Full changelog with commit links: CHANGELOG.md · Compare: 2.1.0...2.2.0
Bug Fixes
- add Scheduler retry backoff and DLQ handling (#3687)
- apigateway,appsync: sandbox VTL rendering with SecureUberspector and execution limits (#3542)
- apigateway: accept a region label before the built-in execute-api suffixes (#4705), closes #4701
- apigateway: capture HTTP proxy greedy suffixes (#4980)
- apigateway: complete API Gateway API key responses (#3817)
- apigateway: create API keys disabled unless enabled is set (#4731)
- apigateway: drop the SigV4 Authorization header before REST integrations (#4567)
- apigateway: format request times with an English locale (#5093)
- apigateway: honor import warnings and strict rollback (#4531)
- apigateway: import x-amazon-apigateway-any-method in the native image and roll back failed imports (#4473)
- apigateway: map authorizer context in HTTP integrations (#4992)
- apigateway: mark custom-domain routed requests so S3 virtual-host does not claim them (#4966)
- apigateway: merge OpenAPI imports in PutRestApi (#4570)
- apigateway: preserve and update method response parameters (#5030)
- apigateway: prevent JWT issuer and JWKS SSRF (#3743)
- apigateway: provision CloudFormation MOCK CORS responses (#4324)
- apigateway: register native VTL map reflection (#4405)
- apigateway: reject method request parameter names AWS refuses (#3549)
- apigateway: resolve AWS variables on REST import (#4547)
- apigateway: return embedded resource methods (#5109)
- apigateway: return integration defaults and patch timeout (#4798)
- apigateway: return stored method, policy, and stage settings (#3857)
- apigateway: route REST execute-api virtual hosts (#4553)
- apigateway: share REST request context and complete mappings (#5035)
- apigatewayv2: allow an idempotent override-id tag on UpdateApi (#4602), closes #3430
- apigatewayv2: block link-local and metadata targets in HTTP_PROXY integrations (#3962)
- apigatewayv2: cap HTTP_PROXY integration responses at the 10 MB payload quota (#4226)
- apigatewayv2: evaluate HTTP and WebSocket authorizer policies (#5020), closes #5086
- apigatewayv2: pin the checked address and cover WebSocket HTTP integrations (#3978)
- apigatewayv2: pin websocket HTTP targets (#4341)
- apigatewayv2: reject an out-of-range AuthorizerResultTtlInSeconds (#4294), closes #4072
- apigateway: validate and cache REST Lambda authorizers (#5002)
- apigateway: verify AWS_IAM signatures against the custom-domain path (#4092)
- appconfig: resolve AppConfigData identifiers by name as well as ID (#4661)
- appconfig: return feature flags in retrieval format (#3890)
- appsync: bound the Lambda authorizer result cache (#4345)
- appsync: move the GraphQL engine to a sidecar, out of the native image (#3534), closes #2917 #2914 #2916 #3799
- appsync: send VTL Lambda payload to function (#4579)
- appsync: supply reflection config so VTL runs on native image (#4729)
- athena: accept IN lists and check each table in the injected-partition filter (#5004)
- athena: keep terminal queries terminal (#4112)
- athena: read Iceberg-format Glue tables via iceberg_scan (#3738), closes #3737
- autoscaling: prevent reconciler resurrecting deleted groups (#3818)
- autoscaling: reconcile groups in every account (#3824)
- autoscaling: retain membership when instance termination fails (#4115)
- autoscaling: round-trip the whole target tracking configuration (#4369)
- backup: run scheduled job transitions in the caller's account (#4965)
- bedrock-agentcore: expire remembered delete client tokens (#4477)
- bring the partition literals that merged past the gate back under it (#4314), closes #4270 #4221 #4304 pull-throu#cache #4298
- build: preserve Quarkus Surefire argLine (#3988)
- ci: add draft PR handling to CI workflows for compatibility and build tests (#4292)
- ci: pass VERSION to the nightly native image build (#5165)
- cloudformation: answer DescribeStackEvents on a missing stack with AWS's wording (#4301), closes #4235
- cloudformation: apply an S3 bucket's declared configuration and its policy (#3950), closes #3947
- cloudformation: apply EC2 Instance UserData and IamInstanceProfile in place (#4206)
- cloudformation: apply every SQS queue property and reset dropped ones on update (#4972)
- cloudformation: apply IAM user tags (#4010), closes #3998
- cloudformation: apply stack tags during updates (#5031)
- cloudformation: await stack completion after ExecuteChangeSet in integration tests (#4078)
- cloudformation: bound operation executor (#3761)
- cloudformation: claim change set atomically before execution (#3564)
- cloudformation: delete UPDATE_FAILED resources on DeleteStack (#4470), closes #4467
- cloudformation: fail an EC2 instance whose LaunchTemplate cannot be resolved (#4058), closes #3810
- cloudformation: forward ProviderARNs on AWS::ApiGateway::Authorizer (#4704)
- cloudformation: honor UsePreviousTemplate on updates (#5015), closes #4881
- cloudformation: identify Lambda microVM images and network connectors by ARN (#4971)
- cloudformation: improve EC2 Instance update fidelity (#4130)
- cloudformation: keep a generated DynamoDB table name across updates (#3721), closes #3699
- cloudformation: keep AWS::ApiGateway::RestApi on stack updates (#4512)
- cloudformation: keep unchanged AWS::ApiGateway::Resource on update and remove it on delete (#4511)
- cloudformation: key the Lambda hot-reload identity on the Docker host path (#4275), closes #4080
- cloudformation: make a stack's collections safe for concurrent requests (#4199), closes #3564 #2473 #2419
- cloudformation: make EKS Nodegroup Ref the composite cluster/nodegroup id (#4136)
- cloudformation: pass Lambda hot-reload code through to the Lambda service (#4093), closes #4053
- cloudformation: propagate nested stack failure status reason and cover changeset rollbacks (#3921)
- cloudformation: propagate nested stack failures to parent (#3609)
- cloudformation: provision Cognito user pool groups (#3695)
- cloudformation: publish EC2 Instance State via Fn::GetAtt (#4203)
- cloudformation: publish EC2 SecurityGroup Id and Instance VpcId for Fn::GetAtt (#4155)
- cloudformation: publish RuleName and the RDS group ARNs the current registry schemas declare (#4135)
- cloudformation: read a TemplateURL on the S3 service host as path-style (#4248)
- cloudformation: reconcile a named secret in place on UpdateStack (#4299), closes #2134
- cloudformation: reconcile and replace IAM leaf resources on update and delete (#3933), closes #3913
- cloudformation: reconcile EC2 security group rules and tags on stack update (#3863)
- cloudformation: reconcile or replace EC2 instances on stack update (#3884), closes #3810
- cloudformation: reject a non-numeric AuthorizerResultTtlInSeconds (#4055), closes #4021
- cloudformation: reject more than one endpoint type on a RestApi update (#4728)
