diff --git a/aws-infrastructure.md b/aws-infrastructure.md index b818d5f..bd6253d 100644 --- a/aws-infrastructure.md +++ b/aws-infrastructure.md @@ -13,13 +13,21 @@ These apply to every Lambda in every project. Verify, don't assume. | Setting | Value | |---|---| -| Runtime | Python 3.12 or Node 24.x | +| Runtime | Python 3.12 or Node 24.x (`nodejs24.x`) | | Architecture | arm64 | | Log retention | 60 days (explicit in IaC template) | | Naming | kebab-case, matching the stack name prefix | Never rely on the CloudWatch default for log retention. Always set `RetentionInDays` explicitly in the template. +### Node runtime + +This is the canonical statement; [dev-environment.md](dev-environment.md#nodejs) and [cdk-project-layout.md](cdk-project-layout.md#lambda-defaults) defer to it. + +- **`nodejs24.x` is the standard.** Every new Node Lambda targets it, set explicitly in the IaC template. +- **`nodejs22.x` is legacy only.** It is valid for functions that already run on it, and those move to 24.x before the AWS deprecation date of 2027-04-30. Do not start a new function on it. +- **Never target `nodejs26.x`,** including once AWS ships it. Lambda applies runtime updates automatically, so a fresh major is only adopted after it has been generally available on Lambda for a full quarter, and only by a deliberate change to this page. Odd majors (25.x, 27.x) never become Lambda runtimes at all. + ## CDK Version Policy Pin `aws-cdk-lib` to an exact version (no `^`, `~`, or `>=`) and let Dependabot keep it current. There is no static "blessed version" — the org standard is the latest release that passes the gates below. Do not add blanket `dependabot.yml` ignore entries for `aws-cdk-lib`; that is how pins rot into carrying known vulnerabilities. diff --git a/dev-environment.md b/dev-environment.md index a727fb1..8a80486 100644 --- a/dev-environment.md +++ b/dev-environment.md @@ -35,7 +35,7 @@ When troubleshooting Python issues, check that pyenv is active before anything e ## Node.js - Local: Node 24 / npm 11 (generates `lockfileVersion: 3`) -- Lambda: Node 22.x or 24.x (set explicitly in IaC) +- Lambda: `nodejs24.x`, set explicitly in IaC. `nodejs22.x` is legacy only and never `nodejs26.x`; see [AWS Infrastructure](aws-infrastructure.md#node-runtime) for the canonical rule - Reusable workflows: always pass `node-version: "24"` (the default is 22 / npm 10, which can fail `npm ci` on npm 11 lockfiles) ## macOS launchd and the TCC Sandbox