AWS CloudFormation Atlas Resources
Parent: MongoDB Atlas Infrastructure as Code · Published reference · snapshot 2026-10-02
↓ Facts as markdownall context files
Depth-first rabbithole dossier for AWS CloudFormation Atlas Resources; source-anchored research pack.
These notes link each claim to its source. A source may be a research report hosted on this site rather than the primary document. A published reference means the content is available; it does not certify independent review or accuracy.Read the editorial policy and follow the sources before relying on a claim.
Structure and components
- 24. The README supports only resources published through "the AWS Cloudformation Third Party registry". Users must activate each type per AWS account and region, under the namespace `MONGODB::ATLAS::[RESOURCE-NAME]`. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 25. Activation requires an execution-role ARN that CloudFormation assumes to run the extension code. Registry publishers must be verified AWS Marketplace sellers or GitHub/BitBucket users. https://aws.amazon.com/blogs/aws/introducing-a-public-registry-for-aws-cloudformation 26. Third-p [source]
- - **F1** The cfn-resources README says UPDATE must be implemented properly for import to work. [P-C24; R1] - **F2** AWS allows import and drift detection only for types whose provisioning type is `FULLY_MUTABLE` or `IMMUTABLE` and that have a default version registered. [M36,E35,P-C23; A3] - **F3** The 2021 AWS launch blog says third-party types take part in drift detection. [H26; A13] - **F4** Schema `propertyTransform` entries exist to suppress false drift caused by value normalisation. [M37,P-C26; A5] - **F5** Issue #1233 (2024-11-27, DatabaseUser v2.1.0) reported false drift because the re [source]
How it works
- 34. Four Atlas resources are deliberately missing because their APIs lack full CRUD: `cloud-backup-snapshot-export-job`, `cloud-provider-access`, `federated-settings-identity-provider`, `federated-settings-org-configs`. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 35. CloudFormation supports import and drift detection only for registry types whose provisioning type is `FULLY_MUTABLE` or `IMMUTABLE`. The default version must be registered in the account. https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/resource-import-supported-r [source]
- 1. MongoDB publishes the resources as third-party extensions in the AWS CloudFormation Public Registry. — https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/cfn-resources/README.md 2. When you activate a third-party public extension, CloudFormation creates an entry for it in your account's registry as a **private** extension. — https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public.html 3. When you activate an extension, you can opt in to automatic minor-version updates. CloudFormation always requires a manual update for a new **major** version [source]
- - **C-20** Handler `timeoutInMinutes` defaults to 120, with minimum 2 and maximum 2160. The cluster schema sets no explicit timeouts, so the 120-minute default applies. Its handlers are create, read, update, and delete, and it has **no list handler**. https://docs.aws.amazon.com/cloudformation-cli/latest/userguide/resource-type-schema.html and https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/mongodb-atlas-cluster.json - **C-21** For `MongoDB::Atlas::Cluster`, `primaryIdentifier` = `[ProjectId, Name, Profile]` and `createOnlyProperties [source]
- - **In scope:** the `MongoDB::Atlas::*` CloudFormation third-party resource types (repo `mongodb/mongodbatlas-cloudformation-resources`). Also in scope: how they are distributed and activated, the credential "profile" mechanism, their versioning, and their dated evolution. The `awscdk-resources-mongodbatlas` CDK wrapper is covered only where it records the evolution of the CloudFormation resources it wraps. - **Out of scope:** Terraform, the Atlas Kubernetes Operator (AKO), Pulumi, the Atlas CLI, the Admin API in general, and the parent IaC domain. Those are separate frontier items. - **Toolin [source]
Measurements and reference values
- - **A1** When you activate a public extension, CloudFormation creates a **private** extension entry for it in your account's registry. [M2,E1,P-C01; A1] - **A2** You can opt in to automatic minor-version updates. Major versions always need a manual update. [M3,E2,P-C28; A1] - **A3** A new extension version does not change resources that are already provisioned. CloudFormation uses the new handler on the next stack operation. [M4,E4,P-C28; A1] - **A4** Each account and Region controls its own update timing. One template can therefore run against different handler versions in different places. A [source]
- 10. Each activated extension needs an IAM execution role. MongoDB's README says the role's trust policy must allow `lambda.amazonaws.com`, `resources.cloudformation.amazonaws.com` and `cloudformation.amazonaws.com`. — https://github.com/mongodb/mongodbatlas-cloudformation-resources 11. The sample role `cfn-resources/execute-role.template.yml` trusts only `lambda.amazonaws.com` and `resources.cloudformation.amazonaws.com`. Its `MaxSessionDuration` is 8400 s. — https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/execute-role.template.yml 12. That [source]
