What's Changed
New Contributors
- @zlberto made their first contribution in #1854
- @gakuto-cw21 made their first contribution in #1857
- @drakeo338 made their first contribution in #1855
- @skialpine made their first contribution in #1885
[1.5.19] — 2026-09-30
Added
- Kinesis —
SubscribeToShard— enhanced fan-out: a registered consumer receives the shard's records asSubscribeToShardEvents over an event stream (HTTP/1.1 or HTTP/2) for up to 5 minutes, from anyStartingPosition, withContinuationSequenceNumberfor resuming andChildShardswhen the shard is split or merged. A second call for the same consumer and shard within 5 seconds is aResourceInUseException; a later one takes the subscription over. - CloudWatch Logs — resource policies —
PutResourcePolicy,DescribeResourcePoliciesandDeleteResourcePolicy, account-scoped (up to 10) or scoped to one log group throughresourceArn, withexpectedRevisionIdchecks.AWS::Logs::ResourcePolicystacks now create real policies. Contributed by @fabio-andre-rodrigues. - CloudFormation —
RollbackStack— rolls a stack leftCREATE_FAILEDorUPDATE_FAILEDwith rollback disabled back to its last stable state: a failed create endsROLLBACK_COMPLETE, a failed update reverts its changes, deletes what it added and endsUPDATE_ROLLBACK_COMPLETE.RetainExceptOnCreateis honoured. Contributed by @fabio-andre-rodrigues. - CloudFormation — stack drift detection —
DetectStackDrift,DescribeStackDriftDetectionStatus,DetectStackResourceDriftandDescribeStackResourceDriftscompare the properties a template sets, plus stack-level tags, with the service's current record (IN_SYNC,MODIFIEDwithPropertyDifferences,DELETED); stacks and resources reportDriftInformation. Contributed by @fabio-andre-rodrigues. - Bedrock AgentCore — resource-based policies —
PutResourcePolicy,GetResourcePolicyandDeleteResourcePolicypersist policies for runtimes and endpoints. WithAUTH=true, runtime invocation evaluates caller principals, explicit denies and the runtime-plus-endpoint policy requirement for cross-account calls. This emulates the documented AgentCore policy contract locally; it does not validate behavior against AWS. Contributed by @pingedbrain. - KMS — grants —
CreateGrant,RevokeGrantandRetireGrant;ListGrantsnow returns the grants they create, filtered byGrantId/GranteePrincipaland paged withLimit/Marker.CreateGrantfollows the key state, rejects operations the key type cannot perform, and is idempotent for a named grant. Grants persist with the key and are not evaluated for authorization. Contributed by @DaviReisVieira. - RDS — IAM database authentication for MySQL and Aurora MySQL — users created
IDENTIFIED WITH AWSAuthenticationPlugin AS 'RDS'log in with an SDK-generated token overmysql_clear_password, as on AWS. The instance or cluster must haveIAMDatabaseAuthenticationEnabled; withAUTH=truethe token and therds-db:connectpolicy are verified too.ModifyDBInstanceacceptsEnableIAMDatabaseAuthentication. Contributed by @Areson.
Fixed
- Bedrock AgentCore — runtime and endpoint ARNs match AWS —
CreateAgentRuntimereturned…:agent/{uuid}:{version}and endpoints…:agentEndpoint/{uuid}, so identity and resource policies written for AWS never matched and every update changed the runtime ARN. Runtimes are now…:runtime/{agentRuntimeId}, stable across updates, endpoints are…:runtime/{agentRuntimeId}/runtime-endpoint/{name}, and theDEFAULTendpoint is created with the runtime and follows its latest version. Saved state moves to the new ARNs on restore. - Bedrock AgentCore —
InvokeAgentRuntimeenforces IAM policies — withAUTH=true, a runtime invocation resolves tobedrock-agentcore:InvokeAgentRuntimeand is authorized against both the runtime ARN and its runtime-endpoint ARN (thequalifier, orDEFAULT), as AWS requires, so a policy can allow one runtime and deny another. Before, the action was not extracted and the invocation skipped policy evaluation. Contributed by @pingedbrain. - IAM — a negated condition operator is true when its key is absent — the evaluator treated an absent key as a failed condition for every operator, so a
Denyguarded byStringNotEquals,StringNotLike,ArnNotLike,NotIpAddressor another negated operator never applied to a request without that key. AWS evaluates such a condition as true and denies. The single-valued negated operators now do the same, whileForAnyValueand the affirmative operators still fail on an absent key. Contributed by @iot-rocket. - Secrets Manager —
BatchGetSecretValuereturns only the secrets the caller may read — underAUTH=truea grant onsecretsmanager:BatchGetSecretValuealone returned every secret in the request, andFilterswere ignored, so a filtered call returned the whole store. Each secret now needssecretsmanager:GetSecretValueand lands inErrorsasAccessDeniedExceptionwithout it, a call byFiltersalso needssecretsmanager:ListSecrets, and the filters select the secrets as inListSecrets. Contributed by @iot-rocket. - CloudFormation — change set members follow the action —
