What's Changed
New Contributors
- @mishukdutta-cz made their first contribution in #1962
[1.5.21] — 2026-10-03
Added
- API Gateway v2 — custom domain names and API mappings —
CreateDomainName,GetDomainName,GetDomainNames,UpdateDomainName,DeleteDomainNameandCreate/Get/Update/DeleteApiMapping(s), with domain tags throughTagResource, list pagination, andBadRequestException"Invalid stage identifier specified" for a mapping to a missing stage;AWS::ApiGatewayV2::DomainNameandAWS::ApiGatewayV2::ApiMappingin CloudFormation. A domain and its mappings are the same resource as the API Gateway v1 domain and base path mappings, and a request whoseHostis the domain reaches the mapped HTTP API. Reported by @wparad. - CloudFormation — stack updates replace resources — a change to a property the change set reports as
RequiresRecreation: Alwaysnow creates a new resource under a new generated name, points its dependents at it and deletes the old one after the update succeeds (a rollback deletes the new one instead). With an explicit, unchanged name the update fails with the AWS message naming the physical id; this now also coversAWS::Lambda::Function. A named SQS queue or SNS topic fails with AWS's already-exists error instead and keeps its messages or subscriptions. Contributed by @iot-rocket. - CloudFormation —
AWS::EFS::FileSystem,AWS::EFS::MountTargetandAWS::EFS::AccessPoint— the three types create, update in place and are replaced on create-only changes through the EFS store, withRefandFn::GetAttas in the template reference, so CDKefs.FileSystemstacks deploy. Contributed by @fabio-andre-rodrigues. - EFS — file system policy, protection and replication —
PutFileSystemPolicy,DescribeFileSystemPolicy,DeleteFileSystemPolicy,UpdateFileSystemProtectionandCreate/Describe/DeleteReplicationConfiguration;CreateMountTargetchecks the subnet, security groups, zone and address (SubnetNotFound,SecurityGroupNotFound,MountTargetConflict,AvailabilityZonesMismatch,IpAddressInUse), andDeleteFileSystemwith mount targets answers 409. Contributed by @fabio-andre-rodrigues. - Bedrock AgentCore — Memory resources —
CreateMemory,GetMemory,ListMemories,UpdateMemoryandDeleteMemory; memory strategies are recorded without extraction. Contributed by @pingedbrain. - Athena — databases, DDL, and Trino-style table references —
ListDatabasesandGetDatabaseread the Glue Data Catalog;CREATE EXTERNAL TABLEandDROP TABLEapply to it, creating the Glue table Athena would (formats, SerDe, TBLPROPERTIES);CREATE TABLEwithoutEXTERNALis rejected as Athena rejects it, and Iceberg tables are not supported; a query may name a table as"awsdatacatalog"."db"."t"ordb.t. Contributed by @sjincho. - CloudFront — distributions serve traffic, plus the AWS-managed policies and monitoring subscriptions — a request to
<label>.cloudfront.net(or<label>.cloudfront.<MINISTACK_HOST>) is served: ordered cache behaviors,ViewerProtocolPolicy,AllowedMethods,DefaultRootObject, cache and origin request policy forwarding (and legacyForwardedValues),viewer-request/viewer-responseCloudFront Functions, response headers policies, and S3 or custom origins; an S3 origin is read only as the bucket policy allows it (OAC, OAI or public).DomainNamehas the AWSd+ 13-character shape.List*Policiesreturn the AWS-managed cache, origin request and response headers policies, andCreate/Get/DeleteMonitoringSubscriptionare implemented. Not modelled: caching, WAF, logging, geo restrictions, custom error pages, signed URLs and cookies, Lambda@Edge. Contributed by @skialpine. - CloudFormation — EKS cluster and node group updates —
AWS::EKS::ClusterappliesVersion,Logging,ResourcesVpcConfig,AccessConfig.AuthenticationModeandTagsin place andAWS::EKS::NodegroupappliesScalingConfig,Labels,Taints,UpdateConfig,LaunchTemplate,Version,ReleaseVersionandTags, where every such change used to reportUPDATE_COMPLETEand was dropped. Contributed by @iot-rocket. - CloudFormation —
