Skip to content

Commit bf77e51

Browse files
authored
feat(ec2): default BastionHostLinux to use Amazon Linux 2023 (under feature flag) (#31996)
### Issue #29493 Closes #29493 ### Reason for this change Right now, if a `machineImage` property isn't passed to `BastionHostLinux`, it defaults to an Amazon Linux 2 image. Since Amazon Linux 2 is hitting end-of-life in June 2025, it'd be better to default to Amazon Linux 2023. Since changing this default would be a breaking change, I placed it behind a feature flag, `@aws-cdk/aws-ec2:bastionHostUseAmazonLinux2023ByDefault`. ### Description of changes - Added the `@aws-cdk/aws-ec2:bastionHostUseAmazonLinux2023ByDefault` - When set, and a `machineImage` is not provided, we use the latest Amazon Linux 2023 image, instead of Amazon Linux 2. ### Description of how you validated changes - Unit Tests - Integration Test ### Checklist - [x] My code adheres to the [CONTRIBUTING GUIDE](https://github.com/aws/aws-cdk/blob/main/CONTRIBUTING.md) and [DESIGN GUIDELINES](https://github.com/aws/aws-cdk/blob/main/docs/DESIGN_GUIDELINES.md) ---- *By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license*
1 parent 9e6bb24 commit bf77e51

29 files changed

+2749
-162
lines changed

packages/@aws-cdk-testing/framework-integ/test/aws-ec2/test/integ.bastion-host-arm-support.js.snapshot/TestStack.assets.json

Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

packages/@aws-cdk-testing/framework-integ/test/aws-ec2/test/integ.bastion-host-arm-support.js.snapshot/TestStack.template.json

