Mastering AWS CDK v2 (TypeScript)
Focused guidance for building, deploying, and troubleshooting AWS CDK v2 infrastructure in TypeScript.
Contents
Use This Skill When
- Building new CDK apps or stacks in TypeScript
- Refactoring or splitting stacks to manage limits
- Debugging synth/diff/deploy failures or CloudFormation rollbacks
- Importing existing resources into CDK management
- Driving stacks from JSON/YAML configuration files
- Setting up GitHub Actions OIDC deployments
- Implementing service patterns across AWS managed services
- Writing CDK tests and running security checks
Trigger Terms
Use for queries mentioning: cdk, cdk deploy, cdk diff, cdk synth, cdk import, cdk watch, cdk refactor, cdk bootstrap, cdk-nag, hotswap, CloudFormation, stack rollback, cdk.context.json, cdk.json, SSM Parameter Store, hnb659fds, or OIDC GitHub Actions.
Quick Start
- Confirm target account, region, and environment (dev/stage/prod).
- Run
cdk synth then cdk diff to validate changes.
- Deploy with
cdk deploy --require-approval=never in CI.
Workflow
1) Intake
Collect:
- account and region
- environment name and stage
- target services and integrations
- existing resources to import or avoid replacement
2) Stack Design
- Keep stacks under 500 resources (split or use nested stacks)
- Pass outputs via props or explicit exports
- Set removal policies for stateful resources (retain by default)
3) Implement
- Prefer L2 constructs; use L1 only for gaps
- Apply least-privilege IAM grants
- Keep resource names deterministic
4) Validate
cdk synth to inspect the template
cdk diff to review changes
cdk doctor for environment issues
5) Deploy
- Ensure bootstrap completed for the account/region
- Review CloudFormation events on failure
- Use
--require-approval=never only for CI
6) Observability
- Add log retention, alarms, and dashboards early
- Use X-Ray where distributed tracing matters
- See observability.md
Reference Map
| Task |
Reference |
| Troubleshooting errors |
troubleshooting.md |
| CI/CD with GitHub Actions |
cicd-github.md |
| Service-specific patterns |
services.md |
| Observability setup |
observability.md |
| Architecture and operations |
architecture-ops.md |
| Testing and security |
testing-security.md |
| Latest features |
latest-features.md |
Guardrails
- Do not modify CloudFormation-managed resources in the console
- Avoid dynamic values (Date.now, random) in resource definitions
- Use
env: { account, region } for lookups (VPC/AZ/AMI)
- Use stable IDs when generating constructs from config data
- Use
cdk import (adopt) for existing resources; use fromXxx only for read-only references
- Do not use hotswap in production pipelines
Debugging Checklist
Copy and track progress:
Debugging Progress:
- [ ] Check CloudFormation events (Console -> Stack -> Events)
- [ ] Re-run with verbose output: `cdk deploy --progress events`
- [ ] Inspect template: `cdk synth > template.yaml`
- [ ] Run diff: `cdk diff`
- [ ] Check service logs (Lambda: CloudWatch, ECS: task events)
- [ ] Run `cdk doctor`
When Not to Use
- Terraform/Pulumi or raw CloudFormation templates
- Manual console-driven resource management
- CDK in Python/Java/Go/C# (TypeScript only)
Reference Files
- references/troubleshooting.md -- Error messages and fixes
- references/cicd-github.md -- GitHub Actions OIDC setup
- references/services.md -- Lambda, ECS, MSK, DynamoDB, Aurora, S3, EventBridge patterns
- references/observability.md -- CloudWatch, X-Ray, dashboards, alarms
- references/architecture-ops.md -- Determinism, configuration-driven patterns, imports, drift, and operational workflows
- references/testing-security.md -- CDK testing, cdk-nag, and compliance checks
- references/latest-features.md -- New constructs, CLI capabilities, and recent patterns
1---2name: mastering-aws-cdk3description: Guides AWS CDK v2 infrastructure-as-code development in TypeScript with patterns, troubleshooting, and deployment workflows. Use when creating or refactoring CDK stacks, debugging CloudFormation or CDK deploy errors, setting up CI/CD with GitHub Actions OIDC, or integrating AWS services (Lambda, API Gateway, ECS/Fargate, S3, DynamoDB, EventBridge, Aurora, MSK).4---56# Mastering AWS CDK v2 (TypeScript)78Focused guidance for building, deploying, and troubleshooting AWS CDK v2 infrastructure in TypeScript.910## Contents1112- [Use This Skill When](#use-this-skill-when)13- [Trigger Terms](#trigger-terms)14- [Quick Start](#quick-start)15- [Workflow](#workflow)16- [Reference Map](#reference-map)17- [Guardrails](#guardrails)18- [Debugging