- | Pass | Focus | New claims | Cumulative | Rate | |---|---|---|---|---| | 0 | README + AWS registry docs | 15 | 15 | 100% | | 1 | handler code, schema, Secrets Manager | 15 | 30 | 50% | | 2 | import/drift/Cloud Control, Flex deprecations, issue #20 | 12 | 42 | 29% | | 3 | verifying credentials in `util.go` (resolved one disagreement) | 2 | 44 | 5% | [source]
- Verdict: **BUDGET_EXHAUSTED (soft stop), not SATURATED-DEPTH.** The rate was still above 5% at pass 2, and only one sub-5% pass was run. At least one more pass would likely pay off on these items: - the per-handler `timeoutInMinutes` values in each Atlas schema JSON; - the per-Region availability list; - whether any release has added service-account auth; - the `provisioningType` of each Atlas type, which decides drift and import eligibility. [source]
- | Pass | Focus | New claims | Cumulative | New-info rate | |---|---|---|---|---| | 0 | README, GA blog, marketing page, AWS registry doc | 14 | 14 | 100% | | 1 | Resource tree, tags/releases, commits, profile secret | 13 | 27 | 48% | | 2 | Schema contract, timeouts, pricing, import/drift, Lambda runtime | 9 | 36 | 25% | | 3 | Issues (#1489, #1233, #506, #982), CDK releases, Flex/ServiceAccount | 7 | 43 | 16% | | 4 | Independent/disconfirming: practitioner blog, AWS DevOps blog, Cloud Control | 3 | 46 | 6.5% | | 5 | Verification re-reads of README/profile.go (confirmations, 1 new) | 1 | 47 | 2. [source]
Problems, failure modes and limitations
- - **B1** MongoDB's README says the role must trust `lambda.amazonaws.com`, `resources.cloudformation.amazonaws.com` and `cloudformation.amazonaws.com`. If those principals are missing, stacks sit in `CREATE_IN_PROGRESS` until they fail. [M10,E9,P-C04; I-1] - **B2** AWS asks for trust in `resources.cloudformation.amazonaws.com` only, scoped with `aws:SourceAccount`/`aws:SourceArn` to prevent confused-deputy access. [M13,E8,P-C03; A1] - **B3** ⚠ The sample `cfn-resources/execute-role.template.yml` trusts 2 principals (lambda and resources.cloudformation) and sets `MaxSessionDuration` to 8400 s. [source]
- - **C1** The README gives the reason for the profile: "AWS CloudFormation limits Third Parties from using non-AWS API Keys as either hardcoded secrets in CloudFormation templates or via CDK". [E13,P-C13; R2] - **C2** The secret is named `cfn/atlas/profile/{ProfileName}` and holds `{"PublicKey","PrivateKey"}`. Templates pass the bare profile name. Passing the full path is a documented misconfiguration. [M14–15,H27,E11,P-C14; R2] - **C3** The prefix is defined as `ProfileNamePrefix = "cfn/atlas/profile"` in `util/constants/constants.go`. [H28,P-C14; R8] - **C4** The secret must be in the same ac [source]
- | Date | Event | Src | |---|---|---| | 2020-05-12 | `v0.1.0` tag, a pre-release marked not for production | H1–2,E7; R15,R16 | | 2021-04 | AWS Quick Start for Atlas | H5; W1 | | 2021-06-21 | CloudFormation Public Registry GA. MongoDB is the first-named APN launch partner. Launch counts: more than 35 extensions from over a dozen partners | H6–9; A12,A13,W1 | | 2021 | Launch requires an org PAK with Org Project Creator and an IP access-list entry | H10; W1 | | 2023-02-28 | GA. Child deltas only: 22 Regions, Apache-2.0, authors Paithankar/Ahmed, post updated 2025-03-12 | H12–13,M8; I-2 | | 2023-0 [source]
- 1. Third-party public extensions must be activated per account and per Region before any template can use them; activation creates a private-extension entry in that account's registry. https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public.html 2. Activation can opt into automatic minor/patch updates; major versions are never auto-applied and need a manual update. https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public.html 3. Failure mode: because each account/Region controls its own update timing, the same template can run against different `Mon [source]
- 8. The execution role must trust `resources.cloudformation.amazonaws.com`. AWS recommends scoping it with `aws:SourceAccount` and `aws:SourceArn` to prevent confused-deputy use. https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public.html 9. MongoDB's README asks for a broader trust (`resources.cloudformation.amazonaws.com`, `cloudformation.amazonaws.com`, `lambda.amazonaws.com`). A role missing these principals leaves stacks in `CREATE_IN_PROGRESS` until they fail. https://github.com/mongodb/mongodbatlas-cloudformation-resources 10. The `MongoDB::Atlas::Cluster` schema [source]
- 1. The repo's earliest tag, `v0.1.0`, is dated May 12, 2020 on the tags page. https://github.com/mongodb/mongodbatlas-cloudformation-resources/tags 2. The releases page marks `v0.1.0` as a pre-release that is not recommended for production use. https://github.com/mongodb/mongodbatlas-cloudformation-resources/releases 3. Users were running `MongoDB::Atlas::Cluster` in stacks by May 14, 2020. Issue #20 reports an "unexpected EOF" API error after about 5 minutes in `CREATE_IN_PROGRESS`, and a second run succeeded. https://github.com/mongodb/mongodbatlas-cloudformation-resources/issues/20 4. In 20 [source]
