Skip to main content

CDK CloudFormation Property Mixins

---

cdk-constructs: Stable


Auto-generated, type-safe CDK Mixins for every CloudFormation resource property. These allow you to apply L1 properties to any construct (L1, L2, or custom) using the Mixins mechanism from aws-cdk-lib.

Usage

For every CloudFormation resource, this package provides a CfnXxxPropsMixin class. Apply it using .with() or Mixins.of():

s3.Bucket(scope, "MyBucket").with(CfnBucketPropsMixin(
    versioning_configuration=CfnBucketPropsMixin.VersioningConfigurationProperty(status="Enabled"),
    public_access_block_configuration=CfnBucketPropsMixin.PublicAccessBlockConfigurationProperty(
        block_public_acls=True,
        block_public_policy=True
    )
))

Cross-Service References

Deeply nested properties support cross-service references:

my_key = kms.Key(scope, "MyKey")

s3.Bucket(scope, "EncryptedBucket").with(CfnBucketPropsMixin(
    bucket_encryption=CfnBucketPropsMixin.BucketEncryptionProperty(
        server_side_encryption_configuration=[CfnBucketPropsMixin.ServerSideEncryptionRuleProperty(
            server_side_encryption_by_default=CfnBucketPropsMixin.ServerSideEncryptionByDefaultProperty(
                sse_algorithm="aws:kms",
                kms_master_key_id=my_key
            )
        )]
    )
))

Merge Strategies

When a mixin is applied, its properties are merged onto the target resource using a merge strategy. The strategy controls what happens when both the mixin and the existing resource define the same property.

There are two built-in strategies:

PropertyMergeStrategy.combine() (default)

Deep merges nested objects from the mixin into the target. When both the existing and new value for a property are plain objects, their keys are merged recursively — existing keys are preserved and new keys are added. Primitives, arrays, and mismatched types are replaced by the mixin value.

This is useful when you want to add configuration without losing what's already set:

combine_bucket = s3.CfnBucket(scope, "CombineBucket")
combine_bucket.public_access_block_configuration = s3.CfnBucket.PublicAccessBlockConfigurationProperty(block_public_acls=True)

# Adds blockPublicPolicy while preserving the existing blockPublicAcls
combine_bucket.with(CfnBucketPropsMixin(
    public_access_block_configuration=CfnBucketPropsMixin.PublicAccessBlockConfigurationProperty(block_public_policy=True)
))

PropertyMergeStrategy.override()

Replaces existing property values with the mixin values. Each property is copied as-is without inspecting nested objects. Any previous value on the target is discarded.

This is useful when you want to fully replace a configuration:

from aws_cdk.cfn_property_mixins.aws_s3 import CfnBucketMixinProps
override_bucket = s3.CfnBucket(scope, "OverrideBucket")
override_bucket.public_access_block_configuration = s3.CfnBucket.PublicAccessBlockConfigurationProperty(block_public_acls=True)

# Replaces the entire publicAccessBlockConfiguration
override_bucket.with(CfnBucketPropsMixin(CfnBucketMixinProps(public_access_block_configuration=CfnBucketPropsMixin.PublicAccessBlockConfigurationProperty(block_public_policy=True)), strategy=PropertyMergeStrategy.override()))

Custom Strategies

You can implement IMergeStrategy to define your own merge behavior. The apply method receives the target object, source object, and an allowlist of property keys:

@jsii.implements(IMergeStrategy)
class ArrayAppendStrategy:
    def apply(self, target, source, allowed_keys):
        for key in allowed_keys:
            if key in source:
                if Array.is_array(target[key]):
                    # append to target
                    target[key] = target[key].concat(source[key])
                else:
                    # override
                    target[key] = source[key]

Deferred Values (Boxes)

Property mixins support Box-backed values. Most L2 constructs in aws-cdk-lib use Boxes internally to defer property computation until synthesis time. When a mixin encounters a Box on the target, the merge is automatically deferred — the merge strategy runs once the Box resolves, ensuring it operates on final values.