Lines changed: 56 additions & 56 deletions
Original file line numberDiff line numberDiff line change
@@ -18,9 +18,6 @@
1818
"VPCPublicSubnet1SubnetB4246D30": {
1919
"Type": "AWS::EC2::Subnet",
2020
"Properties": {
21-
"VpcId": {
22-
"Ref": "VPCB9E5F0B4"
23-
},
2421
"AvailabilityZone": {
2522
"Fn::Select": [
2623
0,
@@ -44,21 +41,24 @@
4441
"Key": "Name",
4542
"Value": "TestStack/VPC/PublicSubnet1"
4643
}
47-
]
44+
],
45+
"VpcId": {
46+
"Ref": "VPCB9E5F0B4"
47+
}
4848
}
4949
},
5050
"VPCPublicSubnet1RouteTableFEE4B781": {
5151
"Type": "AWS::EC2::RouteTable",
5252
"Properties": {
53-
"VpcId": {
54-
"Ref": "VPCB9E5F0B4"
55-
},
5653
"Tags": [
5754
{
5855
"Key": "Name",
5956
"Value": "TestStack/VPC/PublicSubnet1"
6057
}
61-
]
58+
],
59+
"VpcId": {
60+
"Ref": "VPCB9E5F0B4"
61+
}
6262
}
6363
},
6464
"VPCPublicSubnet1RouteTableAssociation0B0896DC": {
@@ -75,12 +75,12 @@
7575
"VPCPublicSubnet1DefaultRoute91CEF279": {
7676
"Type": "AWS::EC2::Route",
7777
"Properties": {
78-
"RouteTableId": {
79-
"Ref": "VPCPublicSubnet1RouteTableFEE4B781"
80-
},
8178
"DestinationCidrBlock": "0.0.0.0/0",
8279
"GatewayId": {
8380
"Ref": "VPCIGWB7E252D3"
81+
},
82+
"RouteTableId": {
83+
"Ref": "VPCPublicSubnet1RouteTableFEE4B781"
8484
}
8585
},
8686
"DependsOn": [
@@ -102,15 +102,15 @@
102102
"VPCPublicSubnet1NATGatewayE0556630": {
103103
"Type": "AWS::EC2::NatGateway",
104104
"Properties": {
105-
"SubnetId": {
106-
"Ref": "VPCPublicSubnet1SubnetB4246D30"
107-
},
108105
"AllocationId": {
109106
"Fn::GetAtt": [
110107
"VPCPublicSubnet1EIP6AD938E8",
111108
"AllocationId"
112109
]
113110
},
111+
"SubnetId": {
112+
"Ref": "VPCPublicSubnet1SubnetB4246D30"
113+
},
114114
"Tags": [
115115
{
116116
"Key": "Name",
@@ -126,9 +126,6 @@
126126
"VPCPublicSubnet2Subnet74179F39": {
127127
"Type": "AWS::EC2::Subnet",
128128
"Properties": {
129-
"VpcId": {
130-
"Ref": "VPCB9E5F0B4"
131-
},
132129
"AvailabilityZone": {
133130
"Fn::Select": [
134131
1,
@@ -152,21 +149,24 @@
152149
"Key": "Name",
153150
"Value": "TestStack/VPC/PublicSubnet2"
154151
}
155-
]
152+
],
153+
"VpcId": {
154+
"Ref": "VPCB9E5F0B4"
155+
}
156156
}
157157
},
158158
"VPCPublicSubnet2RouteTable6F1A15F1": {
159159
"Type": "AWS::EC2::RouteTable",
160160
"Properties": {
161-
"VpcId": {
162-
"Ref": "VPCB9E5F0B4"
163-
},
164161
"Tags": [
165162
{
166163
"Key": "Name",
167164
"Value": "TestStack/VPC/PublicSubnet2"
168165
}
169-
]
166+
],
167+
"VpcId": {
168+
"Ref": "VPCB9E5F0B4"
169+
}
170170
}
171171
},
172172
"VPCPublicSubnet2RouteTableAssociation5A808732": {
@@ -183,12 +183,12 @@
183183
"VPCPublicSubnet2DefaultRouteB7481BBA": {
184184
"Type": "AWS::EC2::Route",
185185
"Properties": {
186-
"RouteTableId": {
187-
"Ref": "VPCPublicSubnet2RouteTable6F1A15F1"
188-
},
189186
"DestinationCidrBlock": "0.0.0.0/0",
190187
"GatewayId": {
191188
"Ref": "VPCIGWB7E252D3"
189+
},
190+
"RouteTableId": {
191+
"Ref": "VPCPublicSubnet2RouteTable6F1A15F1"
192192
}
193193
},
194194
"DependsOn": [
@@ -210,15 +210,15 @@
210210
"VPCPublicSubnet2NATGateway3C070193": {
211211
"Type": "AWS::EC2::NatGateway",
212212
"Properties": {
213-
"SubnetId": {
214-
"Ref": "VPCPublicSubnet2Subnet74179F39"
215-
},
216213
"AllocationId": {
217214
"Fn::GetAtt": [
218215
"VPCPublicSubnet2EIP4947BC00",
219216
"AllocationId"
220217
]
221218
},
219+
"SubnetId": {
220+
"Ref": "VPCPublicSubnet2Subnet74179F39"
221+
},
222222
"Tags": [
223223
{
224224
"Key": "Name",
@@ -234,9 +234,6 @@
234234
"VPCPrivateSubnet1Subnet8BCA10E0": {
235235
"Type": "AWS::EC2::Subnet",
236236
"Properties": {
237-
"VpcId": {
238-
"Ref": "VPCB9E5F0B4"
239-
},
240237
"AvailabilityZone": {
241238
"Fn::Select": [
242239
0,
@@ -260,21 +257,24 @@
260257
"Key": "Name",
261258
"Value": "TestStack/VPC/PrivateSubnet1"
262259
}
263-
]
260+
],
261+
"VpcId": {
262+
"Ref": "VPCB9E5F0B4"
263+
}
264264
}
265265
},
266266
"VPCPrivateSubnet1RouteTableBE8A6027": {
267267
"Type": "AWS::EC2::RouteTable",
268268
"Properties": {
269-
"VpcId": {
270-