AddandRemovechanges carriedReplacement: False, aRemovehad no physical id,PolicyActionwas never sent and aMetadataor policy detail had noRequiresRecreation.RemoveandModifynow name the physical resource, aRemoveanswersPolicyAction: Deleteand a replacingModifyReplaceAndDeleteunless the resource retains or snapshots, and attribute details answerNever.PolicyActionalso reportsRetain,Snapshotand theirReplaceAndforms from the resource's policy. Contributed by @iot-rocket. - CloudFormation —
AWS::SQS::Queueapplies every queue property —RedrivePolicy,RedriveAllowPolicy,KmsMasterKeyId,KmsDataKeyReusePeriodSeconds,SqsManagedSseEnabled,DeduplicationScopeandFifoThroughputLimitwere dropped on create and update, so a dead-letter queue declared in a template never received messages, and a value SQS refuses now fails the resource instead of being stored. A queue from a template also defaults to a 1 MiBMaximumMessageSizeand SSE-SQS encryption, as on AWS. Contributed by @iot-rocket. - Lambda — Docker executor honors timeouts above 300 seconds — pass the configured
Timeoutto AWS RIE throughAWS_LAMBDA_FUNCTION_TIMEOUT, preventing its default 300-second limit from ending longer invocations early. Timeout updates recycle warm containers so the RIE deadline follows the new configuration. Contributed by @gakuto-cw21. - CloudFormation — a nested stack's update deletes the resources its template drops — a resource removed from the child template, or created by a failed child update that was rolled back, stayed in its service and in the nested stack's resource list. A dropped resource with a
RetainorSnapshotDeletionPolicyis kept or snapshotted first, as on AWS. Contributed by @iot-rocket. - KMS —
KeyMaterialId—GenerateDataKey,GenerateDataKeyWithoutPlaintext,GenerateDataKeyPair,GenerateDataKeyPairWithoutPlaintext,Decrypt,ImportKeyMaterialandDeleteImportedKeyMaterialreturn the identifier of the key material they used, andDescribeKeyreports it asCurrentKeyMaterialIdfor symmetric keys. The identifier stays the same until the key material changes. Contributed by @zlberto. - Lambda — VPC configuration includes
VpcId—CreateFunction,GetFunction,GetFunctionConfiguration, andUpdateFunctionConfigurationnow report the VPC of the configured subnets. Previously, VPC-attached functions returned only subnet and security group IDs. Contributed by @jayjanssen. - Lambda — a Docker invocation that reaches its timeout fails — the emulator's plain-text
Task timed outreply was returned as a successful payload, so Step Functions recordedTaskSucceededand skippedCatch. Contributed by @drakeo338. Reported by @gakuto-cw21. - RDS — a persisted instance stays reachable after a restart — when its saved host port was taken, the instance moved to a new port but
Endpoint.Portkept the old one. - RDS — pending boolean modifications read as
true—PendingModifiedValueswrote PythonTrue/False, which the SDKs parse asfalse. - CloudFormation —
OnFailureandOnStackFailureare honoured — CreateStackOnFailureand CreateChangeSetOnStackFailuretakeDO_NOTHING,ROLLBACKorDELETE(roll back, then delete the stack).OnFailurewithDisableRollback, orOnStackFailure=DELETEon a non-CREATEchange set, is aValidationError. ExecuteChangeSet now honoursDisableRollback=true. Contributed by @fabio-andre-rodrigues. - CloudFormation —
DeleteStackDeletionMode=FORCE_DELETE_STACK— on aDELETE_FAILEDstack, resources that fail to delete and their dependencies are retained asDELETE_SKIPPEDand the stack reachesDELETE_COMPLETE; on any other status it is aValidationError. Contributed by @fabio-andre-rodrigues. - CloudFormation —
GetTemplateTemplateStageandChangeSetName—Processed, now the default, returns the template after its transforms;Originalreturns it as sent.StagesAvailableis reported, andChangeSetNamereturns a change set's template (ChangeSetNotFoundwhen unknown). Contributed by @fabio-andre-rodrigues. - CloudFormation — stack events carry
ClientRequestToken— every event of CreateStack, UpdateStack, DeleteStack, ExecuteChangeSet, ContinueUpdateRollback, CancelUpdateStack and RollbackStack carries that call's token. Contributed by @fabio-andre-rodrigues. - RDS — instances become
availableunderMINISTACK_RDS_PUBLIC_ENDPOINT=1in a container — database containers were left off MiniStack's network, so readiness never connected and the instance stayedcreating. They now join the network for readiness and internal wiring, andDescribeDBInstances/DescribeDBClustersstill report{MINISTACK_HOST, host_port}. Contributed by @skialpine. - IoT —
RegisterCACertificatechecks the verification certificate —DEFAULTmode requires averificationCertificatesigned by the CA with the registration code as its CN, andSNI_ONLYrefuses one, each with its own error;AWS::IoT::CACertificatefails the same way. Contributed by @iot-rocket.