AWS Security ChangesHomeSearch

AWS cli medium security documentation change

Service: cli · 2026-04-25 · Security-related medium

File: cli/latest/reference/batch/update-compute-environment.md

Summary

Updated AWS CLI version reference from 2.34.34 to 2.34.37 and changed default AMI for EC2 (ECS) compute environments from ECS_AL2 (Amazon Linux 2) to ECS_AL2023 (Amazon Linux 2023). Updated support timelines: AWS ended support for EKS AL2 AMIs on November 26, 2025, and will end support for ECS AL2 AMIs on June 30, 2026, with new ECS compute environments using AL2 being blocked after that date.

Security assessment

The change explicitly states that Amazon EKS AL2 AMIs no longer receive security patches after November 26, 2025, and Amazon ECS AL2 AMIs will stop receiving security updates after June 30, 2026. This directly addresses security implications of running on unsupported AMIs without security patches. The documentation update warns users about security risks and encourages migration to AL2023 for continued security updates.

Diff

diff --git a/cli/latest/reference/batch/update-compute-environment.md b/cli/latest/reference/batch/update-compute-environment.md
index 4c11bdb6d..181120e04 100644
--- a//cli/latest/reference/batch/update-compute-environment.md
+++ b//cli/latest/reference/batch/update-compute-environment.md
@@ -15 +15 @@
-  * [AWS CLI 2.34.34 Command Reference](../../index.html) »
+  * [AWS CLI 2.34.37 Command Reference](../../index.html) »
@@ -434 +434 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch-
->> Provides information used to select Amazon Machine Images (AMIs) for Amazon EC2 instances in the compute environment. If `Ec2Configuration` isn’t specified, the default is `ECS_AL2` for EC2 (ECS) compute environments and `EKS_AL2023` for EKS compute environments.
+>> Provides information used to select Amazon Machine Images (AMIs) for Amazon EC2 instances in the compute environment. If `Ec2Configuration` isn’t specified, the default is `ECS_AL2023` for EC2 (ECS) compute environments and `EKS_AL2023` for EKS compute environments.
@@ -446 +446 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch-
->>> Provides information used to select Amazon Machine Images (AMIs) for instances in the compute environment. If `Ec2Configuration` isn’t specified, the default is `ECS_AL2` ([Amazon ECS-optimized Amazon Linux 2](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#al2ami) ) for EC2 (ECS) compute environments and `EKS_AL2023` ([Amazon EKS-optimized Amazon Linux 2023 AMI](https://docs.aws.amazon.com/eks/latest/userguide/eks-optimized-ami.html) ) for EKS compute environments.
+>>> Provides information used to select Amazon Machine Images (AMIs) for instances in the compute environment. If `Ec2Configuration` isn’t specified, the default is `ECS_AL2023` ([Amazon ECS-optimized Amazon Linux 2023](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html) ) for EC2 (ECS) compute environments and `EKS_AL2023` ([Amazon EKS-optimized Amazon Linux 2023 AMI](https://docs.aws.amazon.com/eks/latest/userguide/eks-optimized-ami.html) ) for EKS compute environments.
@@ -458 +458 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch-
->>>> If the `imageIdOverride` parameter isn’t specified, then a recent [Amazon ECS-optimized Amazon Linux 2 AMI](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#al2ami) (`ECS_AL2` ) is used. If a new image type is specified in an update, but neither an `imageId` nor a `imageIdOverride` parameter is specified, then the latest Amazon ECS optimized AMI for that image type that’s supported by Batch is used.
+>>>> If the `imageIdOverride` parameter isn’t specified, then a recent [Amazon ECS-optimized Amazon Linux 2023 AMI](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html) (`ECS_AL2023` ) is used. If a new image type is specified in an update, but neither an `imageId` nor a `imageIdOverride` parameter is specified, then the latest Amazon ECS optimized AMI for that image type that’s supported by Batch is used.
@@ -462 +462 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch-
->>>>> Amazon Web Services will end support for Amazon ECS optimized AL2-optimized and AL2-accelerated AMIs. Starting in January 2026, Batch will change the default AMI for new Amazon ECS compute environments from Amazon Linux 2 to Amazon Linux 2023. We recommend migrating Batch Amazon ECS compute environments to Amazon Linux 2023 to maintain optimal performance and security. For more information on upgrading from AL2 to AL2023, see [How to migrate from ECS AL2 to ECS AL2023](https://docs.aws.amazon.com/batch/latest/userguide/ecs-migration-2023.html) in the _Batch User Guide_ .
+>>>>> Amazon Web Services is ending support for Amazon ECS Amazon Linux 2-optimized and accelerated AMIs on June 30, 2026. On January 12, 2026, Batch changed the default AMI for new Amazon ECS compute environments from Amazon Linux 2 to Amazon Linux 2023. Effective June 30, 2026, Batch will block creation of new Amazon ECS compute environments using Batch-provided Amazon Linux 2 AMIs. We strongly recommend migrating your existing Batch Amazon ECS compute environments to Amazon Linux 2023 prior to June 30, 2026. For more information on upgrading from AL2 to AL2023, see [How to migrate from ECS AL2 to ECS AL2023](https://docs.aws.amazon.com/batch/latest/userguide/ecs-migration-2023.html) in the _Batch User Guide_ .
@@ -466 +466 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch-
