<!-- llms-explorer concept facts · https://llms-explorer.com/tree/aws-cdk-awscdk-resources-mongodbatlas/ · pack 2026-10-02 · ~9191 tokens -->

# AWS CDK awscdk-resources-mongodbatlas

> Depth-first rabbithole dossier for AWS CDK awscdk-resources-mongodbatlas; source-anchored research pack.

Parent: [MongoDB Atlas Infrastructure as Code](https://llms-explorer.com/tree/mongodb-atlas-infrastructure-as-code/) · 6 facets · 49 facts · page: https://llms-explorer.com/tree/aws-cdk-awscdk-resources-mongodbatlas/

## Structure and components

- 7. The source tree is `src/index.ts` plus three directories: `l1-resources`, `l2-resources` and `l3-resources`. — https://api.github.com/repos/mongodb/awscdk-resources-mongodbatlas/contents/src 8. L1 constructs are named `CfnXyz` and map one-to-one onto a CloudFormation resource type. They require the caller to set every property. — https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/src/README.md ; https://www.mongodb.com/blog/post/atlas-integrations-aws-cloud-formation-cdk-now-generally-available 9. An L1 class extends `cdk.CfnResource`. Its constructor calls `super` — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/mechanism.md#construct-layering`

## How it works

- 11. The CDK constructs only synthesize `MongoDB::Atlas::*` third-party types. Each type must be activated "in each AWS region and from each AWS account that you wish to deploy". `cdk bootstrap` alone does not activate them. Sources: https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md ; https://www.turbogeek.co.uk/how-to-deploy-mongodb-atlas-with-cdk/ 12. Activation is per type. Even the L3 `AtlasBasic` construct needs four types activated first: `MongoDB::Atlas::Cluster`, `::Project`, `::DatabaseUser`, and `::ProjectIpAccessList`. Source: https://ra — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/edge-cases.md#deploy-time-prerequisites-inherited-from-the-cloudformation-registry`
- 17. Credentials come from a Secrets Manager secret, not from CDK props: - Secret name: `cfn/atlas/profile/{ProfileName}`. - Secret value: `{"PublicKey": "...", "PrivateKey": "..}`. - Atlas for Government adds `"IsMongoDBGovCloud": true`. - The default profile name is `default`. - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 18. The handler code confirms the name format with `fmt.Sprintf("%s/%s", constants.ProfileNamePrefix, name)`, where `ProfileNamePrefix = "cfn/atlas/profile"`. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudfor — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/practice.md#credentials`
- **Independent-source gate: met.** Leaving out the inherited MongoDB GitHub repos and blog, four sources were written independently: AWS docs, turbogeek.co.uk, luanphan.net and blog.tysonworks.com. The package registries are listed separately and not counted, because MongoDB uploads their content. I did not edit the tree. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/rabbithole-synthesis.md`
- Tooling note: Firecrawl and Bash were denied in this session. All evidence came from WebFetch/WebSearch. The shared Firecrawl cache was not used because none of its pages cover the CDK package. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/edge-cases.md#scope`