- cloudformation: reject non-integer target group ports and health check counts (#4970)
- cloudformation: remove the login profile when deleting an IAM user (#3975)
- cloudformation: replace IAM InstanceProfile on a createOnly change (#4133)
- cloudformation: resolve a stack id only to the stack carrying it (#4973)
- cloudformation: resolve change sets by ARN without stack name (#4885)
- cloudformation: resolve dynamic references after Fn::Join (#3610)
- cloudformation: resolve intrinsics in IAM policy documents before storing them (#3739)
- cloudformation: resolve SecretTargetAttachment targets in the stack region (#3740)
- cloudformation: roll back in-place Cognito user pool and client updates (#5006)
- cloudformation: skip unchanged resources during updates (#4442)
- cloudformation: tolerate an already-gone EC2 instance or security group on stack delete (#3842)
- cloudformation: tolerate an already-gone REST API on delete (#4047), closes #3885
- cloudformation: update nested stacks in place (#3859)
- cloudformation: validate required fields on AWS::IAM::Policy (#4050), closes #3971
- cloudfront: dedupe CacheBehavior XML parsing (#3705), closes #3652
- cloudfront: preserve policy configurations (#4009)
- cloudhsm: add issuer key identifiers to hardware chain (#4707)
- cloudmap: answer typed DNS records and honor routing policy (#4534)
- cloudwatch: honor Unit filter in JSON GetMetricStatistics (#3932)
- cloudwatchlogs: add logGroupArn to DescribeLogGroups (#3868)
- cloudwatchlogs: journal log events instead of rewriting the store under persistent mode (#4187), closes #2500
- cloudwatchlogs: persist event batches once (#3767)
- cloudwatchlogs: return creationTime in DescribeLogGroups and DescribeLogStreams (#4137), closes #4084
- cloudwatch: mint the regionless dashboard ARN AWS uses (#5135)
- cloudwatch: raise ResourceNotFoundException when a tag operation names a resource that does not exist (#4783)
- cloudwatch: retain metric-math alarm query definitions (#4594)
- cloudwatch: return DatapointsToAlarm from the JSON DescribeAlarms response (#3660)
- cloudwatch: return storedBytes on DescribeLogGroups (#4202)
- codeartifact: close the remaining register-vs-reset gap in PerKeyContainerPool (#4447), closes #4411
- codeartifact: enforce domains-per-account and repositories-per-domain quotas (#3949)
- codeartifact: extend idempotent asset republish to Published versions (#4708), closes #4619
- codeartifact: harden the pypi upload preflight's URI building and index match (#5029), closes #5019
- codeartifact: log unexpected I/O errors in existingFileMatches (#4769), closes #4708
- codeartifact: populate resourceId/resourceType on error responses (#3977)
- codeartifact: stop npm data plane test from missing a fast response body (#4430), closes #4369 #4422
- codeartifact: stop sidecar containers on state reset and nuke (#4411)
- codeartifact: treat identical-content asset republish as idempotent (#4619)
- codeartifact: treat identical-content maven redeploy as idempotent (#4837)
- codebuild: keep only the tail of phase output for failure messages (#4690)
- codepipeline: fall back when the source poll interval is not positive (#4361)
- codepipeline: handle legacy pipelines without versions (#3677)
- codepipeline: preserve external actions while stopping (#3726)
- codepipeline: release per-pipeline locks after use (#3712)
- codepipeline: resolve effective source revisions (#3514)
- codepipeline: retry failed stages in place (#3513)
- codepipeline: wait for custom jobs while stopping (#3678)
- cognito: accept USER_SRP_AUTH in AdminInitiateAuth (#3973)
- cognito: align pre-authentication trigger events and errors (#3861)
- cognito: default ExplicitAuthFlows to refresh, SRP and custom auth (#4081)
- cognito: expire auth challenge sessions (#4417)
- cognito: fail authentication when token triggers fail (#4727)
- cognito: fire PreTokenGeneration when the token endpoint redeems a code (#4438)
- cognito: hide unknown users in USER_AUTH (#4478)
- cognito: honour admin_only account recovery (#4762)
- cognito: keep tag operations and DescribeUserPoolDomain in the pool's region (#5133)
- cognito: omit AvailableChallenges from RespondToAuthChallenge responses (#4025), closes #4003
- cognito: persist app client AuthSessionValidity (#4481)
- cognito: refuse DeleteUserPool while deletion protection is active (#3961), closes #3948
- cognito: reject missing SRP challenge session (#4578)
- cognito: reject unrecognized AuthFlow instead of issuing tokens (#3923)
- cognito: scope OAuth tokens to the requested scopes (#4771)
- cognito: stop defaulting unset password requirements to enabled (#4250)
- cognito: validate PasswordPolicy MinimumLength and remove default of 8 (#4359), closes #4256
- compat: read VPC ID from OpenTofu state (#3831)
- config: enforce safe default network binding (#3684)
- core: build and recognise AWS hostnames in every partition (#4451), closes #4444 #4272
- core: compare ARN partitions with the resource's region, not the literal aws (#4791), closes #4272 #4790 RdsJdbcCompatTest#createDbInstanceAndConnectWithPassword
- core: let RequestScopes run background work in a given region (#5054)
- core: mint every ARN in the request's partition (#4444), closes #4272
- core: mint every regionless ARN in its partition and gate blank-region Arn.of calls (#4787), closes #4272
- core: name the exception class in a message-less Query catch-all (#3728), closes #3356
- core: read ARNs and Step Functions integration ids in every partition (#4358), closes #4272
- core: refuse a SigV4 scope region that no AWS partition publishes (#4393)
- core: return UnknownOperationException when X-Amz-Target is missing (#3925)
- core: serve HTTP/1.0 requests that omit the Host header (#4174)
- core: service principals are universal in every partition; accept the legacy forms (#4633), closes #4272
- core: stop accepting SigV4 scopes no SDK signs with (#5005)
- core: stop MultipartFormParser.ParsedForm using Optional as a record field (#5011)
- core: use the deployment region where Floci fell back to us-east-1 (#4974)
- create Firehose buckets and backfill EKS OIDC issuers in the resource's region (#5099)
- distinguish a failed verification API call from an unsigned commit (#3840), closes #3812
- docker: follow adopted sidecar containers from now instead of replaying their log history (#3612)
- docker: keep host network mode for containers that publish ports (#4192), closes #2798 #4175
- docker: make the Docker client pool size configurable, default 1024 (#4276), closes #2219 #2224
- docker: move the image bases to UBI 9.8 (#4782)
- docker: pass the resolved TLS config to the Docker HTTP client (#4638), closes #4608
- docker: re-own the configured persistent path, not only /app/data (#4525)
- docker: retry transient daemon I/O at the transport seam and split streaming pools (#4614)
