AWS Security ChangesHomeSearch

AWS batch: Document runtimePlatform and expand evaluateOnExit in Batch job definitions

Service: batch · 2026-09-27 · Documentation low

File: batch/latest/userguide/job_definition_parameters.md

Summary

Adds the runtimePlatform object (cpuArchitecture, operatingSystemFamily) for Fargate/ECS Managed Instances jobs, including a note that Windows containers cannot set privileged, readonlyRootFilesystem, and similar parameters, and updates evaluateOnExit from up to 5 to up to 6 retry/fail conditions.

Security assessment

The added documentation notes which privileged/container-hardening parameters (privileged, readonlyRootFilesystem, linuxParameters) are unavailable for Windows containers on Fargate/ECS Managed Instances. This constrains container configuration options but documents no vulnerability, fix, or security feature, and the evaluateOnExit count change (5 to 6) is purely functional.

Evidence

The following parameters can't be set for Windows containers: `linuxParameters`, `privileged`, `user`, `ulimits`, `readonlyRootFilesystem`, and `efsVolumeConfiguration`.

Diff

diff --git a/batch/latest/userguide/job_definition_parameters.md b/batch/latest/userguide/job_definition_parameters.md
index 5d81ad6f9..9594129b1 100644
--- a//batch/latest/userguide/job_definition_parameters.md
+++ b//batch/latest/userguide/job_definition_parameters.md
@@ -787,0 +788,45 @@ Required: Yes, when `resourceRequirements` is used.
+`runtimePlatform`
+    
+
+An object that represents the compute environment architecture for AWS Batch jobs. This parameter applies to jobs that run on AWS Fargate and Amazon ECS Managed Instances resources.
+    
+    
+    "runtimePlatform": {
+        "cpuArchitecture": "string",
+        "operatingSystemFamily": "string"
+    }
+
+Type: [RuntimePlatform](https://docs.aws.amazon.com/batch/latest/APIReference/API_RuntimePlatform.html) object
+
+Required: No
+
+`cpuArchitecture`
+    
+
+The vCPU architecture. The default value is `X86_64`.
+
+###### Note
+
+This parameter must be set to `X86_64` for Windows containers.
+
+Type: String
+
+Valid values: `X86_64` | `ARM64`
+
+Required: No
+
+`operatingSystemFamily`
+    
+
+The operating system for the compute environment.
+
+###### Note
+
+The following parameters can't be set for Windows containers: `linuxParameters`, `privileged`, `user`, `ulimits`, `readonlyRootFilesystem`, and `efsVolumeConfiguration`.
+
+Type: String
+
+Valid values: `LINUX` | `WINDOWS_SERVER_2019_CORE` | `WINDOWS_SERVER_2019_FULL` | `WINDOWS_SERVER_2022_CORE` | `WINDOWS_SERVER_2022_FULL`
+
+Required: No
+
@@ -1574 +1619 @@ Required: No
-Array of up to 5 objects that specify conditions under which the job is retried or failed. If this parameter is specified, then the `attempts` parameter must also be specified. If `evaluateOnExit` is specified but none of the entries match, then the job is retried.
+Array of up to 6 objects that specify conditions under which AWS Batch retries or fails the job. If this parameter is specified, then the `attempts` parameter must also be specified. If `evaluateOnExit` is specified but none of the entries match, then the job is retried.