## Measurements and reference values

- 20. MongoDB supports only `MongoDB::Atlas::*` types published to the CloudFormation third-party public registry. — https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 21. A third-party public extension is unusable until it is activated per account and per Region. Activation creates a private registry entry in the account. — https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public.html ; https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 22. The activated extension runs under an exec — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/mechanism.md#runtime-path-who-actually-calls-atlas`
- - C25. The README says the library provides "L1, L2 and L3 CDK constructors". — https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/README.md - C26. At GA (Feb 2023), MongoDB said all Atlas resources had "prebuilt L1 Constructs", with "a growing number of L2 and L3 CDK Constructs". — https://www.mongodb.com/blog/post/atlas-integrations-aws-cloud-formation-cdk-now-generally-available - C27. In Nov 2023, MongoDB announced new L3 constructs "including support for MongoDB Atlas Serverless". — https://www.mongodb.com/blog/post/mongodb-atlas-aws-cloud-formation-cdk-integrati — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/history.md#construct-inventory-over-time`
- 28. Activated extensions can auto-update minor versions. Major versions need a manual update. Existing provisioned instances are unaffected. The same template can behave differently across accounts and Regions pinned to different extension versions. — https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public.html 29. Two version axes are independent, so they can skew: the CDK npm version fixes the *schema the code was generated from*, and the activated extension version in each account/Region fixes the *handler that runs*. This is an inference from claims 16, 18 and 28. 30 — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/mechanism.md#versioning-across-the-two-layers`
- Saturation: not reached. Three passes ran: README/registries, then issues, then auth/registry semantics. New-information rate fell only to about 25% on the last pass. This is a soft stop under the edge-cases brief, not depth saturation. Open leads for another pass: - read `profile.go` (or its equivalent) for OAuth support; - read the v4.0.0 PR #562 diff; - check `attrConnectionStrings*` in the `CfnCluster` API docs; - check whether `cdk import` works for `MongoDB::Atlas::*` types. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/edge-cases.md#quality-gate`
- - **Pass log (new atomic claims ÷ running total):** - Pass 0 (repo, GA blog, search): 8/8 = 100%. - Pass 1 (releases, construct inventory, issues): 12/20 = 60%. - Pass 2 (CFN activation README, two practitioner posts, AWS drift doc): 8/28 = 29%. - Pass 3 (handler source, PyPI metadata): 3/31 ≈ 10%. - **Verdict: BUDGET_EXHAUSTED (soft stop), not SATURATED-DEPTH.** - The rate was still above 5%. - Bash, `gh`, and Firecrawl were denied in this session. Only WebFetch and WebSearch were available. - The npm page returned HTTP 403, so npm download counts and the dates of npm-only versions are unveri — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/practice.md#saturation-and-quality-gate`

