What's Changed
[1.5.20] — 2026-10-01
Added
- DynamoDB — global table replicas through
UpdateTableReplicaUpdates— aCreatewas accepted and ignored, so Terraform / OpenTofuaws_dynamodb_tablewith areplicablock waited forever. ACreatenow copies the table and its items to the other region and turns onNEW_AND_OLD_IMAGESstreams;DescribeTablereportsGlobalTableVersion2019.11.21and the other regions underReplicasasACTIVE; writes and TTL settings replicate;Deleteremoves the replica. Reported by @wparad. - IoT — registry events — with a type enabled through
UpdateEventConfigurations, the thing, thing type, thing type association, thing group, thing group hierarchy and thing group membership operations publish the AWS payload to$aws/events/..., where MQTT subscribers and topic rules receive it. Contributed by @iot-rocket. - ElastiCache — serverless caches —
CreateServerlessCache,DescribeServerlessCaches,ModifyServerlessCacheandDeleteServerlessCacheforvalkey(major 7, 8 or 9) andredis(major 7). With Docker each cache gets a TLS-only Valkey or Redis container whose certificate chains to the CA atGET /_ministack/elasticache/ca.pem.ModifyServerlessCacheallows a same-engine major upgrade, redis to valkey, and valkey 7 to redis 7. Memcached serverless caches and serverless snapshots are refused withInvalidParameterValue. Contributed by @skialpine. - CloudFormation —
AWS::Lambda::VersionupdatesFunctionScalingConfigin place — a stack update re-ran the create, which published a new version for every change; aFunctionScalingConfigchange now keeps the version, also when the update rolls back. Contributed by @iot-rocket. - CloudFormation —
AWS::Glue::Database,Table,Partition,Connection,Crawler,JobandTrigger— they failed withUnrecognized resource types; they now create, update and delete through the Glue API, so Athena and the Glue API read a stack's tables. Ref andFn::GetAttfollow the CloudFormation reference, as do replacing and in-place properties; aDatabaseInput.Namechange fails withDatabase <name> not foundand rolls back, as on AWS. Crawlers and jobs are only recorded, never run. Contributed by @fabio-andre-rodrigues. - CloudFormation —
AWS::ElastiCache::SubnetGroup,ParameterGroup,CacheCluster,ReplicationGroup,UserandUserGroup— they failed withUnrecognized resource types; they now go through the ElastiCache API, so a stack's cluster or replication group gets a real container-backed endpoint to pass to a Lambda function or ECS task. Replacement follows the CloudFormation reference (includingNumCacheNodeswhen no Availability Zone is given), everything else updates in place, andFn::GetAtton an endpoint the resource does not have fails, as the reference says. Contributed by @fabio-andre-rodrigues. - IoT —
DescribeEventConfigurationsandUpdateEventConfigurations— both answeredUnsupported IoT path; they now store the registry event switches per account and region, every type starting disabled, an update changing only the types it names, andcreationDate/lastModifiedDateset from the first update on, as on AWS. Contributed by @iot-rocket. - CloudFormation —
AWS::ServiceDiscovery::HttpNamespace,PrivateDnsNamespace,PublicDnsNamespace,ServiceandInstance— they failed withUnrecognized resource types, which blocked the CDK ECS Cloud Map constructs; they now go through the Cloud Map API, with Ref,Fn::GetAttand replacement as in the CloudFormation reference. Namespaces now storeProperties.DnsProperties.SOA.TTL, andDeleteNamespaceremoves the namespace's hosted zone, as on AWS. Contributed by @fabio-andre-rodrigues. - Bedrock AgentCore — runtime version history and endpoint pinning — runtime updates now retain version snapshots,
GetAgentRuntimeretrieves a selected version, andListAgentRuntimeVersionspaginates the history.DEFAULTadvances with the latest version while named endpoints stay pinned until updated; invocations use the selected snapshot, with containers isolated by version. Contributed by @pingedbrain. - Bedrock AgentCore —
ListAgentRuntimesandListAgentRuntimeEndpointspaginate — both takemaxResultsandnextTokenand return anextTokenonly when another page exists. Contributed by @pingedbrain.
Changed
- botocore 1.43.106 — the service models MiniStack reads move from 1.43.63 to 1.43.106; the images keep
awscli1.45.63, installed on the same botocore instead of its pinned one.
