github ministackorg/ministack v1.5.22

3 hours ago

What's Changed

New Contributors

[1.5.22] — 2026-10-05

Added

  • Bedrock AgentCore — Memory data plane — the bedrock-agentcore data-plane endpoint now serves the short-term event log (CreateEvent, GetEvent, ListEvents, DeleteEvent, ListActors, ListSessions), the long-term record store (BatchCreateMemoryRecords, BatchUpdateMemoryRecords, BatchDeleteMemoryRecords, GetMemoryRecord, ListMemoryRecords, DeleteMemoryRecord) and RetrieveMemoryRecords (token-overlap scoring, no embeddings); extraction does not run so StartMemoryExtractionJob returns ResourceNotFoundException; a cross-account memory ARN is refused AccessDeniedException under AUTH=true. Shapes verified against botocore bedrock-agentcore. Contributed by @pingedbrain.
  • AWS Budgets — CreateBudget, DescribeBudget, DescribeBudgets, UpdateBudget, DeleteBudget, CreateNotification, UpdateNotification, DeleteNotification, DescribeNotificationsForBudget, CreateSubscriber, UpdateSubscriber, DeleteSubscriber, DescribeSubscribersForNotification, TagResource, UntagResource and ListTagsForResource. Account-scoped JSON 1.1 service; omitted TimePeriod.Start defaults to the period start, omitted End to 06/15/87 00:00 UTC and omitted ThresholdType to PERCENTAGE; the 10-notification/budget and 11-subscriber/notification limits are enforced with CreationLimitExceededException; deleting the last subscriber of a notification deletes it. Budget Actions and DescribeBudgetPerformanceHistory are out of scope. Contributed by @skialpine.
  • OpenSearch Serverless — collections, security and access policies, and a proxied data plane — CreateCollection, BatchGetCollection, ListCollections, UpdateCollection, DeleteCollection; Create/Get/Update/Delete/ListSecurityPolicy (encryption, network); Create/Get/Update/Delete/ListAccessPolicy (data); GetPoliciesStats; tag operations; enough for Terraform's aws_opensearchserverless_collection, _security_policy and _access_policy to apply and destroy; a collection requires a matching encryption policy (exact name or prefix*), an update must name the current policyVersion, a data policy refuses empty or wildcard principals, TIMESERIES collections refuse custom ids and updates, and with OPENSEARCH_DATAPLANE=1 each collection is backed by an OpenSearch container on a named Docker volume, otherwise 503; data access and network policies are stored but not enforced. Contributed by @skialpine.
  • CloudFormation — AWS::RDS::DBSubnetGroup, AWS::RDS::DBParameterGroup, AWS::RDS::DBClusterParameterGroup and AWS::SecretsManager::SecretTargetAttachment — these CDK rds.DatabaseInstance/rds.DatabaseCluster types were refused as Unrecognized resource types; they now create, update and delete via the RDS and Secrets Manager APIs. Ref returns the group name or the secret ARN; Fn::GetAtt gives DBSubnetGroupArn, DBParameterGroupName and DBParameterGroupArn; a parameter requiring a reboot goes pending-reboot; the attachment writes engine, host, port and dbname into the secret JSON and removes them on delete. Reported by @fabio-andre-rodrigues.
  • Aurora DSQL — partial indexes — CREATE INDEX ASYNC ... WHERE predicate was refused 0A000; the predicate now reaches the backend (unique partial indexes scope uniqueness to covered rows). A volatile-function predicate fails 42P17 and a subquery fails 0A000 at submit time, in the order the live service checks (eu-central-1, 2026-10-04). Contributed by @vivedo.
  • Aurora DSQL — dsql.enable_batched_nestloop and the reserved dsql. prefix — the setting shows on by default, RESET returns to on, and a non-Boolean value or value list is refused 22023; any other dsql.* name is refused 42602 "reserved prefix"; work_mem, statement_timeout and default_statistics_target can no longer be set (0A000), as on the live service. Plans remain Postgres-shaped. Contributed by @vivedo.
  • Aurora DSQL — extended statistics limits — a sixth CREATE STATISTICS on a table fails 54000 "more than 5 extended statistics per table are not allowed"; targets above 100 are refused 22023; ALTER TABLE ... ALTER COLUMN ... SET STATISTICS is refused 0A000, as on the live service. Contributed by @vivedo.
  • IoT — ListCertificatesByCA — GET /certificates-by-ca/{caCertificateId} answered Unsupported IoT path; it now lists device certificates under the CA in every status, newest first (or ascending with isAscendingOrder=true), with pageSize (1–250) and nextMarker pagination; an unknown CA returns an empty list; invalid page sizes, ids or markers return InvalidRequestException. Contributed by @iot-rocket.
  • IoT — lifecycle events — the broker publishes $aws/events/presence/connected|disconnected/{clientId} and $aws/events/subscriptions/subscribed|unsubscribed/{clientId} with the AWS payload (sessionIdentifier, principalIdentifier, versionNumber, disconnectReason, clientInitiatedDisconnect); rules or subscriptions with a #/+ prefix filter do not receive $aws/events messages, and client ids containing # or + get none. Contributed by @iot-rocket.
  • Cognito — SetUICustomization and GetUICustomization — store and return the hosted UI CSS per user pool or per app client (client falls back to pool default); the pool needs a domain first, as on AWS. ImageFile is accepted but not stored. Supports Terraform's aws_cognito_user_pool_ui_customization. Contributed by @antonie-popovic.