- 30. `MongoDB::Atlas::Cluster` requires `ProjectId` and `Name`. Its create-only properties are `Profile`, `ProjectId`, `Name` and `GlobalClusterSelfManagedSharding`, and changing any of them triggers replacement. — https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/cfn-resources/cluster/docs/README.md 31. The cluster's read-only outputs, available through `Fn::GetAtt`, include `Id`, `StateName`, `MongoDBVersion`, `CreatedDate`, and the connection-string variants `Standard`, `StandardSrv`, `Private`, `PrivateSrv`, `PrivateEndpoints`, `PrivateEndpointsSrv` and `SRVShardO [source]
- - **C-13** The README states the rule: "AWS CloudFormation limits Third Parties from using non-AWS API Keys as either hardcoded secrets in CloudFormation templates or via CDK". As a result, Atlas credentials must live in AWS Secrets Manager. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md - **C-14** The secret name is `cfn/atlas/profile/{ProfileName}`, and the constant is `ProfileNamePrefix = "cfn/atlas/profile"`. The secret value is `{"PublicKey": …, "PrivateKey": …}`, optionally with `BaseURL`/`BaseUrl` or `IsMongoDBGovCloud`. Templates refere [source]
- 26. Non-idempotent create and orphan on rollback: project create returned `409 (request "Conflict") A group with name "cloudformation_resource_demo" already exists`. The stack rolled back, but the rollback did not delete the Atlas project, which was left orphaned (2020-05-15). https://github.com/mongodb/mongodbatlas-cloudformation-resources/issues/23 27. Transient polling failure: a cluster stack sat in `CREATE_IN_PROGRESS` for about 5 minutes, then failed with `error fetching cluster info ... unexpected EOF`. A retry without changes succeeded. https://github.com/mongodb/mongodbatlas-cloudform [source]
- In scope: the `MongoDB::Atlas::*` third-party resource types in the AWS CloudFormation registry. That covers how they are activated, authenticated, versioned, and billed. It also covers their handler contract (create-only properties, drift, import), their current maintenance state, known failure modes, and what follows for teams that run them. The CDK package is in scope only where it wraps these same types. [source]
- - **C-07** MongoDB's GA announcement (published 2023-02-28, updated 2025-03-12) states 33 resources, published to 22 AWS Regions. https://www.mongodb.com/blog/post/atlas-integrations-aws-cloud-formation-cdk-now-generally-available - **C-08** The status table in `cfn-resources/README.md` lists 43 resource types. It marks only `private-endpoint` as deprecated. https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/cfn-resources/README.md - **C-09** The `cfn-resources/` tree on `master` holds more resource directories than that table lists. Examples: `flex-cluster`, `service [source]
- - **C-34** From 2026-07-06 to 2026-09-28, every commit on `master` is a dependency or CI chore. The last feature PR is #1614 (2026-03-06); fix PRs ran until #1668 (2026-06-03). https://github.com/mongodb/mongodbatlas-cloudformation-resources/commits/master and https://github.com/mongodb/mongodbatlas-cloudformation-resources/pulls?q=is%3Apr+is%3Amerged+-label%3Adependencies - **C-35** PR #1692 (2026-08-10) "Ignores cfn-lint W2531 warning for deprecated provided.al2 runtime". Handlers were still declared on `provided.al2` at that date. https://github.com/mongodb/mongodbatlas-cloudformation-resou [source]
- - **D-1 — Is CloudFormation at parity with the other Atlas IaC tools?** The parent extract says the choice "depends on where your platform engineering already lives, not on capability gaps". Against that, the CloudFormation provider cannot authenticate with Service Accounts (C-15). It has no list handler on Cluster (C-20). It has an open delete-all IP-list update bug (C-39). Its repo has received only maintenance commits since 2026-07 (C-34). Both positions are kept. The parent's position may hold for resource *coverage*. It does not hold for *auth* or *update semantics*. - **D-2 — Resource co [source]
- Handoffs for concept-family-explorer (not chased here): Atlas Service Account OAuth for IaC, AWS Cloud Control API as an Atlas control plane, Lambda `provided.al2` → `provided.al2023` migration risk for third-party registry types, CloudFormation registry versioning governance. [source]
- - **In scope:** the `MongoDB::Atlas::*` registry types themselves: activation, the execution role, the credential profile, the handler lifecycle, schema invariants, import and drift, coverage, history and failure modes. CDK is covered only where it records or changes how the CloudFormation types behave. - **Out of scope:** Terraform, the Atlas Kubernetes Operator (AKO), Pulumi, the Atlas CLI, and the comparison between IaC tools. [source]
