github ministackorg/ministack v1.5.18

3 hours ago

What's Changed

New Contributors

[1.5.18] — 2026-09-28

Added

  • Bedrock AgentCore — InvokeAgentRuntime runs the runtime's container — with Docker available (full image), the runtime's containerConfiguration.containerUri image is started, checked on /ping, and invocations are forwarded to its /invocations on port 8080; container failures answer RuntimeClientError (424). The container is removed on update, delete or reset. Without Docker, or for a code artifact, the deterministic echo remains. Contributed by @pingedbrain.
  • CloudWatch Logs — delivery destination policy — PutDeliveryDestinationPolicy, GetDeliveryDestinationPolicy and DeleteDeliveryDestinationPolicy, so a delivery that needs a destination policy can be created. Contributed by @fabio-andre-rodrigues.
  • Cognito — OIDC discovery through the real issuer host (USE_SSL=1) — the generated certificate covers cognito-idp.<region>.amazonaws.com for every region and Lambda containers resolve those hosts to MiniStack and trust it. With an /etc/hosts entry and the certificate trusted, an unmodified client follows the token's iss to MiniStack while iss stays exactly as AWS issues it. Reported by @epcap90.
  • KMS — ListGrants — it answered InvalidAction. It now lists the key's grants (empty, since grants are not modelled) and answers NotFoundException for an unknown key. Reported by @DaviReisVieira.
  • S3 — object annotations — PutObjectAnnotation, GetObjectAnnotation, ListObjectAnnotations and DeleteObjectAnnotation: up to 1,000 UTF-8 payloads per object version, carried by CopyObject unless the directive is EXCLUDE, removed with their version, and announced with s3:ObjectAnnotation:* events. Under AUTH=true, Object Lock refuses annotation writes with 403 AccessDenied. Previously a PUT ?annotation replaced the object with the payload. Contributed by @BoLaMN.
  • SNS — AddPermission and RemovePermission — they add and remove labelled statements in the topic's Policy; a duplicate label answers InvalidParameter. Contributed by @AdrianAcala.

Fixed

  • API Gateway v1 — REQUEST authorizer events carry requestContext.identity — an authorizer reading sourceIp or userAgent crashed; both are now present, as in the AWS_PROXY event. Contributed by @yosriady.
  • DynamoDB — a table ARN is accepted wherever TableName is — item, query, scan, batch, transaction and table operations answered ValidationException or ResourceNotFoundException for the table's ARN. Batch responses keep the key form the request used. Contributed by @valeryan.
  • Gateway — the soft open-file limit is raised to the hard limit at startup — a burst of about a thousand client connections exhausted the default 1024 descriptors. Reported by @fabio-andre-rodrigues.
  • KMS — ListAliases entries carry CreationDate and LastUpdatedDate — both were missing; UpdateAlias moves LastUpdatedDate and keeps CreationDate. Reported by @DaviReisVieira.
  • Lambda — ReservedConcurrentExecutions is shared across versions — $LATEST and published versions each counted separately and could exceed the reservation together. Contributed by @jgrumboe.
  • S3 — event notification records match S3's — the key is URL-encoded, versionId and a growing sequencer are set, eventVersion is 2.6, a delete marker is ObjectRemoved:DeleteMarkerCreated, and DeleteObjects sends one event per object it removes. Contributed by @BoLaMN.
  • S3 — notification destinations are validated at PUT time — under AUTH=true, PutBucketNotificationConfiguration fails with InvalidArgument when an SQS/SNS destination's policy does not let S3 publish; cross-account destinations are accepted. Contributed by @AdrianAcala.
  • SQS/SNS — queue and topic policies are enforced under AUTH=true — they were stored but never evaluated. Cross-account calls need an explicit Allow (AccessDenied for SQS, AuthorizationError for SNS), and S3 and SNS deliveries need the destination policy to allow them. With AUTH=false nothing changes. Contributed by @AdrianAcala.
  • STS — GetCallerIdentity resolves IAM-user callers — keys from CreateAccessKey reported root; they now return the user's ARN and ID. Contributed by @AdrianAcala.
  • STS — an unknown access key answers InvalidClientTokenId — under AUTH=true, STS answered UnrecognizedClientException.

Don't miss a new ministack release

NewReleases is sending notifications on new releases.