<!-- llms-explorer concept facts · https://llms-explorer.com/tree/aws-cloudformation-atlas/ · pack 2026-10-02 · ~13053 tokens -->

# AWS CloudFormation Atlas

> Depth-first rabbithole dossier for AWS CloudFormation Atlas; source-anchored research pack.

Parent: [MongoDB Atlas AWS Networking](https://llms-explorer.com/tree/mongodb-atlas-aws-networking/) · 5 facets · 76 facts · page: https://llms-explorer.com/tree/aws-cloudformation-atlas/

## How it works

- **Verdict: BUDGET_EXHAUSTED (soft stop), not SATURATED-DEPTH.** The core mechanism (activation, profile, async loop, schema invariants) has converged: each new report mostly corroborated it. The periphery has not converged. One or two more passes would likely still pay off on: 1. A live GCP or Azure `MongoDB::Atlas::Cluster` deploy. This would settle the AWS-only dispute. 2. `aws cloudformation list-type-versions` / `describe-type` for registry version history and the real published-type count. 3. Per-resource `callBackSeconds`, `timeoutInMinutes` and `replacementStrategy`. 4. Per-resource CHA — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#saturation`
- 1. MongoDB publishes the Atlas resource types as third-party public extensions in the AWS CloudFormation registry. MongoDB supports only resources published through that registry: "Any usage outside of this workflow is not supported or recommended." — https://github.com/mongodb/mongodbatlas-cloudformation-resources 2. Resource type names follow `MongoDB::Atlas::<RESOURCE-NAME>`, for example `MongoDB::Atlas::Cluster`. — https://github.com/mongodb/mongodbatlas-cloudformation-resources 3. You must activate each extension separately in every AWS account and Region where you deploy. — https://www.m — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/mechanism.md#distribution-and-activation`
- 16. Atlas credentials live in an AWS Secrets Manager secret named `cfn/atlas/profile/{ProfileName}`. Its value is JSON: `{"PublicKey": ..., "PrivateKey": ...}`. — https://github.com/mongodb/mongodbatlas-cloudformation-resources 17. A template names only the profile, not the full secret path. If you omit `Profile`, the handlers use `default`. — https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/mongodb-atlas-cluster.json 18. The secret must be in the same AWS account and Region as the stack. — https://github.com/mongodb/mongodbatlas-clou — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/mechanism.md#credential-flow-the-profile`
- 6. At activation you can opt in to automatic minor and patch version updates. A new minor version takes effect at the next stack operation that uses the type. https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public.html 7. CloudFormation never applies a major version update automatically. You must update to a new major version manually. https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public.html 8. An extension version update does not change resource instances that stacks have already provisioned. https://docs.aws.amazon.com/AWSCloudFormation/late — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#versioning`
- **In scope:** how the `MongoDB::Atlas::*` CloudFormation resource types work. This covers distribution and activation, credential flow, handler execution and the async provisioning loop, schema invariants, cost, and limits. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/mechanism.md#scope`
- 39. The repository `cfn-resources/` holds 58 resource directories. These cover projects, clusters, users, backups, networking, encryption at rest, Data Federation, Streams, Search, service accounts, triggers and others. — https://github.com/mongodb/mongodbatlas-cloudformation-resources/tree/master/cfn-resources 40. MongoDB lists four Atlas resources as unsupported because they lack full CRUD: cloud-backup-snapshot-export-job, cloud-provider-access, federated-settings-identity-provider and federated-settings-org-configs. — https://github.com/mongodb/mongodbatlas-cloudformation-resources 41. The — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/mechanism.md#coverage-and-limits`

## Measurements and reference values

- 59. Third-party handler operations cost $0.0009 each after 1,000 free per month (a quota shared with Hooks), plus $0.00008/s beyond the first 30 s of each operation. These fees are separate from the Atlas bill. [M43, P28, P29] https://aws.amazon.com/cloudformation/pricing/ — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#i-cost`
- Verdict: **BUDGET_EXHAUSTED (soft stop)**, not SATURATED-DEPTH. The rate is falling but has not had two passes under 5%. One or two more passes could still pay off: (a) dated Secrets Manager migration notes in the repo's per-resource CHANGELOGs, and (b) per-type version history from `aws cloudformation list-type-versions` / `describe-type` in the Public Registry. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/history.md#saturation`
- | Pass | Focus | New claims | Cumulative | New-info rate | |---|---|---|---|---| | 0 | README + Cluster schema | 15 | 15 | 100% | | 1 | AWS registry docs + repo issues | 14 | 29 | 48% | | 2 | Quick Start, forum, blog, NetworkContainer docs | 6 | 35 | 17% | — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/edge-cases.md#saturation-curve`
- | Pass | Focus | New claims | Cumulative | Rate | |---|---|---|---|---| | 0 | GA blog, changelog, repo README | 8 | 8 | 100% | | 1 | 2019/2021 origin (AWS what's-new ×2, press release, 2021 blog) | 8 | 16 | 50% | | 2 | Schema, repo metadata, releases/tags, Quick Start archive | 6 | 22 | 27% | | 3 | Secrets Manager profile, Partner Solution, AWS PG, PyPI | 4 | 26 | 15% | — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/history.md#saturation`