- - **D1** The handlers are written in Go. Each resource exposes `Create`, `Read`, `Update`, `Delete` and `List`, and each returns a `handler.ProgressEvent`. [M24; G4] - **D2** ⚠ The Cluster `Create` handler does not wait for the cluster: - It returns `InProgress` with `CallbackDelaySeconds: 40` and `CallbackContext {"callbackCluster": true}`. - CloudFormation calls it again, and it polls `StateName` until the cluster reaches `IDLE`. [M25; R5] - **D3** This is the CloudFormation CLI progress-chaining and callback pattern, designed for stabilization waits of minutes or hours. [M26; A4] - **D4** E [source]
- - **G1** Newer types include: - from M: `stream-instance`, `stream-connection`, `search-deployment`, `private-endpoint-aws`, `organization`, `api-key`; - from H and P: `stream-processor`, `stream-workspace`, `stream-privatelink-endpoint`, `backup-compliance-policy`, `log-integration`, `mongodb-employee-access-grant`, `resource-policy`, `flex-cluster`, and the service-account family. [M39,H34,P-C09; R1,R11] - **G2** `private-endpoint` is marked deprecated. [M39,P-C08; R1] - **G3** General support for M2/M5 clusters in Atlas CloudFormation ended on 2026-01-22. Serverless private endpoints and th [source]
- - The CDK construct library as its own concept (L1/L2/L3, the jsii multi-language build). - Partner Solution `cfn-ps-mongodb-atlas`. - Atlas Service Account OAuth adoption across IaC tools. - Secrets Manager managed rotation (`MongoDBAtlasServiceAccount`, `MongoDBAtlasDatabaseUser`). - Cloud Control API as an Atlas control plane. - The Lambda `provided.al2` → `provided.al2023` risk for third-party registry types. - Flex migration across IaC tools. - Version governance for the CloudFormation registry. [source]
- In scope: the `MongoDB::Atlas::*` third-party public CloudFormation extensions (repo `mongodb/mongodbatlas-cloudformation-resources`), how they are activated, authenticated, versioned, and how their handlers fail. Also the CDK wrapper only where it changes CFN behaviour. Out of scope: Terraform, AKO, Pulumi, the Atlas Admin API in general, and the parent-domain comparison of IaC tools. [source]
- In scope: how the `MongoDB::Atlas::*` CloudFormation resource types work internally. That covers registry activation, the execution role, credential profiles, the handler lifecycle, schema invariants, and the limits and failure modes of these types. [source]
- 39. The current resource README lists more than 45 types. These include `stream-instance`, `stream-connection`, `search-deployment`, `private-endpoint-aws`, `organization` and `api-key`. `private-endpoint` is marked deprecated and `resource-policy` is marked Beta. — https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/cfn-resources/README.md 40. Flex clusters are created through `MongoDB::Atlas::Cluster`, not `MongoDB::Atlas::FlexCluster`. MongoDB says future upgrades will come only through `MongoDB::Atlas::Cluster`. — https://www.mongodb.com/docs/atlas/flex-migration/ [source]
- - **C-30** `awscdk-resources-mongodbatlas` now ships on npm, PyPI, NuGet (`MongoDB.AWSCDKResourcesMongoDBAtlas`), Maven (`org.mongodb:awscdk-resources-mongodbatlas`), and Go (`github.com/mongodb/awscdk-resources-mongodbatlas-go`). The parent's "promised" languages have therefore shipped. https://github.com/mongodb/awscdk-resources-mongodbatlas - **C-31** CDK v4.0.0 (2026-03-26) had the breaking change "Remove serverless". v3.10.0 (2025-03-28) had deprecated ServerlessInstance/ServerlessPrivateEndpoint. v3.13.0 (2025-09-15) added FlexCluster. https://github.com/mongodb/awscdk-resources-mongodba [source]
- 43. Issue #20 (2020-05-14): a `MongoDB::Atlas::Cluster` stack sat in `CREATE_IN_PROGRESS` for about 5 minutes. It then failed with `error fetching cluster info (...): Get ... unexpected EOF`. The half-created cluster went into auto-shutdown and then disappeared from Atlas. Re-running the same template succeeded. — https://github.com/mongodb/mongodbatlas-cloudformation-resources/issues/20 44. Lesson: a transient error while the handler polls the cluster fails the whole stack operation. The rollback can then delete or orphan the Atlas-side resource. Claim 25's 40 s callback loop narrows this win [source]
Comparisons and alternatives
- - **H1** Issue #20 (2020-05-14): the stack failed with `error fetching cluster info … unexpected EOF` after about 5 minutes. The half-created cluster auto-shut down and disappeared, and a retry succeeded. [M43,H3,E27; R19] - **H2** Issue #23 (2020-05-15): project create returned `409 … A group with name "…" already exists`. The rollback did not delete the Atlas project, which was left orphaned. [E26; R20] - **H3** Issue #87 (2021-06-12): requests got `403 … IP address 18.118.114.43 is not allowed`. The handler's egress IP changes on every deploy. The issue closed with no fix. [H11,E18; R21] - [source]
