docs(lambda): unify the node runtime rule on 24.x

The three pages disagreed: two listed Node 24.x while the workstation
page still allowed 22.x or 24.x, and none said anything about 26.x.
State the rule once under Lambda defaults (24.x standard, 22.x legacy
only until the 2027-04-30 deprecation, never 26.x) and have the other
two pages defer to it.
This commit is contained in:
Adam Moussa 2026-07-28 19:42:53 -04:00
parent fc0e9bdc93
commit 670336506f
No known key found for this signature in database
2 changed files with 10 additions and 2 deletions

View file

@ -13,13 +13,21 @@ These apply to every Lambda in every project. Verify, don't assume.
| Setting | Value |
|---|---|
| Runtime | Python 3.12 or Node 24.x |
| Runtime | Python 3.12 or Node 24.x (`nodejs24.x`) |
| Architecture | arm64 |
| Log retention | 60 days (explicit in IaC template) |
| Naming | kebab-case, matching the stack name prefix |
Never rely on the CloudWatch default for log retention. Always set `RetentionInDays` explicitly in the template.
### Node runtime
This is the canonical statement; [dev-environment.md](dev-environment.md#nodejs) and [cdk-project-layout.md](cdk-project-layout.md#lambda-defaults) defer to it.
- **`nodejs24.x` is the standard.** Every new Node Lambda targets it, set explicitly in the IaC template.
- **`nodejs22.x` is legacy only.** It is valid for functions that already run on it, and those move to 24.x before the AWS deprecation date of 2027-04-30. Do not start a new function on it.
- **Never target `nodejs26.x`,** including once AWS ships it. Lambda applies runtime updates automatically, so a fresh major is only adopted after it has been generally available on Lambda for a full quarter, and only by a deliberate change to this page. Odd majors (25.x, 27.x) never become Lambda runtimes at all.
## CDK Version Policy
Pin `aws-cdk-lib` to an exact version (no `^`, `~`, or `>=`) and let Dependabot keep it current. There is no static "blessed version" — the org standard is the latest release that passes the gates below. Do not add blanket `dependabot.yml` ignore entries for `aws-cdk-lib`; that is how pins rot into carrying known vulnerabilities.

View file

@ -35,7 +35,7 @@ When troubleshooting Python issues, check that pyenv is active before anything e
## Node.js
- Local: Node 24 / npm 11 (generates `lockfileVersion: 3`)
- Lambda: Node 22.x or 24.x (set explicitly in IaC)
- Lambda: `nodejs24.x`, set explicitly in IaC. `nodejs22.x` is legacy only and never `nodejs26.x`; see [AWS Infrastructure](aws-infrastructure.md#node-runtime) for the canonical rule
- Reusable workflows: always pass `node-version: "24"` (the default is 22 / npm 10, which can fail `npm ci` on npm 11 lockfiles)
## macOS launchd and the TCC Sandbox