- docker: stop the bundled AWS CLI fetching URL-valued parameters (#3426)
- docs: prevent stale service action counts (#5018)
- dynamodb: add missing ConsumedCapacity for PartiQL's ExecuteStatement and BatchExecuteStatement (#4165)
- dynamodb: add missing ConsumedCapacity to transaction responses (#4151)
- dynamodb: apply the ProjectionExpression of a TransactGetItems Get (#4061)
- dynamodb: cancel TransactWriteItems on a key that does not match the schema (#3674)
- dynamodb: enforce the 400KB item limit on every update surface (#3991)
- dynamodb: escape composite key segments (#3804)
- dynamodb: filter an unkeyed PartiQL index read on the index view (#4319)
- dynamodb: honor MICROSECOND ApproximateCreationDateTimePrecision for Kinesis destinations and streams false enablement (#3874)
- dynamodb: match AWS error messages for item calls and projections (#4315)
- dynamodb: match the AWS shape of the Kinesis destination responses (#4917)
- dynamodb: recompute UpdateTable AttributeDefinitions (#4046)
- dynamodb: reject a request member of the wrong JSON type (#4636)
- dynamodb: reject an unknown BillingMode (#4554)
- dynamodb: reject undefined expression attribute placeholders (#4398), closes #2893
- dynamodb: report a global table's home region as a replica in DescribeTable (#4197)
- dynamodb: report a missing GSI on UpdateTable the way AWS does (#4564)
- dynamodb: route stream consumers through one account-scoped reader (#4394)
- dynamodb: scope streams and sequence counters by account (#4116)
- dynamodb: size numbers by base-100 digit pairs (#4530)
- dynamodb: size() of a Binary counts its bytes, not its base64 text (#5058)
- dynamodb: treat resolved projection aliases as literal names, not list indices (#3633)
- dynamodb: validate GSI and LSI index names like AWS (#4601)
- dynamodb: validate transaction condition expressions (#3691)
- ec2: add t2.nano, t2.small, t3.nano and t3a.nano to the instance type catalog (#4788)
- ec2: an interface VPC endpoint reports its network interfaces, and they resolve (#4598), closes #21
- ec2: apply filters to transit gateway route table lookups (#3820)
- ec2: attach Docker-hosted Floci to VPC networks (#3862)
- ec2: decode CloudFormation launch template user data (#4711)
- ec2: delete VPC default security group, route table and network ACL with the VPC (#3878)
- ec2: deliver flow log records in the format the flow log declares (#4429)
- ec2: honor dry run for replace route (#4300)
- ec2: honor RunInstances dry run before provisioning (#3599)
- ec2: instances under security group enforcement no longer terminate at launch (#4510)
- ec2: issue instance-profile role credentials through IMDS (#3742)
- ec2: plan a VPC's CIDR against another Region's network for the same VPC id (#5134)
- ec2: reject a DescribeVpcs filter name the service does not serve (#4366)
- ec2: reject key pair requests without KeyName (#3727), closes #3307 #3356
- ec2: release a capture when a whole batch of instances is terminated (#4127)
- ec2: remove tags on the default resources deleted with the VPC (#3917)
- ec2: report a flow log's custom LogFormat (#4386)
- ec2: report an unknown subnet id from DescribeSubnets as an error (#4408)
- ec2: report instance platform details (#4322)
- ec2: report the calling account as resource owner (#3814), closes #3775
- ec2: resolve instance profile names through IAM (#3856)
- ec2: return and filter image tags (#3808)
- ec2: return DependencyViolation from DeleteVpc while dependents remain (#3916)
- ec2: return user data from DescribeInstanceAttribute (#3601)
- ec2: stage user data outside guest temporary mounts (#3736)
- ec2: store omitted tag values as empty strings (#3880)
- ec2: use regional private DNS names (#5033)
- ec2: validate and expire IMDSv2 session tokens (#4303)
- ec2: validate CreateSecurityGroup required parameters (#3888)
- ec2: validate DescribeVpcs ids at the query boundary (#4482)
- ecr: answer GetAuthorizationToken without the backing registry (#4635), closes #4634
- ecr: forward every Accept header to the backing registry (#5069), closes #4869
- ecr: return a proxyEndpoint for the request's region (#4277), closes #4264
- ecr: serve the registry data plane over TLS (#4040)
- ecr: support image scanning configuration updates (#4928)
- ecs: a service reaches steady state, and a finished deployment stays finished (#4694)
- ecs: apply volumesFrom to task containers (#3811)
- ecs: complete failed service deployment handling (#4874)
- ecs: delete a service's deployment records with the service (#4757)
- ecs: end a deployment the circuit breaker detects as failed (#4767)
- ecs: keep task definitions and their revisions per region (#5078)
- ecs: pull task images at launch so a moved tag reaches the next task (#4583)
- ecs: reconcile persisted services at boot (#4501)
- ecs: register reachable task addresses in Cloud Map and bound synthesised ENI addresses (#4509)
- ecs: release stale task containers and registrations, and evict ones that would misroute a reused address (#4513)
- ecs: report serviceConnectConfiguration on the service's deployment (#3662)
- ecs: retry teardown of redeployed task containers (#4280)
- ecs: roll a DAEMON service's tasks when its task definition changes (#4766), closes #4744
- ecs: run ECS Exec sessions as root like the real agent (#5074), closes #4850
- ecs: send container logs to the awslogs group and stream from the task definition (#4808)
- ecs: send container logs to the task's account (#4833)
- ecs: use shared Docker Hub image in leftover test (#4645)
- eks: accept IAM authentication tokens for the authenticator's token lifetime (#4186)
- eks: claim the cluster user data slot atomically (#4190)
- eks: fail the delete when Docker cannot remove the cluster container (#4960)
- eks: isolate capacity backups from live clusters (#4663)
- eks: persist explicit version flag across restarts (#4101)
- eks: populate clusterSecurityGroupId on cluster responses (#3924)
- eks: preserve worker webhook scope in the URL path (#3849)
- eks: release the API server port when a cluster is deleted or fails to start (#4937)
- eks: remove the k3s container on DeleteCluster when shutdown retention is on (#4241), closes #4239
- eks: resolve the token webhook's access keys from any account (#5003)
- eks: stop mirroring cluster audit logs to the Floci console (#4589)
- eks: store and return encryptionConfig and logging on clusters (#4007)
- eks: store and return node group launchTemplate, taints, remoteAccess, nodeRepairConfig and warmPoolConfig (#4102)
- eks: validate the node group launchTemplate against EC2 on CreateNodegroup (#4148)
- elasticache: create single-node redis clusters and close provisioning races (#3634)
- elasticache: honor top-level user passwords and let ModifyUser change auth and access string (#4431)