->>>> [Amazon Linux 2](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#al2ami) : Default for all non-GPU instance families.
+>>>> [Amazon Linux 2](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html) : Used for non-GPU instance families.
@@ -470 +470 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch-
->>>> [Amazon Linux 2 (GPU)](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#gpuami) : Default for all GPU instance families (for example `P4` and `G4` ) and can be used for all non Amazon Web Services Graviton-based instance types.
+>>>> [Amazon Linux 2 (GPU)](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#gpuami) : Used for GPU instance families (for example `P4` and `G4` ) and non Amazon Web Services Graviton-based instance types.
@@ -474 +474 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch-
->>>> [Amazon Linux 2023](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html) : Batch supports Amazon Linux 2023.
+>>>> [Amazon Linux 2023](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html) : Default for all non-GPU instance families.
@@ -482 +482 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch-
->>>> [Amazon Linux 2023 (GPU)](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#gpuami) : For all GPU instance families and can be used for all non Amazon Web Services Graviton-based instance types.
+>>>> [Amazon Linux 2023 (GPU)](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#gpuami) : Default for all GPU instance families and can be used for all non Amazon Web Services Graviton-based instance types.
@@ -496 +496 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch-
->>>>> Amazon Web Services will end support for Amazon EKS AL2-optimized and AL2-accelerated AMIs, starting 11/26/25. You can continue using Batch-provided Amazon EKS optimized Amazon Linux 2 AMIs on your Amazon EKS compute environments beyond the 11/26/25 end-of-support date, these compute environments will no longer receive any new software updates, security patches, or bug fixes from Amazon Web Services. For more information on upgrading from AL2 to AL2023, see [How to upgrade from EKS AL2 to EKS AL2023](https://docs.aws.amazon.com/batch/latest/userguide/eks-migration-2023.html) in the _Batch User Guide_ .
+>>>>> Amazon Web Services ended support for Amazon EKS AL2-optimized and AL2-accelerated AMIs on November 26, 2025. Batch Amazon EKS compute environments using Amazon Linux 2 will no longer receive software updates, security patches, or bug fixes from Amazon Web Services. We recommend migrating to Amazon Linux 2023. For more information on upgrading from AL2 to AL2023, see [How to upgrade from EKS AL2 to EKS AL2023](https://docs.aws.amazon.com/batch/latest/userguide/eks-migration-2023.html) in the _Batch User Guide_ .
@@ -531 +531 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch-
->>>> The AMI that you choose for a compute environment must match the architecture of the instance types that you intend to use for that compute environment. For example, if your compute environment uses A1 instance types, the compute resource AMI that you choose must support ARM instances. Amazon ECS vends both x86 and ARM versions of the Amazon ECS-optimized Amazon Linux 2 AMI. For more information, see [Amazon ECS-optimized Amazon Linux 2 AMI](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#ecs-optimized-ami-linux-variants.html) in the _Amazon Elastic Container Service Developer Guide_ .
+>>>> The AMI that you choose for a compute environment must match the architecture of the instance types that you intend to use for that compute environment. For example, if your compute environment uses A1 instance types, the compute resource AMI that you choose must support ARM instances. Amazon ECS vends both x86 and ARM versions of the Amazon ECS-optimized Amazon Linux 2023 AMI. For more information, see [Amazon ECS-optimized Amazon Linux 2023 AMI](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#ecs-optimized-ami-linux-variants.html) in the _Amazon Elastic Container Service Developer Guide_ .
@@ -608 +608 @@ See also: [AWS API Documentation](https://docs.aws.amazon.com/goto/WebAPI/batch-
->> The AMI that you choose for a compute environment must match the architecture of the instance types that you intend to use for that compute environment. For example, if your compute environment uses A1 instance types, the compute resource AMI that you choose must support ARM instances. Amazon ECS vends both x86 and ARM versions of the Amazon ECS-optimized Amazon Linux 2 AMI. For more information, see [Amazon ECS-optimized Amazon Linux 2 AMI](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#ecs-optimized-ami-linux-variants.html) in the _Amazon Elastic Container Service Developer Guide_ .
+>> The AMI that you choose for a compute environment must match the architecture of the instance types that you intend to use for that compute environment. For example, if your compute environment uses A1 instance types, the compute resource AMI that you choose must support ARM instances. Amazon ECS vends both x86 and ARM versions of the Amazon ECS-optimized Amazon Linux 2023 AMI. For more information, see [Amazon ECS-optimized Amazon Linux 2023 AMI](https://docs.aws.amazon.com/AmazonECS/latest/developerguide/ecs-optimized_AMI.html#ecs-optimized-ami-linux-variants.html) in the _Amazon Elastic Container Service Developer Guide_ .
@@ -895 +895 @@ computeEnvironmentArn -> (string)
-  * [AWS CLI 2.34.34 Command Reference](../../index.html) »
+  * [AWS CLI 2.34.37 Command Reference](../../index.html) »