## Problems, failure modes and limitations

- 17. Atlas API keys are stored in Secrets Manager as `cfn/atlas/profile/{ProfileName}` with the value `{"PublicKey","PrivateKey"}`. They cannot appear inline in a template. [M16, H16, E10, P12] https://github.com/mongodb/mongodbatlas-cloudformation-resources 18. The repository's reason is that CloudFormation does not let third parties use hardcoded non-AWS API keys. [H16] https://github.com/mongodb/mongodbatlas-cloudformation-resources 19. The secret must be in the same account and Region as the stack, so a multi-Region rollout needs one secret per Region. [M18, H16, E11, P13] https://github.co — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#c-credential-profile`
- 28. Under the handler contract, create, update and delete handlers must return a ProgressEvent within 60 s. Read and list handlers must return within 30 s and may never return `IN_PROGRESS`. [M24] https://docs.aws.amazon.com/cloudformation-cli/latest/userguide/resource-type-test-contract.html 29. The cluster handler submits the Atlas call and returns `InProgress` with a `CallbackContext`. The callback delay is the constant `callBackSeconds = 40`. [M25, M26] https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/cmd/resource/resource.go 30. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#d-handler-runtime-and-async-provisioning-loop`
- 41. Coverage includes project, user, custom role, encryption-at-rest, peering, container, backup and restore, online archive, search index and search deployment, triggers, Streams, organization, api-key, teams and cloud-outage-simulation. [M39, H20, P23] https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/README.md 42. `private-endpoint` (V1) is Deprecated. Its replacements are `private-endpoint-regional-mode`, `private-endpoint-service` and `private-endpoint-aws`, and the AWS-side `AWS::EC2::VPCEndpoint` stays native. `resource-policy` is Beta. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#f-coverage`
- 52. Orphan (2020): the Project handler created the Atlas project but reported failure. The retry hit 409 "A group with name ... already exists", and rollback left the project behind. [E24, P33] https://github.com/mongodb/mongodbatlas-cloudformation-resources/issues/23 53. A transient `unexpected EOF` on `GET .../clusters/<name>` failed a stack after about 5 min. A retry with no template change succeeded. [E23] https://github.com/mongodb/mongodbatlas-cloudformation-resources/issues/20 54. An invalid enum (bad instance size) sends the stack to `UPDATE_ROLLBACK_COMPLETE`. This rests on the issue — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#h-failure-modes-and-observability`
- - https://github.com/mongodb/mongodbatlas-cloudformation-resources - https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/README.md - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md - https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/cfn-resources/README.md - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/README.md - https://github.com/mongodb/mongodbatlas-cloudformation-resources/tree/master/cfn-resources - https://raw.githubusercontent.com/ — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#sources-child-evidence-every-url-comes-from-the-four-reports`
- 19. The registry meta-schema gives each handler a `timeoutInMinutes` (min 2, max 2160, default 120). https://docs.aws.amazon.com/cloudformation-cli/latest/userguide/resource-type-schema.html 20. The Cluster schema sets no `timeoutInMinutes`, so the 120-minute default applies (inferred from claims 19 and 20). A cluster create or update that runs longer than 2 hours would fail even if Atlas later finishes it. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/mongodb-atlas-cluster.json 21. The Cluster handlers request only `secretsmanager — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/edge-cases.md#handler-timing-retries-and-orphans`
- 15. MongoDB supports only the types published in the third-party registry ("select 'Third party' as Provider and search by 'MongoDB::Atlas'"). Users must activate each type in every AWS account and region where they deploy. — https://github.com/mongodb/mongodbatlas-cloudformation-resources 16. Atlas API keys are no longer template properties. They must live in AWS Secrets Manager as `cfn/atlas/profile/{ProfileName}` with `{"PublicKey","PrivateKey"}`, in the same account and region as the stack. The repo explains that CloudFormation does not let third parties use hardcoded non-AWS API keys. — h — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/history.md#current-mechanism-as-of-2026-10`
- 22. The AWS Quick Start repo `aws-quickstart/quickstart-mongodb-atlas` was deprecated "in favor of https://github.com/aws-ia/cfn-ps-mongodb-atlas" and archived on 2024-10-04. — https://github.com/aws-quickstart/quickstart-mongodb-atlas 23. The Partner Solution guide is dated February 2023 and takes about 10–20 minutes to deploy. It deploys a two-AZ application VPC peered to an Atlas project VPC. It uses `MongoDB::Atlas::Project`, `Cluster`, `DatabaseUser`, `ProjectIPAccessList`, `NetworkPeering`, and the now-deprecated `PrivateEndpoint`. — https://aws-ia.github.io/cfn-ps-mongodb-atlas/ 24. The — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/history.md#template-packaging-lineage`