- elasticache: re-provision caches on restart instead of reporting a dead endpoint as available (#4094)
- elasticache: report a ConfigurationEndpoint only for cluster-mode-enabled replication groups (#4469)
- elasticache: report a memcached cluster's node count, type, ARN and nodes (#5000)
- elasticache: serve a second cache asking for 6379 instead of refusing it (#4693), closes #4094
- elasticache: support HELLO AUTH handshakes (#4476)
- elb: populate source security group (#3807)
- elbv2: block link-local and metadata targets (#4031)
- elbv2: dispatch a shared listener port by the hostnames rules declare (#4207)
- elbv2: probe the target group's HealthCheckPort instead of always the traffic port (#4432)
- elbv2: round-trip the authenticate-oidc and authenticate-cognito configs (#3664)
- elbv2: scope SetRulePriorities conflicts to the rule's listener (#4507)
- elbv2: stop mutating immutable fallbacks on the delete paths (#4030)
- elbv2: tunnel WebSocket upgrades to instance and ip targets (#4517), closes #4516
- emr: keep cluster operations in the cluster's region (#5097)
- eventbridge: preserve target role ARN configuration (#4946)
- eventbridge: stop a cron rule deleted or disabled mid-delivery (#4346)
- firehose: serialise flusher ticks so two polls cannot buffer the same records (#4141)
- glue: ignore Avro custom attributes in schema identity (#4692)
- glue: keep counting a trigger chain when its origin is gone (#4472)
- glue: make DeleteJob idempotent (#3866)
- iam: apply the documented MaxItems and ServiceNamespaces limits (#4543)
- iam: authorize a server-certificate rename against both names (#5016)
- iam: authorize a virtual-hosted bucket request against the bucket ARN (#3942) lex00/floci#213
- iam: authorize REST and Query serving services (#4419)
- iam: authorize the service that serves the request, not the one it was signed for (#4295)
- iam: compare numeric and boolean condition values (#5086)
- iam: derive the AWS managed policy catalog per partition (#4742), closes #4633 #4272
- iam: emit State before Description in GenerateCredentialReport (#4329)
- iam: enforce case-insensitive resource names (#3986)
- iam: enforce tag constraints across every IAM tagging action (#4485), closes #4407
- iam: evaluate policies against real request resources and conditions (#3765)
- iam: give a role session's aws:PrincipalArn as its role's ARN under enforcement (#4810), closes #4716
- iam: hold untag TagKeys to the tag key constraints (#4506)
- iam: match a resource policy's Principal by the kind of caller it names (#4839)
- iam: match condition values case-sensitively (#4672)
- iam: match IAM's constraint-violation message shape (#4613), closes #4543
- iam: populate PrincipalIsAWSService for signed requests (#4695)
- iam: refuse an unsigned management call under enforcement (#4489)
- iam: reject an access key that exists nowhere under enforcement (#4182)
- iam: reject duplicate tag keys and make user and role tags case-insensitive (#4484) (#4520)
- iam: resolve s3:ExistingObjectTag and s3:RequestObjectTag under enforcement (#3946), closes #209
- iam: resolve server certificate references in ELB and CloudFront (#5075), closes #4875
- iam: return PermissionsBoundary from GetRole/GetUser and accept it on CreateRole/CreateUser (#4964)
- iam: return protocol-correct access-denied statuses (#4673)
- iam: scope managed policy attachment counts (#4213)
- iam: share case-sensitive condition matching (#4725)
- iam: use SecureRandom for secret credentials and tokens (#3960)
- identitystore: persist model fields across a restart (#5013), closes #4993
- iot: accept MQTT packets up to the AWS 128 KB payload limit (#4307)
- iot: parse exponent and large integer literals in rule SQL (#4441)
- iot: run MQTT topic rules off the event loop (#4462)
- iot: stabilize MQTT WebSocket concurrent sessions (#3816)
- kinesisanalytics: isolate applications by account and region (#3760)
- kinesisanalytics: make the savepoints volume writable by the Flink user (#4490), closes #4443
- kinesis: expire shard records past the stream's retention period (#4224)
- kinesis: paginate ListShards with an opaque NextToken (#4098)
- kms: match the AWS error codes, messages and check order (#3968)
- kms: return an empty Description when CreateKey omits one (#4349)
- lambda: apply FunctionResponseTypes on UpdateEventSourceMapping (#4584)
- lambda: back off DynamoDB Streams retries and expire aged records (#3613)
- lambda: bound a destination cycle that re-enters through SNS or EventBridge (#4279), closes #4267
- lambda: check RevisionId before applying UpdateFunctionConfiguration changes (#4637), closes #4605
- lambda: deliver DynamoDB stream failures to S3 (#3622)
- lambda: drop a DynamoDB Streams batch whose OnFailure send fails (#4338)
- lambda: honor alias async destination configuration (#4348)
- lambda: honor LATEST and stop deleted DynamoDB stream mappings writing back (#4318), closes #4311
- lambda: include the resource namespace in code volume names (#4872)
- lambda: invoke the version or alias that a qualified function reference names (#4231)
- lambda: isolate layer extraction paths (#3685)
- lambda: mount hot-reload read-only and refuse Docker socket directories (#4154)
- lambda: pass ClientContext to synchronous invocations (#5014), closes #4968
- lambda: poll Kinesis event source in the mapping account (#3964)
- lambda: preserve CloudFormation event source mapping options (#4316), closes #4313
- lambda: preserve owner account for execution logs (#3787)
- lambda: reject invalid configuration numbers before mutation (#4726)
- lambda: resolve hot-reload paths before checking the allow-list (#4053)
- lambda: return current reserved concurrency in GetFunction (#4592)
- lambda: return event source mapping ARN and support tagging mappings (#4587)
- lambda: skip Runtime API ports held by other processes (#4969)
- lambda: store hot-reload host paths with POSIX separators (#4080)
- lambda: support async retries and dead-letter queue (DLQ) for asynchronous invocations (#4251), closes #4194
- lambda: validate enum and pattern-constrained request fields (#4611)
- lifecycle: exit when startup is interrupted (#4420)
- lifecycle: keep SageMaker and ECS background work running after a state reset (#3797), closes #3718
- lifecycle: run afterReset on every Resettable when a beforeReset throws (#4024), closes #3937 #3952 #3796
- lifecycle: stop managed containers on state reset, not just shutdown (#3718)
- marketplace: serve Entitlement and Agreement in every region AWS publishes (#5028)
- mint ARNs in the request region for Amazon MQ, MSK, EKS Fargate, AppSync and ElastiCache users (#5053)
- mwaa: restrict CLI proxy to supported commands (#4797)
- mwaa: run CLI commands off the event loop (#4343)
- networkfirewall: honor dry run for rule groups and policies (#4799)