- 1. **AWS-only clusters?** MongoDB's integration page says: "CloudFormation only deploys MongoDB Atlas clusters to AWS Cloud. For Azure or Google Cloud support, we suggest either our Terraform Atlas Provider or CDK." https://www.mongodb.com/products/integrations/aws-cloudformation — but the `MongoDB::Atlas::Cluster` schema's `ProviderName` enum includes `"AWS", "GCP", "AZURE", "TENANT", "FLEX"` https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/mongodb-atlas-cluster.json. The page also recommends CDK for multi-cloud, although CDK synthes [source]
- | # | Position A | Position B (and C) | |---|---|---| | X1 Auth | A search-engine summary says profiles accept SA `clientId`/`clientSecret` (M). The parent says "OAuth or Digest". | `profile.go`/`util.go` show Digest only (M,H,E,P). The `MongoDBAtlasServiceAccount` secret type is a Secrets Manager rotation feature, and no source shows CloudFormation consuming it. | | X2 Trust principals | 3 principals: README; P's sample `execution-role.yaml` | 2 principals: M's `execute-role.template.yml`. AWS docs show 1. Which principals are required is undocumented. | | X3 Role permissions | Sample role us [source]
- 31. "Logging for AWS CloudFormation Public extensions is currently disabled". Handler-side debugging relies on the stack event status message, plus `DebugClient` in the profile. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 32. Production support requires an Atlas support plan (Developer tier or above). GitHub issues are monitored without an SLA. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 33. The CDK repo auto-closes stale issues after 10 days of inactivity. This matches claims 28–29, where [source]
- - **Service Account (OAuth 2.0) support in the profile.** A search-engine summary claimed the CloudFormation resources accept a service-account `clientId`/`clientSecret` in the profile. The primary sources contradict this. The README documents only `PublicKey`/`PrivateKey` (https://github.com/mongodb/mongodbatlas-cloudformation-resources). `util.go` on `master` builds only a Digest transport (https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/util/util.go). The `MongoDBAtlasServiceAccount` secret type (https://docs.aws.amazon.com/secretsmanager [source]
- 20. Third-party handlers default to a 120-minute `timeoutInMinutes` per operation (min 2, max 2160). https://docs.aws.amazon.com/cloudformation-cli/latest/userguide/resource-type-schema.html 21. The `MongoDB::Atlas::Cluster` schema sets no `timeoutInMinutes`, so it inherits the 120-minute default. Inference: any cluster create/update/delete that takes longer than this fails the stack while Atlas keeps working. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/mongodb-atlas-cluster.json 22. The cluster's `createOnlyProperties` are `Name [source]
- - **E1** `ProjectId` and `Name` are required. [M30; R3] - **E2** ⚠ The create-only properties are `Profile`, `ProjectId`, `Name` and `GlobalClusterSelfManagedSharding`. The `primaryIdentifier` is `ProjectId`+`Name`+`Profile`. [M30,E22,P-C21; R3,R4] - **E3** By default, replacement creates the new resource before deleting the old one, unless the schema sets `replacementStrategy: delete_then_create`. [M32,E23,P-C22; A5] - **E4** *Inference, untested, and both E and P agree:* changing `Profile` replaces the cluster. Because the name and project stay the same, the create step collides and the stac [source]
- Met. The pass used 4 independent hosts: docs.aws.amazon.com (3 pages), mongodb.com (2 pages), github.com / raw.githubusercontent.com (MongoDB repos, issues, source), and turbogeek.co.uk (practitioner report). The pass looked for disconfirming evidence, which produced disagreements 1–3 and both parent corrections. Limits: Firecrawl, `gh` and shell were unavailable in this session, so all fetches went through WebFetch summaries of each page, and quoted code came from a summarizing model rather than raw bytes. Claims 15 and 21 and disagreement 4 should be re-verified against raw source before any [source]
- 1. **v0.1.0 date.** The tags page gives May 12, 2020. The releases-page summary showed "April 24" for both v0.1.0 and v0.2.0 with no year. Issue #20 (May 14, 2020) supports a 2020 origin. The tags page is preferred, but the releases-page date was not re-read verbatim. 2. **Resource count.** "33" comes from the GA blog (Feb 2023) and the v0.2.0 note (Apr 2023), against about 58 directories on master today. The two reads gave inconsistent totals of 61 and 67 subdirectories, so the current number needs a direct `gh api` listing. 3. **Service accounts.** Service-account resource types exist (claim [source]
Facts and statements
- 35. MongoDB says CloudFormation import works for its Atlas resources. — https://github.com/mongodb/mongodbatlas-cloudformation-resources 36. CloudFormation supports import and drift detection for private resource types only if their provisioning type is `FULLY_MUTABLE` or `IMMUTABLE` and a default version is registered. An activated public extension counts as a private type (claim 2). — https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/resource-import-supported-resources.html 37. Drift comparison can be tuned with schema `propertyTransform` entries to avoid false drift. — https:// [source]
