Product updates

AWS CDK Landing Zone Changelog

A monthly summary of what shipped to customer landing zones: new guardrails, account baselines, and fixes across the foundation, constructs, and core packages.

413 commits shipped to the AWS CDK Landing Zone in the past year

3 package updates
Landing Zone Core

Manage organization cost recommendations from a FinOps account

A dedicated FinOps account brings cost optimization into the landing zone. Teams can review organization-wide recommendations with savings estimates that reflect discounts.

  • NewA central place for cost optimizationThe landing zone enrolls the organization in AWS Compute Optimizer and Cost Optimization Hub and provides a dedicated FinOps account for delegated administration.
  • ImprovedSavings estimates reflect your discountsCost Optimization Hub shows estimated savings after discounts and shares discount visibility with member accounts, giving teams a more useful basis for prioritizing recommendations.
  • ImprovedControl which security services runConfigure Security Hub CSPM, GuardDuty, Inspector, and Macie individually, so security coverage can follow your organization’s requirements as they change.
cdk-landing-zone-foundationv1.12.2

Restore Inspector administration across Regions more reliably

Existing Inspector administration is handled more reliably when restoring a Region, reducing deployment interruptions.

  • FixedExisting Inspector administration no longer blocks restorationRestoring Inspector administration in a Region now handles an existing registration for the intended account, reducing manual recovery during deployment.
cdk-landing-zone-constructsv1.13.0 – v1.15.0

Cost recommendations and security controls fit your organization

Enroll accounts in AWS cost optimization services and show savings after discounts. Security services gain explicit configuration choices and more reliable changes across Regions.

  • NewOrganization-wide cost optimization enrollmentEnroll your organization in AWS Compute Optimizer and Cost Optimization Hub, so teams can find resource recommendations and savings opportunities across accounts.
  • NewSavings estimates include discountsCost Optimization Hub preferences show savings after discounts and make discount information visible to member accounts, helping teams evaluate recommendations against their actual rates.
  • ImprovedChoose the security capabilities you needExplicit service switches and options let you configure Security Hub CSPM, GuardDuty, Inspector, and Macie, including protection plans, scan types, and compliance controls.
  • FixedSecurity changes finish more reliablyRemoving a Region or disabling security services now completes cleanup more reliably, reducing manual recovery when your security coverage changes.
2 package updates
Landing Zone Core

GitHub deploy access stays with approved repositories

Organization and landing zone deployment roles now trust immutable GitHub identity claims and the protected landingzone environment. Access stays pinned to the repositories you approved, while CDK synthesis runs without GitHub tokens.

  • ImprovedOne repository list for every deployment roleConfigure extra deployment repositories once and both the organization and landing zone roles use the same identities, so access does not drift between deployment phases.
  • ImprovedRepository trust survives recycled namesDeployment roles pin repository and owner IDs, so renaming a repository or someone claiming its old name cannot silently redirect AWS access.
  • ImprovedProtected environments remain part of the trust boundaryEvery deployment role expects the landingzone GitHub environment, keeping its protection rules in force across organization and landing zone deployments.
cdk-landing-zone-foundationv1.10.0

GitHub OIDC deployments locked to immutable identities

CI deployments now trust immutable GitHub repository and environment IDs instead of renameable names. Renaming a repository, or someone claiming an old repository name, can no longer inherit deploy access to your AWS accounts.

  • NewImmutable OIDC trust subjectsThe GitHub OIDC deploy role pins repository and environment IDs that survive renames, so the trust policy keeps pointing at the repository you actually approved.
  • NewOIDC identifiers resolve automaticallyYou configure the repository by name and the foundation resolves the underlying IDs at synthesis time, with lookups that stay safe to run in CI.
  • ImprovedDeployments default to a protected GitHub environmentThe deploy role now expects the landingzone GitHub environment by default, which makes environment protection rules part of the trust boundary instead of an optional extra.
  • FixedNo GitHub tokens during CDK synthesisSynthesis jobs no longer receive repository tokens, keeping credentials out of the part of the pipeline that only needs to produce templates.
3 package updates
Landing Zone Core

StackSets deploy from a dedicated landing zone account

Deployment plumbing moved out of the management account, baseline coverage expanded to every active Region, and retiring an AWS account is now an automated flow instead of a manual checklist.

  • NewDeployments run from their own accountStackSets now roll out from a dedicated landing zone account rather than the management account, shrinking what your CI pipeline can touch in the most privileged account of the organization.
  • NewClose accounts through a managed flowA dedicated organizational unit plus scheduled reconciliation retires accounts safely: move an account there and the landing zone handles the close process.
  • NewEvery active Region gets the baselineCDK bootstrap, service quota, and organization security StackSets now deploy to all Regions you mark active in the settings, not just the primary one.
  • ImprovedStackSet names that say what they doThe account baseline StackSet is now called AccountSecurityStackSet and the organization trail StackSet became OrganizationSecurityStackSet, matching what each one actually deploys.
cdk-landing-zone-foundationv1.4.0 – v1.9.2

Delegated administration grows into a full registry

Registering a security service as delegated administrator now takes one line, deployment assets moved out of the management account, and StackSet rollouts gained the tuning options you would expect from the console.

