Recommended Free Tools
To configure an AWS Glue job in Python CDK, define an execution role trusted by Glue, provide executable script code, and choose the job command and capacity settings that match the workload. Use the higher-level aws_glue.Job construct when its modeled properties fit; choose aws_glue.CfnJob when you need direct access to CloudFormation job properties.
Choose between aws_glue.Job and aws_glue.CfnJob
Python CDK provides two ways to define a Glue job. The L2 aws_glue.Job construct offers a higher-level interface for common job behavior, including a Code object for the script. The L1 aws_glue.CfnJob maps more directly to the CloudFormation resource and exposes its properties, such as command, worker_type, and number_of_workers. See the CfnJob API reference and JobProps API reference.
| Consideration | aws_glue.Job (L2) |
aws_glue.CfnJob (L1) |
|---|---|---|
| Abstraction | Higher-level construct for common job configuration. | Direct CloudFormation resource properties. |
| Script packaging | Requires a Code object, which can refer to an asset or S3 code. |
Set command.script_location to an S3 URI. |
| Configuration access | Use when its modeled properties cover the workload. | Use when you need exact CloudFormation fields or less commonly modeled options. |
| Arguments and role | Provides construct-level properties for job configuration; supply an IAM role trusted by Glue. | Specify the role ARN and CloudFormation job properties directly. |
Configure the role, script, and command
Execution role
Every job needs an IAM execution role that trusts the glue.amazonaws.com service principal. Add only the permissions the script actually needs, such as access to its input and output locations, catalog resources, network resources, and logging. The construct cannot infer those permissions from the script. Consult the JobProps role guidance.
Script location
For the L1 resource, set command.script_location to the S3 URI of the executable script. For the L2 construct, supply its required Code object; the code can be packaged as a local asset or referenced from S3. Ensure the selected location and the role’s permissions let the job retrieve the script.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
Command name
Choose the command name based on the workload: glueetl for Spark ETL, pythonshell for Python shell jobs, gluestreaming for streaming ETL, or glueray for Ray. The L1 command configuration is documented in the CfnJob JobCommandProperty reference.
Example: define a Spark ETL job with CfnJob
This example creates a role and a Spark ETL job using the L1 resource. Its Glue version, S3 path, worker count, retry count, timeout, and bookmark setting are example choices, not universal requirements.
Rank #2
from aws_cdk import Stack, aws_glue as glue, aws_iam as iam
from constructs import Construct
class GlueStack(Stack):
def __init__(self, scope: Construct, construct_id: str, **kwargs):
super().__init__(scope, construct_id, **kwargs)
role = iam.Role(
self, "GlueRole",
assumed_by=iam.ServicePrincipal("glue.amazonaws.com"),
)
# Add only the S3, catalog, network, and logging permissions required.
glue.CfnJob(
self, "EtlJob",
role=role.role_arn,
command=glue.CfnJob.JobCommandProperty(
name="glueetl",
python_version="3",
script_location="s3://example-bucket/scripts/etl.py",
),
glue_version="4.0",
worker_type="G.1X",
number_of_workers=10,
max_retries=1,
timeout=60,
default_arguments={"--job-bookmark-option": "job-bookmark-enable"},
)
Replace the example S3 URI with the script’s real location. Adjust the role policies, Glue version, worker sizing, connections, and arguments for the job. For an L2 definition, use aws_glue.Job with its required Code object and the properties modeled by that construct.
Set arguments without exposing secrets
Use job arguments for non-secret configuration, such as the bookmark option shown in the example. Do not put passwords, tokens, or other credentials in default_arguments: those values are emitted into the CloudFormation template. Retrieve secrets at runtime through an appropriate secret-management mechanism, and grant the execution role only the access needed to retrieve them. The JobProps reference also describes dedicated properties for construct-managed or Glue-reserved arguments.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Choose worker capacity and understand defaults
With CfnJob, set worker_type and number_of_workers explicitly when the workload requires specific capacity. AWS documents G and R worker families and their capacities in the CfnJob API reference. Worker type and count affect both available capacity and cost, so size them for the workload rather than copying the example values.
The Spark L2 reference documents G.1X with 10 workers as its default configuration; that is a construct default, not a recommendation for every job. The L2 reference also lists Glue-version defaults by job type, a default maximum concurrency of one, and timeout behavior that falls back to Glue service behavior when unset. Check the current SparkJobProps reference and JobProps reference when relying on defaults.
Quick Recap
Best Value
Rank #4
Validate the configuration before deployment
- Confirm that the command name matches the job type and that the script URI or L2
Codeobject points to executable code. - Verify that the role trusts
glue.amazonaws.comand has the least-privilege permissions needed for the script’s data, catalog, network, and logging operations. - Keep credentials out of job argument maps and CloudFormation-visible configuration.
- Review Glue version, worker type and count, retry count, timeout, connections, and any job arguments against the workload.
- Choose L2 for modeled common configuration or L1 when direct access to CloudFormation fields is needed.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