AWS::Pipes::PipeandAWS::Scheduler::ScheduleGroupupdate in place — a pipe keeps its stream position andCreationTimewhenDescription,Target,RoleArn,DesiredStateorTagschange, getsDescriptionandTagson create and refuses a create-only source change under an explicitName, and a schedule group takes template and stack tag changes while keeping tags added throughTagResource. Contributed by @iot-rocket. - CloudFormation — ECR repositories are replaced — an
EncryptionConfigurationchange onAWS::ECR::Repositoryreplaces the repository under a new generated name (generated names now carry the usual suffix) and is refused for an explicitRepositoryName, where it used to be ignored. Contributed by @iot-rocket. - CloudFormation — IAM roles and managed policies are replaced — a
Pathchange onAWS::IAM::Roleand aPathorDescriptionchange onAWS::IAM::ManagedPolicyreplace the resource under a new generated name, a named role refuses it as a custom-named replacement, a named policy fails with the IAM duplicate-name error as on AWS, also when only itsPathchanges, generated policy names get the suffix other generated names have, and both ARNs include thePath. Contributed by @iot-rocket. - CloudFormation —
IMPORTchange sets execute — existing SQS queues, SSM parameters, S3 buckets, DynamoDB tables, IAM roles, log groups, Lambda functions, IoT policies, IoT CA certificates and Cognito user pools are adopted into a new or existing stack without being changed (IMPORT_IN_PROGRESStoIMPORT_COMPLETE, or a rollback when a resource is gone), and an import that changesOutputsor stack tags is refused, as on AWS. Contributed by @iot-rocket.
Fixed
- Docker — the image healthcheck probes
GATEWAY_PORT— it always requestedlocalhost:4566, so a container started on another port reportedunhealthywhile serving; it now resolves the port as the server does (GATEWAY_PORT, thenEDGE_PORT, then4566). Contributed by @skialpine. - Lambda — Node.js and Python functions start in the code directory —
process.cwd()andos.getcwd()were MiniStack's own directory, so libraries that read files relative to it (such asnode-config) missed the function's files; the working directory is now the code root (LAMBDA_TASK_ROOT), as on AWS. Contributed by @drakeo338. Reported by @shane-patzlsberger. - STS —
AssumeRolehonors trust-policy denies and conditions — withAUTH=true, a matchingDeny(includingNotAction) overrides anAllow, andsts:ExternalIdandsts:RoleSessionNameconditions are evaluated; a denied call returnsAccessDeniedand creates no session. Contributed by @AdrianAcala. - Cognito — federated sign-in tokens — the ID token carries the
noncefrom/oauth2/authorize, both tokens carrycognito:groups, and a user linked by a PreSignUp trigger signs in as the linked profile instead of a new one. Contributed by @kjdev. - CloudFormation — nested stack with a
Transform— underAUTH=true, a nested stack whose template declares aTransformor callsFn::Transformfails withRequires capabilities : [CAPABILITY_AUTO_EXPAND]unless the parent acknowledgedCAPABILITY_AUTO_EXPAND, as on AWS. Contributed by @iot-rocket. - CloudFormation —
AWS::RDS::DBClusterandAWS::RDS::DBInstanceupdate in place — a stack update re-ran the create, which gave the resource a new endpoint, resource id and create time and emptied the cluster's member list; the properties the create stores now change on the existing record, a create-only orEnginechange replaces the resource or, under a custom identifier, is refused, a clusterMasterUsernamechange leaves the cluster as it is, change sets report which properties replace, and a stack-created cluster can now be described and answersFn::GetAtt DBClusterResourceId. Contributed by @iot-rocket. - SES — a sandboxed account sends only to verified or simulator recipients — SES v2
PutAccountDetailswithProductionAccessEnabled=falseputs the account (per region) in the sandbox, as on AWS, andGetAccountreports it with the submittedDetails. A sandboxed send to a recipient that is neither a verified address or domain identity nor a@simulator.amazonses.comaddress fails withMessageRejected"Email address is not verified. The following identities failed the check in region …" for v1SendEmail,SendRawEmailandSendTemplatedEmailand v2SendEmail; bulk sends reject only the affected entries. Accounts stay in production by default. Reported by @skialpine. - CloudFormation —