  • NewDelegated admins from just a service principalThe foundation ships a registry of per-service registration strategies, so delegating administration for a new AWS service no longer requires writing custom resource plumbing.
  • NewCentralized root accessRoot credentials for member accounts are centrally managed, removing per-account root access as an attack surface across the organization.
  • NewAsset buckets bootstrapped where they belongLanding zone asset buckets are provisioned in the delegated admin account with cleanup handled on deletion, keeping deployment artifacts out of the management account.
  • ImprovedStackSet rollouts you can tuneDeployment options now use console-aligned names for concurrency and failure tolerance, and quota guards warn before you hit CloudFormation output, parameter, or SCP limits.
  • FixedOrdering issues in organization teardownDelegated admin deregistration, trusted access removal, and policy type teardown now happen in a safe order, so removing a service no longer strands organization resources.
cdk-landing-zone-constructsv1.5.0 – v1.10.3

One organization trail, queryable with Athena

Per-account CloudTrail became a single delegated-admin organization trail with KMS encryption and ready-made Athena querying, alongside new IAM guardrails and a far more resilient enable and teardown story for the security services.

  • NewOrganization CloudTrail with built-in log analyticsOne KMS-encrypted organization trail replaces per-account trails, with a Glue database, Athena workgroup, and CIS CloudWatch alarms ready for the security team on day one.
  • NewIAM Access Analyzer and EBS snapshot protectionA new IamAccessAnalyzerConstruct finds unintended external access, and public EBS snapshot sharing is blocked organization-wide by default.
  • ImprovedTune Security Hub CSPM to your organizationPass your own list of disabled control IDs when a specific control does not fit how your organization works, instead of accepting the full default set.
  • FixedSecurity services that converge instead of failGuardDuty, Macie, and Inspector now adopt pre-existing states, wait for policy convergence, retry transient errors, and tolerate Region-deny guardrails, so both first deployments and teardowns finish cleanly.
3 package updates
Landing Zone Core

The multi-account foundation ships as a deployable CDK app

The core landing zone app went live: a CDK application that builds your AWS organization, provisions accounts with secure defaults, and rolls out security baselines as StackSets from your own GitHub repository.

  • NewOrganization and account provisioning in typed configurationOrganizational units, accounts, and their defaults live in one typed settings file; the app reconciles the organization on every deploy and new accounts are ready in minutes.
  • NewSecurity baselines delivered as StackSetsCloudTrail, GuardDuty, AWS Config, cost controls, and secure account defaults roll out to every account automatically, including accounts you create later.
  • NewGuardrail SCPs with practical exemptionsRegion and tag-protection guardrails ship enabled, tuned so legitimate global services keep working instead of tripping over the deny rules.
cdk-landing-zone-foundationv1.0.0 – v1.3.2

Organization management and credential-free CI deployments

The first releases of the foundation package cover what a landing zone needs before workloads arrive: AWS Organizations management, GitHub OIDC deployments without stored credentials, and the StackSet prerequisites everything else builds on.

  • NewDeploy from GitHub Actions without long-lived keysA GitHub OIDC role trusts your repository directly, and additional repositories can be granted deploy access when more teams need to ship infrastructure.
  • NewStackSet execution roles handled for youService-managed StackSet execution role patterns and automatic permission-model inference remove the manual IAM setup that usually precedes a StackSet rollout.
  • ImprovedPinned CDK feature flags and strong referencesThe foundation pins explicit CDK feature flags and strong cross-stack references, so CDK upgrades change behavior when you decide, not when a default flips.
  • FixedStackSet asset uploads that always resolveStackSet asset keys are aligned with their uploads, ending the intermittent missing-asset failures that could interrupt a first deployment.
cdk-landing-zone-constructsv1.0.0 – v1.4.2

The security baseline goes organization-wide by default

The constructs library launched with the full security baseline: Security Hub, GuardDuty, Macie, Inspector, and hardened account defaults, each enabled across the organization through delegated administration.

  • NewSecurity Hub with FSBP and CIS v5 standardsAWS Foundational Security Best Practices and the CIS AWS Foundations Benchmark v5.0.0 apply organization-wide, with account associations and finding aggregation managed for you.
  • NewGuardDuty protection plans enable themselvesGuardDuty auto-enables its organization protection plans for every member account, and Macie ships with automated sensitive data discovery included.
  • NewService quota increases on account creationNew accounts automatically request the quota increases the baseline needs, with idempotent handling so re-deploys never file duplicate requests.
  • FixedAccount contact details stay reconciledAlternate contacts and marketing mail preferences are reconciled on every deploy, so security and billing notifications reach the right people in every account.
How releases reach you

Every release lands in your landing zone as a version bump.

Improvements ship as package releases. Your team pulls them in by bumping two versions and redeploying, following the update guide, or a support plan does it for you. See what each package deploys in the documentation.