← Platform Changes

Documentation — August 29, 2026

10 files changed, 78 insertions, 42 deletionsview the commit on the mirror.

AWS audit log role renamed to cortex-logs-ingestion-access-*; manual deployment method added for AWS, GCP and Azure

  • The AWS audit log reader role is renamed from CloudTrailReadRole / CortexLogsReadRole to cortex-logs-ingestion-access-*, including in the cross-account KMS key policy example.
  • A new Deployment Method advanced setting offers Infrastructure as Code (recommended) or Manual onboarding on AWS, Google Cloud Platform and Microsoft Azure.
  • Custom (BYOB) audit log collection is rebuilt around SNS: the Cortex-created SQS queue subscribes to your SNS topic, so S3 event notifications now target the topic rather than the queue.
  • Two new BYOB constraints are documented — the Control Tower log bucket must use Bucket owner enforced object ownership, and its objects may be encrypted under at most one customer-managed KMS key.

Highlights

Changes

10 files listed, 9 written up and shaded below.