Added an optional KMS key ARN to AWS Batch compute environments, so pipeline secrets in AWS Secrets Manager can be encrypted with a customer-managed key instead of the AWS-managed default.
Fixed AWS Cloud head job failures returning an empty log page when the compute environment's IAM instance profile has no role attached.
Fixed compute environment create and update accepting credentials already recorded as invalid or soft-deleted, and update resetting a credential's status without checking it.
Fixed exhausted Google Cloud IAM retries to report a meaningful error, and added jitter to the retry backoff.