- - **C-01** CloudFormation does not pre-install MongoDB's Atlas resource types. You activate each type per AWS account and per Region. Activation creates a private-extension entry in that account's registry. https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public.html - **C-02** MongoDB tells you to activate each `MONGODB::ATLAS::[RESOURCE-NAME]` in every region and every account you deploy from. It also says to remove any conflicting private extension that uses the same namespace. https://github.com/mongodb/mongodbatlas-cloudformation-resources - **C-03** Activation take [source]
- **Next pass, ranked by how much each item would settle:** 1. Raw-read `cluster/mongodb-atlas-cluster.json`: its `handlers` (list?), `timeoutInMinutes`, permissions and `provisioningType`. Settles X3, X5 and F2. 2. Run `aws cloudformation list-types --visibility PUBLIC --filters TypeNamePrefix=MongoDB::Atlas` in each target Region. Settles X4, X13 and X18. 3. Raw-read `profile.go` and `constants.go`. Settles X1, X10 and X11. 4. Trace the fix PR and version for #1233 (settles X9), and the status of #1489. 5. Check the status of `FlexCluster` against the flex-migration doc (X6). 6. Check MongoDB' [source]
- 17. If an organization is created in the Atlas UI, Atlas requires an IP access list for the Admin API by default. Requests from IPs not on the list get HTTP 403. https://www.mongodb.com/docs/atlas/configure-api-access/ 18. CFN handlers call Atlas from AWS-managed infrastructure whose egress IPs change between deployments. In practice this produced `IP address 18.118.114.43 is not allowed to access this resource`, and the reporter called allow-listing AWS regional ranges "impractical" and "insecure". The issue closed with no documented fix. https://github.com/mongodb/mongodbatlas-cloudformation [source]
- Out of scope: the AWS CDK package (a separate frontier item), Terraform, AKO, Pulumi, and the parent "Atlas IaC" comparison. Claims already in the parent extract are not repeated as new findings. That includes the `MongoDB::Atlas::*` namespace, the repo name, per-region `activate-type`, and "33+ resources". [source]
- 14. Credentials are stored in an AWS Secrets Manager secret named `cfn/atlas/profile/{ProfileName}`. The secret value is the JSON `{"PublicKey": …, "PrivateKey": …}`. — https://github.com/mongodb/mongodbatlas-cloudformation-resources 15. A template's `Profile` property holds only the profile name, not the full secret path. — https://github.com/mongodb/mongodbatlas-cloudformation-resources 16. If `Profile` is omitted, the handler calls `SetDefaultProfileIfNotDefined` and uses the `default` profile. — https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-reso [source]
- - **C-39** `MongoDB::Atlas::ProjectIpAccessList` updates by deleting every entry and then recreating the list. This opens a connectivity gap. Concurrent multi-region CDK deploys that share entries can race and leave entries deleted. Issue #1489 has been open since 2025-11-26. https://github.com/mongodb/mongodbatlas-cloudformation-resources/issues/1489 - **C-40** An import change set stalled in `CREATE_IN_PROGRESS` for about an hour and then failed (issue #506, marked stale, no documented fix). This contradicts the unqualified "import is supported" in C-24. https://github.com/mongodb/mongodbatl [source]
- 1. https://github.com/mongodb/mongodbatlas-cloudformation-resources 2. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 3. https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/cfn-resources/README.md 4. https://github.com/mongodb/mongodbatlas-cloudformation-resources/tree/master/cfn-resources 5. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/profile/profile.go 6. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/util/co [source]
- 1. **"33+ resources" is out of date.** 33 was the count at GA (Feb–Apr 2023). The current counts conflict with each other (see disagreement X4). [H13,H16,M39,P-C08,P-C09] 2. **CDK "Python/Java/Go/.NET promised" is out of date.** Packages now ship on npm, PyPI, NuGet `MongoDB.AWSCDKResourcesMongoDBAtlas`, Maven `org.mongodb:awscdk-resources-mongodbatlas` and Go `github.com/mongodb/awscdk-resources-mongodbatlas-go`. [H36,E-corr,P-C30; I-3] 3. **CDK "L1/L2" is now "L1, L2 and L3"** according to the CDK README. [H36,E-corr; I-3] 4. **"OAuth 2.0 or HTTP Digest" does not hold for CloudFormation.** O [source]
- Also: the Atlas "Infrastructure as Code" docs page lists CloudFormation but not CDK. [H37; W2] [source]
- **AWS** - A1 https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public.html - A2 https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public-activate-extension.html - A3 https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/resource-import-supported-resources.html - A4 https://docs.aws.amazon.com/cloudformation-cli/latest/userguide/resource-type-develop-stabilize.html - A5 https://docs.aws.amazon.com/cloudformation-cli/latest/userguide/resource-type-schema.html - A6 https://docs.aws.amazon.com/cloudformation-cli/latest/userguide/resource-type-te [source]
