What's Changed
New Contributors
- @koh-sh made their first contribution in #1986
- @antonie-popovic made their first contribution in #1996
- @Pintouch made their first contribution in #2007
[1.5.22] — 2026-10-05
Added
- Bedrock AgentCore — Memory data plane — the
bedrock-agentcoredata-plane endpoint now serves the short-term event log (CreateEvent,GetEvent,ListEvents,DeleteEvent,ListActors,ListSessions), the long-term record store (BatchCreateMemoryRecords,BatchUpdateMemoryRecords,BatchDeleteMemoryRecords,GetMemoryRecord,ListMemoryRecords,DeleteMemoryRecord) andRetrieveMemoryRecords(token-overlap scoring, no embeddings); extraction does not run soStartMemoryExtractionJobreturnsResourceNotFoundException; a cross-account memory ARN is refusedAccessDeniedExceptionunderAUTH=true. Shapes verified against botocorebedrock-agentcore. Contributed by @pingedbrain. - AWS Budgets —
CreateBudget,DescribeBudget,DescribeBudgets,UpdateBudget,DeleteBudget,CreateNotification,UpdateNotification,DeleteNotification,DescribeNotificationsForBudget,CreateSubscriber,UpdateSubscriber,DeleteSubscriber,DescribeSubscribersForNotification,TagResource,UntagResourceandListTagsForResource. Account-scoped JSON 1.1 service; omittedTimePeriod.Startdefaults to the period start, omittedEndto06/15/87 00:00 UTCand omittedThresholdTypetoPERCENTAGE; the 10-notification/budget and 11-subscriber/notification limits are enforced withCreationLimitExceededException; deleting the last subscriber of a notification deletes it. Budget Actions andDescribeBudgetPerformanceHistoryare out of scope. Contributed by @skialpine. - OpenSearch Serverless — collections, security and access policies, and a proxied data plane —
CreateCollection,BatchGetCollection,ListCollections,UpdateCollection,DeleteCollection;Create/Get/Update/Delete/ListSecurityPolicy(encryption,network);Create/Get/Update/Delete/ListAccessPolicy(data);GetPoliciesStats; tag operations; enough for Terraform'saws_opensearchserverless_collection,_security_policyand_access_policyto apply and destroy; a collection requires a matching encryption policy (exact name orprefix*), an update must name the currentpolicyVersion, a data policy refuses empty or wildcard principals,TIMESERIEScollections refuse custom ids and updates, and withOPENSEARCH_DATAPLANE=1each collection is backed by an OpenSearch container on a named Docker volume, otherwise 503; data access and network policies are stored but not enforced. Contributed by @skialpine. - CloudFormation —
AWS::RDS::DBSubnetGroup,AWS::RDS::DBParameterGroup,AWS::RDS::DBClusterParameterGroupandAWS::SecretsManager::SecretTargetAttachment— these CDKrds.DatabaseInstance/rds.DatabaseClustertypes were refused asUnrecognized resource types; they now create, update and delete via the RDS and Secrets Manager APIs.Refreturns the group name or the secret ARN;Fn::GetAttgivesDBSubnetGroupArn,DBParameterGroupNameandDBParameterGroupArn; a parameter requiring a reboot goespending-reboot; the attachment writesengine,host,portanddbnameinto the secret JSON and removes them on delete. Reported by @fabio-andre-rodrigues. - Aurora DSQL — partial indexes —
CREATE INDEX ASYNC ... WHERE predicatewas refused0A000; the predicate now reaches the backend (unique partial indexes scope uniqueness to covered rows). A volatile-function predicate fails42P17and a subquery fails0A000at submit time, in the order the live service checks (eu-central-1, 2026-10-04). Contributed by @vivedo. - Aurora DSQL —
dsql.enable_batched_nestloopand the reserveddsql.prefix — the setting showsonby default,RESETreturns toon, and a non-Boolean value or value list is refused22023; any otherdsql.*name is refused42602"reserved prefix";work_mem,statement_timeoutanddefault_statistics_targetcan no longer be set (0A000), as on the live service. Plans remain Postgres-shaped. Contributed by @vivedo. - Aurora DSQL — extended statistics limits — a sixth
CREATE STATISTICSon a table fails54000"more than 5 extended statistics per table are not allowed"; targets above 100 are refused22023;ALTER TABLE ... ALTER COLUMN ... SET STATISTICSis refused0A000, as on the live service. Contributed by @vivedo. - IoT —
ListCertificatesByCA—GET /certificates-by-ca/{caCertificateId}answeredUnsupported IoT path; it now lists device certificates under the CA in every status, newest first (or ascending withisAscendingOrder=true), withpageSize(1–250) andnextMarkerpagination; an unknown CA returns an empty list; invalid page sizes, ids or markers returnInvalidRequestException. Contributed by @iot-rocket. - IoT — lifecycle events — the broker publishes
$aws/events/presence/connected|disconnected/{clientId}and$aws/events/subscriptions/subscribed|unsubscribed/{clientId}with the AWS payload (sessionIdentifier,principalIdentifier,versionNumber,disconnectReason,clientInitiatedDisconnect); rules or subscriptions with a#/+prefix filter do not receive$aws/eventsmessages, and client ids containing#or+get none. Contributed by @iot-rocket. - Cognito —
SetUICustomizationandGetUICustomization— store and return the hosted UI CSS per user pool or per app client (client falls back to pool default); the pool needs a domain first, as on AWS.ImageFileis accepted but not stored. Supports Terraform'saws_cognito_user_pool_ui_customization. Contributed by @antonie-popovic.