AWS::ECS::ClusterandAWS::ECS::TaskDefinitionupdate in place — a cluster change keeps the cluster (settings or configuration dropped from the template stay), and a task definition change registers the next revision of the family and deregisters the old one instead of overwriting revision 1. Contributed by @iot-rocket. - CloudFormation — more
IMPORTtypes — SNS topics, KMS keys and aliases, IoT thing types, Cognito user pool clients, groups, resource servers and identity pools, and API Gateway REST APIs and stages can be imported, including two-key identifiers, andFn::GetAtton an identity pool'sIdresolves. Contributed by @iot-rocket. - CloudFormation —
ImportExistingResources— aCREATEorUPDATEchange set imports an added resource whose static custom name already exists (it needsDeletionPolicyRetainorRetainExceptOnCreate), and a rollback releases imported resources instead of deleting them. Contributed by @iot-rocket. - ECS —
UpdateServicewithforceNewDeploymentreplaces the tasks — it was ignored when the task definition did not change. Rolling deployments now pin image digests from the first task, honorversionConsistencydisabled, userepositoryCredentialsfor private registries, and reportimageDigestand the Fargate platform version; a task falls back to the local image when the pull fails. Contributed by @AdrianAcala. - AutoScaling — target tracking alarms —
PutScalingPolicywithTargetTrackingScalingcreates theTargetTracking-<group>-AlarmHigh-<uuid>alarm and, unlessDisableScaleInis set, theAlarmLowone on the tracked metric, lists them inAlarmsofPutScalingPolicyandDescribePolicies, replaces them when the policy is updated and deletes them with the policy or its group. AnAWS::AutoScaling::ScalingPolicyin a template does the same. Contributed by @iot-rocket. - IoT — mTLS trusts every registered device certificate — the listener no longer fails the TLS handshake for an ACTIVE certificate whose CA was deactivated or deleted before its first connect, or that was registered without a CA; as on AWS, only the certificate's own status refuses it. Contributed by @iot-rocket.
- API Gateway — usage plan throttling — a REST API request carrying an API key from a usage plan on the stage is throttled with
429 Too Many Requestsby the plan'sthrottleand its per-methodapiStages[].throttle, in addition to the stage's method settings, and a throttled response carriesx-amzn-ErrorType: TooManyRequestsException. Contributed by @iot-rocket. - API Gateway — request body validation follows JSON Schema draft 4 — a request validator checks the body against the draft 4 keywords of the model (
enum,pattern, length, range andmultipleOfbounds,integerversusnumberversusboolean,items,additionalProperties,patternProperties,dependencies,allOf/anyOf/oneOf/not, formats, and$refto local definitions and to other models of the API); an empty body and a body nested more than 1000 levels deep are refused, and a schema that applies itself to the same value again answers 500.BAD_REQUEST_BODYandBAD_REQUEST_PARAMETERSread{"message": "..."}and carryx-amzn-ErrorType: BadRequestException. Contributed by @iot-rocket. - API Gateway v2 (WebSocket API) —
$connectauthorization — aCUSTOM$connectroute ran no authorizer. It now runs its REQUEST authorizer, refuses the handshake with 401, 403 or 500 and passesprincipalIdand the context torequestContext.authorizerof the connection's events.CreateAuthorizer,CreateRoute,UpdateRouteand the CloudFormation resources refuse a JWT authorizer, JWT route authorization and authorization on a route other than$connectwithBadRequestException, as AWS does; a JWT$connectroute kept in saved state refuses the handshake with 500 instead of validating the token.requestContext.stagenames the stage in the connection URL instead of$default. Contributed by @iot-rocket. - Lambda — Docker executor under