- **MongoDB web (not inherited)** - W1 https://www.mongodb.com/blog/post/deploy-manage-mongodb-atlas-aws-cloud-formation - W2 https://www.mongodb.com/docs/atlas/infrastructure/ - W3 https://www.mongodb.com/docs/atlas/flex-migration/ - W4 https://www.mongodb.com/docs/atlas/configure-api-access/ - W5 https://www.mongodb.com/products/integrations/aws-cloudformation - W6 https://www.mongodb.com/resources/products/platform/deploy-manage-mongodb-atlas-aws-cloud-formation [source]
- 11. Credentials live in Secrets Manager as `cfn/atlas/profile/{ProfileName}` with JSON `{"PublicKey": ..., "PrivateKey": ...}`. The template's `Profile` property takes the bare profile name, not the secret name. Passing `cfn/atlas/profile/X` is a documented misconfiguration. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md 12. If `Profile` is omitted, the handler uses `default`. https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/mongodb-atlas-cluster.json 13. The CDK README gives the reaso [source]
- - https://github.com/mongodb/mongodbatlas-cloudformation-resources - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/mongodb-atlas-cluster.json - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/profile/profile.go - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/util/util.go - https://github.com/mongodb/mongodbatlas-cloudformation-r [source]
- - The parent says CDK Python/Java/Go/.NET support is "promised". That was true in February 2023 (claim 14) but is now stale: all four are published (claim 36). - The parent says CDK wraps resources in "L1/L2" constructs. The README now claims L1, L2 and L3 (claim 36). - The parent counts "33+ resources". The figure 33 is the February–April 2023 GA count (claims 13, 16). The current tree holds about 58 types (claim 34, ⚠). - The parent says every IaC tool calls the API "under OAuth 2.0 or HTTP Digest". For CloudFormation, only Digest via Programmatic API keys is evidenced (claim 30, ⚠). Service [source]
- Verdict: **BUDGET_EXHAUSTED (soft stop), not saturated.** Further passes would likely still add: per-resource CHANGELOG dates, the date the `ApiKeys`→`Profile` cutover shipped, the publisher ID and current registry version numbers from `aws cloudformation describe-type`, and per-type serverless deprecation on the CloudFormation side. [source]
- - https://github.com/mongodb/mongodbatlas-cloudformation-resources - https://github.com/mongodb/mongodbatlas-cloudformation-resources/tags - https://github.com/mongodb/mongodbatlas-cloudformation-resources/releases - https://github.com/mongodb/mongodbatlas-cloudformation-resources/tree/master/cfn-resources - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/profile/profile.go - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation [source]
- - The CDK construct library as its own concept: L1/L2/L3 design and the multi-language jsii build. - The AWS Partner Solution `cfn-ps-mongodb-atlas` as its own concept. - Atlas Service Account OAuth adoption across the IaC tools, a cross-tool question for the parent. [source]
- 24. The handlers are written in Go. Each resource exposes `Create`, `Read`, `Update`, `Delete` and `List` functions, and each returns a `handler.ProgressEvent`. — https://pkg.go.dev/github.com/mongodb/mongodbatlas-cloudformation-resources/cluster/cmd/resource 25. The cluster `Create` handler does not block until the cluster is ready. It returns `OperationStatus: InProgress` with `CallbackDelaySeconds: 40` and `CallbackContext {"callbackCluster": true}`. CloudFormation then calls the handler again, and the handler polls `StateName` until it reaches the target state (`IDLE`, passing through `CRE [source]
- Met, with gaps. This run used more than 3 independent hosts: `github.com` / `raw.githubusercontent.com` (MongoDB repo), `docs.aws.amazon.com` (4 separate AWS docs: CloudFormation registry, CLI schema, Secrets Manager, Cloud Control), `www.mongodb.com` (blog + flex-migration docs), and `pkg.go.dev`. Two disconfirming lines of evidence were found: GitHub issue #20, and the source code that contradicts the service-account summary. [source]
- - AWS CDK `awscdk-resources-mongodbatlas` L1/L2/L3 constructs (sibling frontier item). - AWS Partner Solutions templates for Atlas (quick-start reference architectures). - Secrets Manager managed rotation for Atlas service accounts and database users (`MongoDBAtlasServiceAccount`, `MongoDBAtlasDatabaseUser`). - Atlas Flex cluster migration tooling across IaC tools. [source]
- - https://github.com/mongodb/mongodbatlas-cloudformation-resources - https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/cfn-resources/README.md - https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/cfn-resources/cluster/docs/README.md - https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/examples/profile-secret.yaml - https://github.com/mongodb/mongodbatlas-cloudformation-resources/issues/20 - https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/execute-role.template.yml [source]