Fixed
- Cognito — app client secret hashes —
GenerateSecret=trueclients now require a validSecretHashon signup, confirmation, password recovery and auth; missing/wrong hashes returnNotAuthorizedExceptionbefore any user change. Clients without a secret reject a hash on self-service and initial auth; refresh/challenge ignore it. Refresh auth verifies the token owner and custom challenges cannot be answered through a different client. Applies underAUTH=true. Contributed by @AdrianAcala. - Cognito —
/oauth2/tokenrefreshes tokens issued by the API — therefresh_tokengrant answeredinvalid_grantfor tokens fromInitiateAuth,AdminInitiateAuth,RespondToAuthChallengeor federated sign-in; it now validates them asREFRESH_TOKEN_AUTHdoes, refusing revoked, signed-out or wrong-client tokens withinvalid_grantand returning new ID and access tokens. A missing or wrong client secret or unknown client returnsinvalid_client. Contributed by @Pintouch. - Bedrock — foundation model agreement offers —
ListFoundationModelAgreementOffersreturned an empty list, so there was noofferTokenforCreateFoundationModelAgreement; it now returns one offer for third-party models (Amazon models have none),CreateFoundationModelAgreementrequiresofferTokenand returnsResourceNotFoundExceptionfor an unknown model, andGetFoundationModelAvailabilityreportsAVAILABLEonly while an agreement exists, so the Terraformaws_bedrock_foundation_model_agreementresource can be destroyed. Reported by @wparad. - SES — an unreachable SMTP relay no longer blocks the emulator — with
SMTP_HOSTset, a relay that drops packets held every service request for the OS connect timeout (~2 min). The relay now runs in the background with a 10-second timeout after SES returns theMessageId; Cognito email delivery uses the same relay. Reported by @bawdo. - RDS — MySQL instances apply their DB parameter group — parameters were stored but never reached the server; a MySQL or MariaDB instance now starts with its group's parameters as server options.