- 26. **The parent claim "CloudFormation only deploys Atlas clusters to AWS — Azure/GCP require Terraform or CDK" is contradicted by the schema.** The `MongoDB::Atlas::Cluster` region config `ProviderName` accepts `AWS | GCP | AZURE | TENANT | FLEX`. — https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/cfn-resources/cluster/docs/advancedregionconfig.md - Two limits are real. The control plane (stack, activation, and Secrets Manager profile) runs only in AWS (claims 15–16). And CDK cannot be the escape hatch, because it compiles to the same CFN types (claim 12). — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/history.md#correction-to-inherited-parent-fact`
- 24. Every create, update and delete handler must return a ProgressEvent within 60 seconds. Read and list handlers must return within 30 seconds and may never return `IN_PROGRESS`. — https://docs.aws.amazon.com/cloudformation-cli/latest/userguide/resource-type-test-contract.html 25. Atlas cluster builds take minutes, so the cluster handler submits the Atlas API call and returns `OperationStatus: InProgress` with a `CallbackContext` and `CallbackDelaySeconds`. — https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/cmd/resource/resource.go 2 — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/mechanism.md#async-provisioning-loop`
- - **Only AWS clusters, or multi-cloud?** MongoDB's integration page says: "No, CloudFormation only deploys MongoDB Atlas clusters to AWS Cloud. For Azure or Google Cloud support, we suggest either our Terraform Atlas Provider or CDK." (https://www.mongodb.com/products/integrations/aws-cloudformation). Against this, the current `MongoDB::Atlas::Cluster` schema accepts `GCP` and `AZURE` as `ProviderName` (claim 37), and the handlers call the cloud-agnostic Atlas Admin API (claim 21). The CDK constructs also synthesize to the same CloudFormation types with the same profile (claim 23), so "use CDK — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/mechanism.md#unresolved-disagreements`
- 12. Atlas programmatic API keys must be stored in AWS Secrets Manager under the name `cfn/atlas/profile/{ProfileName}`, with the value `{"PublicKey": "...", "PrivateKey": "..."}`. You cannot hardcode them in a template. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 13. The secret must be in the same AWS account and region as the stack. Templates pass the profile name, not the secret name, as `"Profile": "ProfileName"`. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 14. The official example temp — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#authentication-profile`
- - **The parent says "CloudFormation only deploys Atlas clusters to AWS — Azure/GCP require Terraform or CDK." The primary schema contradicts this.** The `MongoDB::Atlas::Cluster` region-config schema allows `ProviderName` values of `AWS | GCP | AZURE | TENANT | FLEX`. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/docs/advancedregionconfig.md - **The "CDK" alternative in that claim is also wrong.** CDK compiles to CloudFormation templates and uses the same `MongoDB::Atlas::*` profile model, so it cannot reach clouds that CloudFormat — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#corrections-to-inherited-parent-facts`
- **Scope:** this covers the `MongoDB::Atlas::*` third-party CloudFormation resource types: how they are distributed and activated, the execution role, the credential profile, the handler runtime, schema invariants, coverage, update/delete/drift semantics, failure modes, cost, history and template packaging. Terraform, networking design, KMS, EventBridge and CDK as standalone topics are out of scope. Inherited parent claims are not restated. One of them is corrected below. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md`
- 68. `aws-quickstart/quickstart-mongodb-atlas` was deprecated in favor of `aws-ia/cfn-ps-mongodb-atlas` and archived on 2024-10-04. [H22] https://github.com/aws-quickstart/quickstart-mongodb-atlas 69. `aws-ia/cfn-ps-mongodb-atlas` was flagged "subject to deprecation in Q4 2024" and archived on 2024-12-09. No maintained AWS-side template package replaced it. [H24] https://github.com/aws-ia/cfn-ps-mongodb-atlas 70. The Partner Solution guide (Feb 2023) deploys a two-AZ VPC with NAT gateways, a project, cluster, user and access list. It offers four options: no peering, peering into a new VPC, peer — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#k-template-packaging-lineage`
- - **Evidence against it (child-only):** the current `MongoDB::Atlas::Cluster` `ProviderName` enum accepts `AWS | GCP | AZURE | TENANT | FLEX` [M37, H26, E-disagreement, P-correction]. The handlers call the cloud-agnostic Admin API [M21]. CDK compiles to the same CFN types and profile, so CDK cannot be the escape hatch [M23, H26, P-correction]. Sources: https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/mongodb-atlas-cluster.json and https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/cfn-resources/cluster/docs/a — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#correction-to-inherited-parent-fact-contested-not-resolved`