- networkfirewall: validate replacement before replacing state (#4114)
- opensearch,mwaa: remove containers on explicit delete when shutdown retention is on (#4225)
- opensearch: report an endpoint for a domain with no container behind it (#4284)
- organizations: start a new root with no policy types enabled (#4756)
- partition: drop baseline rows #4317 re-added after #4314 cleared them (#4333)
- proxy: preserve half-closed relay connections (#3762)
- rds-data: reject invalid secret credentials (#3759)
- rds: accept the master usernames each engine really allows (#3730), closes #3729
- rds: align snapshot copy and encryption responses (#4355)
- rds: apply DBInstanceClass, AllocatedStorage and EngineVersion on ModifyDBInstance (#4214)
- rds: apply IAM auth toggles to running proxies (#3668)
- rds: bind PostgreSQL IAM tokens to the published endpoint and authorize rds-db:connect (#4100)
- rds: harden MySQL IAM authentication (#3686)
- rds: honor Port on cluster snapshot restore (#4326)
- rds: keep an instance's endpoint port when its restore fails (#4497)
- rds: keep instance available when the liveness probe fails (#5070), closes #4847
- rds: read the Parameters list the way every SDK sends it on ModifyDBParameterGroup (#3780), closes #3779
- rds: recover metadata after backend startup failures (#4532)
- rds: report the monitoring and lifecycle settings a DB instance was given (#3688)
- rds: store and return DeletionProtection in DescribeDBInstances (#4557)
- rds: support IPV6 and DUAL network types on RDS Proxy (#3639)
- rds: support tagging DB snapshots (#3649)
- rds: warn once for failed cluster member relays (#4721)
- redshift: accept s3table log destination and reject mutual snapshot restore params (#4340), closes #4242
- redshift: fix Redshift emulation gaps found against the Terraform AWS provider (#3987), closes #3628
- redshift: remove a stale cluster container before creating it (#4537)
- route53resolver: CreateResolverEndpoint reads IpAddresses, as AWS names it (#4180)
- route53: store CloudFormation record names fully qualified (#4734)
- run MWAA CLI commands without a shell (#4750)
- s3: allow delete markers and new versions over object-locked versions (#4390)
- s3: allow presigned CORS preflight (#3675)
- s3: answer 501 for PutObject conditions S3 does not implement (#5128)
- s3: apply AWS's CreateBucket region rules in every partition (#4494), closes #4272
- s3: complete multipart uploads larger than 2 GiB in disk storage modes (#4976)
- s3: copy objects over 2 GiB without reading them into memory (#5080)
- s3: delete null object versions (#3867)
- s3: emit ObjectRemoved:Delete when deleting a specific object version (#4710), closes #4680
- s3: give a role session's aws:PrincipalArn as its role's ARN in S3's bucket-policy checks (#4838)
- s3: honor bucket-policy grants on presigned POST uploads (#4278), closes #4243
- s3: honour CopyObject destination and copy-source preconditions (#4984)
- s3: honour If-Match on DeleteObject and the ETag element on DeleteObjects (#4526)
- s3: include bucket name in bucket-scoped errors (#4624)
- s3: journal the object index under persistent storage (#4642)
- s3: keep a bucket's data inside its own account directory (#4244)
- s3: keep a virtual-hosted key whole when it contains the bucket name (#3944), closes #208
- s3: match a bucket policy's Principal the way IAM does in S3's own checks (#4961), closes #4838 #4839
- s3: promote a version on delete without reading its body (#5064)
- s3: read only the copied range in UploadPartCopy, with offsets past 2 GiB (#5034)
- s3: reject a malformed aws-chunked upload instead of storing its framing (#5082)
- s3: reject reserved storage bucket names (#4289)
- s3: reject unknown bucket location constraints (#4259)
- s3: reject unsigned checksum headers on presigned requests (#4153)
- s3: return account owner IDs in bucket and parts listings (#4884)
- s3: return copy destination version id (#3669)
- s3: return NoSuchTagSet from GetBucketTagging on untagged buckets (#4585)
- s3: sign generated presigned URLs with SigV4 (#4373)
- s3: stop S3InternalErrorIntegrationTest racing background callers of the mock (#3887), closes #3833
- s3: store x-amz-meta-* passed in a presigned URL query string (#4753), closes #4752
- s3: stream GetObject bodies from disk instead of the heap (#4691)
- s3: stream PutObject and UploadPart bodies to disk (#5106)
- s3: stream UploadPartCopy ranges into the part (#5162)
- s3: support virtual-hosted routing via X-Forwarded-Host and prevent unintended bucket creation (#3621)
- s3: validate checksum passed via presigned url query parameters (#4254), closes #4188
- s3: validate Content-MD5 on PutObject and UploadPart (#4524)
- s3: validate CreateBucketConfiguration before creating the bucket (#4113)
- s3: validate notification destinations before storing configuration (#4747)
- s3: verify header and presigned POST signatures under validate-signatures (#4786)
- s3: verify SigV4 signatures against the wire path for leading-slash keys (#4125), closes #4123
- sagemaker: restore the worker pools in afterReset, not clear() (#3937), closes #3797 #3796
- scheduler: deliver the default event to targets without Input (#4018), closes #3951
- scheduler: keep a schedule's account across UpdateSchedule (#4258)
- scheduler: validate expressions and target role ARNs (#4561)
- scope event source mappings, DynamoDB jobs, scaling activities and user pools to the request region (#5056)
- secretsmanager: bound rotation threads and lock storage (#4344)
- secretsmanager: keep the versions map safe to iterate during a rotation (#3754), closes #3247 #3753
- secretsmanager: refuse a rotation function in another Region with InvalidParameterException (#4873)
- secretsmanager: refuse an unreadable rotation function reference with InvalidParameterException (#4768)
- secretsmanager: require lambda:InvokeFunction for RotateSecret under IAM enforcement (#4697)
- secretsmanager: serialize DeleteSecret and a rotation's last save with the secret's other writes (#4962)
- send ElastiCache, Memcached, DocDB and Amazon MQ container logs to the resource's region (#5098)
- servicequotas: curate real AWS VPC quota codes (#4997)
- ses: apply the v2 boolean coercion to the remaining boolean members (#4944)
- ses: authorize SES v2 calls against their IAM actions under enforcement (#4775)
- ses: authorize the SES v2 operations and routes botocore added since the rule table (#4811)
- ses: coerce a v2 boolean string only when it names a boolean (#4887)
- ses: emit SES v2 timestamps as epoch seconds with milliseconds (#4422)
- ses: publish a Bounce for suppressionlist@simulator and split events by cause (#4073)
- ses: refuse a list token whose scope only starts with the request's (#4870)
- ses: reject send addresses longer than 320 characters (#4749)