Fixed

  • Cognito — app client secret hashes — GenerateSecret=true clients now require a valid SecretHash on signup, confirmation, password recovery and auth; missing/wrong hashes return NotAuthorizedException before any user change. Clients without a secret reject a hash on self-service and initial auth; refresh/challenge ignore it. Refresh auth verifies the token owner and custom challenges cannot be answered through a different client. Applies under AUTH=true. Contributed by @AdrianAcala.
  • Cognito — /oauth2/token refreshes tokens issued by the API — the refresh_token grant answered invalid_grant for tokens from InitiateAuth, AdminInitiateAuth, RespondToAuthChallenge or federated sign-in; it now validates them as REFRESH_TOKEN_AUTH does, refusing revoked, signed-out or wrong-client tokens with invalid_grant and returning new ID and access tokens. A missing or wrong client secret or unknown client returns invalid_client. Contributed by @Pintouch.
  • Bedrock — foundation model agreement offers — ListFoundationModelAgreementOffers returned an empty list, so there was no offerToken for CreateFoundationModelAgreement; it now returns one offer for third-party models (Amazon models have none), CreateFoundationModelAgreement requires offerToken and returns ResourceNotFoundException for an unknown model, and GetFoundationModelAvailability reports AVAILABLE only while an agreement exists, so the Terraform aws_bedrock_foundation_model_agreement resource can be destroyed. Reported by @wparad.
  • SES — an unreachable SMTP relay no longer blocks the emulator — with SMTP_HOST set, a relay that drops packets held every service request for the OS connect timeout (~2 min). The relay now runs in the background with a 10-second timeout after SES returns the MessageId; Cognito email delivery uses the same relay. Reported by @bawdo.
  • RDS — MySQL instances apply their DB parameter group — parameters were stored but never reached the server; a MySQL or MariaDB instance now starts with its group's parameters as server options. ModifyDBParameterGroup with ApplyMethod=immediate runs SET GLOBAL on running instances; ResetDBParameterGroup restores engine defaults; a static parameter with immediate is refused InvalidParameterCombination; a pending-reboot change shows ParameterApplyStatus: pending-reboot until next start. Names, values and formula values are not validated. Contributed by @skialpine.
  • RDS — creating an existing parameter group is refused — CreateDBParameterGroup and CreateDBClusterParameterGroup with a name already in use replaced the group with an empty one, dropping its parameters; they now return DBParameterGroupAlreadyExists, as AWS does. Contributed by @skialpine.
  • RDS — a backup retention period of 0 turns binary logging off — on RDS for MySQL, BackupRetentionPeriod=0 turns binary logging off; MiniStack's MySQL 8.0/8.4 instances kept the image default, binary logging on. Such an instance now starts with binary logging off. Contributed by @skialpine.
  • RDS — ModifyDBInstance settings that are not pending modifications apply immediately — without ApplyImmediately, DeletionProtection, CopyTagsToSnapshot, PreferredBackupWindow, PreferredMaintenanceWindow, PubliclyAccessible, MaxAllocatedStorage, MonitoringInterval and MonitoringRoleArn were queued in PendingModifiedValues, which has no such members, and never applied. They now apply at once on every instance. Contributed by @AdrianAcala.
  • RDS — the MySQL master user gets the privileges AWS gives it — the master user was granted ALL PRIVILEGES including SUPER and SYSTEM_VARIABLES_ADMIN, so SET GLOBAL/SET PERSIST worked where RDS denies them; an instance started in the background got no global grant at all. Every start path now grants the RDS/Aurora master user privileges for the engine and version WITH GRANT OPTION. Contributed by @skialpine.
  • API Gateway — GetApiKeys filters by nameQuery — GetApiKeys ignored nameQuery and returned all the API keys, so a lookup by name could get the wrong key. It now returns only the keys whose names start with nameQuery. Contributed by @mishukdutta-cz.