USE_SSL=1when MiniStack runs in a container — the gateway certificate, CA bundle and Java truststore were bind-mounted into every Lambda container from MiniStack's own filesystem (MINISTACK_SSL_CERT, or the generatedministack-tls/server.crtunder the temp directory), paths the host Docker daemon cannot see, so every invocation failed withbind source path does not exist. In a container they are now copied into the Lambda container, as function code already is. Contributed by @skialpine. - RDS —
DescribeDBClusterSnapshotAttributes— was unimplemented (InvalidAction: Unknown RDS action), so Terraform'saws_db_cluster_snapshotresource failed on read (reading RDS DB Cluster Snapshot … attribute) after creating the snapshot. Returns therestoreattribute with no shared accounts (the manual-snapshot default);ModifyDBClusterSnapshotAttributeis not implemented. Unknown snapshot ids answerDBClusterSnapshotNotFoundFault. Contributed by @skialpine. - SES — a send from an unverified sender is rejected — v1
SendEmail,SendRawEmail,SendTemplatedEmailandSendBulkTemplatedEmailand v2SendEmailandSendBulkEmailaccepted anySource/FromEmailAddress. AWS requires the sender to be a verified identity in the account and region, in production as well as the sandbox, and now so does MiniStack: the send fails withMessageRejected"Email address is not verified. The following identities failed the check in region …". A verified domain covers its addresses and subdomains, domain names compare case-insensitively and email addresses case-sensitively, as AWS documents. Tests that send from an address they never created as an identity need aVerifyEmailIdentity/CreateEmailIdentityfirst. Reported by @skialpine. - CloudFormation — a change set with only new stack tags lists them — it ended
FAILEDwith "didn't contain changes"; it now lists each resource the stack holds, other than a custom resource or wait condition, as aModifywithScope: Tags, and stack tags given in another order are no change for a change set orUpdateStack. Contributed by @iot-rocket. - CloudFormation — change sets list what a change reaches — a resource that references a replaced resource, an attribute of a modified resource or a changed parameter is now listed as a
Modifywhose detail names the cause (ChangeSourceResourceReference,ResourceAttributeorParameterReference, withCausingEntity). Contributed by @iot-rocket. - ECS —
DescribeClustersstatistics —include=["STATISTICS"]returns the sixteen running/pending task and active/draining service counters per launch type instead of an empty list. Contributed by @iot-rocket. - ECS —
DescribeClustershonoursinclude—settingsandtagscome back empty andattachmentsandconfigurationare left out unless requested,CreateClusterkeepsconfiguration, and a CloudFormation cluster reports its tags and the defaultcontainerInsightssetting. Contributed by @iot-rocket. - CloudFormation —
AWS::S3::MultiRegionAccessPointandAWS::AutoScaling::LaunchConfigurationare replaced on update — every property of both types is create-only, so a change now creates the resource under a new generated name and deletes the old one after the update (aRegionschange was dropped and the stack reported the alias as the physical id, a launch configuration was overwritten under its old name), fails with the custom-named-resource error when the name is explicit, and is reported asReplacement: Truein a change set. Contributed by @iot-rocket. - CloudFormation —
AWS::SQS::QueuewithFifoQueuegets a generated.fifoname —FifoQueue: truewithout aQueueNamecreates a FIFO queue with a generated.fifoname instead of a standard queue, and aQueueNamewhose.fifosuffix disagrees withFifoQueuefails the resource. Contributed by @iot-rocket. - CloudFormation —
Fn::Selectin a condition — a condition such as!Not [!Equals [!Select [2, !Ref KeySpec], ""]]was always true; conditions now resolveFn::Select, and an index outside the list fails withTemplate error: Fn::Select cannot select nonexistent value at index N, in conditions and in properties. Contributed by @mishukdutta-cz. - CloudFormation —
Refto a list parameter — aRefto aCommaDelimitedListorList<...>parameter gave the raw string, so a list property got one item per character; it now gives the space-trimmed list. A list in a nested stack'sParametersor in anAWS::SSM::ParameterValuefails the resource. Contributed by @mishukdutta-cz.