Skip to content
cdkd

Tier-2 Stateful Candidates

Auto-generated by scripts/audit-stateful-candidates.ts (issue #2553). Do not edit by hand; re-run the script to regenerate.

A candidate is a tier-2 CloudFormation resource type — no cdkd SDK provider, so a replacement routes through Cloud Control API — whose registry schema declares at least one createOnlyProperties entry (so a rename is a property-driven replacement a plain cdkd deploy reaches with no flag) AND on which at least one data-bearing signal fires. Candidacy is a proposal for review, not a verdict: each one must end up either in STATEFUL_TYPES or in the script's NOT_GUARDED map with a reason, and tests/unit/scripts/stateful-candidates.test.ts fails on any that is in neither.

  • Generated: 2026-09-04T22:38:45.494Z
  • Schema version: 1

Summary

Measure Count
Tier-2 types considered 1468
Registry schemas read 1468
...of which declare a createOnly property 1278
Schemas declaring no top-level properties 0
...and fire a data-bearing signal (candidates) 99
Candidates already guarded 72
Candidates not guarded 27
Schemas unreadable (excluded, NOT cleared) 0

Signals

Signal Candidates What firing claims
snapshot-or-backup 12 The type declares a snapshot / backup / restore-from property. AWS adds those to a type whose contents survive independently of the resource, which is a statement that the resource has contents.
retention-window 9 The type declares its own retention period. A retention window is a promise about how long WRITTEN DATA is kept, so the resource holds writes rather than pointing at them.
storage-capacity 15 The type declares provisioned storage. A resource you size in gibibytes or provisioned IOPS has a disk, and DELETE + CREATE hands back an empty one.
deletion-protection 10 The type has a deletion-protection switch. AWS ships one where an accidental delete is expensive to undo, which is the same judgement this guard makes.
encryption-at-rest 13 The type declares encryption AT REST specifically (not a generic KmsKeyId, which every type that encrypts anything in transit or in a log also carries). Data at rest is data the resource stores.
data-store-noun 65 The type name ends in a noun AWS uses for a thing that HOLDS things — the only mechanical signal left for a type whose contents are entirely out-of-band and therefore absent from its schema (a vault, a repository, a collection). Deliberately the noisiest signal: its false positives are dispositioned in NOT_GUARDED, not tuned out of the pattern.