- 10. You cannot put Atlas API keys inline in a template. They must live in AWS Secrets Manager under `cfn/atlas/profile/{ProfileName}`. https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/README.md 11. The secret must exist in the same account and Region as the stack. A multi-Region rollout therefore needs one secret per Region. https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/README.md 12. If you omit `Profile`, the handler silently uses the profile named `default`. The cluster schema declares `"default": "default"`. https://raw.githubuserco — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/edge-cases.md#credentials-profile-secret`
- 26. `ProjectIpAccessList` updates delete every entry and then recreate the current set. The access list is briefly empty, which blocks connections. https://github.com/mongodb/mongodbatlas-cloudformation-resources/issues/1489 27. If several Regional stacks share one access list, their concurrent updates fight. One incident deleted a critical VPC CIDR entry. Issue #1489 was still open as of 2025-11-26. https://github.com/mongodb/mongodbatlas-cloudformation-resources/issues/1489 28. Deleting a stack can fail with `409 CONTAINERS_IN_USE` on `MongoDB::Atlas::NetworkContainer` if clusters or peering — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/edge-cases.md#update-delete-and-drift-semantics`
- 22. The registry index lists 43 resource types. 41 are GA, `private-endpoint` is Deprecated (replaced by `private-endpoint-regional-mode`, `private-endpoint-service`, and `private-endpoint-aws`), and `resource-policy` is Beta. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/README.md 23. Coverage goes well beyond clusters. It includes project, database-user, custom-db-role, encryption-at-rest, network-peering, network-container, backup schedule, snapshot and restore jobs, online-archive, search-index, search-deployment, trigger, stream-insta — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#resource-coverage`
- 30. Logging is currently disabled for MongoDB's third-party extensions, which makes handler failures harder to diagnose. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 31. A drift-detection bug caused false drift on `MongoDB::Atlas::DatabaseUser`. The Read handler did not return `AWSIAMType` or `Scopes`. The issue was opened 2024-11-27 and is now closed. https://github.com/mongodb/mongodbatlas-cloudformation-resources/issues/1233 32. Implication: drift detection depends on how completely each resource's Read handler is written. Third-party drif — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#operational-failure-modes`
- - **Good fit:** AWS-centric organizations that already standardize on CloudFormation, StackSets, Service Catalog, or CDK. These teams want Atlas projects, users, peering, and private endpoints in the same stacks as the VPC side (claims 1, 23, 38). - **Costs to plan for:** activation per account and region, which brings version skew (2, 9); Lambda-IP access-list friction (16); per-operation and per-second registry fees (28–29); no handler logs (30); and weaker drift fidelity (31–32). - **Gaps that force a second tool:** cloud-provider-access and federation settings (24–25). - **Evaluation check — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#evaluation-when-to-choose-it`
- 45. A `ProjectIpAccessList` update deletes every entry and then recreates the set. The list is briefly empty, which blocks connections. [E26] https://github.com/mongodb/mongodbatlas-cloudformation-resources/issues/1489 46. Concurrent Regional stacks that share one access list fight each other. One incident deleted a critical VPC CIDR. The issue was still open on 2025-11-26. [E27] same issue 47. A stack delete can fail with `409 CONTAINERS_IN_USE` on NetworkContainer. The fix is a `DependsOn` from the cluster. [E28] README 48. A container's `AtlasCidrBlock` cannot change while the project has a — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#g-update-delete-and-drift-semantics`
- Met. This run used 5 independent hosts: github.com (publisher repo and issues), docs.aws.amazon.com (AWS registry docs), aws-ia.github.io (AWS Quick Start), mongodb.com community forums, and turbogeek.co.uk (practitioner blog). Disconfirming evidence found: the `ProviderName` enum contradicts the inherited "AWS-only" limitation. Limits: repost.aws returned 403 and could not be read. The MongoDB docs IaC page returned 404. Firecrawl was not available in this session. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/edge-cases.md#quality-gate`
- - https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/README.md - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/mongodb-atlas-cluster.json - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/network-container/docs/README.md - https://github.com/mongodb/mongodbatlas-cloudformation-resources/tree/master/examples/cluster - https://github.com/mongodb/mongodbatlas-cloudformation-resources/issues/20 - https://github.com/mongodb/mongodbatlas-cloudformation-resourc — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/edge-cases.md#sources`