## Problems, failure modes and limitations

- 29. Connection strings are not readable from construct props. `atlas_basic_l3.m_cluster.props.connection_strings.standard` raised `AttributeError: 'NoneType' object has no attribute 'standard'` (#26, 2023-04-18). `props` echoes the inputs, and these values are deploy-time outputs. Source: https://github.com/mongodb/awscdk-resources-mongodbatlas/issues/26 30. The same symptom recurred on v3.9.0 (#369, 2024). `cluster.props.connectionStrings?.standardSrv` / `privateSrv` were empty; the reporter said this had worked through L3 in 1.0.2. The issue was closed without a documented workaround. Source — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/edge-cases.md#observed-failure-modes-github-issues`
- - C1. The earliest CDK path to Atlas was a set of AWS-generated L1 packages in the `@cdk-cloudformation/mongodb-atlas-*` scope. They come from the `cdklabs/cdk-cloudformation` project. `@cdk-cloudformation/mongodb-atlas-networkpeering` was created 2021-11-08 and last modified 2023-11-21. — https://registry.npmjs.org/@cdk-cloudformation/mongodb-atlas-networkpeering - C2. Those `@cdk-cloudformation` packages are "automatically generated" from the CFN Registry schema. One example is the type `MongoDB::Atlas::NetworkPeering` v1.2.0. Their README says users must activate the registry type in their — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/history.md#lineage-three-generations-of-cdk-packaging`
- 33. Some Atlas resources have no CFN type, and therefore no CDK L1, because they lack full CRUD: `cloud-backup-snapshot-export-job`, `cloud-provider-access`, `federated-settings-identity-provider`, `federated-settings-org-configs`. Note that `federated-settings-identity-provider` exists as a CDK L1 directory, which contradicts this list (see disagreements). — https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md ; https://api.github.com/repos/mongodb/awscdk-resources-mongodbatlas/contents/src/l1-resources?ref=v4.0.0 34. `Failed to deploy MongoDB::Atla — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/mechanism.md#failure-modes-and-limits`
- - **C1 (correction).** The parent fact says the package is "available for TypeScript/JavaScript, with Python/Java/Go/.NET support promised." That was true only at GA: the 2023-02-28 GA post says "Today we announce MongoDB Atlas availability for AWS CDK in JavaScript and TypeScript, with plans for Python, Java, Go, and .NET support coming later in 2023." https://www.mongodb.com/blog/post/atlas-integrations-aws-cloud-formation-cdk-now-generally-available - Today the repo README documents packages for npm, PyPI, NuGet, Maven and Go. https://github.com/mongodb/awscdk-resources-mongodbatlas - PyPI — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/practice.md#corrections-to-inherited-parent-facts`
- - C37. Issue #26 (2023-04-18, 15 comments) reports that `AtlasBasic`'s `m_cluster.props.connection_strings` returned `None` in Python: `AttributeError: 'NoneType' object has no attribute 'standard'`. — https://github.com/mongodb/awscdk-resources-mongodbatlas/issues/26 - C38. Issue #187 (2024-01-05, 16 comments) is the repo's most-discussed issue. It reports a nil-pointer runtime error when deploying `AtlasServerlessBasic`. — https://api.github.com/repos/mongodb/awscdk-resources-mongodbatlas/issues?state=all&per_page=50&sort=comments - C39. The independent guide reports EU-WEST-1 deployment fai — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/history.md#documented-failure-modes`
- - **In scope:** the `awscdk-resources-mongodbatlas` construct library itself: languages and packages, construct levels and names, how it depends on the `MongoDB::Atlas::*` CloudFormation registry types at deploy time, credentials, release and breaking-change history, known failure modes, and practitioner experience. - **Out of scope:** the CloudFormation resources as a standalone tool, Terraform, AKO, Pulumi, the Atlas CLI, and the wider IaC comparison. Those are sibling frontier items. CloudFormation facts appear here only where CDK depends on them at deploy time. - **Inherited claims not rep — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/practice.md#scope`
- 1. The library "provides L1, L2 and L3 CDK constructors" and is licensed Apache 2.0. https://github.com/mongodb/awscdk-resources-mongodbatlas 2. The latest release is **v4.0.0**, published 2026-03-26. Its one breaking change is "Remove serverless." It also adds Datadog third-party-integration `sendUserProvidedResourceTags`. https://github.com/mongodb/awscdk-resources-mongodbatlas/releases 3. The release cadence has slowed: - Earlier releases: 3.9.0 (2024-09-27), 3.10.0 (2025-03-28), 3.11.0 (2025-04-16), 3.12.0 (2025-05-02), 3.12.1 (2025-05-22), 3.13.0 (2025-09-15) and 3.13.1 (2025-11-06). - Af — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/practice.md#packaging-and-versions`
- 6. **L1 constructs (34 listed):** - alert-configuration, auditing - cloud-backup-restore-jobs, cloud-backup-schedule, cloud-backup-snapshots, cloud-backup-snapshot-export-bucket - cluster, custom-db-role, custom-dns-configuration-cluster-aws, database-user - encryption-at-rest, federated-settings-org-role-mapping, global-cluster-config - ldap-configuration, ldap-verify, maintenance-window - network-container, network-peering, online-archive - org-invitation, project, project-invitation, project-ip-access-list - private-endpoint, private-endpoint-regional-mode, resource-policy - search-deployme — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/practice.md#construct-inventory`