Fixed
- SES v2 —
ListEmailIdentitiesandListConfigurationSetsanswer the routes newer SDKs use — botocore 1.43.106 sends them asPOST /v2/email/list-identitiesandPOST /v2/email/list-configuration-setswithNextToken,PageSizeandFilterin the body; those paths answeredNotFoundException. Both forms page, and theFilterkeys are applied. - Kinesis —
ApproximateArrivalTimestampkeeps milliseconds — it was truncated to whole seconds, so anAT_TIMESTAMPiterator from an SDK that sends fractional seconds skipped records written earlier in the same second. - CloudFormation — an empty
Capabilitieslist is accepted — botocore sends it as a bareCapabilities=, which was read as one empty value and refused, soaws cloudformation deploywithout--capabilitiesandCapabilities=[]from an SDK failed with aValidationErrorsince 1.5.11. - API Gateway v2 (HTTP API) — the request path keeps a
%25escape —/items/a%252Ebreached the Lambda'srawPathas/items/a%2Eb, because the path was fully percent-decoded. The HTTP API path now keeps%25and decodes every other escape as before;rawPath,requestContext.http.path,pathParametersand route matching all use it. Contributed by @skialpine. - Step Functions — JSONPath
$$.paths read the context object — a Choice rule'sVariableand its variable-to-variable comparison paths (including insideAnd,OrandNot), and a state'sInputPath,OutputPathand MapItemsPath, resolved$$.against the state input, so a Choice on$$.Execution.Inputsilently took its default branch. They now read the context object, as the AWS context object reference lists for those fields. Contributed by @jayjanssen. - CloudFormation —
AWS::EC2::VPCGatewayAttachmentupdates in place — a changedInternetGatewayIdorVpnGatewayIdmoves the attachment under the sameIGW|vpc-…/VGW|vpc-…physical id,VpnGatewayIdis attached at all, and aVpcIdchange leaves the gateway attached to the new VPC, or to the old one when the update rolls back.AttachInternetGatewayon a gateway already attached to a VPC answersResource.AlreadyAssociated, and a stack attaching it to a second VPC leaves it on the first, as AWS does. Contributed by @iot-rocket. - CloudFormation —
AWS::Lambda::Versionpublishes throughPublishVersion— the version takes itsDescription, a version of a function unchanged since its latest version fails with theAlreadyExistserror AWS reports,FunctionScalingConfigon a function without a capacity provider is refused, and a function keeps itsCapacityProviderConfig. Contributed by @iot-rocket. - AppConfig — hosted configuration version numbers are never reused — a version created after a delete, and the replacement CloudFormation makes for a changed
HostedConfigurationVersion, get the next unused number instead of overwriting the live one, and aLatestVersionNumbermismatch reports the AWS message. Contributed by @iot-rocket. - CloudFormation — a deleted
AWS::AppConfig::Deploymentstays inListDeployments— the stack delete removed the deployment, so a replaced deployment left the environment's history and the next one reused its number; it now stays until its environment is deleted, which, through the API or with its stack, also removes its deployments and their tags. Contributed by @iot-rocket. - CloudFormation —
AWS::ECS::ServicestoresNetworkConfigurationandLoadBalancersin the ECS API shape —DescribeServicesreturns them in camelCase on create and update, and a service from a template registers its tasks in its target groups. Contributed by @iot-rocket. - SESv2 —
CreateEmailIdentity/GetEmailIdentityreturn Easy DKIM tokens for a DOMAIN identity — a domain identity created withoutDkimSigningAttributesanswered an emptyTokenslist withStatus: NOT_STARTED. AWS provides a set of DKIM tokens for its CNAME records in that case (Easy DKIM), so the Terraformaws_sesv2_email_identityresource'sdkim_signing_attributes[0].tokensindexing failed. A DOMAIN identity now gets three tokens,SigningAttributesOrigin: AWS_SESandStatus: PENDING, unlessDkimSigningAttributesbrings its own key (BYODKIM); EMAIL_ADDRESS identities are unchanged. Contributed by @skialpine. - Lambda — functions reach a