## Comparisons and alternatives

- 1. MongoDB publishes the types as third-party extensions in the CloudFormation Public Registry. They are found under Publisher = "Third party" by searching "MongoDB::Atlas". MongoDB supports nothing outside this channel: "Any usage outside of this workflow is not supported or recommended." [M1, H15, P1, P5] https://github.com/mongodb/mongodbatlas-cloudformation-resources 2. Type names follow the pattern `MongoDB::Atlas::<RESOURCE-NAME>`. [M2] https://github.com/mongodb/mongodbatlas-cloudformation-resources 3. Each type must be activated separately in every account and every Region where it is — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#a-distribution-and-activation`
- | Topic | Side A | Side B | |---|---|---| | Size of the catalogue | 33 at GA, 2023 [H10] | Today: 58 `cfn-resources/` directories [M39], about 42 directories [H20], 43 listed types (41 GA, 1 Deprecated, 1 Beta) [P22]. The three counts are not reconciled. They may count different things: raw directories vs. the README index. | | Unsupported or unpublished types | Four lack full CRUD: export-job, cloud-provider-access, fed-identity-provider, fed-org-configs [M40, E33, P24] | Two are "deliberately not published": export-job and fed-identity-provider [H21]. Also, a `federated-settings-identity-pro — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#contradictions-side-by-side`
- 1. You must activate each `MongoDB::Atlas::<Resource>` extension separately in every AWS account and every Region where you deploy it. Activation is not global. https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/README.md 2. When you activate a third-party public extension, CloudFormation registers it as a private extension in that account and Region. Activation alone does not let you use it anywhere else. https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public.html 3. If auto-update is enabled, the extension picks up each new minor version at t — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/edge-cases.md#activation-and-registry-scope`
- - **Is CloudFormation AWS-only for clusters?** The inherited parent claim says CloudFormation "only deploys Atlas clusters to AWS". The current Cluster schema's `ProviderName` enum lists `AWS`, `GCP`, `AZURE`, `TENANT`, and `FLEX`: https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/mongodb-atlas-cluster.json None of the repo's cluster examples (`cluster.json`, `flex-cluster.json`, `free-tier-M0-cluster.json`, and others) shows a GCP or Azure deployment: https://github.com/mongodb/mongodbatlas-cloudformation-resources/tree/master/example — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/edge-cases.md#unresolved-disagreements`
- 32. The primary identifier is the composite (`ProjectId`, `Name`, `Profile`). — https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/mongodb-atlas-cluster.json 33. `Name`, `ProjectId`, `Profile` and `GlobalClusterSelfManagedSharding` are `createOnlyProperties`. — https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/mongodb-atlas-cluster.json 34. A change to a create-only property makes CloudFormation replace the resource, and the default order is create-then-delete. As a result, chan — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/mechanism.md#schema-invariants-mongodb-atlas-cluster`
- 1. The Atlas resources are published as third-party extensions in the AWS CloudFormation Public Registry. You find them by searching for "MongoDB::Atlas" under the "Third party" publisher filter. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 2. You must activate each resource type separately, in each AWS account and each region where you deploy. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 3. CloudFormation requires third-party public extensions to be activated per account and region before s — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#delivery-and-activation`
- - **When Public Registry availability happened:** the MongoDB and AWS blogs say 2021-06-21, but the Atlas changelog says 13 July 2021. This is probably a docs-release lag rather than a real conflict, but no source reconciles them. - **When GA happened:** the blog says 2023-02-28 and the changelog says 2023-03-01. The gap is one day. - **What "support" meant in 2019–2020:** the 2019-12-03 press release does not say whether the support was preview, private-registry, or GA. Claim 4 shows only that private `cfn` registration came first. No dated preview or beta announcement was found. - **When API — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/history.md#unresolved-disagreements-and-gaps`