ModifyDBParameterGroupwithApplyMethod=immediaterunsSET GLOBALon running instances;ResetDBParameterGrouprestores engine defaults; a static parameter withimmediateis refusedInvalidParameterCombination; apending-rebootchange showsParameterApplyStatus: pending-rebootuntil next start. Names, values and formula values are not validated. Contributed by @skialpine. - RDS — creating an existing parameter group is refused —
CreateDBParameterGroupandCreateDBClusterParameterGroupwith a name already in use replaced the group with an empty one, dropping its parameters; they now returnDBParameterGroupAlreadyExists, as AWS does. Contributed by @skialpine. - RDS — a backup retention period of 0 turns binary logging off — on RDS for MySQL,
BackupRetentionPeriod=0turns binary logging off; MiniStack's MySQL 8.0/8.4 instances kept the image default, binary logging on. Such an instance now starts with binary logging off. Contributed by @skialpine. - RDS —
ModifyDBInstancesettings that are not pending modifications apply immediately — withoutApplyImmediately,DeletionProtection,CopyTagsToSnapshot,PreferredBackupWindow,PreferredMaintenanceWindow,PubliclyAccessible,MaxAllocatedStorage,MonitoringIntervalandMonitoringRoleArnwere queued inPendingModifiedValues, which has no such members, and never applied. They now apply at once on every instance. Contributed by @AdrianAcala. - RDS — the MySQL master user gets the privileges AWS gives it — the master user was granted
ALL PRIVILEGESincludingSUPERandSYSTEM_VARIABLES_ADMIN, soSET GLOBAL/SET PERSISTworked where RDS denies them; an instance started in the background got no global grant at all. Every start path now grants the RDS/Aurora master user privileges for the engine and versionWITH GRANT OPTION. Contributed by @skialpine. - API Gateway —
GetApiKeysfilters bynameQuery—GetApiKeysignorednameQueryand returned all the API keys, so a lookup by name could get the wrong key. It now returns only the keys whose names start withnameQuery. Contributed by @mishukdutta-cz. - API Gateway v2 — JWT claims reach a Lambda as strings —
requestContext.authorizer.jwt.claimsholds every claim as a string, as on AWS: numbers as digits, booleans astrue/falseand arrays as their items in brackets, e.g.[admin dev]. Typed event models (for exampleaws_lambda_eventsin Rust, or Go'smap[string]string) parse the event. Contributed by @antonie-popovic. - API Gateway v2 (WebSocket API) —
$connectwithAWS_IAM— an unsigned handshake is refused with 403Missing Authentication Token, and underAUTH=truethe caller needsexecute-api:Invokeonarn:aws:execute-api:<region>:<account>:<api-id>/<stage>/$connect. Contributed by @iot-rocket. - ALB — repeated HTTP target response headers — forwards every
Set-Cookieas a separate header, preserving cookie attributes and repeated fields even when their names use different casing; previously only the first value survived. Contributed by @AdrianAcala. Reported by @bawdo. - IoT —
CreateThingGroupon an existing name returns the group when nothing differs — a repeatedCreateThingGroupalways failed withResourceAlreadyExistsException. It now returns the existing group's name, ARN and id when the description, attributes (in any order), parent and tags match, and answers 409 with AWS's message otherwise, leaving the group unchanged, as AWS does. AnAWS::IoT::ThingGroupthat names an existing group still fails its stack, with or without matching properties, now with AWS's name-conflict message. Contributed by @iot-rocket. - IoT — just-in-time registration under a CA in
SNI_ONLYmode — a device certificate signed by a CA registered withcertificateModeSNI_ONLYand auto-registration enabled was refused on its first mTLS connect, so onlyDEFAULTCAs auto-registered. Such a CA now registers the certificatePENDING_ACTIVATIONand publishes the registered event when the device's TLS ClientHello carries a server name, and does nothing without one. Under either mode, an endpoint name with another account's prefix auto-registers nothing. Contributed by @iot-rocket. - IoT —
RegisterCertificatelinks the CA that signed the certificate — a certificate registered withoutcaCertificatePemcarried nocaCertificateId, even when a registered ACTIVE CA had signed it, soDescribeCertificatenamed no CA andListCertificatesByCAleft it out. It is now linked to that CA, as AWS does; when several registered CAs share a subject, the signature decides. Contributed by @iot-rocket. - IoT — a CONTINUOUS job runs again for a thing that rejoins its target group — executions were one per thing/job, so a thing that finished, left and rejoined a group never got another execution. Rejoining now queues the next execution number; leaving moves a QUEUED execution to
REMOVED; both publishjobs/notify(-next);notify-nextomitsthingNameand emptystatusDetails; andListJobExecutionsForThing,DescribeJobExecutionandjobProcessDetailsinclude earlier executions. Contributed by @iot-rocket. - IoT — a