- Child deltas against the inherited parent facts: - The parent's "33+ resources" figure is stale (see C-07 to C-09). - The parent says CDK supports TypeScript/JavaScript, "with Python/Java/Go/.NET support promised". That is also stale (see C-30). - The parent says tool choice "depends on where your platform engineering already lives, not on capability gaps". This report found real capability gaps for CloudFormation (see C-15, C-16, C-34 and Disagreements D-1). [source]
- - **C-28** With auto-update on, the activated type moves to new minor versions at the next stack operation. Major versions always need a manual update. Updating the type does not touch resources that are already provisioned. https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public.html - **C-29** AWS warns that different accounts and Regions can end up on different versions of the same extension. The same template can then behave differently. https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/registry-public.html - **C-29a** The repo versions each resource wit [source]
- - **C-43** The AWS Partner Solution "MongoDB Atlas on AWS" (doc dated February 2023) deploys a 2-AZ VPC, VPC peering, a single-region M10 cluster, a DB user, and an IP access list entry. It auto-activates the Atlas types on first deploy, with a `ActivateMongoDBResources` parameter to skip activation later, and it uses the same `cfn/atlas/profile/${ProfileName}` secret. https://aws-ia.github.io/cfn-ps-mongodb-atlas/ [source]
- Non-inherited origins: 1. **AWS**: docs.aws.amazon.com, aws.amazon.com, aws-ia.github.io. 2. **MongoDB docs and marketing pages** other than the GA blog (W1–W6). 3. **turbogeek.co.uk**: independent practitioner (T1). 4. **PyPI and npm registry metadata** (G1–G3). 5. **pkg.go.dev** (G4). [source]
- Counting only origins independent of MongoDB, AWS and T1 still pass. Third-party issue reporters strengthen this, though their reports are hosted in I-1. **The gate is met.** [source]
- **MongoDB CloudFormation repo (same origin as I-1)** - R1 https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/cfn-resources/README.md - R2 https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/README.md - R3 https://github.com/mongodb/mongodbatlas-cloudformation-resources/blob/master/cfn-resources/cluster/docs/README.md - R4 https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-resources/master/cfn-resources/cluster/mongodb-atlas-cluster.json - R5 https://raw.githubusercontent.com/mongodb/mongodbatlas-cloudformation-reso [source]
- **Met, with caveats.** The run used 6 hosts: mongodb.com, aws.amazon.com, github.com (MongoDB-owned repos plus third-party issue reporters), aws-ia.github.io, pypi.org and registry.npmjs.org. The sources independent of MongoDB are AWS, the PyPI and npm registry metadata, and the issue reporters. The disconfirming sources are issues #20 and #87, the stale CDK-language promise, and the `profile.go` auth gap. Claims marked ⚠ rest on one WebFetch read and need a direct check with `gh`. [source]
- Limits on this run: - Shell and Firecrawl tools were denied in this session. All evidence came through `WebFetch`/`WebSearch`, which return model-summarised page text. Verbatim quotes above are as the fetch tool returned them. - The shared parent-source cache was not read. Its pages cover AKO, Terraform and the Admin API, not CloudFormation. [source]
- As of 2026-10-02. Parent context: MongoDB Atlas Infrastructure as Code. [source]
- Out of scope: Terraform, AKO, Pulumi, Atlas CLI, and the Atlas Admin API as tools in their own right. Those are sibling frontier items. [source]
- Method: 6 passes (Pass 0 to Pass 5). Firecrawl, `gh`, and `curl` were denied in this non-interactive session, so every source was read with WebFetch/WebSearch. No shared-source cache page was relevant to the CloudFormation delta, so none was used. [source]
- 1. Bake activation into account vending. Use one `activate-type` per type × Region × account, with a pinned execution role, and decide auto-update once for the whole fleet (C-01, C-05, C-28, C-29). 2. Treat `Profile` as immutable per stack. Rotate PAK values inside the existing secret (C-21, C-22a). 3. Grant `kms:Decrypt` before you move the profile secret to a CMK (C-19a). 4. Avoid `ProjectIpAccessList` updates on hot paths, or split entries across stacks with no overlap (C-39). 5. Do not rely on CloudFormation drift results for `DatabaseUser` without checking the resource version (C-25). 6. [source]
- Quality gate: **met**. Independent hosts: github.com (mongodb repos), raw.githubusercontent.com (same origin as github.com, not counted separately), docs.aws.amazon.com, aws.amazon.com, mongodb.com, aws-ia.github.io, turbogeek.co.uk. That is at least 5 independent hosts, with primary sources from both vendors and a disconfirming field report (C-42) and issues (C-39, C-40). [source]
Related concepts
- AWS — is a part of AWS CloudFormation Atlas Resources
- Atlas — is a part of AWS CloudFormation Atlas Resources
- CloudFormation — is a part of AWS CloudFormation Atlas Resources
- Resources — is a part of AWS CloudFormation Atlas Resources
Children
- No children recorded.