## Facts and statements

- 13. CloudFormation runs the handler code itself, assuming the execution role supplied at activation. [M11] https://aws.amazon.com/blogs/aws/introducing-a-public-registry-for-aws-cloudformation/ 14. AWS requires the trust principal `resources.cloudformation.amazonaws.com` and recommends `aws:SourceAccount`/`aws:SourceArn` conditions to prevent confused-deputy access. [M12, E8, P20] https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public.html 15. MongoDB's README and sample `execution-role.yaml` also trust `cloudformation.amazonaws.com` and `lambda.amazonaws.com`. The samp — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#b-execution-role`
- 60. 2019-11-18: AWS launched the CloudFormation Registry. MongoDB was not a named partner. [H1] https://aws.amazon.com/about-aws/whats-new/2019/11/now-extend-aws-cloudformation-to-model-provision-and-manage-third-party-resources/ 61. 2019-11-21: MongoDB created the `mongodb/mongodbatlas-cloudformation-resources` repo (Apache-2.0). [H2] https://api.github.com/repos/mongodb/mongodbatlas-cloudformation-resources 62. Before the Public Registry, customers registered the types privately in their own account with the `cfn` CLI. [H4] https://www.mongodb.com/blog/post/deploy-manage-mongodb-atlas-aws-cl — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#j-history-child-timeline`
- The parent says: "CloudFormation only deploys Atlas clusters to AWS — Azure/GCP require Terraform or CDK." — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#correction-to-inherited-parent-fact-contested-not-resolved`
- - Atlas CDK constructs `awscdk-resources-mongodbatlas` (L1/L2/L3) - StackSets / `AWS::CloudFormation::TypeActivation` and Service Catalog for org-wide rollout - Cloud Control API use of Atlas types - Secrets Manager managed external secret `MongoDBAtlasServiceAccount` (rotation) - Atlas cloud-provider-access (IAM role authorization) outside IaC - Atlas resource policies via CFN `resource-policy` - The Partner Solution template as its own artifact — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#handoffs-siblings-surfaced-not-chased`
- In scope: the `MongoDB::Atlas::*` third-party CloudFormation resource types. This covers their activation, their credentials model, handler behaviour, update, delete and drift semantics, and the failures users have reported. The Atlas CDK constructs are in scope only where they inherit CloudFormation behaviour. Out of scope: Terraform, Atlas networking design, KMS, EventBridge, and the parent "Atlas AWS Networking" topic. Inherited parent claims are not repeated except where this run corrects them. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/edge-cases.md#scope`
- **In scope:** the MongoDB Atlas resource provider for AWS CloudFormation (`MongoDB::Atlas::*` third-party resource types). That covers its origin, its distribution channel (the CloudFormation Registry and the Public Registry), its GA milestone, how credentials work, its resource catalogue and deprecations, its template packaging (the Quick Start, later the Partner Solution), and its limits. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/history.md#scope`
- 1. On 2019-11-18 AWS launched the CloudFormation Registry, which lets publishers "submit, discover, and manage resource providers." MongoDB was not among the launch partners named. — https://aws.amazon.com/about-aws/whats-new/2019/11/now-extend-aws-cloudformation-to-model-provision-and-manage-third-party-resources/ 2. MongoDB created the GitHub repository `mongodb/mongodbatlas-cloudformation-resources` on 2019-11-21, three days after the Registry launch. It is licensed Apache-2.0. — https://api.github.com/repos/mongodb/mongodbatlas-cloudformation-resources 3. A MongoDB press release dated 2019 — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/history.md#origin-2019-2020`
- 5. In April 2021 AWS released a Quick Start for MongoDB Atlas, which "launch[es] a basic MongoDB Atlas deployment from the AWS CLI or console." It was distinct from the older EC2-based "MongoDB on the AWS Cloud" Quick Start. — https://www.mongodb.com/blog/post/deploy-manage-mongodb-atlas-aws-cloud-formation 6. On 2021-06-21 AWS announced the CloudFormation Public Registry, a "searchable collection of extensions" for third-party resource types and modules. MongoDB is named first among the launch APN partners. — https://aws.amazon.com/about-aws/whats-new/2021/06/announcing-a-new-public-registry- — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/history.md#quick-start-and-public-registry-2021`
- 10. A MongoDB blog post dated 2023-02-28 declared the Atlas CloudFormation and CDK integrations generally available. It listed "33 Atlas Resources" in the Public Registry across "22+ AWS Regions", and the code is Apache-2.0. — https://www.mongodb.com/blog/post/atlas-integrations-aws-cloud-formation-cdk-now-generally-available 11. The Atlas changelog dates the same GA on its 1 March 2023 release, one day after the blog. — https://www.mongodb.com/docs/atlas/release-notes/changelog/ (shared cache) 12. At GA the CDK constructs (L1 maps one-to-one to the CFN types; L2 and L3 sit on top) were availa — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/history.md#general-availability-2023`
- 11. CloudFormation itself runs the extension's handler code. It assumes the execution role ARN you supply at activation. — https://aws.amazon.com/blogs/aws/introducing-a-public-registry-for-aws-cloudformation/ 12. The execution role's trust policy must allow `resources.cloudformation.amazonaws.com`. AWS recommends `aws:SourceAccount` and `aws:SourceArn` conditions to prevent confused-deputy access. — https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public.html 13. MongoDB's sample `execution-role.yaml` trusts `cloudformation.amazonaws.com`, `resources.cloudformation.amaz — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/mechanism.md#execution-role-and-handler-runtime`
