AWS cli medium security documentation change
Summary
Updated AWS CLI version from 2.34.34 to 2.34.37 and changed default AMI from Amazon Linux 2 to Amazon Linux 2023 for ECS compute environments. Updated end-of-support timelines for Amazon Linux 2 AMIs, with EKS AL2 support ending on November 26, 2025 and ECS AL2 support ending June 30, 2026.
Security assessment
The change explicitly documents that Amazon Linux 2 AMIs will no longer receive security patches after their end-of-support dates (November 26, 2025 for EKS and June 30, 2026 for ECS). This directly addresses security implications of running outdated AMIs without security updates. The documentation warns users about the security risks of continuing to use unsupported AMIs and encourages migration to Amazon Linux 2023 to maintain security.
Diff
diff --git a/cli/latest/reference/batch/create-compute-environment.md b/cli/latest/reference/batch/create-compute-environment.md index 38f737147..bc5caf2c6 100644 --- a//cli/latest/reference/batch/create-compute-environment.md +++ b//cli/latest/reference/batch/create-compute-environment.md @@ -15 +15 @@ - * [AWS CLI 2.34.34 Command Reference](../../index.html) » + * [AWS CLI 2.34.37 Command Reference](../../index.html) » @@ -280 +280 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch- ->> The AMI that you choose for a compute environment must match the architecture of the instance types that you intend to use for that compute environment. For example, if your compute environment uses A1 instance types, the compute resource AMI that you choose must support ARM instances. Amazon ECS vends both x86 and ARM versions of the Amazon ECS-optimized Amazon Linux 2 AMI. For more information, see [Amazon ECS-optimized Amazon Linux 2 AMI](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#ecs-optimized-ami-linux-variants.html) in the _Amazon Elastic Container Service Developer Guide_ . +>> The AMI that you choose for a compute environment must match the architecture of the instance types that you intend to use for that compute environment. For example, if your compute environment uses A1 instance types, the compute resource AMI that you choose must support ARM instances. Amazon ECS vends both x86 and ARM versions of the Amazon ECS-optimized Amazon Linux 2023 AMI. For more information, see [Amazon ECS-optimized Amazon Linux 2023 AMI](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#ecs-optimized-ami-linux-variants.html) in the _Amazon Elastic Container Service Developer Guide_ . @@ -479 +479 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch- ->> Provides information that’s used to select Amazon Machine Images (AMIs) for Amazon EC2 instances in the compute environment. If `Ec2Configuration` isn’t specified, the default is `ECS_AL2` for EC2 (ECS) compute environments and `EKS_AL2023` for EKS compute environments. +>> Provides information that’s used to select Amazon Machine Images (AMIs) for Amazon EC2 instances in the compute environment. If `Ec2Configuration` isn’t specified, the default is `ECS_AL2023` for EC2 (ECS) compute environments and `EKS_AL2023` for EKS compute environments. @@ -489 +489 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch- ->>> Provides information used to select Amazon Machine Images (AMIs) for instances in the compute environment. If `Ec2Configuration` isn’t specified, the default is `ECS_AL2` ([Amazon ECS-optimized Amazon Linux 2](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#al2ami) ) for EC2 (ECS) compute environments and `EKS_AL2023` ([Amazon EKS-optimized Amazon Linux 2023 AMI](https://docs.aws.amazon.com/eks/latest/userguide/eks-optimized-ami.html) ) for EKS compute environments. +>>> Provides information used to select Amazon Machine Images (AMIs) for instances in the compute environment. If `Ec2Configuration` isn’t specified, the default is `ECS_AL2023` ([Amazon ECS-optimized Amazon Linux 2023](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html) ) for EC2 (ECS) compute environments and `EKS_AL2023` ([Amazon EKS-optimized Amazon Linux 2023 AMI](https://docs.aws.amazon.com/eks/latest/userguide/eks-optimized-ami.html) ) for EKS compute environments. @@ -501 +501 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch- ->>>> If the `imageIdOverride` parameter isn’t specified, then a recent [Amazon ECS-optimized Amazon Linux 2 AMI](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#al2ami) (`ECS_AL2` ) is used. If a new image type is specified in an update, but neither an `imageId` nor a `imageIdOverride` parameter is specified, then the latest Amazon ECS optimized AMI for that image type that’s supported by Batch is used. +>>>> If the `imageIdOverride` parameter isn’t specified, then a recent [Amazon ECS-optimized Amazon Linux 2023 AMI](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html) (`ECS_AL2023` ) is used. If a new image type is specified in an update, but neither an `imageId` nor a `imageIdOverride` parameter is specified, then the latest Amazon ECS optimized AMI for that image type that’s supported by Batch is used. @@ -505 +505 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch- ->>>>> Amazon Web Services will end support for Amazon ECS optimized AL2-optimized and AL2-accelerated AMIs. Starting in January 2026, Batch will change the default AMI for new Amazon ECS compute environments from Amazon Linux 2 to Amazon