Candidates

Type Guarded Signals createOnly properties
AWS::AIOps::InvestigationGroup yes retention-window Name, RetentionInDays
AWS::AmazonMQ::Broker yes storage-capacity AuthenticationStrategy, BrokerName, DeploymentMode, EncryptionOptions, EngineType, PubliclyAccessible, StorageType, SubnetIds
AWS::Amplify::Domain no data-store-noun AppId, DomainName
AWS::AppConfig::ConfigurationProfile yes deletion-protection ApplicationId, LocationUri, Type
AWS::AppConfig::Environment no deletion-protection ApplicationId
AWS::AppRunner::Service no encryption-at-rest EncryptionConfiguration, ServiceName, Tags
AWS::Backup::BackupVault yes data-store-noun BackupVaultName, EncryptionKeyArn
AWS::Backup::LogicallyAirGappedBackupVault yes data-store-noun BackupVaultName, EncryptionKeyArn, MaxRetentionDays, MinRetentionDays
AWS::Bedrock::DataAutomationLibrary yes encryption-at-rest EncryptionConfiguration, LibraryName
AWS::Bedrock::KnowledgeBase yes storage-capacity KnowledgeBaseConfiguration/KendraKnowledgeBaseConfiguration, KnowledgeBaseConfiguration/ManagedKnowledgeBaseConfiguration, KnowledgeBaseConfiguration/SqlKnowledgeBaseConfiguration/RedshiftConfiguration/QueryEngineConfiguration, KnowledgeBaseConfiguration/SqlKnowledgeBaseConfiguration/RedshiftConfiguration/StorageConfigurations, KnowledgeBaseConfiguration/SqlKnowledgeBaseConfiguration/Type, KnowledgeBaseConfiguration/Type, KnowledgeBaseConfiguration/VectorKnowledgeBaseConfiguration, StorageConfiguration
AWS::Cases::Domain yes data-store-noun Name
AWS::Cassandra::Table yes data-store-noun ClientSideTimestampsEnabled, ClusteringKeyColumns, KeyspaceName, PartitionKeyColumns, TableName
AWS::CleanRooms::IdMappingTable yes data-store-noun InputReferenceConfig, MembershipIdentifier, Name
AWS::CleanRooms::IntermediateTable yes data-store-noun MembershipIdentifier, Name, PopulationAnalysisConfiguration
AWS::CloudFront::KeyValueStore yes data-store-noun Name
AWS::CloudHSM::Cluster yes data-store-noun, snapshot-or-backup HsmType, Mode, NetworkType, SubnetIds
AWS::CodeArtifact::Domain yes data-store-noun DomainName, EncryptionKey
AWS::CodeArtifact::Repository yes data-store-noun DomainName, DomainOwner, RepositoryName
AWS::Cognito::UserPoolDomain no data-store-noun Domain, UserPoolId
AWS::Connect::DataTable yes data-store-noun InstanceArn, Status
AWS::Connect::InstanceStorageConfig no storage-capacity InstanceArn, ResourceType
AWS::CustomerProfiles::Domain yes data-store-noun DomainName
AWS::DataZone::Domain yes data-store-noun DomainVersion, KmsKeyIdentifier
AWS::DocDB::GlobalCluster no data-store-noun, deletion-protection, storage-capacity Engine, EngineVersion, GlobalClusterIdentifier, SourceDBClusterIdentifier, StorageEncrypted
AWS::DocDBElastic::Cluster yes data-store-noun, snapshot-or-backup AdminUserName, AuthType, ClusterName, KmsKeyId
AWS::DynamoDB::Backup yes snapshot-or-backup BackupName, TableName
AWS::EC2::LocalGatewayRouteTable no data-store-noun LocalGatewayId, Mode
AWS::EC2::TransitGatewayMulticastDomain no data-store-noun TransitGatewayId
AWS::EC2::TransitGatewayPolicyTable no data-store-noun TransitGatewayId
AWS::EC2::TransitGatewayRouteTable no data-store-noun TransitGatewayId
AWS::ECR::PublicRepository yes data-store-noun RepositoryName
AWS::ECR::RepositoryCreationTemplate no encryption-at-rest Prefix
AWS::EKS::Cluster yes data-store-noun, deletion-protection AccessConfig/BootstrapClusterCreatorAdminPermissions, BootstrapSelfManagedAddons, EncryptionConfig, KubernetesNetworkConfig/IpFamily, KubernetesNetworkConfig/ServiceIpv4Cidr, Name, OutpostConfig, RoleArn