#region no longer widens topic filters — a WebSocket session whose credential names#as its region received every message published under that region, whatever its filter, because filters were matched with the account and region prefix in front of them. Contributed by @iot-rocket. - Lambda — a timed-out invocation reports
Sandbox.Timedout— functions past theirTimeoutreturnedRuntime.ExitError, so Step FunctionsRetry/CatchonSandbox.Timedoutnever matched; all executors now returnSandbox.TimedoutwithTask timed out after N.00 seconds; a runtime that exits before responding still reportsRuntime.ExitError. Contributed by @mishukdutta-cz. - Lambda — throttle
retryAfterSecondsis a string — aTooManyRequestsExceptionreturnsretryAfterSecondsas a string, as the Lambda API model declares, so SDK clients such as the AWS SDK for Rust parse the response as a throttle. Contributed by @antonie-popovic. - Step Functions —
TimeoutSecondsapplies to Lambda and service integration tasks — only.waitForTaskTokentasks respectedTimeoutSeconds; Lambda and service integration tasks now failStates.TimeoutafterTimeoutSeconds; activity tasks andTimeoutSecondsPathunchanged. Contributed by @mishukdutta-cz. - Step Functions —
States.TaskFailedno longer matchesStates.Timeout—States.TaskFailedmatched timeouts, so retries/catches ran where AWS doesn't; it now matches every error exceptStates.Timeout. Contributed by @mishukdutta-cz. - AppConfig — predefined deployment strategies —
AppConfig.AllAtOnce,AppConfig.Linear50PercentEvery30Seconds,AppConfig.Canary10Percent20MinutesandAppConfig.Linear20PercentEvery6Minutesnow exist in every account/region and cannot be updated or deleted;StartDeploymentandAWS::AppConfig::DeploymentfailResourceNotFoundExceptionfor an unknown strategy id. Contributed by @koh-sh. - Aurora DSQL — the 8-key index limit comes first — measured live, DSQL reports
54011before the mode, key-expression andINCLUDErules; the proxy reported those first, so a plainCREATE INDEXon nine columns drew "unsupported mode".sys.jobs.detailsis now NULL for a job that succeeded, where it was an empty string. Contributed by @vivedo. - Aurora DSQL —
CALL sys.wait_for_job($1)with a bound job id — a bound job id went to the backing Postgres and failed3F000; it now works forsys.wait_for_jobandsys.jobs ... WHERE job_id = $1,CALLreturnssucceededwith theCALLtag (eu-central-1, 2026-10-04), and a malformed id is refused22P02;CREATE INDEX ASYNC/ALTER TABLE ASYNCreturn the matching tags,sys.jobsdeclaresoidandtimestamptzcolumns, a constraint validation job carriesclass_id2606, and a failing unique index reports the service'sdetails. Contributed by @vivedo. - Aurora DSQL —
TimeZonemissing at startup — the proxy's startup greeting reported noTimeZone, so a driver that decodestimestamptzby it could stall on the first value; it now reportsTimeZone,IntervalStyleand the rest of the parameters the live service does. Contributed by @vivedo. - OpenSearch — data-plane containers are named per account — containers were named
ministack-opensearch-<region>-<domain>, causing Docker name conflicts across accounts and erroneous cleanup; names now include an account and region hash, as RDS does. Contributed by @skialpine. - ElastiCache — serverless caches run in cluster mode — MiniStack's container ran without cluster mode, accepting multi-key commands that hash to different slots where AWS fails with
CROSSSLOT; the container now runs as one cluster-mode shard holding all slots, andCLUSTER SLOTSreports the cache endpoint. Contributed by @skialpine. - CloudTrail —
PutEventSelectorsstoresAdvancedEventSelectorsand setsHasCustomEventSelectors— advanced selectors were dropped instead of stored; they are now stored in place ofEventSelectors, a request with both kinds, neither, or an empty or oversized list failsInvalidEventSelectorsException, basic selectors fill in omitted members, andGetTrail/DescribeTrailsreportHasCustomEventSelectors: truewhen non-default selectors exist. Contributed by @iot-rocket. - CloudTrail —
GetEventSelectorsreturns the default selector of a new trail — a trail that never hadPutEventSelectorsanswered an emptyEventSelectorslist instead of the default selector that logs all read and write management events. Contributed by @iot-rocket. - STS —
GetAccessKeyInfoanswers the account that owns the key — it always returned the caller's account; it now returns the owning account for known keys, or decodes it from the key id for anyAKIA/ASIAkey as AWS does, and returnsValidationErrorfor a key id that encodes no account or violates constraints. Contributed by @iot-rocket. - STS —
GetAccessKeyInfois authorized like other actions — underAUTH=trueit was allowed likeGetCallerIdentityandGetSessionToken, whatever the caller's policies said. It now needs an identity policy that allows it and no deny, and otherwise answersAccessDenied, as AWS does; the other two stay allowed. Contributed by @iot-rocket. - SNS —
CreateTopickeeps its tags — the handler readTag.member.Nwhere the API sendsTags.member.N, so tags given at creation were dropped. Contributed by @iot-rocket.