Linux 2023. We recommend migrating Batch Amazon ECS compute environments to Amazon Linux 2023 to maintain optimal performance and security. For more information on upgrading from AL2 to AL2023, see [How to migrate from ECS AL2 to ECS AL2023](https://docs.aws.amazon.com/batch/latest/userguide/ecs-migration-2023.html) in the _Batch User Guide_ . +>>>>> Amazon Web Services is ending support for Amazon ECS Amazon Linux 2-optimized and accelerated AMIs on June 30, 2026. On January 12, 2026, Batch changed the default AMI for new Amazon ECS compute environments from Amazon Linux 2 to Amazon Linux 2023. Effective June 30, 2026, Batch will block creation of new Amazon ECS compute environments using Batch-provided Amazon Linux 2 AMIs. We strongly recommend migrating your existing Batch Amazon ECS compute environments to Amazon Linux 2023 prior to June 30, 2026. For more information on upgrading from AL2 to AL2023, see [How to migrate from ECS AL2 to ECS AL2023](https://docs.aws.amazon.com/batch/latest/userguide/ecs-migration-2023.html) in the _Batch User Guide_ . @@ -509 +509 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch- ->>>> [Amazon Linux 2](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#al2ami) : Default for all non-GPU instance families. +>>>> [Amazon Linux 2](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html) : Used for non-GPU instance families. @@ -513 +513 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch- ->>>> [Amazon Linux 2 (GPU)](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#gpuami) : Default for all GPU instance families (for example `P4` and `G4` ) and can be used for all non Amazon Web Services Graviton-based instance types. +>>>> [Amazon Linux 2 (GPU)](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#gpuami) : Used for GPU instance families (for example `P4` and `G4` ) and non Amazon Web Services Graviton-based instance types. @@ -517 +517 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch- ->>>> [Amazon Linux 2023](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html) : Batch supports Amazon Linux 2023. +>>>> [Amazon Linux 2023](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html) : Default for all non-GPU instance families. @@ -525 +525 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch- ->>>> [Amazon Linux 2023 (GPU)](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#gpuami) : For all GPU instance families and can be used for all non Amazon Web Services Graviton-based instance types. +>>>> [Amazon Linux 2023 (GPU)](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#gpuami) : Default for all GPU instance families and can be used for all non Amazon Web Services Graviton-based instance types. @@ -539 +539 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch- ->>>>> Amazon Web Services will end support for Amazon EKS AL2-optimized and AL2-accelerated AMIs, starting 11/26/25. You can continue using Batch-provided Amazon EKS optimized Amazon Linux 2 AMIs on your Amazon EKS compute environments beyond the 11/26/25 end-of-support date, these compute environments will no longer receive any new software updates, security patches, or bug fixes from Amazon Web Services. For more information on upgrading from AL2 to AL2023, see [How to upgrade from EKS AL2 to EKS AL2023](https://docs.aws.amazon.com/batch/latest/userguide/eks-migration-2023.html) in the _Batch User Guide_ . +>>>>> Amazon Web Services ended support for Amazon EKS AL2-optimized and AL2-accelerated AMIs on November 26, 2025. Batch Amazon EKS compute environments using Amazon Linux 2 will no longer receive software updates, security patches, or bug fixes from Amazon Web Services. We recommend migrating to Amazon Linux 2023. For more information on upgrading from AL2 to AL2023, see [How to upgrade from EKS AL2 to EKS AL2023](https://docs.aws.amazon.com/batch/latest/userguide/eks-migration-2023.html) in the _Batch User Guide_ . @@ -574 +574 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch- ->>>> The AMI that you choose for a compute environment must match the architecture of the instance types that you intend to use for that compute environment. For example, if your compute environment uses A1 instance types, the compute resource AMI that you choose must support ARM instances. Amazon ECS vends both x86 and ARM versions of the Amazon ECS-optimized Amazon Linux 2 AMI. For more information, see [Amazon ECS-optimized Amazon Linux 2 AMI](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#ecs-optimized-ami-linux-variants.html) in the _Amazon Elastic Container Service Developer Guide_ . +>>>> The AMI that you choose for a compute environment must match the architecture of the instance types that you intend to use for that compute environment. For example, if your compute environment uses A1 instance types, the compute resource AMI that you choose must support ARM instances. Amazon ECS vends both x86 and ARM versions of the Amazon ECS-optimized Amazon Linux 2023 AMI. For more information, see [Amazon ECS-optimized Amazon Linux 2023 AMI](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#ecs-optimized-ami-linux-variants.html) in the _Amazon Elastic Container Service Developer Guide_ . @@ -1028 +1028 @@ computeEnvironmentArn -> (string) - * [AWS CLI 2.34.34 Command Reference](../../index.html) » + * [AWS CLI 2.34.37 Command Reference](../../index.html) »