- ses: serve the POST list bindings and Filter of ListEmailIdentities and ListConfigurationSets (#5010)
- ses: validate EventBridge default bus ARNs (#4677)
- sfn: resolve Reference Paths rooted at the Context Object (#4445)
- sfn: validate Map numeric path fields (#3827)
- sns: apply the subscribed queue's DelaySeconds to SQS fan-out (#4170)
- sns: match nested message-body policies in arrays (#4234)
- sns: match String.Array attributes per element and honour $or in filter policies (#3746)
- sns: refuse http endpoints on link-local and metadata addresses (#4400)
- sns: require IAM role ARN for Firehose subscriptions (#4233)
- sns: retry failed sqs subscription deliveries (#4468)
- sns: validate Publish Subject (#4172)
- sqs: honor ReceiveMessage message attribute selectors (#4699)
- sqs: match AWS on stale, gone and invalid receipt handles (#4730)
- sqs: reflect CancelMessageMoveTask at once instead of after the rate interval (#3757), closes #3756
- sqs: retain fifo deduplication after message deletion (#4460)
- sqs: set SenderId from caller principal instead of queue owner (#5066), closes #4829
- ssm: bound direct-execution output to the GetCommandInvocation limits (#4257)
- ssm: reject SendCommand with more than 50 InstanceIds (#4754)
- ssm: resolve Secrets Manager references in GetParameter (#4581)
- ssm: run direct executions on virtual threads (#4689)
- ssm: support parameter selectors in GetParameter and align LabelParameterVersion with AWS (#4461), closes #4396
- stepfunctions: bound a .sync Task by its TimeoutSeconds, not by a poll count (#4519), closes #4518
- stepfunctions: fail a .sync Task on its child with States.TaskFailed and the child's description (#4675), closes #4562
- stepfunctions: fail a Parallel the moment any branch fails, whichever is listed first (#4713), closes #4646 #4660
- stepfunctions: honor Wait Timestamp and TimestampPath (#4099)
- stepfunctions: preserve Lambda service errors in tasks (#4845)
- stepfunctions: preserve object details in PutEvents (#4022)
- stepfunctions: preserve Scheduler task timestamps (#4056)
- stepfunctions: record TaskSubmitted for a .sync Task, named as AWS names it (#4719), closes #4648
- stepfunctions: record the iterations a failing Map iteration cuts, and the state each was in (#4724), closes #4722
- stepfunctions: resolve a Lambda task's function ARN in its own account and region (#5079)
- stepfunctions: return the PascalCase execution envelope from states:startExecution, .sync and .sync:2 (#4737), closes #4675 #4723
- stepfunctions: serialize Scheduler target input (#4168)
- stepfunctions: stop a .sync job whenever its Task is cut, and record the cut state (#4660), closes #4519 #4646
- sts: evaluate AssumeRole trust-policy conditions against the real caller (#4716), closes #4555
- sts: evaluate GetSessionToken and GetFederationToken sessions as the user that minted them (#5081)
- sts: mint global STS and IAM ARNs per partition and add a strict partition mode (#4743), closes #4272
- sts: preserve assumed role session identity (#4403)
- sts: reject AssumeRole for roles that do not exist (#4463), closes #4392
- sts: Reject SAML signature transforms that AWS rejects (bonus: native image shrunk by 7 MB) (#4372)
- sts: validate DurationSeconds (#4418)
- tagging: find resources by the tags their own service holds (#4563)
- test: stabilize S3 concurrent overwrite test (#3770)
- textract: retain async results until expiry (#3965)
- tls: add key identifiers to local CA certificates (#4644)
- transcribe: honor list pagination tokens (#3927)
- transfer: preserve server detail structures (#3928)
- ui: render startup messages as text (#4421)
- wafv2: enforce the 50-tag limit and key/value constraints on tags (#4118), closes #4035
- wafv2: persist tags on TagResource/UntagResource (#3915), closes #3910
- wafv2: return WAFNonexistentItemException as 400 (#4117), closes #4034
Features
- add DynamoDB to Redshift zero-ETL replication (#3872)
- apigateway: enforce Cognito user pool authorizers (#4323)
- apigateway: honour the remaining REST integration settings (#3434)
- apigateway: implement GetUsage (#3561)
- apigateway: support Gateway Responses on REST APIs (#3326) (#3585)
- appconfig: implement ListDeployments (#3749)
- appconfig: serve feature flag variants to the AppConfig Agent as Amazon Ion (#4674)
- appsync: authorize data source service roles (#4555)
- appsync: execute APPSYNC_JS resolvers via a Node sidecar (#3422)
- appsync: execute VTL pipeline resolvers on sidecar (#4586)
- appsync: execute VTL unit resolvers over data sources (#4423)
- appsync: execute VTL unit resolvers over NONE (#4356)
- backup: configure a vault with an access policy, notifications and a lock (#4412), closes #4103 KinesisJsonHandler#optionalMaxRecordSize #16 KinesisJsonHandler#optionalMaxRecordSize SecretsManagerService#lockFor
- batch: support canceling and terminating jobs (#3922)
- batch: tag actions and one-lock teardown, wired into the CloudFormation provisioner (#4268), closes #2861
- bedrock-agentcore: implement InvokeHarness (#3557), closes #3556
- ce: manage anomaly monitors and subscriptions (#4221)
- cloudformation: apply AWS::IAM::AccessKey Status (#4060), closes #3933
- cloudformation: apply DynamoDB GlobalTable Replicas (#4134)
- cloudformation: list a deleted stack and report its DeletionTime (#4246), closes #849
- cloudformation: provision AWS::ApiGatewayV2::VpcLink (#5008)
- cloudformation: provision AWS::IoT::Authorizer (#4830), closes #4822
- cloudformation: provision AWS::Transfer::User (#5076), closes #4655
- cloudformation: provision Cloud Map namespaces and services (#4599), closes #4596
- cloudformation: provision CloudWatch log streams (#3869)
- cloudformation: provision Transfer Family servers (#4809)
- cloudformation: write Route53 RecordSet records into the zone (#4132)
- cloudfront: forward viewer headers, cookies and query strings per origin request policy (#4230), closes #4217
- cloudfront: serve POST, PUT, PATCH and DELETE viewer requests (#4229), closes #4216
- cloudfront: Support HTTPS locally with correct key id (#3845)
- cloudmap: honor service TTL in DNS A answers (#4448)
- cloudmap: resolve DNS namespaces and register ECS tasks in them (#4122)
- codeartifact: add CodeArtifact control-plane support (#3713)
- codeartifact: add PyPI format support via pypiserver sidecar (#4998)
- codeartifact: bridge GetPackageVersionAsset to Maven, npm, and pypi sidecars (#5019)
- codeartifact: release a deleted repository's Maven storage (#4210)
- codeartifact: serve the maven format through a real Reposilite-backed proxy (#4059)
- codeartifact: serve the npm format through a real Verdaccio proxy (#4336)
- codeartifact: support publishing and reading generic-format package versions (#3839)
- codepipeline: emit EventBridge state-change events and SNS approval notifications (#4616)
- codepipeline: evaluate V2 stage conditions and rules (#4617)