- **In scope:** the `MongoDB::Atlas::*` CloudFormation resource types. This covers how they are delivered and activated, how they authenticate, their IAM role, resource coverage, the cost of handler operations, versioning, drift and rollback behavior, the CDK wrapper, the AWS Partner Solution template, and what these facts mean in practice. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#scope`
- 28. Third-party resource types cost $0.0009 per handler operation (CREATE, UPDATE, DELETE, READ, or LIST). The first 1,000 operations per month are free, a quota shared with custom hooks. Each operation running longer than 30 seconds adds $0.00008 per second. https://aws.amazon.com/cloudformation/pricing/ 29. Implication: Atlas cluster creation takes minutes, so long-running cluster handlers add per-second charges on top of the operation fee. These charges are separate from the Atlas bill. (Inference from claim 28.) https://aws.amazon.com/cloudformation/pricing/ — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#cost`
- | Topic | Side A | Side B | |---|---|---| | Can CloudFormation place Atlas clusters on GCP or Azure? | Parent skill: AWS only. | Schema enum includes GCP and AZURE: https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/docs/advancedregionconfig.md. No official non-AWS example exists. | | Execution-role trust principals | MongoDB README: lambda, resources.cloudformation, and cloudformation (https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md). | AWS docs: only resources.cloudformation, scoped wit — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#unresolved-disagreements`
- - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/README.md - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/README.md - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/docs/advancedregionconfig.md - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/examples/profile-secret.yaml - https:/ — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#sources`
- 35. The README says that "Logging for AWS CloudFormation Public extensions is currently disabled". https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/README.md — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/edge-cases.md#observability`
- - CDK Atlas constructs (`awscdk-resources-mongodbatlas`) as their own concept. - CloudFormation StackSets / `TypeActivation` for org-wide third-party type rollout. - Atlas resource policies (Cedar) via CFN `resource-policy`. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/history.md#handoffs-not-chased-separate-frontier-items`
- - https://aws.amazon.com/about-aws/whats-new/2019/11/now-extend-aws-cloudformation-to-model-provision-and-manage-third-party-resources/ - https://aws.amazon.com/about-aws/whats-new/2021/06/announcing-a-new-public-registry-for-aws-cloudformation/ - https://www.mongodb.com/company/newsroom/press-releases/mongodb-atlas-adds-support-for-aws-cloudformation-eventbridge-privatelink-and-more - https://www.mongodb.com/blog/post/deploy-manage-mongodb-atlas-aws-cloud-formation - https://www.mongodb.com/blog/post/atlas-integrations-aws-cloud-formation-cdk-now-generally-available - https://www.mongodb.com/ — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/history.md#sources`
- 43. Third-party handler operations cost $0.0009 each after a free tier of 1,000 operations per month, which Hook operations share. Each operation also incurs $0.00008 per second beyond its first 30 seconds. — https://aws.amazon.com/cloudformation/pricing/ 44. Inference, not verified: a cluster create that polls every 40 seconds for 10–20 minutes produces about 15–30 billable handler invocations. AWS pricing does not say whether each `IN_PROGRESS` re-invocation counts as a separate operation. — derived from claims 26, 31 and 43 — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/mechanism.md#cost`
- - Atlas CDK constructs (L1/L2/L3) - AWS Partner Solution "MongoDB Atlas on AWS" template - Secrets Manager managed external secret type `MongoDBAtlasServiceAccount` (rotation) - Cloud Control API usage of Atlas types — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/mechanism.md#handoffs-siblings-surfaced-not-chased`
- - https://github.com/mongodb/mongodbatlas-cloudformation-resources - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/examples/execution-role.yaml - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/examples/profile-secret.yaml - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/examples/cluster/cluster.json - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resourc — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/mechanism.md#sources`
- **Out of scope:** Atlas networking design (peering and PrivateLink as concepts), KMS, EventBridge, the Terraform provider, the Atlas Kubernetes Operator, and the parent domain "MongoDB Atlas AWS Networking". Those belong to other frontier items. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#scope`
- 19. The activation execution role must trust `lambda.amazonaws.com`, `resources.cloudformation.amazonaws.com`, and `cloudformation.amazonaws.com`. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 20. AWS's generic guidance needs only `resources.cloudformation.amazonaws.com` in the trust policy for a resource-type extension. It recommends scoping the role with `aws:SourceAccount` and `aws:SourceArn` to prevent the confused-deputy problem. https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public.html 21. The execution role nee — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#iam-execution-role`
- 35. MongoDB handles production support through Atlas support plans (Developer tier or higher). GitHub Issues get best-effort handling with no SLA. Feature requests go to the Atlas infra-as-code feedback portal. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 36. MongoDB's Atlas docs list the CloudFormation resources under "Infrastructure As Code" next to the Terraform provider. They link only to the GitHub repo and give no comparison or recommendation. https://www.mongodb.com/docs/atlas/terraform/ — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#support`