- 25. A patch release broke the API. Issue #278 (2024-05-09), "Version 3.5.2 is NOT backwards compatible with version 3.5.1," reports that `cluster.connectionStrings.standardSrv` threw "TypeError: Cannot read properties of undefined (reading 'standardSrv')." https://github.com/mongodb/awscdk-resources-mongodbatlas/issues/278 - Implication: pin exact versions. A caret range is not enough. 26. Issue #508 (opened 2025-09-23, v3.13.0): `MongoDB::Atlas::Project` failed with a bare "Internal error." There was no matching activity in the Atlas activity feed. The issue is closed with no documented root — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/practice.md#known-failure-modes-evaluation-evidence`
- - **Before the first `cdk deploy`:** these steps cannot be done from the CDK app. - Activate every `MongoDB::Atlas::*` type you use, in each account and region. - Create the execution role. - Create the `cfn/atlas/profile/<name>` secret (claims 12–19). - **Credentials:** budget for PAK rotation. Service Accounts are not available on this path (C2). - **Versions:** pin exact versions and read the release notes before every bump. Breaking changes have shipped in a patch (claim 25) and in v4 (claim 11). - **Abstraction level:** expect mostly L1, CloudFormation-shaped code. There are only two L2 a — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/practice.md#operational-implications-derived-from-the-claims-above`
- **Child findings that correct or add to the parent:** - **CDK does not authenticate with Service Accounts (disconfirms the parent's per-operation OAuth claim).** The CloudFormation handler code (`util.go` and `profile.go`) uses only a Programmatic API key over HTTP Digest. All the README and profile-secret templates show only `PublicKey`/`PrivateKey`. The v4 `CfnServiceAccount*` constructs create and manage service accounts in Atlas; they don't change how the handler logs in. Caveat: all this evidence comes from MongoDB, and no report searched the whole handler repo. - **All five languages shi — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/rabbithole-synthesis.md`
- 1. The current release is v4.0.0, published 2026-03-26. Its only breaking change is "Remove serverless" (#562). Source: https://github.com/mongodb/awscdk-resources-mongodbatlas/releases 2. v3.10.0 (2025-03-28) deprecated `ServerlessInstance`, `ServerlessPrivateEndpoint`, and the `Serverless` type in CloudBackupRestoreJobs. v4.0.0 then removed them. Any stack still using those constructs cannot upgrade past 3.x without migrating. Source: https://github.com/mongodb/awscdk-resources-mongodbatlas/releases 3. v3.13.0 (2025-09-15) added `CfnFlexCluster` and flex support in `CfnCluster`. This is the — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/edge-cases.md#packaging-and-versions`
- - C14. GitHub Releases start at v1.0.2 on 2023-07-13. That release's notes say it fixes a failed "Publishing v1.0.1 to GitHub Go Module Repository" (INTMDB-762). So v1.0.0 and v1.0.1 never got GitHub Release entries. — https://api.github.com/repos/mongodb/awscdk-resources-mongodbatlas/releases?per_page=100 - C15. The major versions came in this order: v2.0.0 on 2023-11-06, v3.0.0 on 2023-11-20, and v4.0.0 on 2026-03-26. — https://api.github.com/repos/mongodb/awscdk-resources-mongodbatlas/releases?per_page=100 - C16. v2.0.0's notes list a private endpoint service change, a fix to the CloudBacku — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/history.md#release-timeline-github-releases-28-total`
- IN: what the package is made of, how its L1/L2/L3 constructs turn into Atlas API calls, the runtime prerequisites, how code is generated and released, the invariants that hold, and the known failure modes and limits. OUT: the CloudFormation resource handlers as a product of their own (sibling frontier item), Terraform, AKO, Pulumi, and the parent domain "Atlas IaC". This report cites the CFN handlers only where they set the CDK package's behavior. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/mechanism.md#scope`
- 31. GA was announced 2023-02-28. At GA the package had L1s for all Atlas CFN resources (33 at the time) in JS/TS only, plus "a growing number" of L2/L3. Python/Java/Go/.NET were planned for later in 2023. — https://www.mongodb.com/blog/post/atlas-integrations-aws-cloud-formation-cdk-now-generally-available 32. v3.9.0 (2024-09-27) added `ResourcePolicy` and deprecated data-lake. v3.10.0 (2025-03-28) deprecated Serverless. v3.13.0 (2025-09-15) added `CfnFlexCluster` and Flex support in `CfnCluster`. v4.0.0 (2026-03-26) removed serverless as a BREAKING change. — https://api.github.com/repos/mongo — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/mechanism.md#evolution`
- Met: claims are backed by at least 3 independent hosts. Those hosts are GitHub (MongoDB repos and the API), docs.aws.amazon.com, mongodb.com, registry.npmjs.org and blog.tysonworks.com. The independent disconfirming sources are AWS docs on versions and aliases, the handler source on the parent auth claim, and the third-party tutorial. Caveat: most mechanism claims trace to MongoDB-authored artifacts. AWS docs independently confirm only the registry, activation and execution-role layer. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/mechanism.md#quality-gate`