  • API Gateway v2 — JWT claims reach a Lambda as strings — requestContext.authorizer.jwt.claims holds every claim as a string, as on AWS: numbers as digits, booleans as true/false and arrays as their items in brackets, e.g. [admin dev]. Typed event models (for example aws_lambda_events in Rust, or Go's map[string]string) parse the event. Contributed by @antonie-popovic.
  • API Gateway v2 (WebSocket API) — $connect with AWS_IAM — an unsigned handshake is refused with 403 Missing Authentication Token, and under AUTH=true the caller needs execute-api:Invoke on arn:aws:execute-api:<region>:<account>:<api-id>/<stage>/$connect. Contributed by @iot-rocket.
  • ALB — repeated HTTP target response headers — forwards every Set-Cookie as a separate header, preserving cookie attributes and repeated fields even when their names use different casing; previously only the first value survived. Contributed by @AdrianAcala. Reported by @bawdo.
  • IoT — CreateThingGroup on an existing name returns the group when nothing differs — a repeated CreateThingGroup always failed with ResourceAlreadyExistsException. It now returns the existing group's name, ARN and id when the description, attributes (in any order), parent and tags match, and answers 409 with AWS's message otherwise, leaving the group unchanged, as AWS does. An AWS::IoT::ThingGroup that names an existing group still fails its stack, with or without matching properties, now with AWS's name-conflict message. Contributed by @iot-rocket.
  • IoT — just-in-time registration under a CA in SNI_ONLY mode — a device certificate signed by a CA registered with certificateMode SNI_ONLY and auto-registration enabled was refused on its first mTLS connect, so only DEFAULT CAs auto-registered. Such a CA now registers the certificate PENDING_ACTIVATION and publishes the registered event when the device's TLS ClientHello carries a server name, and does nothing without one. Under either mode, an endpoint name with another account's prefix auto-registers nothing. Contributed by @iot-rocket.
  • IoT — RegisterCertificate links the CA that signed the certificate — a certificate registered without caCertificatePem carried no caCertificateId, even when a registered ACTIVE CA had signed it, so DescribeCertificate named no CA and ListCertificatesByCA left it out. It is now linked to that CA, as AWS does; when several registered CAs share a subject, the signature decides. Contributed by @iot-rocket.
  • IoT — a CONTINUOUS job runs again for a thing that rejoins its target group — executions were one per thing/job, so a thing that finished, left and rejoined a group never got another execution. Rejoining now queues the next execution number; leaving moves a QUEUED execution to REMOVED; both publish jobs/notify(-next); notify-next omits thingName and empty statusDetails; and ListJobExecutionsForThing, DescribeJobExecution and jobProcessDetails include earlier executions. Contributed by @iot-rocket.
  • IoT — a # region no longer widens topic filters — a WebSocket session whose credential names # as its region received every message published under that region, whatever its filter, because filters were matched with the account and region prefix in front of them. Contributed by @iot-rocket.
  • Lambda — a timed-out invocation reports Sandbox.Timedout — functions past their Timeout returned Runtime.ExitError, so Step Functions Retry/Catch on Sandbox.Timedout never matched; all executors now return Sandbox.Timedout with Task timed out after N.00 seconds; a runtime that exits before responding still reports Runtime.ExitError. Contributed by @mishukdutta-cz.
  • Lambda — throttle retryAfterSeconds is a string — a TooManyRequestsException returns retryAfterSeconds as a string, as the Lambda API model declares, so SDK clients such as the AWS SDK for Rust parse the response as a throttle. Contributed by @antonie-popovic.
  • Step Functions — TimeoutSeconds applies to Lambda and service integration tasks — only .waitForTaskToken tasks respected TimeoutSeconds; Lambda and service integration tasks now fail States.Timeout after TimeoutSeconds; activity tasks and TimeoutSecondsPath unchanged. Contributed by @mishukdutta-cz.