This means mixins work correctly with L2 constructs that use Boxes for properties like replicas, rules, or tags, without any special handling from the user:

from aws_cdk.cfn_property_mixins.aws_dynamodb import CfnGlobalTableMixinProps
# TableV2 uses a Box internally for replicas.
# The mixin defers the merge and appends the new replica at synthesis time.
table = dynamodb.TableV2(scope, "Table",
    partition_key=dynamodb.Attribute(name="pk", type=dynamodb.AttributeType.STRING),
    # L2 prop: pointInTimeRecovery is a boolean
    replicas=[dynamodb.ReplicaTableProps(region="us-east-1", point_in_time_recovery=True)]
)

# Mixins always use L1 (CloudFormation) property names and shapes,
# regardless of what the L2 API looks like.
table.with(CfnGlobalTablePropsMixin(CfnGlobalTableMixinProps(
    replicas=[CfnGlobalTablePropsMixin.ReplicaSpecificationProperty(
        region="eu-west-1",
        # L1 prop: pointInTimeRecoverySpecification is an object
        point_in_time_recovery_specification=CfnGlobalTablePropsMixin.PointInTimeRecoverySpecificationProperty(point_in_time_recovery_enabled=True)
    )]
), strategy=PropertyMergeStrategy.combine(arrays=ArrayMergeStrategy.append())))

Most L2 constructs in aws-cdk-lib use Boxes or Lazys internally to defer property computation until synthesis time. Property mixins detect these automatically and defer the merge until the value resolves, so the merge strategy always operates on final values — no special handling is needed from the user. The only case where merging cannot be deferred is a raw Token that is not backed by a Box. This is very rare in the AWS Construct Library, but may occur in third-party packages. If you encounter a construct where merging doesn't work as expected, please open an issue so we can investigate.

CloudFormation Property Mixins for Every Service

This package provides auto-generated property mixins for every CloudFormation resource across all AWS services. Each service has its own submodule that mirrors the aws-cdk-lib module structure. Import the mixin for the resource you want to configure from the corresponding service submodule:

from aws_cdk.cfn_property_mixins.aws_s3 import CfnBucketPropsMixin
from aws_cdk.cfn_property_mixins.aws_lambda import CfnFunctionPropsMixin
from aws_cdk.cfn_property_mixins.aws_dynamodb import CfnTablePropsMixin
from aws_cdk.cfn_property_mixins.aws_logs import CfnLogGroupPropsMixin
from aws_cdk.cfn_property_mixins.aws_cloudfront import CfnDistributionPropsMixin
from aws_cdk.cfn_property_mixins.aws_rds import CfnDBInstancePropsMixin

The naming convention follows a consistent pattern: for a CloudFormation resource AWS::S3::Bucket, the mixin class is CfnBucketPropsMixin and lives in the aws-s3 submodule. The mixin props interface is named CfnBucketMixinProps and all properties are optional, so you only need to specify the ones you want to set.

Property mixins work with any construct that has the target resource as its default child. This means you can apply them to L1 constructs, L2 constructs, and custom constructs alike:

# L1 construct
s3.CfnBucket(scope, "L1Bucket").with(CfnBucketPropsMixin(versioning_configuration=CfnBucketPropsMixin.VersioningConfigurationProperty(status="Enabled")))

# L2 construct — the mixin finds the CfnBucket default child
s3.Bucket(scope, "L2Bucket").with(CfnBucketPropsMixin(versioning_configuration=CfnBucketPropsMixin.VersioningConfigurationProperty(status="Enabled")))

Release files for aws-cdk.cfn-property-mixins 2.271.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for aws-cdk.cfn-property-mixins 2.271.0
File Size Uploaded
aws_cdk_cfn_property_mixins-2.271.0.tar.gz 24.9 MB Details

Built distribution (wheel)

Table of built distributions (wheels) for aws-cdk.cfn-property-mixins 2.271.0
File Interpreter ABI Platform
aws_cdk_cfn_property_mixins-2.271.0-py3-none-any.whl Python 3 none any Details

Total release size: 50.2 MB

Release files / aws_cdk_cfn_property_mixins-2.271.0.tar.gz

Download URL aws_cdk_cfn_property_mixins-2.271.0.tar.gz
Size 24.9 MB
Tags Source
SHA-256 checksum
How to use checksums
c380f14b4e1578e2ab188ae78b9fbb50da3091d33f7db96077d26c10e04cf6b2
BLAKE2b-256 checksum
How to use checksums
e0a3161f1f83b426f40e56b5856b7675b93e46972706e8b0fc7067c30dad5709
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.15

Release files / aws_cdk_cfn_property_mixins-2.271.0-py3-none-any.whl

Download URL aws_cdk_cfn_property_mixins-2.271.0-py3-none-any.whl
Size 25.3 MB
Tags Python 3
SHA-256 checksum
How to use checksums
68c03feba5e55bc6dd8dba76f25117dd2d803392aa60eea0e6a4c213c6fe823b
BLAKE2b-256 checksum
How to use checksums
1a3415d1dacf23f1d77b4d275280c4072bb4589f548160b6bf163b6c49e68955
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.15
Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page