AWS::ElastiCache::ReplicationGroup yes encryption-at-rest, snapshot-or-backup AtRestEncryptionEnabled, CacheSubnetGroupName, DataTieringEnabled, GlobalReplicationGroupId, KmsKeyId, NetworkType, Port, PreferredCacheClusterAZs, ReplicationGroupId, SnapshotArns, SnapshotName
AWS::ElastiCache::ServerlessCache yes snapshot-or-backup KmsKeyId, ServerlessCacheName, SnapshotArnsToRestore, SubnetIds
AWS::EMRContainers::VirtualCluster no data-store-noun ContainerProvider, Name, SecurityConfigurationId, SessionEnabled
AWS::Events::Archive yes data-store-noun, retention-window ArchiveName, SourceArn
AWS::FSx::Volume yes data-store-noun, snapshot-or-backup BackupId, OntapConfiguration/AggregateConfiguration, OntapConfiguration/AggregateConfiguration/Aggregates, OntapConfiguration/AggregateConfiguration/ConstituentsPerAggregate, OntapConfiguration/OntapVolumeType, OntapConfiguration/SnaplockConfiguration/SnaplockType, OntapConfiguration/StorageVirtualMachineId, OntapConfiguration/VolumeStyle, OpenZFSConfiguration/OriginSnapshot, OpenZFSConfiguration/OriginSnapshot/CopyStrategy, OpenZFSConfiguration/OriginSnapshot/SnapshotARN, OpenZFSConfiguration/ParentVolumeId, VolumeType
AWS::HealthImaging::Datastore yes data-store-noun DatastoreName, KmsKeyArn, Tags
AWS::HealthLake::FHIRDatastore yes data-store-noun DatastoreName, DatastoreTypeVersion, IdentityProviderConfiguration, PreloadDataConfig, SseConfiguration
AWS::IoTAnalytics::Channel yes retention-window ChannelName
AWS::IoTAnalytics::Dataset yes retention-window DatasetName
AWS::IoTAnalytics::Datastore yes data-store-noun, retention-window DatastoreName
AWS::IoTSiteWise::Workspace yes encryption-at-rest EncryptionConfiguration, KmsKeyId, WorkspaceName
AWS::Kendra::Index yes data-store-noun Edition, ServerSideEncryptionConfiguration
AWS::KinesisVideo::Stream yes retention-window Name
AWS::Lightsail::Bucket yes data-store-noun BucketName
AWS::Lightsail::Database yes data-store-noun AvailabilityZone, MasterDatabaseName, MasterUsername, RelationalDatabaseBlueprintId, RelationalDatabaseBundleId, RelationalDatabaseName
AWS::Lightsail::Domain no data-store-noun DomainName
AWS::Location::GeofenceCollection yes data-store-noun CollectionName, KmsKeyId
AWS::Location::PlaceIndex no data-store-noun DataSource, IndexName
AWS::MediaLive::Cluster no data-store-noun ClusterType, InstanceRoleArn
AWS::MemoryDB::Cluster yes data-store-noun, snapshot-or-backup, storage-capacity ClusterName, DataTiering, KmsKeyId, MultiRegionClusterName, NetworkType, Port, SnapshotArns, SnapshotName, SubnetGroupName, TLSEnabled
AWS::MemoryDB::MultiRegionCluster yes data-store-noun, storage-capacity EngineVersion, MultiRegionClusterNameSuffix, MultiRegionParameterGroupName, TLSEnabled
AWS::MSK::Channel yes encryption-at-rest ChannelName, ClusterArn, EncryptionConfiguration, IcebergDestinationConfiguration/AppendOnly, IcebergDestinationConfiguration/Catalog, IcebergDestinationConfiguration/Catalog/CatalogArn, IcebergDestinationConfiguration/Catalog/WarehouseLocation, IcebergDestinationConfiguration/CompressionType, IcebergDestinationConfiguration/DeadLetterQueueS3, IcebergDestinationConfiguration/DeadLetterQueueS3/BucketArn, IcebergDestinationConfiguration/DeadLetterQueueS3/ErrorOutputPrefix, IcebergDestinationConfiguration/DeadLetterQueueS3/ExpectedBucketOwner, IcebergDestinationConfiguration/DestinationTableList, IcebergDestinationConfiguration/DestinationTableList/*/DestinationDatabaseName, IcebergDestinationConfiguration/DestinationTableList/*/DestinationTableName, IcebergDestinationConfiguration/DestinationTableList/*/PartitionSpec, IcebergDestinationConfiguration/DestinationTableList/*/PartitionSpec/PartitionStrategy, IcebergDestinationConfiguration/DestinationTableList/*/PartitionSpec/SourceList, IcebergDestinationConfiguration/DestinationTableList/*/PartitionSpec/SourceList/*/SourceName, IcebergDestinationConfiguration/SchemaEvolution, IcebergDestinationConfiguration/SchemaEvolution/EnableSchemaEvolution, IcebergDestinationConfiguration/ServiceExecutionRoleArn, IcebergDestinationConfiguration/TableCreation, IcebergDestinationConfiguration/TableCreation/EnableTableCreation, LoggingInfo, S3DestinationConfiguration/DeadLetterQueueS3, S3DestinationConfiguration/DeadLetterQueueS3/BucketArn, S3DestinationConfiguration/DeadLetterQueueS3/ErrorOutputPrefix, S3DestinationConfiguration/DeadLetterQueueS3/ExpectedBucketOwner, S3DestinationConfiguration/ServiceExecutionRoleArn, S3DestinationConfiguration/Storage, S3DestinationConfiguration/Storage/BucketArn, S3DestinationConfiguration/Storage/CompressionType, S3DestinationConfiguration/Storage/ExpectedBucketOwner, S3DestinationConfiguration/Storage/OutputKeyTemplate, S3DestinationConfiguration/Storage/OutputPrefix, S3DestinationConfiguration/Storage/StorageClass, TopicConfigurationList
AWS::MSK::Cluster yes data-store-noun, encryption-at-rest BrokerNodeGroupInfo/BrokerAZDistribution, BrokerNodeGroupInfo/ClientSubnets, BrokerNodeGroupInfo/SecurityGroups, ClusterName, EncryptionInfo/EncryptionAtRest, EncryptionInfo/EncryptionInTransit/InCluster
AWS::MSK::ServerlessCluster yes data-store-noun ClientAuthentication, ClusterName, Tags, VpcConfigs
AWS::MWAAServerless::Workflow no encryption-at-rest EncryptionConfiguration, Name
AWS::Neptune::GlobalCluster no data-store-noun, deletion-protection, storage-capacity Engine, GlobalClusterIdentifier, SourceDBClusterIdentifier, StorageEncrypted
AWS::NeptuneGraph::Graph yes deletion-protection GraphName, KmsKeyIdentifier, ReplicaCount, VectorSearchConfiguration
AWS::NeptuneGraph::GraphSnapshot yes snapshot-or-backup GraphIdentifier, SnapshotName
AWS::ODB::CloudAutonomousVmCluster yes data-store-noun AutonomousDataStorageSizeInTBs, CloudExadataInfrastructureId, CpuCoreCountPerNode, DbServers, Description, DisplayName, IsMtlsEnabledVmCluster, LicenseModel, MaintenanceWindow, MemoryPerOracleComputeUnitInGBs, OdbNetworkId, ScanListenerPortNonTls, ScanListenerPortTls, TimeZone, TotalContainerDatabases
AWS::ODB::CloudVmCluster yes data-store-noun CloudExadataInfrastructureId, ClusterName, CpuCoreCount, DataCollectionOptions, DataStorageSizeInTBs, DbNodeStorageSizeInGBs, DbNodes/*/DbServerId, DbServers, DisplayName, GiVersion, Hostname, IsLocalBackupEnabled, IsSparseDiskgroupEnabled, LicenseModel, MemorySizeInGBs, OdbNetworkId, ScanListenerPortTcp, SshPublicKeys, SystemVersion, TimeZone
AWS::Omics::Workflow no storage-capacity Accelerators, ContainerRegistryMap, ContainerRegistryMapUri, DefinitionRepository, DefinitionUri, Engine, Main, ParameterTemplate, ParameterTemplatePath, StorageCapacity, WorkflowBucketOwnerId, readmePath, readmeUri
AWS::Omics::WorkflowVersion no storage-capacity Accelerators, Accelerators, ContainerRegistryMap, ContainerRegistryMapUri, DefinitionRepository, DefinitionUri, Engine, Main, ParameterTemplate, ParameterTemplatePath, VersionName, WorkflowBucketOwnerId, WorkflowId, readmePath, readmeUri