USE_SSL=1gateway — the gateway listener serves only HTTPS, but a function's defaultAWS_ENDPOINT_URLwas plain HTTP in every executor (Docker, the warm worker and the local subprocess), and the Docker executor's Node shim downgraded a function'shttps.requestto the gateway to HTTP, which the listener resets. The default endpoint now follows the gateway's scheme, the shim keeps TLS, and a host process trusts the gateway's certificate throughAWS_CA_BUNDLE/REQUESTS_CA_BUNDLE/NODE_EXTRA_CA_CERTSunless they are already set. WithoutUSE_SSLnothing changes. Contributed by @skialpine. - RDS —
MINISTACK_RDS_PUBLIC_ENDPOINT=1works with a Composehostname:— a containerised MiniStack whose container sets a hostname left instancescreating, because the self-lookup byHOSTNAMEfound no container. A containerised MiniStack now detects its network as with the setting off (DOCKER_NETWORK, then the self-lookup). Contributed by @skialpine. - IoT —
DeleteThingGrouprefuses a group with child groups — the delete went through and left the children pointing at a missing parent; it now fails withInvalidRequestException"Cannot delete thing group : {name} when there are still child groups attached to it", and a CloudFormation stack delete that reaches such a group ends inDELETE_FAILED. Contributed by @iot-rocket. - IoT —
UpdateThinghonoursremoveThingType— the flag was ignored, so the thing kept its type, and an update withoutattributePayloadcleared the attributes. Contributed by @iot-rocket. - API Gateway v2 (HTTP API) — a doubled leading slash still selects the route — a request to
//items/abcmatched no route and answered404 {"message":"Not Found"}. Route selection andpathParametersnow ignore the extra leading slashes;rawPathkeeps the path as received. Contributed by @skialpine. - Cloud Map —
DeleteNamespacerefuses a namespace that still has services — it deleted the namespace (and now its hosted zone) anyway. It answers400 ResourceInUse"Namespace has associated services; delete the services before deleting the namespace", as on AWS. - Lambda —
PublishVersionof an unchanged function returns the latest version — it published a new version every time; AWS doesn't publish when the code and configuration haven't changed since the last version, and returns that version with its original description. - API Gateway v2 (HTTP API) — REQUEST authorizer identity sources — a declared identity source missing from the request answers
401 {"message":"Unauthorized"}without invoking the authorizer, cached or not (it required caching).$context.*sources such as$context.routeKeyare resolved from the request instead of counting as missing, so an authorizer caching per route no longer answered 401 to every request. Contributed by @skialpine. - ECS — optional task-definition fields stay omitted — registering an EC2 task definition without task-level
cpu,memory, orrequiresCompatibilitiesno longer invents256,512, or["EC2"]in register, describe, and deregister responses. Explicitly supplied values remain in the definition. Contributed by @AdrianAcala. - IAM — customer-managed permissions use the explicit account — policy evaluation now resolves the complete policy ARN in the principal's account, so a different ambient request account cannot hide that policy or supply a foreign account's document. Permissions continue to follow the policy's current default version. Contributed by @AdrianAcala.
- Cognito —
USER_SRP_AUTHchecks the password —PASSWORD_VERIFIERaccepted any response, so a wrong password or a disabled or unconfirmed user got tokens. The challenge now carries SRP-6a parameters with a stable salt per user, and a response whose signature does not prove the stored password is refused withNotAuthorizedException;TIMESTAMPmust readEEE MMM d HH:mm:ss z yyyy, and a temporary password leads toNEW_PASSWORD_REQUIRED.CUSTOM_WITH_SRPgets the same check. Contributed by @iot-rocket. - Cognito — refresh tokens are checked against the pool and client —
REFRESH_TOKEN_AUTH(InitiateAuth,AdminInitiateAuth) andGetTokensFromRefreshTokenissued tokens for the first user in the pool when the refresh token was malformed, from another pool or of a deleted user, and accepted a token issued to another client; they now answerNotAuthorizedExceptionwith the message AWS gives for each case, and the refresh token from a SAML or OIDC federated sign-in now refreshes the federated user's session. Contributed by @iot-rocket. - CloudFormation —