  • Step Functions — States.TaskFailed no longer matches States.Timeout — States.TaskFailed matched timeouts, so retries/catches ran where AWS doesn't; it now matches every error except States.Timeout. Contributed by @mishukdutta-cz.
  • AppConfig — predefined deployment strategies — AppConfig.AllAtOnce, AppConfig.Linear50PercentEvery30Seconds, AppConfig.Canary10Percent20Minutes and AppConfig.Linear20PercentEvery6Minutes now exist in every account/region and cannot be updated or deleted; StartDeployment and AWS::AppConfig::Deployment fail ResourceNotFoundException for an unknown strategy id. Contributed by @koh-sh.
  • Aurora DSQL — the 8-key index limit comes first — measured live, DSQL reports 54011 before the mode, key-expression and INCLUDE rules; the proxy reported those first, so a plain CREATE INDEX on nine columns drew "unsupported mode". sys.jobs.details is now NULL for a job that succeeded, where it was an empty string. Contributed by @vivedo.
  • Aurora DSQL — CALL sys.wait_for_job($1) with a bound job id — a bound job id went to the backing Postgres and failed 3F000; it now works for sys.wait_for_job and sys.jobs ... WHERE job_id = $1, CALL returns succeeded with the CALL tag (eu-central-1, 2026-10-04), and a malformed id is refused 22P02; CREATE INDEX ASYNC/ALTER TABLE ASYNC return the matching tags, sys.jobs declares oid and timestamptz columns, a constraint validation job carries class_id 2606, and a failing unique index reports the service's details. Contributed by @vivedo.
  • Aurora DSQL — TimeZone missing at startup — the proxy's startup greeting reported no TimeZone, so a driver that decodes timestamptz by it could stall on the first value; it now reports TimeZone, IntervalStyle and the rest of the parameters the live service does. Contributed by @vivedo.
  • OpenSearch — data-plane containers are named per account — containers were named ministack-opensearch-<region>-<domain>, causing Docker name conflicts across accounts and erroneous cleanup; names now include an account and region hash, as RDS does. Contributed by @skialpine.
  • ElastiCache — serverless caches run in cluster mode — MiniStack's container ran without cluster mode, accepting multi-key commands that hash to different slots where AWS fails with CROSSSLOT; the container now runs as one cluster-mode shard holding all slots, and CLUSTER SLOTS reports the cache endpoint. Contributed by @skialpine.
  • CloudTrail — PutEventSelectors stores AdvancedEventSelectors and sets HasCustomEventSelectors — advanced selectors were dropped instead of stored; they are now stored in place of EventSelectors, a request with both kinds, neither, or an empty or oversized list fails InvalidEventSelectorsException, basic selectors fill in omitted members, and GetTrail/DescribeTrails report HasCustomEventSelectors: true when non-default selectors exist. Contributed by @iot-rocket.
  • CloudTrail — GetEventSelectors returns the default selector of a new trail — a trail that never had PutEventSelectors answered an empty EventSelectors list instead of the default selector that logs all read and write management events. Contributed by @iot-rocket.
  • STS — GetAccessKeyInfo answers the account that owns the key — it always returned the caller's account; it now returns the owning account for known keys, or decodes it from the key id for any AKIA/ASIA key as AWS does, and returns ValidationError for a key id that encodes no account or violates constraints. Contributed by @iot-rocket.
  • STS — GetAccessKeyInfo is authorized like other actions — under AUTH=true it was allowed like GetCallerIdentity and GetSessionToken, whatever the caller's policies said. It now needs an identity policy that allows it and no deny, and otherwise answers AccessDenied, as AWS does; the other two stay allowed. Contributed by @iot-rocket.
  • SNS — CreateTopic keeps its tags — the handler read Tag.member.N where the API sends Tags.member.N, so tags given at creation were dropped. Contributed by @iot-rocket.

Don't miss a new ministack release

NewReleases is sending notifications on new releases.