"Ref": "VPCB9E5F0B4"
271-
},
272269
"Tags": [
273270
{
274271
"Key": "Name",
275272
"Value": "TestStack/VPC/PrivateSubnet1"
276273
}
277-
]
274+
],
275+
"VpcId": {
276+
"Ref": "VPCB9E5F0B4"
277+
}
278278
}
279279
},
280280
"VPCPrivateSubnet1RouteTableAssociation347902D1": {
@@ -291,21 +291,18 @@
291291
"VPCPrivateSubnet1DefaultRouteAE1D6490": {
292292
"Type": "AWS::EC2::Route",
293293
"Properties": {
294-
"RouteTableId": {
295-
"Ref": "VPCPrivateSubnet1RouteTableBE8A6027"
296-
},
297294
"DestinationCidrBlock": "0.0.0.0/0",
298295
"NatGatewayId": {
299296
"Ref": "VPCPublicSubnet1NATGatewayE0556630"
297+
},
298+
"RouteTableId": {
299+
"Ref": "VPCPrivateSubnet1RouteTableBE8A6027"
300300
}
301301
}
302302
},
303303
"VPCPrivateSubnet2SubnetCFCDAA7A": {
304304
"Type": "AWS::EC2::Subnet",
305305
"Properties": {
306-
"VpcId": {
307-
"Ref": "VPCB9E5F0B4"
308-
},
309306
"AvailabilityZone": {
310307
"Fn::Select": [
311308
1,
@@ -329,21 +326,24 @@
329326
"Key": "Name",
330327
"Value": "TestStack/VPC/PrivateSubnet2"
331328
}
332-
]
329+
],
330+
"VpcId": {
331+
"Ref": "VPCB9E5F0B4"
332+
}
333333
}
334334
},
335335
"VPCPrivateSubnet2RouteTable0A19E10E": {
336336
"Type": "AWS::EC2::RouteTable",
337337
"Properties": {
338-
"VpcId": {
339-
"Ref": "VPCB9E5F0B4"
340-
},
341338
"Tags": [
342339
{
343340
"Key": "Name",
344341
"Value": "TestStack/VPC/PrivateSubnet2"
345342
}
346-
]
343+
],
344+
"VpcId": {
345+
"Ref": "VPCB9E5F0B4"
346+
}
347347
}
348348
},
349349
"VPCPrivateSubnet2RouteTableAssociation0C73D413": {
@@ -360,12 +360,12 @@
360360
"VPCPrivateSubnet2DefaultRouteF4F5CFD2": {
361361
"Type": "AWS::EC2::Route",
362362
"Properties": {
363-
"RouteTableId": {
364-
"Ref": "VPCPrivateSubnet2RouteTable0A19E10E"
365-
},
366363
"DestinationCidrBlock": "0.0.0.0/0",
367364
"NatGatewayId": {
368365
"Ref": "VPCPublicSubnet2NATGateway3C070193"
366+
},
367+
"RouteTableId": {
368+
"Ref": "VPCPrivateSubnet2RouteTable0A19E10E"
369369
}
370370
}
371371
},
@@ -383,11 +383,11 @@
383383
"VPCVPCGW99B986DC": {
384384
"Type": "AWS::EC2::VPCGatewayAttachment",
385385
"Properties": {
386-
"VpcId": {
387-
"Ref": "VPCB9E5F0B4"
388-
},
389386
"InternetGatewayId": {
390387
"Ref": "VPCIGWB7E252D3"
388+
},
389+
"VpcId": {
390+
"Ref": "VPCB9E5F0B4"
391391
}
392392
}
393393
},
@@ -486,7 +486,7 @@
486486
"Ref": "BastionHostInstanceProfile770FCA07"
487487
},
488488
"ImageId": {
489-
"Ref": "SsmParameterValueawsserviceamiamazonlinuxlatestamzn2amikernel510hvmarm64gp2C96584B6F00A464EAD1953AFF4B05118Parameter"
489+
"Ref": "SsmParameterValueawsserviceamiamazonlinuxlatestal2023amikernel61arm64C96584B6F00A464EAD1953AFF4B05118Parameter"
490490
},
491491
"InstanceType": "t4g.nano",
492492
"SecurityGroupIds": [
@@ -525,9 +525,9 @@
525525
}
526526
},
527527
"Parameters": {
528-
"SsmParameterValueawsserviceamiamazonlinuxlatestamzn2amikernel510hvmarm64gp2C96584B6F00A464EAD1953AFF4B05118Parameter": {
528+
"SsmParameterValueawsserviceamiamazonlinuxlatestal2023amikernel61arm64C96584B6F00A464EAD1953AFF4B05118Parameter": {
529529
"Type": "AWS::SSM::Parameter::Value<AWS::EC2::Image::Id>",
530-
"Default": "/aws/service/ami-amazon-linux-latest/amzn2-ami-kernel-5.10-hvm-arm64-gp2"
530+
"Default": "/aws/service/ami-amazon-linux-latest/al2023-ami-kernel-6.1-arm64"
531531
},
532532
"BootstrapVersion": {
533533
"Type": "AWS::SSM::Parameter::Value<String>",

packages/@aws-cdk-testing/framework-integ/test/aws-ec2/test/integ.bastion-host-arm-support.js.snapshot/cdk.out

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

packages/@aws-cdk-testing/framework-integ/test/aws-ec2/test/integ.bastion-host-arm-support.js.snapshot/integ.json

Lines changed: 1 addition & 1 deletion
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

packages/@aws-cdk-testing/framework-integ/test/aws-ec2/test/integ.bastion-host-arm-support.js.snapshot/manifest.json

Lines changed: 6 additions & 4 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

0 commit comments

Comments
 (0)