Checklist](#debugging-checklist)19- [When Not to Use](#when-not-to-use)20- [Reference Files](#reference-files)2122## Use This Skill When2324- Building new CDK apps or stacks in TypeScript25- Refactoring or splitting stacks to manage limits26- Debugging synth/diff/deploy failures or CloudFormation rollbacks27- Importing existing resources into CDK management28- Driving stacks from JSON/YAML configuration files29- Setting up GitHub Actions OIDC deployments30- Implementing service patterns across AWS managed services31- Writing CDK tests and running security checks3233## Trigger Terms3435Use for queries mentioning: `cdk`, `cdk deploy`, `cdk diff`, `cdk synth`, `cdk import`, `cdk watch`, `cdk refactor`, `cdk bootstrap`, `cdk-nag`, `hotswap`, `CloudFormation`, `stack rollback`, `cdk.context.json`, `cdk.json`, `SSM Parameter Store`, `hnb659fds`, or `OIDC GitHub Actions`.3637## Quick Start38391. Confirm target account, region, and environment (dev/stage/prod).402. Run `cdk synth` then `cdk diff` to validate changes.413. Deploy with `cdk deploy --require-approval=never` in CI.4243## Workflow4445### 1) Intake4647Collect:48- account and region49- environment name and stage50- target services and integrations51- existing resources to import or avoid replacement5253### 2) Stack Design5455- Keep stacks under 500 resources (split or use nested stacks)56- Pass outputs via props or explicit exports57- Set removal policies for stateful resources (retain by default)5859### 3) Implement6061- Prefer L2 constructs; use L1 only for gaps62- Apply least-privilege IAM grants63- Keep resource names deterministic6465### 4) Validate6667- `cdk synth` to inspect the template68- `cdk diff` to review changes69- `cdk doctor` for environment issues7071### 5) Deploy7273- Ensure bootstrap completed for the account/region74- Review CloudFormation events on failure75- Use `--require-approval=never` only for CI7677### 6) Observability7879- Add log retention, alarms, and dashboards early80- Use X-Ray where distributed tracing matters81- See [observability.md](references/observability.md)8283## Reference Map8485| Task | Reference |86|------|-----------|87| Troubleshooting errors | [troubleshooting.md](references/troubleshooting.md) |88| CI/CD with GitHub Actions | [cicd-github.md](references/cicd-github.md) |89| Service-specific patterns | [services.md](references/services.md) |90| Observability setup | [observability.md](references/observability.md) |91| Architecture and operations | [architecture-ops.md](references/architecture-ops.md) |92| Testing and security | [testing-security.md](references/testing-security.md) |93| Latest features | [latest-features.md](references/latest-features.md) |9495## Guardrails9697- Do not modify CloudFormation-managed resources in the console98- Avoid dynamic values (Date.now, random) in resource definitions99- Use `env: { account, region }` for lookups (VPC/AZ/AMI)100- Use stable IDs when generating constructs from config data101- Use `cdk import` (adopt) for existing resources; use `fromXxx` only for read-only references102- Do not use hotswap in production pipelines103104## Debugging Checklist105106Copy and track progress:107```108Debugging Progress:109- [ ] Check CloudFormation events (Console -> Stack -> Events)110- [ ] Re-run with verbose output: `cdk deploy --progress events`111- [ ] Inspect template: `cdk synth > template.yaml`112- [ ] Run diff: `cdk diff`113- [ ] Check service logs (Lambda: CloudWatch, ECS: task events)114- [ ] Run `cdk doctor`115```116117## When Not to Use118119- Terraform/Pulumi or raw CloudFormation templates120- Manual console-driven resource management121- CDK in Python/Java/Go/C# (TypeScript only)122123## Reference Files124125- [references/troubleshooting.md](references/troubleshooting.md) -- Error messages and fixes126- [references/cicd-github.md](references/cicd-github.md) -- GitHub Actions OIDC setup127- [references/services.md](references/services.md) -- Lambda, ECS, MSK, DynamoDB, Aurora, S3, EventBridge patterns128- [references/observability.md](references/observability.md) -- CloudWatch, X-Ray, dashboards, alarms129- [references/architecture-ops.md](references/architecture-ops.md) -- Determinism, configuration-driven patterns, imports, drift, and operational workflows130- [references/testing-security.md](references/testing-security.md) -- CDK testing, cdk-nag, and compliance checks131- [references/latest-features.md](references/latest-features.md) -- New constructs, CLI capabilities, and recent patterns