- codepipeline: execute ThirdParty GitHub version 1 source actions (#4615)
- cognito: add GetUserAuthFactors (#4764)
- cognito: enforce app client ExplicitAuthFlows in InitiateAuth and AdminInitiateAuth (#3974)
- cognito: implement DeleteUser self-service API action (#4493)
- cognito: implement federated sign-in (#3748)
- cognito: offer an email code on managed login (#4765), closes #4759
- cognito: provision user group attachments (#4806)
- cognito: provision user pool users (#4805)
- cognito: serve managed login for native users with PKCE (#4238), closes #4218
- cognito: support software-token MFA setup and challenges (#4620)
- cognito: support the USER_AUTH choice-based auth flow (#3930), closes #3926
- config: add aggregation authorization CRUD (#3627)
- core: partition foundation from botocore's published partition data (#4317), closes #4272
- core: vendor the per-region hosted zones, SAML URLs and VPC endpoint prefixes (#4545), closes #4494 #4272
- dlm: manage lifecycle policies (#4335)
- dms: add endpoint, replication instance and replication task lifecycles (#5001)
- dms: add replication subnet group lifecycle and tagging (#3630)
- dns: transparent AWS endpoint interception for spawned containers (#4610)
- docker: add cpu limits and readonly rootfs to container specs (#3893)
- docker: attach link-local addresses to a container's network endpoint (#4063), closes #2987
- docker: give internal Docker labels io.floci.* names and keep the old keys as aliases (#4871)
- docker: own the floci-aws- container and volume prefix (#4273)
- docker: support explicit GPU device requests (#3789) containers/podman#22645
- docs: add a service inventory reconciler and fix what it found (#3656)
- dynamodb: add the legacy global table operations (#4288)
- dynamodb: improve PartiQL grammar coverage (#3798)
- dynamodb: optional DynamoDB Local backend (#4504)
- dynamodb: vector indexes and SearchVectors (#4215)
- ec2: add an arm64 Amazon Linux 2023 image catalog entry (#4163)
- ec2: attach volumes as real block devices (#4354)
- ec2: bound instance containers to their instance type resources (#4189)
- ec2: expose synthesized cluster node instances to the EC2 service (#4262)
- ec2: implement ModifyVolume and volume modification state (#4320)
- ec2: report DnsEntries for interface VPC endpoints (#3895)
- ec2: resize volume backing files and loop devices on ModifyVolume (#4666)
- ec2: return spot price history for known instance types (#4698)
- ec2: support an external image catalog (#4144)
- ec2: support Dedicated Hosts (AllocateHosts, DescribeHosts, ModifyHosts, ReleaseHosts) (#4816)
- ec2: support DescribeIpamScopes (#4843)
- ec2: support instance and network-interface route targets (#4416)
- ec2: validate DescribeVpnGateways and add DescribeEgressOnlyInternetGateways (#3879)
- ecr: advertise TLS registry URIs on opt-in (#4252)
- ecr: manage pull through cache rules (#4304)
- ecr: update and validate pull-through cache rules (#4342)
- ecs: add FireLens task logging support (#3768)
- ecs: complete the fargate launch surface (#4017)
- ecs: complete the operations outside the launch path (#4019)
- ecs: give task containers their role credentials (#4486)
- ecs: hold 169.254.170.2 on the task's network with a small proxy container (#4293), closes #4063 #2987
- ecs: implement ExecuteCommand (#4121)
- ecs: issue task-role credentials and serve them over the AWS wire contract (#4160)
- ecs: let the startup container sweep be turned off, and derive the credentials proxy owner from the shared helper (#4696)
- ecs: publish awsvpc ports on demand (#3766)
- ecs: serve the task metadata endpoint v4 (#4120)
- ecs: service members, service role and capacity provider management (#4037)
- ecs: support fluentd FireLens routers and s3-hosted FireLens config (#3790)
- eks: add the EBS CSI driver to the addon version catalog (#4371)
- eks: apply nodegroup labels, taints and capacity type to the node (#5063)
- eks: authenticate EC2 workers through access entries (#3805)
- eks: bound cluster containers and derive kubelet reservations (#4590)
- eks: deliver audit logs from the cluster API server (#4146)
- eks: deliver control plane logs to CloudWatch Logs (#4111)
- eks: enable IMDS and link-local metadata access from pod network (#4039)
- eks: expose IMDS on 169.254.169.254 inside cluster containers (#3693)
- eks: implement access-entry management (#3745)
- eks: implement cluster addon management (#4038)
- eks: implement pod identity association management (#4012)
- eks: inject pod identity credentials through a mutating webhook (#4110)
- eks: label cluster nodes with their topology zone and region (#4308)
- eks: link containerd certs directory for launch template registry hosts (#4265)
- eks: name cluster nodes after their EC2 instance (#4916)
- eks: program cluster routes from emulated VPC route tables (#4496)
- eks: run node group launch template user data in cluster containers (#4149)
- eks: serve pod identity credentials on 169.254.170.23 (#4124)
- eks: set the cluster node providerID (#4255)
- eks: sign k3s service account tokens with the cluster OIDC key (#3783)
- eks: stop shipping a default storage class in clusters (#5061)
- eks: support native kubernetes versions and network cidrs (#4064)
- eks: support per-cluster kubelet and API server arguments (#4772)
- elasticache: authenticate each RBAC user by its own authentication mode (#4536)
- emr-serverless: tag, untag and list tags for applications (#4667), closes #4662
- emr: resize instance groups and fleets, list bootstrap actions (#4900)
- emr: scaling and termination policies and block public access (#4893), closes #4888
- eventbridge: add ApiDestination target support (#4702) (#5009)
- eventbridge: execute target retry and dead-letter policies (#4736)
- eventbridge: provision AWS::Events::Archive (#4818), closes #4815
- eventbridge: start Step Functions targets (#4006)
- glue: add crawler classifier APIs (#3985)
- glue: add security configuration CRUD (#3870)
- glue: catalog resource policy and Data Catalog encryption settings (#4027), closes #4023
- glue: create and run workflows (#4471), closes #4380
- glue: create, run and chain triggers (#4436), closes #4380
- glue: Data Catalog connections (#3939), closes #3938
- glue: implement partition indexes (#3551)
- glue: start and stop crawls, crawler metrics, listing and schedules (#4427), closes #4380
- glue: start, read and stop job runs, and list and batch get jobs (#4382), closes #4380
- glue: table version reads and deletes, batch partition delete, SearchTables (#3828), closes #3826
- iam: add ECS task-role session registration and orphan sweep (#4143)
- iam: add GenerateCredentialReport and GetCredentialReport (#4298)
- iam: add GetAccountAuthorizationDetails (#4208), closes #4205
- iam: add last-accessed reporting actions (#4488), closes #4487