## Comparisons and alternatives

- 1. **GA date vs. package existence.** MongoDB's GA post is dated 2023-02-28 and links `constructs.dev/.../awscdk-resources-mongodbatlas/v/1.0.1` (https://www.mongodb.com/blog/post/atlas-integrations-aws-cloud-formation-cdk-now-generally-available). The registries disagree: the dedicated repo was created 2023-03-10 (https://api.github.com/repos/mongodb/awscdk-resources-mongodbatlas), and PyPI 1.0.1 was uploaded 2023-04-19 (https://pypi.org/pypi/awscdk-resources-mongodbatlas/json). The blog shows "Updated: March 12, 2025", so the v1.0.1 link was probably added later. On the GA date, the live CDK — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/history.md#unresolved-disagreements`
- 16. `scripts/cdk.sh <resource>` downloads `mongodb-atlas-<resource>.json` from `mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/<resource>/`. It reads `.typeName` with `jq`. It then runs `cdk-import cfn -l typescript -s <schema> -o src/l1-resources/<resource> <typeName>`. — https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/scripts/cdk.sh 17. After generation, the script runs `sed` to strip `UNDERSCORE_`, `HYPHEN_`, `PERIOD_` and `VALUE_` from generated identifiers, and patches eslint rules. Generated enum names therefore differ from raw cdk-import — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/mechanism.md#code-generation-the-l1-invariant`
- - **Auth model.** The parent extract says CDK operations mint per-operation OAuth service-account tokens. The handler source (claim 26) uses Digest auth with PublicKey/PrivateKey. Only `util.go` and the README were inspected. A service-account code path elsewhere in the handler is not ruled out. - **Unsupported-resource list vs. shipped L1s.** The CFN README lists `federated-settings-identity-provider` as unsupported, yet the CDK has an L1 directory of that name at v4.0.0. Either the README is stale or the type exists with partial CRUD. Unverified. - **Go module path.** npm 4.0.0 jsii metadata — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/mechanism.md#unresolved-disagreements`
- **Contradictions kept side by side (14 in the file):** - The number of L1 constructs is 58, 47 or 34, depending on whether you count the v4.0.0 tag, `main`, or the src README. - For #369, one report found a `getAtt` workaround in the comments; another says the issue closed with none. - For #341, one report says a stable construct ID fixed it; another says it closed with no visible fix. - For #508, the maintainer listed possible permission causes; two reports say no root cause was ever confirmed. - The handler's execution role trusts different services in AWS's docs versus MongoDB's README. - T — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/rabbithole-synthesis.md`
- - **OAuth service accounts for CDK.** The parent extract says CDK operations mint per-operation OAuth tokens. Every CDK/CFN primary source found (README, profile-secret template) shows only API-key profiles (claims 20–21). No source confirms CDK service-account support, and none explicitly denies it. The handler source (`profile.go`) returned 404 at the guessed path, so this could not be settled from code. - **Language support.** The GA blog (updated 2025-03-12) says TS/JS only. The npm and PyPI metadata show five languages are published (claims 7–8). The registries are authoritative; the blog — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/edge-cases.md#unresolved-disagreements`