- 37. MongoDB launched the AWS Quick Start for Atlas in April 2021. MongoDB's own article about it was published 2021-06-21 and updated 2024-01-11. https://www.mongodb.com/resources/products/platform/deploy-manage-mongodb-atlas-aws-cloud-formation 38. The AWS Partner Solution deploys a two-AZ VPC, NAT gateways, an Atlas cluster, a database user, and an IP access-list entry. It offers four options: no peering, peering into a new VPC, peering into an existing VPC, or a private endpoint. https://aws-ia.github.io/cfn-ps-mongodb-atlas/ 39. The Partner Solution guide was last updated in February 2023. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#partner-solution-formerly-quick-start`
- - MongoDB Atlas CDK constructs (`awscdk-resources-mongodbatlas`, L1/L2/L3) - CloudFormation StackSets and Service Catalog distribution of Atlas resource types across accounts - Atlas cloud-provider-access (IAM role authorization) outside IaC — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#handoffs-adjacent-concepts-not-researched-here`
- 34. The Cluster primary identifier is the composite (`ProjectId`, `Name`, `Profile`). The create-only properties are `Name`, `ProjectId`, `Profile` and `GlobalClusterSelfManagedSharding`. [M32, M33, E13] cluster schema 35. Changing a create-only property replaces the cluster (create-then-delete by default). Renaming the profile therefore forces replacement. Rotating keys inside the same secret does not. [M34, E13] resource-type-schema.html, plus the cluster schema 36. `NetworkContainer` also treats `ProjectId` and `Profile` as replace-on-update. [E14] https://raw.githubusercontent.com/mongodb/ — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#e-schema-invariants-cluster-and-others`
- 72. Production support comes through Atlas support plans from Developer tier up. GitHub Issues are best-effort with no SLA. Feature requests go to the IaC feedback portal. [H19, P35] README 73. The Atlas docs list the CFN resources under "Infrastructure As Code" next to Terraform. They link only to the repo and offer no comparison. [P36] https://www.mongodb.com/docs/atlas/terraform/ — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#l-support`
- **Met.** These independent origins back child claims: 1. **MongoDB primary code and docs:** the GitHub repo, schemas, Go handlers, examples, and the mongodb.com blogs and docs. 2. **AWS platform:** docs.aws.amazon.com, aws.amazon.com (what's-new, blog, pricing), and AWS-IA (Partner Solution, archived repos). 3. **Independent third parties:** GitHub issue reporters (#20, #23, #608, #1233, #1489, quickstart #46), the MongoDB community forum poster, and turbogeek.co.uk. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#three-independent-origin-gate-inherited-sources-excluded`
- PyPI only corroborates MongoDB's own package. Excluded from the gate: the inherited integration page, the inherited 2019 press release, and the shared-cache Atlas changelog (used only as corroboration). None of the five shared-cache Firecrawl pages backs a child claim. History claim 71 cites a different page (`best-practices.html`) of the same Prescriptive Guidance guide as one cached page (`architecture.html`), so treat it as weakly independent. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#three-independent-origin-gate-inherited-sources-excluded`
- **Corroboration only (shared cache; not counted):** https://www.mongodb.com/docs/atlas/release-notes/changelog/ — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/rabbithole-synthesis.md#sources-child-evidence-every-url-comes-from-the-four-reports`
- **Out of scope:** VPC peering, PrivateLink, KMS, EventBridge, Terraform, and CDK as standalone concepts. CDK appears below only where it shares a milestone or a package with the CloudFormation resources. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/history.md#scope`
- Met. The claims rest on independent hosts: - MongoDB: mongodb.com and github.com/mongodb. - AWS: aws.amazon.com what's-new ×2 and docs.aws.amazon.com. - AWS-IA: aws-ia.github.io and github.com/aws-ia / aws-quickstart. - PyPI: pypi.org. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/history.md#quality-gate`
- **Out of scope:** Terraform, VPC peering and PrivateLink network design, KMS, EventBridge, and Atlas networking in general. These are parent or sibling frontier items. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/mechanism.md#scope`
- The gate is **met**. Five independent hosts were used: github.com/raw.githubusercontent.com (MongoDB source), docs.aws.amazon.com (AWS docs), aws.amazon.com (AWS blog and pricing), mongodb.com (MongoDB product page) and aws-ia.github.io (AWS Partner Solution). The MongoDB product page was the disconfirming source for the AWS-only claim. The Go handler code and the JSON schema are the primary sources. No shared-source cache page was used for child claims. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/mechanism.md#quality-gate`
- **Met (≥3 independent sources).** Distinct hosts: raw.githubusercontent.com and github.com (MongoDB repos), docs.aws.amazon.com, aws.amazon.com, aws-ia.github.io, and mongodb.com. The disconfirming evidence I found is the `ProviderName` enum, which contradicts the parent's AWS-only claim. The GitHub issue tracker also contradicts the vendor's "GA" framing on drift and rollback. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/aws-cloudformation-atlas-98432a23a3/reports/practice.md#quality-gate`

## Related concepts

- AWS — is a part of AWS CloudFormation Atlas
- Atlas — is a part of AWS CloudFormation Atlas
- CloudFormation — is a part of AWS CloudFormation Atlas