- iam: add ListInstanceProfileTags (#4140)
- iam: add SimulateCustomPolicy and GetContextKeysFor*Policy (#4185)
- iam: enforce DeleteUser prerequisites and carry access keys and group membership through a rename (#3918)
- iam: expand wildcard service grants against a vendored namespace catalog (#4544)
- iam: finish the SAML provider lifecycle (#4360)
- iam: implement CreateLoginProfile, UpdateLoginProfile, DeleteLoginProfile (#3865)
- iam: model server certificates (#4975)
- iam: model service-specific credentials (#5084)
- iam: model signing certificates (#5024)
- iam: model SSH public keys (#5051)
- iam: model virtual MFA devices with real TOTP verification (#4820), closes #4814
- iot: manage custom authorizers (#4826), closes #4821
- kms: implement ReplicateKey for multi-region keys (#4176)
- kms: serve the AWS managed keys under alias/aws/* in every region (#4792)
- kms: support ECC imported key material (#4428)
- kms: support RSA imported key material (#4152)
- lambda: allow per-runtime image reference overrides (#4552)
- lambda: bisect failing DynamoDB stream batches and keep refused failures (#4337)
- lambda: bound the warm pool globally with LRU eviction (#4683), closes #4682
- lambda: deliver asynchronous invocation results to configured destinations (#4247)
- lambda: durable function callbacks (#5100)
- lambda: honour the Invoke Qualifier and wait between asynchronous retries as AWS does (#4733)
- lambda: manage code signing configurations (#4286)
- lambda: run durable functions with checkpoints, waits and step retries (#5047)
- lambda: store DurableConfig on functions (execution later) (#5007)
- lambda: support custom Docker flags (#3751)
- logs: deliver log events through subscription filters (#5021)
- macie2: add member administration (#3488)
- network: add opt-in security group enforcement (#3681)
- ram: add ListResourceSharePermissions (#5073), closes #4883
- rds: add and remove a subscription's source identifiers (#4363)
- rds: add SQL Server support to RDS (#3752)
- rds: Aurora custom cluster endpoints (#5090), closes #5072
- rds: copy and reset parameter groups and copy option groups (#3781), closes #3777
- rds: DB cluster snapshots (#4097), closes #4042
- rds: global clusters and FailoverDBCluster (#3819), closes #3778
- rds: manage event notification subscriptions (#4332), closes #4286
- rds: pause and resume Aurora Serverless v2 clusters at zero capacity (#4232), closes #4219
- rds: read replicas with a point-in-time copy of the source (#3813), closes #3778
- rds: restore DB instances and clusters to a point in time (#4963), closes #4952
- rds: stop, start and reboot DB instances and clusters (#4071), closes #4043
- rds: support instance snapshot lifecycle operations (#4066)
- redshift-serverless: add running workgroups and Data API WorkgroupName support (#5012)
- redshift: add external catalog statement parsing and metadata writers (#4679)
- redshift: add ModifyClusterIamRoles, DescribeClusterVersions and DescribeOrderableClusterOptions (#3990)
- redshift: authorize COPY and UNLOAD with IAM_ROLE (#3815)
- redshift: implement snapshot copy grant lifecycle (#3628)
- redshift: implement zero-ETL integrations (#3559)
- redshift: manage master password with secrets manager (#3871)
- redshift: materialize Glue external tables into PostgreSQL (#4996)
- redshift: seed catalog and system views (#3552)
- redshiftserverless: add namespace lifecycle and tagging (#3631)
- redshift: support Redshift Spectrum phase one (#4184)
- redshift: support S3 COPY JSON and manifest, and DynamoDB zero-ETL backfill (#3889)
- release: sign published image attestations with keyless cosign (#3914), closes #2397
- route53: implement UpdateHostedZoneComment (#3906)
- route53: resolve private hosted zone records from cluster containers (#4353)
- route53resolver: apply resolver rules to DNS resolution (#4538)
- s3: enforce Block Public Access on the data plane (#4253)
- s3: evaluate bucket policies for authenticated callers (#3632)
- sagemaker: add SageMaker emulation with Docker-backed training (#1949)
- sagemaker: support GPU-backed training jobs (#4015) containers/podman#22645
- scheduler: start Step Functions targets (#3936)
- secretsmanager: add the five missing actions and correct response fidelity (#3711)
- ses: add the S/MIME identity certificate operations (#5111)
- ses: add UpdateConfigurationSet and MessageSecurityOptions (#5092)
- ses: add v2 BatchGetMetricData (#4302)
- ses: add v2 export jobs (#4327)
- ses: add v2 GetMessageInsights (#4157)
- ses: add v2 import jobs for the suppression list and contact lists (#3892)
- ses: apply the ListContacts filter (#4981)
- ses: apply the ListTenants filter (#5060)
- ses: paginate template lists and align ListExportJobs paging (#4465)
- ses: paginate the contact, dedicated IP pool, suppressed destination and receipt rule set lists (#4877)
- ses: paginate the identity, configuration set and custom verification template lists (#4781)
- ses: paginate the tenant and import job lists (#4819)
- ses: run custom verification emails through the shared send preamble (#4212)
- ses: scan raw sends for the EICAR test file and keep it out of the mailbox store (#4156)
- sfn: apply ItemBatcher to distributed Map children (#3604)
- sfn: honour ToleratedFailureCount and ToleratedFailurePercentage (#3605)
- sfn: Map ItemReader with s3:listObjectsV2 (#3460), closes #3409
- sfn: resolve dynamic ItemReader max items (#3731)
- sfn: support ItemReader InputType CSV (#3603)
- sfn: support ItemReader InputType JSONL (#3602)
- sns: add the MaximumMessageSize topic attribute for 1 MiB payloads (#3953)
- sns: deliver published messages to firehose subscriptions (#4079), closes #4068
- sns: support SMS account preferences (#4597)
- sqs: expire messages after MessageRetentionPeriod (#4706)
- ssm: seed the EKS optimized AMI parameter paths (#4191)
- stepfunctions: route RDS Data execute statement (#4179)
- stepfunctions: support Scheduler DeleteSchedule (#3983)
- timestream-influxdb: add Timestream for InfluxDB backed by InfluxDB 2.x containers (#3683), closes #2566
- ui: add a bind address for the web console sidecar (#4175)
- verifiedpermissions: run Cedar from the floci-sidecar-cedar image (#3799)
- wafv2: provision web ACL associations (#4804)
Performance Improvements
- docker: trim docker-java reflection, 3 MB off the native image (#4625)
- iam: cache parsed policy and lowercase patterns once (#3635)
- iam: find sessions across accounts without scanning every session (#3881)
- kms: drop unused BouncyCastle curves from the native image (#4868)
- logs: filter log events by time before sorting (#4474)
- s3: assemble multipart uploads without doubling the object in heap (#4227)
- s3: compute CRC64NVME eight bytes at a time (#4126)
- s3: speed up CompleteMultipartUpload by reusing part ETags (#4145)