aws-cdk.aws-certificatemanager
The CDK Construct Library for AWS::CertificateManager
Decision gist · record as of 2026-08-14
No—this package is end-of-support. AWS CDK v1 reached end-of-support on 2023-06-01 and this library is no longer being updated. Users should migrate to AWS CDK v2, which has a replacement package. Installing this package locks you into an unsupported framework version and exposes you to unpatched security issues in the v1 runtime.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires AWS CDK v1 environment; AWS CDK v1 is end-of-support as of 2023-06-01 and users should migrate to AWS CDK v2 instead.
- Low install friction with pure Python wheel distribution.
- Package is actively maintained in the AWS CDK repository, though marked as Development Status 7 (Inactive) because AWS CDK v1 reached end-of-support on 2023-06-01; users should migrate to AWS CDK v2.
License · maintenance · safety
Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive), allowing use in commercial and open-source projects with minimal restrictions.
last release 2023-06-19 (1152 days) · last repo commit 2026-08-14 · 12,868 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 156,954 downloads/mo, #10,771 on PyPI
Alternatives
Verify before relying
pip install aws-cdk.aws-certificatemanager
import aws_cdk.aws_certificatemanager as acm
import aws_cdk.aws_route53 as route53
hosted_zone = route53.HostedZone(self, "HostedZone", zone_name="example.com")
cert = acm.Certificate(self, "Certificate",
domain_name="hello.example.com",
validation=acm.CertificateValidation.from_dns(hosted_zone)
)- Whether AWS CDK v2 has a replacement package with equivalent functionality and whether migration path is straightforward.
- Specific account-level ACM certificate request limits and whether the 2000 default limit applies to all regions and account types.
What it is and what it does
This package provides CDK Constructs that wrap AWS Certificate Manager (ACM) functionality, allowing you to define SSL/TLS certificate provisioning as code within your infrastructure stack. It handles the complexity of creating, validating, and renewing certificates for domains, subdomains, and wildcard domains, with support for both public and private certificates. The library integrates with Route 53 for automated DNS validation, supports email validation as a fallback, and includes utilities for cross-region certificates needed by CloudFront.
The package depends on core CDK modules (aws-cdk.core, constructs, jsii) and integrates with related AWS services like Route 53, IAM, CloudWatch, and Private Certificate Authority. Because ACM certificate validation can take time—especially with manual DNS methods—the documentation recommends provisioning certificates in separate stacks or importing pre-existing certificates. The package also provides CloudWatch metrics for monitoring certificate expiry and creating renewal alarms.
Use it for
- Automate SSL/TLS certificate provisioning for web applications deployed via CDK, with Route 53 DNS validation.
- Create cross-region certificates for CloudFront distributions that require certificates in us-east-1.
- Issue private certificates from a Private Certificate Authority for internal service-to-service communication.
- Set up CloudWatch alarms to monitor certificate expiry and trigger renewal workflows before expiration.
- Import existing ACM certificates into CDK stacks by ARN for use with load balancers and CloudFront.
- Provision multi-domain certificates with subject alternative names across multiple Route 53 hosted zones.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
No—this package is end-of-support.
AWS CDK v1 reached end-of-support on 2023-06-01 and this library is no longer being updated. Users should migrate to AWS CDK v2, which has a replacement package. Installing this package locks you into an unsupported framework version and exposes you to unpatched security issues in the v1 runtime.
Install
aws-cdk-aws-certificatemanager on PyPI
Before you install
Low install friction with pure Python wheel distribution. Package is actively maintained in the AWS CDK repository, though marked as Development Status 7 (Inactive) because AWS CDK v1 reached end-of-support on 2023-06-01; users should migrate to AWS CDK v2.
Requires AWS CDK v1 environment; AWS CDK v1 is end-of-support as of 2023-06-01 and users should migrate to AWS CDK v2 instead.
License in practice
Licensed under Apache-2.0 (permissive), allowing use in commercial and open-source projects with minimal restrictions.
Quickstart
pip install aws-cdk.aws-certificatemanager
import aws_cdk.aws_certificatemanager as acm
import aws_cdk.aws_route53 as route53
hosted_zone = route53.HostedZone(self, "HostedZone", zone_name="example.com")
cert = acm.Certificate(self, "Certificate",
domain_name="hello.example.com",
validation=acm.CertificateValidation.from_dns(hosted_zone)
)
Verify before relying
- Whether AWS CDK v2 has a replacement package with equivalent functionality and whether migration path is straightforward.
- Specific account-level ACM certificate request limits and whether the 2000 default limit applies to all regions and account types.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release ~=3.7 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 10 packagesaws-cdk.aws-acmpcaaws-cdk.aws-cloudwatchaws-cdk.aws-iamaws-cdk.aws-lambdaaws-cdk.aws-route53aws-cdk.coreconstructsjsiipublicationtypeguard |
| Maintenance | Actively maintained 1,152 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 156,954 / month, #10,771 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 7 - InactiveFramework :: AWS CDKFramework :: AWS CDK :: 1Intended Audience :: DevelopersLicense :: OSI ApprovedOperating System :: OS IndependentProgramming Language :: JavaScriptProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Typing :: Typed |
Evidence: aws_cdk.aws_certificatemanager-1.204.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “acm constructs infrastructure as code”
- aws-cdk.aws-certificatemanagerProvides AWS CDK Constructs for provisioning and managing ACM…
- aws-cdk.aws-cloudfrontDefines AWS CloudFront distributions and behaviors as code using the…
- mypy-boto3-acmProvides type annotations and IDE autocompletion for boto3's AWS…
Give your agent the search over MCP, or paste the wish link into any chat.
More Build Tools packages
Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.
Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.
pip is the standard installer for Python packages, enabling you to download and install packages from the Python Package Index and other indexes into your Python environment.
Hatchling is a standards-compliant Python build backend that handles packaging, metadata, and distribution of Python projects when configured in a project's pyproject.toml file.
Generates Python gRPC service stubs and message classes from Protocol Buffer definitions, enabling developers to build gRPC clients and servers.
pre-commit is a framework for installing and running git hooks written in any language before commits are made, automating code quality and validation checks across multi-language projects.
Install it if your team needs consistent, automated validation at commit time.
See also aws-cdk.aws-acmpca · awsiot · aws-cdk.aws-servicediscovery · aws-cdk.aws-route53-targets · aws-cdk.aws-route53 · checkdmarc · aws-cdk.aws-cloudfront · aws-cdk.aws-imagebuilder · aws-cdk.aws-cloudwatch · aws-cdk.aws-autoscaling-common