github ministackorg/ministack v1.5.19

2 hours ago

What's Changed

New Contributors

[1.5.19] — 2026-09-30

Added

  • Kinesis — SubscribeToShard — enhanced fan-out: a registered consumer receives the shard's records as SubscribeToShardEvents over an event stream (HTTP/1.1 or HTTP/2) for up to 5 minutes, from any StartingPosition, with ContinuationSequenceNumber for resuming and ChildShards when the shard is split or merged. A second call for the same consumer and shard within 5 seconds is a ResourceInUseException; a later one takes the subscription over.
  • CloudWatch Logs — resource policies — PutResourcePolicy, DescribeResourcePolicies and DeleteResourcePolicy, account-scoped (up to 10) or scoped to one log group through resourceArn, with expectedRevisionId checks. AWS::Logs::ResourcePolicy stacks now create real policies. Contributed by @fabio-andre-rodrigues.
  • CloudFormation — RollbackStack — rolls a stack left CREATE_FAILED or UPDATE_FAILED with rollback disabled back to its last stable state: a failed create ends ROLLBACK_COMPLETE, a failed update reverts its changes, deletes what it added and ends UPDATE_ROLLBACK_COMPLETE. RetainExceptOnCreate is honoured. Contributed by @fabio-andre-rodrigues.
  • CloudFormation — stack drift detection — DetectStackDrift, DescribeStackDriftDetectionStatus, DetectStackResourceDrift and DescribeStackResourceDrifts compare the properties a template sets, plus stack-level tags, with the service's current record (IN_SYNC, MODIFIED with PropertyDifferences, DELETED); stacks and resources report DriftInformation. Contributed by @fabio-andre-rodrigues.
  • Bedrock AgentCore — resource-based policies — PutResourcePolicy, GetResourcePolicy and DeleteResourcePolicy persist policies for runtimes and endpoints. With AUTH=true, runtime invocation evaluates caller principals, explicit denies and the runtime-plus-endpoint policy requirement for cross-account calls. This emulates the documented AgentCore policy contract locally; it does not validate behavior against AWS. Contributed by @pingedbrain.
  • KMS — grants — CreateGrant, RevokeGrant and RetireGrant; ListGrants now returns the grants they create, filtered by GrantId / GranteePrincipal and paged with Limit / Marker. CreateGrant follows the key state, rejects operations the key type cannot perform, and is idempotent for a named grant. Grants persist with the key and are not evaluated for authorization. Contributed by @DaviReisVieira.
  • RDS — IAM database authentication for MySQL and Aurora MySQL — users created IDENTIFIED WITH AWSAuthenticationPlugin AS 'RDS' log in with an SDK-generated token over mysql_clear_password, as on AWS. The instance or cluster must have IAMDatabaseAuthenticationEnabled; with AUTH=true the token and the rds-db:connect policy are verified too. ModifyDBInstance accepts EnableIAMDatabaseAuthentication. Contributed by @Areson.

