# AWS CLI 2.36.28 - Product: AWS CLI (https://whatsnew.fyi/product/aws-cli) - Vendor: Amazon Web Services - Date: 2026-08-20 - Version: 2.36.28 - Original notes: https://github.com/aws/aws-cli/releases/tag/2.36.28 - Permalink: https://whatsnew.fyi/product/aws-cli/releases/2.36.28 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — Amazon SES now supports per-message tracking overrides using the new ConfigurationOverrides parameter in SendEmail and SendBulkEmail to enable or disable open and click tracking for individual messages - **changed** — EC2 marks UEFI instance metadata field as sensitive - **added** — Lambda adds support for full JSON resource-based policies, enabling customers to create, retrieve, update, and delete function resource policies as complete JSON documents - **added** — Direct Connect now supports custom route prefix pool allocations allowing you to set IPv4 and IPv6 route prefix counts on private and transit virtual interfaces - **changed** — Amplify increased the maximum allowed length for access tokens from 255 to 4,096 characters - **changed** — Arc Region Switch adds support for RDS switchover read replica for Oracle databases in Region switch plans - **added** — AWS Batch now supports a new compute environment type that provides fully managed EC2 capacity with broader compute flexibility than Fargate, including GPU instances, bare metal, and specific instance type selection - **added** — SageMaker added IAM Identity Center (IdC) support to CreatePartnerApp and UpdatePartnerApp APIs - **added** — SageMaker added Customer Managed Key (CMK) support to CreateMlflowApp and DescribeMlflowApp - **added** — CloudFront added SigV4a as a supported signing protocol for Origin Access Control (OAC), enabling CloudFront to sign requests to Amazon S3 Multi-Region Access Point origins * api-change:``sesv2``: Amazon SES now supports per-message tracking overrides. You can use the new ConfigurationOverrides parameter in SendEmail and SendBulkEmail to enable or disable open and click tracking for individual messages without changing your account-level or configuration set settings. * api-change:``ec2``: EC2 marks UEFI instance metadata field as sensitive. * api-change:``lambda``: Adds support for full JSON resource-based policies, enabling customers to create, retrieve, update, and delete function resource policies as complete JSON documents. * api-change:``directconnect``: This release adds custom route prefix pool allocations for Direct Connect. You can set IPv4 and IPv6 route prefix counts on private and transit virtual interfaces, and view pool size and unallocated counts on connections and LAGs, plus direct connect gateway attachment prefix allocation totals. * api-change:``amplify``: Increased the maximum allowed length from 255 to 4,096 characters to support longer access tokens. * api-change:``pricing-plan-manager``: Documentation update for the CreateSubscription API to correct the default value of the approval mode parameter. The default value for paid subscriptions is MANUAL, not IMMEDIATE as previously documented. The default value remains IMMEDIATE for FREE tier subscriptions. * api-change:``arc-region-switch``: Adds support for Rds switchover read replica for Oracle databases in Region switch plans * api-change:``batch``: AWS Batch now supports a new compute environment type that provides fully managed EC2 capacity with broader compute flexibility than Fargate, including GPU instances, bare metal, and specific instance type selection, without infrastructure management overhead. * api-change:``sagemaker``: Added IAM Identity Center (IdC) support to CreatePartnerApp and UpdatePartnerApp APIs. Added Customer Managed Key (CMK) support to CreateMlflowApp and DescribeMlflowApp. * api-change:``cloudfront``: Added SigV4a as a supported signing protocol for Origin Access Control (OAC), enabling CloudFront to sign requests to Amazon S3 Multi-Region Access Point (S3-MRAP) origins.