AWS::S3Tables::TableBucketandAWS::S3Tables::Tableupdate in place — a stack update re-ran the create, which reset the bucket'screatedAtand rebuilt the table with a newcreatedAtand its initial metadata location, dropping committed metadata; a maintenance setting or tag change now keeps both, and a create-only table change under an unchanged name fails with the conflict AWS reports. Contributed by @iot-rocket. - RDS —
DescribeGlobalClusterslists clusters asGlobalClusterMember— each cluster was a<GlobalCluster>element, so SDKs that match the list member name, such as aws-sdk-go-v2, found none. Contributed by @IamYipi. - Amazon MQ —
DescribeBrokerInstanceOptionsreturnssupportedEngineVersionsas strings — they were{"name": ...}objects, which aws-sdk-go-v2 could not deserialize. Contributed by @IamYipi. - EventBridge —
UpdateEventBusreturns the bus — it answeredEventBusArnandLastModifiedTime, which are not response members, so SDKs returned nothing; it now returnsArn,Nameand the bus'sDescription,KmsKeyIdentifier,DeadLetterConfigandLogConfig. Contributed by @IamYipi. - CloudFormation —
AWS::CodeBuild::ProjectstoresSource,ArtifactsandEnvironmentunder CodeBuild API names — the template's PascalCase members andBuildSpecwere stored as written, soBatchGetProjectsdropped them and a build of a stack's project found no buildspec, image or environment variables. Contributed by @IamYipi. - Inspector2 — responses aws-sdk-go-v2 can read — timestamps are epoch seconds,
ListFiltersreturnscriteria,ownerId,createdAtandupdatedAt,CreateFilterreturnsarn, and coveragescanStatusis{statusCode, reason}. Saved state is converted on restore. Contributed by @IamYipi. - EventBridge —
PutEventsrefusesaws.*sources — an entry whoseSourcestarts withaws.fails withNotAuthorizedForSourceException(Not authorized for the source.) in its result entry and counts inFailedEntryCount, while the rest of the batch is delivered, as on AWS. Events published with anaws.*source throughPutEventsto simulate AWS services now get this error. Contributed by @iot-rocket. - SQS —
QueueUrlmatches the gateway's TLS scheme (USE_SSL=1) —CreateQueue/GetQueueUrl/ListQueuesalways returnedhttp://URLs, and the AWS SDK v3 uses the QueueUrl itself as the request endpoint (useQueueUrlAsEndpointdefaults true), so a client handed that URL left the TLS-only gateway. TheAWS::SQS::QueueCloudFormation provisioner built the same hardcoded scheme and now reuses the shared helper. Contributed by @skialpine. - API Gateway v2 (HTTP API) — a request no stage or route matches answers AWS's exact 404 body — an unmatched route answered
{"message": "No route found"}and an unknown stage{"message": "Stage '…' not found"}; both now answer{"message":"Not Found"}(compact JSON), as AWS does. Contributed by @skialpine. - API Gateway v2 —
apiEndpointfollows the gateway's TLS scheme — withUSE_SSL=1the gateway listener serves only HTTPS, but CreateApi and theAWS::ApiGatewayV2::ApiCloudFormation resource always returned anhttp://apiEndpoint, which nothing answers. They now returnhttps://, orwss://for a WebSocket API, as AWS does. WithoutUSE_SSLthe endpoint keepshttp://. Contributed by @skialpine. - IAM — condition value lists and request-tag key matching — negated conditions now match only when none of their policy values match, so a
StringNotEqualsdeny listing permitted values no longer denies one of those values. Request-tag condition keys match every tag name without regard to case, including names that differ only by case; affirmative conditions match any of those values and negated conditions match none. Comparisons of tag values keep the selected operator's case rules. Contributed by @AdrianAcala. - SSM — parameter tag actions authorize the parameter named by
ResourceId— withAUTH=true,AddTagsToResource,RemoveTagsFromResource, andListTagsForResourcecheckedNameinstead, so an exact ARN allow could fail and an exact ARN deny could be missed under a broad allow. Accepted parameter-name and ARN aliases now use the canonical parameter ARN for the IAM check. SSM authorization denials now match AWS's HTTP 400 JSON 1.1 response, including the canonical resource and explicit-deny reason. Contributed by @AdrianAcala. - Bedrock AgentCore — a missing runtime answers AWS's message — the control-plane runtime operations answered
Agent runtime <id> not found; they now answerResourceNotFoundException"Agent '' was not found. Please check the agent ID and try again.", as AWS does.