Fixed

  • Bedrock AgentCore — runtime and endpoint ARNs match AWS — CreateAgentRuntime returned …:agent/{uuid}:{version} and endpoints …:agentEndpoint/{uuid}, so identity and resource policies written for AWS never matched and every update changed the runtime ARN. Runtimes are now …:runtime/{agentRuntimeId}, stable across updates, endpoints are …:runtime/{agentRuntimeId}/runtime-endpoint/{name}, and the DEFAULT endpoint is created with the runtime and follows its latest version. Saved state moves to the new ARNs on restore.
  • Bedrock AgentCore — InvokeAgentRuntime enforces IAM policies — with AUTH=true, a runtime invocation resolves to bedrock-agentcore:InvokeAgentRuntime and is authorized against both the runtime ARN and its runtime-endpoint ARN (the qualifier, or DEFAULT), as AWS requires, so a policy can allow one runtime and deny another. Before, the action was not extracted and the invocation skipped policy evaluation. Contributed by @pingedbrain.
  • IAM — a negated condition operator is true when its key is absent — the evaluator treated an absent key as a failed condition for every operator, so a Deny guarded by StringNotEquals, StringNotLike, ArnNotLike, NotIpAddress or another negated operator never applied to a request without that key. AWS evaluates such a condition as true and denies. The single-valued negated operators now do the same, while ForAnyValue and the affirmative operators still fail on an absent key. Contributed by @iot-rocket.
  • Secrets Manager — BatchGetSecretValue returns only the secrets the caller may read — under AUTH=true a grant on secretsmanager:BatchGetSecretValue alone returned every secret in the request, and Filters were ignored, so a filtered call returned the whole store. Each secret now needs secretsmanager:GetSecretValue and lands in Errors as AccessDeniedException without it, a call by Filters also needs secretsmanager:ListSecrets, and the filters select the secrets as in ListSecrets. Contributed by @iot-rocket.
  • CloudFormation — change set members follow the action — Add and Remove changes carried Replacement: False, a Remove had no physical id, PolicyAction was never sent and a Metadata or policy detail had no RequiresRecreation. Remove and Modify now name the physical resource, a Remove answers PolicyAction: Delete and a replacing Modify ReplaceAndDelete unless the resource retains or snapshots, and attribute details answer Never. PolicyAction also reports Retain, Snapshot and their ReplaceAnd forms from the resource's policy. Contributed by @iot-rocket.
  • CloudFormation — AWS::SQS::Queue applies every queue property — RedrivePolicy, RedriveAllowPolicy, KmsMasterKeyId, KmsDataKeyReusePeriodSeconds, SqsManagedSseEnabled, DeduplicationScope and FifoThroughputLimit were dropped on create and update, so a dead-letter queue declared in a template never received messages, and a value SQS refuses now fails the resource instead of being stored. A queue from a template also defaults to a 1 MiB MaximumMessageSize and SSE-SQS encryption, as on AWS. Contributed by @iot-rocket.
  • Lambda — Docker executor honors timeouts above 300 seconds — pass the configured Timeout to AWS RIE through AWS_LAMBDA_FUNCTION_TIMEOUT, preventing its default 300-second limit from ending longer invocations early. Timeout updates recycle warm containers so the RIE deadline follows the new configuration. Contributed by @gakuto-cw21.
  • CloudFormation — a nested stack's update deletes the resources its template drops — a resource removed from the child template, or created by a failed child update that was rolled back, stayed in its service and in the nested stack's resource list. A dropped resource with a Retain or Snapshot DeletionPolicy is kept or snapshotted first, as on AWS. Contributed by @iot-rocket.
  • KMS — KeyMaterialId — GenerateDataKey, GenerateDataKeyWithoutPlaintext, GenerateDataKeyPair, GenerateDataKeyPairWithoutPlaintext, Decrypt, ImportKeyMaterial and DeleteImportedKeyMaterial return the identifier of the key material they used, and DescribeKey reports it as CurrentKeyMaterialId for symmetric keys. The identifier stays the same until the key material changes. Contributed by @zlberto.
  • Lambda — VPC configuration includes VpcId — CreateFunction, GetFunction, GetFunctionConfiguration, and UpdateFunctionConfiguration now report the VPC of the configured subnets. Previously, VPC-attached functions returned only subnet and security group IDs. Contributed by @jayjanssen.
  • Lambda — a Docker invocation that reaches its timeout fails — the emulator's plain-text Task timed out reply was returned as a successful payload, so Step Functions recorded TaskSucceeded and skipped Catch. Contributed by @drakeo338. Reported by @gakuto-cw21.
  • RDS — a persisted instance stays reachable after a restart — when its saved host port was taken, the instance moved to a new port but Endpoint.Port kept the old one.
  • RDS — pending boolean modifications read as true — PendingModifiedValues wrote Python True/False, which the SDKs parse as false.
  • CloudFormation — OnFailure and OnStackFailure are honoured — CreateStack OnFailure and CreateChangeSet OnStackFailure take DO_NOTHING, ROLLBACK or DELETE (roll back, then delete the stack). OnFailure with DisableRollback, or OnStackFailure=DELETE on a non-CREATE change set, is a ValidationError. ExecuteChangeSet now honours DisableRollback=true. Contributed by @fabio-andre-rodrigues.
  • CloudFormation — DeleteStack DeletionMode=FORCE_DELETE_STACK — on a DELETE_FAILED stack, resources that fail to delete and their dependencies are retained as DELETE_SKIPPED and the stack reaches DELETE_COMPLETE; on any other status it is a ValidationError. Contributed by @fabio-andre-rodrigues.
  • CloudFormation — GetTemplate TemplateStage and ChangeSetName — Processed, now the default, returns the template after its transforms; Original returns it as sent. StagesAvailable is reported, and ChangeSetName returns a change set's template (ChangeSetNotFound when unknown). Contributed by @fabio-andre-rodrigues.
  • CloudFormation — stack events carry ClientRequestToken — every event of CreateStack, UpdateStack, DeleteStack, ExecuteChangeSet, ContinueUpdateRollback, CancelUpdateStack and RollbackStack carries that call's token. Contributed by @fabio-andre-rodrigues.
  • RDS — instances become available under MINISTACK_RDS_PUBLIC_ENDPOINT=1 in a container — database containers were left off MiniStack's network, so readiness never connected and the instance stayed creating. They now join the network for readiness and internal wiring, and DescribeDBInstances / DescribeDBClusters still report {MINISTACK_HOST, host_port}. Contributed by @skialpine.
  • IoT — RegisterCACertificate checks the verification certificate — DEFAULT mode requires a verificationCertificate signed by the CA with the registration code as its CN, and SNI_ONLY refuses one, each with its own error; AWS::IoT::CACertificate fails the same way. Contributed by @iot-rocket.

Don't miss a new ministack release

NewReleases is sending notifications on new releases.