## Facts and statements

- 19. The profile is an AWS Secrets Manager secret named `cfn/atlas/profile/{ProfileName}` with value `{"PublicKey": ..., "PrivateKey": ...}`. Constructs take the profile name, not the full secret path. Sources: https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/README.md ; https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 20. The official profile-secret template stores `PublicKey`, `PrivateKey`, and `BaseURL` (default `https://cloud.mongodb.com`). It has no `ClientId`/`ClientSecret` fields. Source: https://raw.githubuserco — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/edge-cases.md#credentials`
- 1. https://github.com/mongodb/awscdk-resources-mongodbatlas 2. https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/README.md 3. https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/src/README.md 4. https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/scripts/cdk.sh 5. https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/scripts/cdk-all.sh 6. https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/CONTRIBUTING.md 7. https://raw.githubusercontent.com/mongodb/awscdk-resources-mong — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/mechanism.md#sources`
- IN: the `awscdk-resources-mongodbatlas` construct library (L1/L2/L3), its packaging across languages, its credential (profile) model, and the CloudFormation-registry behaviour the library inherits at deploy time. OUT: Terraform, AKO, Pulumi, Atlas CLI, and standalone CloudFormation authoring. Those belong to sibling frontier items. CloudFormation behaviour appears below only where a CDK user hits it during `cdk deploy`. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/edge-cases.md#scope`
- - https://github.com/mongodb/awscdk-resources-mongodbatlas/releases - https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/README.md - https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/src/l3-resources/atlas-basic/index.ts - https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/src/l3-resources/atlas-basic/README.md - https://github.com/mongodb/awscdk-resources-mongodbatlas/issues?q=is%3Aissue - https://github.com/mongodb/awscdk-resources-mongodbatlas/issues/26 - https://github.com/mongodb/awscdk-resources-mongodbatlas/i — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/edge-cases.md#sources`
- - C9. The package is published to npm (`awscdk-resources-mongodbatlas`), PyPI (same name), Maven (`org.mongodb:awscdk-resources-mongodbatlas`), NuGet (`MongoDB.AWSCDKResourcesMongoDBAtlas`) and Go. The Go module lives in a separate repo, `github.com/mongodb/awscdk-resources-mongodbatlas-go`. — https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/README.md - C10. The Python package's first upload was 1.0.0 on 2023-04-14, followed by 1.0.1 on 2023-04-19. So Python shipped about seven weeks after the GA post said Python would come "later in 2023". — https://pypi.org/pypi/a — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/history.md#language-bindings-correcting-the-inherited-ts-js-only-claim`
- 1. https://github.com/mongodb/awscdk-resources-mongodbatlas 2. https://api.github.com/repos/mongodb/awscdk-resources-mongodbatlas 3. https://api.github.com/repos/mongodb/awscdk-resources-mongodbatlas/releases?per_page=100 4. https://github.com/mongodb/awscdk-resources-mongodbatlas/releases 5. https://api.github.com/repos/mongodb/awscdk-resources-mongodbatlas/git/trees/main?recursive=1 6. https://api.github.com/repos/mongodb/awscdk-resources-mongodbatlas/issues?state=all&per_page=50&sort=comments 7. https://github.com/mongodb/awscdk-resources-mongodbatlas/issues/26 8. https://raw.githubusercont — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/history.md#sources`
- 12. CDK synthesizes to CloudFormation. The `MongoDB::Atlas::*` types must be activated from the CloudFormation third-party public registry "for each AWS Account and Region where you want to deploy." Activation is per resource type. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 13. Activation needs an IAM execution role whose trust policy includes `resources.cloudformation.amazonaws.com`, `cloudformation.amazonaws.com` and `lambda.amazonaws.com`. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 14 — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/practice.md#deploy-time-mechanism-cdk-depends-on-activated-cloudformation-registry-types`
- 21. CloudFormation supports import and drift detection for third-party types only if they are provisionable (`FULLY_MUTABLE` or `IMMUTABLE`). The default version must also be registered in the account. https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/resource-import-supported-resources.html 22. The CFN resources README supports import of existing resources. It says nothing about drift detection, and it notes that four resource types lack full CRUD support. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 23. Support for the resource — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/practice.md#drift-import-support`
