cdktf synth fails with "jsii.errors.JSIIError: Missing required properties" for a resource config block
Explains the CDKTF synth-time JSIIError raised when a nested configuration block is missing a required property (e.g. applyServerSideEncryptionByDefault on an S3 encryption rule). Shows how to read the error, find the required property in the provider docs, and supply it. Use when cdktf synth raises JSIIError naming a specific construct type. Not for TypeScript compile errors or Terraform plan-time validation.
TL;DR
Supply the missing required property the error names. For aws.S3BucketServerSideEncryptionConfigurationRule, add applyServerSideEncryptionByDefault with your sseAlgorithm inside it.
The error
jsii.errors.JSIIError: Missing required properties for aws.S3BucketServerSideEncryptionConfigurationRule: applyServerSideEncryptionByDefaultFix it
- Read the construct type in the error (
aws.S3BucketServerSideEncryptionConfigurationRule) and the missing property (applyServerSideEncryptionByDefault). - Find where you configure that block in your stack code (e.g. the
serverSideEncryptionConfigurationof an S3 bucket). - Nest the required property correctly. Python example:
server_side_encryption_configuration={
"rule": {
"apply_server_side_encryption_by_default": {
"sse_algorithm": "aws:kms"
}
}
}TypeScript example:
serverSideEncryptionConfiguration: {
rule: {
applyServerSideEncryptionByDefault: { sseAlgorithm: "aws:kms" },
},
},- Re-run
cdktf synthand confirm the JSIIError is gone.
Expected result: synth completes and the S3 bucket resource appears in cdk.tf.json with the encryption block.
When to use this
cdktf synthraisesJSIIError: Missing required properties for [type]: [property]- You passed a nested block (encryption, versioning, logging) as a flat dict instead of the required nested shape
When NOT to use this
- The error is a TypeScript compile error (TS2305 etc.) about a missing export, not a JSII runtime error
- Terraform plan rejects the value after synth succeeds (that is provider-side validation, a different stage)
Root cause
The jsii kernel validates required properties when a construct is created, before any Terraform JSON is generated. CDKTF provider bindings mark nested blocks required by the provider schema, and many AWS blocks (like the S3 SSE rule) require a wrapper object even when you only want to set one inner field. Passing "sse_algorithm": "aws:kms" directly at the rule level skips the mandatory applyServerSideEncryptionByDefault wrapper, so the kernel rejects the construct.
Edge cases
- Property naming differs by language:
applyServerSideEncryptionByDefault(TS),apply_server_side_encryption_by_default(Python),ApplyServerSideEncryptionByDefault(Go). - Some blocks require the wrapper even when empty; check the provider schema via
cdktf get-generated docs when unsure.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.