster uses the AWS-owned key.
  • api-change:sso-admin: AWS IAM Identity Center now lets you create organization-level instances without enabling multi-account permissions. You can enable multi-account permissions during instance creation or later via console or API, which then provisions the necessary service-linked roles.
  • api-change:workspaces: Added ClientExperiencePolicy to ClientProperties object for ModifyClientProperties and DescribeClientProperties APIs.
  • api-change:dynamodb: Vector indexes are a type of index in Amazon DynamoDB that enable similarity search on vector embedding stored in your table items. Vector indexes use approximate nearest neighbor search to find items whose vectors are most similar to a query vector that you provide.
  • api-change:ec2: Amazon EC2 now supports Application Status Checks, a new status check that monitors your application's health through configurable HTTP(S) paths and ports, so you can detect and automatically respond to application-level impairments.
  • api-change:organizations: Improved accuracy of CloudTrail event documentation for AWS Organizations membership operations.
  • api-change:partnercentral-selling: Partners can now create leads with only 5 required fields and free-text values for all other fields, reducing import friction. Engagement invitations now include enrichment data (propensity scores, lead readiness) directly in the response.
  • api-change:connect: Amazon Connect Customer now supports up to 50 attachments per email, increased from the previous limit of 10. The individual maximum attachment size limit of 20 MB and the total email size limit of 25 MB still hold true.

View originalPermalink

2.36.15
  • api-change:eks-auth: Added eksNodeName, instanceId, and zone optional parameters to the AssumeRoleForPodIdentity API.
  • api-change:network-firewall: This launch allows customers to use Network Firewall as an explicit Proxy and protect their workloads against threat of data exfiltration.
  • api-change:mediaconvert: Updates Kantar server URL validation to accept Fifty5Blue domain. Adds support for output to S3 Glacier Instant Retrieval.
  • api-change:directconnect: Added route visibility support for AWS Direct Connect, allowing customers to call ListVirtualInterfaceRoutes to view the BGP routes including AS path and BGP communities advertised over their virtual interfaces.
  • api-change:wafv2: Updated descriptions for number of PreParseTextTransformations allowed per rule statement
  • api-change:timestream-influxdb: This release adds support for customer-managed backup restore, and encryption of new DbInstances and DbClusters using customer-managed KMS keys.
  • api-change:observabilityadmin: Launch CMK support for Telemetry Enablement Organization and Account Rules.

View originalPermalink

2.36.14
  • api-change:rds: Adds StorageOperationStatus and StorageOperationPercentProgress to DescribeDBInstances, letting you monitor RDS storage initialization and optimization progress.
  • api-change:datazone: Adding support for enhanced Git experience in Sagemaker Unified Studio.
  • api-change:logs: Amazon CloudWatch Logs now lets you create and update lookup tables directly from CloudWatch Logs query results by passing a queryId, and configure a lookup table as a scheduled query destination so it refreshes automatically with the latest query results on each run.
  • api-change:cloudformation: Adding enum for sensitive property to DriftIgnoredReason
  • api-change:outposts: Adds the "EKS" value to the AWSServiceName enum and marks the Address field as sensitive.
  • api-change:marketplace-catalog: This release enhances the ListEntities API to support TargetAgreementId, TargetAgreementIntent, and CreatedBySource filters for the Offer entity type.
  • api-change:connectcampaignsv2: Launching feature for abandonment rate pacing control for outbound campaigns.
  • api-change:bedrock-runtime: Added support for mid-conversation tool changes in the Amazon Bedrock Converse and ConverseStream APIs
  • api-change:network-firewall: Doc Updates for Container Attributes
  • api-change:elementalinference: AWS Elemental Inference now supports graphic composition on cropped video outputs, enabling branded graphics and other visual elements to be overlaid as part of the inference workflow.
  • api-change:amp: Amazon Managed Service for Prometheus adds support for an Amazon OpenSearch Service exporter for managed collectors.
  • api-change:billing: Adds GetEnterpriseSupportChargeSummary, GetEnterpriseSupportContractDetails, and ListEnterpriseSupportLinkedAccountCharges. These APIs provide first-time programmatic access to billing data for Enterprise Support usage previously only available upon request through AWS Concierge or Support.
  • api-change:resiliencehubv2: Adding support for new testing capability in AWS Resilience Hub.
  • api-change:quicksight: Adding TopicV2 management APIs, adding possibility to use Topics in Analysis
  • enhancement:telemetry: Add the AWS_CLI_SESSION_ID_DISABLED environment variable to opt out of session id collection.

View originalPermalink

2.36.13
  • api-change:bcm-recommended-actions: Removing Smithy RPC v2 CBOR support that was added in previous SDK release.
  • api-change:bcm-pricing-calculator: Removing Smithy RPC v2 CBOR support that was added in previous SDK release.

View originalPermalink

2.36.12
  • api-change:securityagent: Adds support for providing a branch override when configured integrated repositories
  • api-change:iam: Improved IAM Policy Simulator accuracy. Simulator now evaluates SCP conditions and resource scoping, returns explicitDeny for explicit SCP denials, and reports accurate cross-account decisions.
  • api-change:kafka: Amazon MSK Express brokers now support streaming tables for Apache Iceberg, continuously materializing Apache Kafka topics as Iceberg tables in Amazon S3 Tables. Express brokers also now support data delivery to Amazon S3 general purpose buckets.
  • api-change:sagemaker: Adds support for g7 family instance types for SageMaker Studio JupyterLab and CodeEditor apps for IAD (us-east-1), PDX (us-west-2), CMH (us-east-2).
  • api-change:network-firewall: Adds UPDATING field to Container Association Status
  • api-change:lambda: Add Python3.15 (python3.15) and NodeJs 26 (nodejs26.x) support to AWS Lambda
  • api-change:bedrock-agentcore-control: Adds support for configuring models through the OpenResponses API for custom evaluators. CreateEvaluator and UpdateEvaluator now accept an OpenResponses model configuration for LLM-as-a-Judge evaluations.
  • api-change:pricing-plan-manager: Adds support for Public PricingPlanManager SDK

View originalPermalink

2.36.11
  • api-change:ec2: This release adds support for policy-based routing on AWS Transit Gateway, enabling you to route traffic based on 5-tuple matching (source IP, destination IP, source port, destination port, and protocol) using new policy table entry APIs that direct matching traffic to a target route table.
  • api-change:wafv2: AWS WAF now supports pre-parse text transformations, letting you normalize raw query strings before parsing, available on rule statements that use SingleQueryArgument or AllQueryArguments as the FieldToMatch. AWS WAF also added 10 new text transformations, including ModSecurity v3 parity options.
  • api-change:iotsitewise: We have released a new set of APIs in support of a major new feature within AWS IoT SiteWise called Scenario Discover. Please see user guide about the feature and the API guide in public documentation for new APIs.
  • api-change:dms: Updated documentation for various DMS Schema Conversion operations
  • api-change:glue: Adding filtering, partitioning, and VPC support to AWS Glue REST API connector
  • api-change:gameliftstreams: Adds ListApplicationShaderCaches API to retrieve shader cache metadata for applications and adds stream URLs, which give end users temporary, unauthenticated access to a stream session in their browser. Includes CreateStreamUrl, GetStreamUrl, ListStreamUrls, and RevokeStreamUrl operations.

View originalPermalink