- - **Service Accounts on the CDK path.** The parent context says CDK operations mint OAuth Service Account tokens. The current CFN handler `Profile` struct (C2) has only PAK fields. I found no source that documents Service Account support for CFN/CDK. Unresolved until a CFN release note or MongoDB doc says otherwise. - **Drift detection.** AWS says drift detection works for provisionable third-party types (claim 21). The parent context says third-party drift detection is "less mature," and MongoDB's README is silent. I found no source that tests drift detection on `MongoDB::Atlas::*` types. - * — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/practice.md#unresolved-disagreements`
- - https://github.com/mongodb/awscdk-resources-mongodbatlas - https://github.com/mongodb/awscdk-resources-mongodbatlas/releases - https://github.com/mongodb/awscdk-resources-mongodbatlas/issues?q=is%3Aissue - https://github.com/mongodb/awscdk-resources-mongodbatlas/issues/278 - https://github.com/mongodb/awscdk-resources-mongodbatlas/issues/508 - https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/src/README.md - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloud — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/practice.md#sources`
- All four runs, and this session, were denied Bash, `gh` and Firecrawl. The open questions (service-account code anywhere in the handler, the L1 count, the #369 and #341 comment threads, drift and `cdk import`) need authenticated code search or a live deploy. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/rabbithole-synthesis.md`
- 24. If `dbUserProps` is omitted, `AtlasBasic` creates the database user `atlas-user` with the hardcoded password `atlas-pwd` and the role `atlasAdmin` on `admin`. That is an admin user with a public, known password. Source: https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/src/l3-resources/atlas-basic/index.ts 25. The code does not inject `0.0.0.0/0`. It spreads `props.ipAccessListProps`. The README example, however, uses `0.0.0.0/0`. Combined with claim 24, copying the README example verbatim yields an internet-open cluster that has a known admin password. Sources: — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/edge-cases.md#l3-atlasbasic-defaults-security-boundary`
- Met. More than 3 independent hosts were used: github.com / raw.githubusercontent.com (MongoDB primary), registry.npmjs.org, pypi.org, docs.aws.amazon.com (AWS primary), mongodb.com (blog), and turbogeek.co.uk (independent practitioner). Disconfirming evidence was sought and found against two parent claims (language support, OAuth per-operation tokens). — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/edge-cases.md#quality-gate`
- **Out of scope:** the CloudFormation resource provider itself (`mongodbatlas-cloudformation-resources`), Terraform, AKO, Pulumi, CDKTF, and the parent IaC comparison. Each is a separate frontier item. I mention the CFN provider only where the CDK package depends on it. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/history.md#scope`
- **Inherited parent claims I do not repeat:** the package wraps the `MongoDB::Atlas::*` CFN third-party resources, offers L1/L2 constructs, and installs with `npm install awscdk-resources-mongodbatlas`. The parent says the package is "TypeScript/JavaScript, with Python/Java/Go/.NET support promised". That is out of date; claims C9–C12 correct it. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/history.md#scope`
- - C32. The package's README still documents the profile secret as `cfn/atlas/profile/{ProfileName}` with the value `{"PublicKey": ..., "PrivateKey": ...}`. That is a Programmatic API key pair, not Service Account OAuth credentials. — https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/README.md - C33. The repo's `examples/profile-secret.yaml` template takes `ProfileName`, `PublicKey` and `PrivateKey` and describes the secret as "MongoDB Atlas API Key". — https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/examples/profile-secret.yaml - C34. The — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/history.md#credentials-and-activation-prerequisites`
- **Quality gate: met.** There are at least three independent hosts beyond the MongoDB-owned GitHub and blog: pypi.org, registry.npmjs.org, pkg.go.dev, docs.aws.amazon.com, turbogeek.co.uk and blog.tysonworks.com. Two disconfirming findings came out of this: the Python ship date (C10) and the credential model (disagreement 3). — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/history.md#saturation`
- 1. The repo `mongodb/awscdk-resources-mongodbatlas` was created on 2023-03-10. It is TypeScript, Apache-2.0 licensed, and not archived. Its last push was 2026-09-29. — https://api.github.com/repos/mongodb/awscdk-resources-mongodbatlas 2. The package is published to npm (`awscdk-resources-mongodbatlas`), PyPI (`awscdk-resources-mongodbatlas`), NuGet (`MongoDB.AWSCDKResourcesMongoDBAtlas`), Maven (`org.mongodb:awscdk-resources-mongodbatlas`) and Go (`github.com/mongodb/awscdk-resources-mongodbatlas-go`). — https://raw.githubusercontent.com/mongodb/awscdk-resources-mongodbatlas/main/README.md 3. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cdk-awscdk-resources-mongodbatlas-5aa0397654/reports/mechanism.md#package-identity-and-distribution`

## Related concepts

- awscdk-resources-mongodbatlas — is a part of AWS CDK awscdk-resources-mongodbatlas
- CDK — is a part of AWS CDK awscdk-resources-mongodbatlas
- AWS — is a part of AWS CDK awscdk-resources-mongodbatlas