AWS::OpenSearchServerless::Collection yes data-store-noun, deletion-protection CollectionGroupName, EncryptionConfig, Name, StandbyReplicas, Tags, Type
AWS::OpenSearchServerless::CollectionIndex yes data-store-noun Id, IndexName
AWS::OpenSearchServerless::Index yes data-store-noun CollectionEndpoint, IndexName, Settings/Analysis
AWS::OpenSearchService::Domain yes data-store-noun, encryption-at-rest DomainName, EngineMode
AWS::OSIS::Pipeline yes encryption-at-rest PipelineName
AWS::PCS::Cluster no data-store-noun Name, Networking, Size
AWS::QBusiness::Application yes encryption-at-rest ClientIdsForOIDC, EncryptionConfiguration, IamIdentityProviderArn, IdentityType, QuickSightConfiguration
AWS::QBusiness::Index yes data-store-noun ApplicationId, Type
AWS::Rbin::Rule yes retention-window ResourceType
AWS::RDS::ClusterSnapshot yes storage-capacity DBClusterIdentifier, DBClusterSnapshotIdentifier
AWS::RDS::DBSnapshot yes storage-capacity DBInstanceIdentifier, DBSnapshotIdentifier
AWS::RDS::GlobalCluster no data-store-noun, deletion-protection, storage-capacity Engine, GlobalClusterIdentifier, SourceDBClusterIdentifier, StorageEncrypted
AWS::Redshift::Cluster yes data-store-noun, snapshot-or-backup, storage-capacity ClusterIdentifier, ClusterSubnetGroupName, DBName, MasterUsername, OwnerAccount, SnapshotClusterIdentifier, SnapshotIdentifier
AWS::RedshiftServerless::Namespace yes snapshot-or-backup NamespaceName
AWS::RedshiftServerless::Snapshot yes retention-window, snapshot-or-backup NamespaceName, SnapshotName, Tags, Tags/*/Key, Tags/*/Value
AWS::RedshiftServerless::Workgroup no snapshot-or-backup NamespaceName, WorkgroupName
AWS::Rekognition::Collection yes data-store-noun CollectionId
AWS::Route53::CidrCollection no data-store-noun Name
AWS::Route53RecoveryControl::Cluster no data-store-noun Name, Tags
AWS::S3Files::FileSystem no data-store-noun AcceptBucketWarning, Bucket, ClientToken, KmsKeyId, Prefix, RoleArn
AWS::S3Outposts::Bucket yes data-store-noun BucketName, OutpostId
AWS::S3Vectors::Index yes data-store-noun, encryption-at-rest DataType, Dimension, DistanceMetric, EncryptionConfiguration, IndexName, MetadataConfiguration, VectorBucketArn, VectorBucketName
AWS::SageMaker::Cluster yes data-store-noun ClusterName, Orchestrator/Eks, VpcConfig
AWS::SageMaker::Domain yes data-store-noun AuthMode, DomainName, DomainSettings/RStudioServerProDomainSettings/DefaultResourceSpec, KmsKeyId
AWS::SecurityAgent::TargetDomain no data-store-noun TargetDomainName
AWS::SES::MailManagerArchive yes data-store-noun KmsKeyArn
AWS::SMSVOICE::PhoneNumber yes deletion-protection IsoCountryCode, NumberCapabilities, NumberType
AWS::SMSVOICE::SenderId yes deletion-protection IsoCountryCode, SenderId
AWS::StepFunctions::Activity no encryption-at-rest EncryptionConfiguration, Name
AWS::Timestream::Database yes data-store-noun DatabaseName
AWS::Timestream::InfluxDBCluster yes data-store-noun, storage-capacity AllocatedStorage, Bucket, DbStorageType, DeploymentType, Name, NetworkType, Organization, Password, PubliclyAccessible, Username, VpcSecurityGroupIds, VpcSubnetIds
AWS::Timestream::InfluxDBInstance yes storage-capacity Bucket, Name, NetworkType, Organization, Password, PubliclyAccessible, Username, VpcSecurityGroupIds, VpcSubnetIds
AWS::Timestream::Table yes data-store-noun, retention-window DatabaseName, TableName
AWS::WorkspacesInstances::Volume yes data-store-noun AvailabilityZone, Encrypted, Iops, KmsKeyId, SizeInGB, SnapshotId, TagSpecifications, Throughput, VolumeType

Last updated: