fix(secretsmanager): correct SAR rotation app versions for GovCloud - #38462
Draft
aemada-aws wants to merge 1 commit into
Draft
fix(secretsmanager): correct SAR rotation app versions for GovCloud#38462aemada-aws wants to merge 1 commit into
aemada-aws wants to merge 1 commit into
Conversation
The `aws-us-gov` semantic versions for the SecretsManager rotation
serverless applications point to versions that are not published in the
GovCloud (us-gov-west-1) SAR catalog. This causes the SAM transform to
fail at change-set creation with errors such as:
Application arn:aws-us-gov:serverlessrepo:us-gov-west-1:023102451235:applications/SecretsManagerRDSMySQLRotationSingleUser does not have a version 1.1.397
Update every rotation application's `aws-us-gov` version to the latest
version actually published in the GovCloud SAR catalog. The `aws` and
`aws-cn` versions are unchanged.
These versions were never deployable in GovCloud, so no feature flag is
required.
Contributor
|
👋 It looks like your PR description follows the template but is missing a valid issue number in the first section. PRs without a linked issue will receive lower priority for review and merging. Please update the description to include a reference like |
aws-cdk-automation
requested changes
Jul 31, 2026
aws-cdk-automation
left a comment
Collaborator
There was a problem hiding this comment.
The pull request linter fails with the following errors:
❌ Fixes must contain a change to an integration test file and the resulting snapshot.
If you believe this pull request should receive an exemption, please comment and provide a justification. A comment requesting an exemption should contain the text Exemption Request. Additionally, if clarification is needed, add Clarification Request to a comment.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Issue
The
aws-us-govsemantic versions pinned for the SecretsManager secret-rotation serverless applications reference versions that are not published in the GovCloud (us-gov-west-1) SAR catalog. Any stack that usesSecretRotationin GovCloud fails at change-set creation when the SAM transform runs, e.g.:This affects all engines (MySQL, PostgreSQL, MariaDB, Oracle, SQL Server, Redshift, MongoDB, Db2) in both single- and multi-user schemes.
Description of changes
Update the
aws-us-govversion for every rotation application insecret-rotation.tsto the latest version actually published in the GovCloud SAR catalog:The
awsandaws-cnversions are unchanged. Affected integration test snapshots (RDS cluster-rotation, RDS cluster-snapshot, DocDB cluster-rotation) are updated to reflect the new GovCloud version.Why no feature flag
Adding synth-time changes to versions normally warrants a feature flag when it alters previously-working behavior. Here the old
aws-us-govversions never deployed successfully in GovCloud (the referenced SAR versions do not exist), so this is a fail-forward bug fix and no feature flag is required.Checklist
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache-2.0 license