github ministackorg/ministack v1.5.23

3 hours ago

What's Changed

New Contributors

[1.5.23] — 2026-10-07

Added

  • AppConfig — gradual rollout and alarm rollback — deployments completed as soon as they started. They now move through DEPLOYING, BAKING and COMPLETE on the strategy's schedule, a CloudWatch alarm in the environment's Monitors that goes to ALARM rolls the deployment back, and a concurrent or stale deployment returns ConflictException. Contributed by @Jolley71717.
  • API Gateway v1 — AWS integrations targeting SQS — a non-proxy integration whose URI is sqs:path/{account}/{queue} now renders its requestTemplates, sends the message to the queue and maps the reply through integrationResponses; other AWS service URIs still take the Lambda path. Contributed by @pingedbrain. Reported by @teruyukisuda.
  • CloudFormation — IoT things, certificates and attachments — AWS::IoT::Thing, AWS::IoT::Certificate, AWS::IoT::ThingPrincipalAttachment and AWS::IoT::PolicyPrincipalAttachment failed with Unrecognized resource types; they now provision onto the IoT registry with AWS's Ref and Fn::GetAtt values. CreateCertificateFromCsr was added, and DescribeCertificate now reports certificateMode. Contributed by @iot-rocket.
  • CloudFormation — enum properties are validated before provisioning — a value outside a resource schema's enum was refused only by that resource's create, after earlier resources existed; it now fails the stack with VALIDATION_FAILED before anything is provisioned. Contributed by @iot-rocket.
  • CloudFront — custom error responses — CustomErrorResponses were stored but never applied; when the origin answers a configured ErrorCode, the data plane now returns ResponsePagePath with ResponseCode. Contributed by @skialpine.
  • Cognito — CustomMessage_AdminCreateUser trigger — AdminCreateUser now invokes the pool's CustomMessage Lambda before sending the invitation, and {username} expands to the email or phone number in pools with UsernameAttributes. Contributed by @kjdev.
  • DynamoDB — multi-attribute GSI keys — a GSI with several HASH or RANGE attributes failed every Query with "Query condition missed key schema element". Query now needs equality on every partition-key attribute and takes sort-key attributes left to right, only the last with a range condition. Reported by @jun-ut.
  • IoT — domain configurations — CreateDomainConfiguration, DescribeDomainConfiguration, ListDomainConfigurations, UpdateDomainConfiguration, DeleteDomainConfiguration and AWS::IoT::DomainConfiguration. Contributed by @iot-rocket.
  • IoT — job templates — CreateJobTemplate, DescribeJobTemplate, ListJobTemplates, DeleteJobTemplate, CreateJob with jobTemplateArn, and AWS::IoT::JobTemplate. Contributed by @iot-rocket.
  • SES — identity notifications — SetIdentityNotificationTopic stored topics that nothing published to; v1 sends now publish a Delivery, Bounce or Complaint notification per recipient, following the mailbox simulator. Contributed by @kjdev.
  • SES — receipt rule sets and rules — rule sets can be created, activated, described, listed and deleted, and rules created, described and deleted; they are stored only, since inbound mail is not emulated. Contributed by @AdrianAcala. Reported by @wparad.
  • SES v2 — tenants and resource associations — CreateTenant, GetTenant, ListTenants, DeleteTenant, PutTenantSuppressionAttributes and the tenant resource association operations; a resource with associations cannot be deleted. Contributed by @AdrianAcala. Reported by @wparad.
  • SES v2 — dedicated IP pools — CreateDedicatedIpPool, GetDedicatedIpPool, ListDedicatedIpPools and DeleteDedicatedIpPool, with tags on the pool ARN. Reported by @wparad.
  • Signer — CloudFormation profiles, profile permissions and CancelSigningProfile — AWS::Signer::SigningProfile and AWS::Signer::ProfilePermission provision, and AddProfilePermission, ListProfilePermissions, RemoveProfilePermission and CancelSigningProfile are routed. Contributed by @iot-rocket.

Fixed

  • API Gateway — management IAM actions — with AUTH=true, management requests were checked against SDK operation names; they now use apigateway:GET, POST, PUT, PATCH and DELETE on the requested resource path, so scoped grants and stage denies apply. Contributed by @AdrianAcala.
  • AppConfig — GetLatestConfiguration and StopDeployment — a poll returned the full configuration every time, and StopDeployment marked any deployment ROLLED_BACK. An unchanged poll now returns an empty body, and StopDeployment follows the documented states. Contributed by @Jolley71717.
  • CloudWatch — Values/Counts and StatisticValues — values were stored once per count and statistic sets as their average, so SampleCount, Sum, Minimum and Maximum were wrong. They now aggregate weighted, and percentiles are omitted for negative values and for statistic sets that are not one repeated value. Contributed by @DimQ1.
  • CloudWatch Logs — IAM tag conditions — with AUTH=true, authorization now includes existing and requested tags, and ARN-based tagging APIs authorize the supplied ARN instead of *. Contributed by @AdrianAcala.
  • Cognito — RESET_REQUIRED users cannot sign in with a password — after AdminResetUserPassword, password and SRP sign-in with the old password succeeded; they now return PasswordResetRequiredException. Contributed by @prandogabriel.
  • Container reaping — one unreadable container no longer stops the sweep — if one container's inspect failed, the boot sweep removed no leftover containers; containers are now listed without inspecting each one. Reported by @iot-rocket.
  • DynamoDB — Query and Scan stop each page at 1 MB — without Limit, every matching item came back in one response with no LastEvaluatedKey; a page now stops at 1 MB of data read and returns LastEvaluatedKey. Contributed by @DimQ1.
  • DynamoDB — index Query and writes no longer slow down as a table grows — a GSI or LSI Query read every item in the table and every write recounted it; index partitions and ItemCount are now kept per write. Contributed by @DimQ1.
  • DynamoDB — ClientRequestToken expires after 10 minutes — transaction tokens were kept forever; after 10 minutes a reused token is a new request. Contributed by @DimQ1.
  • DynamoDB — transactions are authorized per item — with AUTH=true, TransactWriteItems and TransactGetItems were checked as non-existent IAM actions on the first table; each item is now checked as PutItem, UpdateItem, DeleteItem, ConditionCheckItem or GetItem on its own table. Contributed by @drakeo338. Reported by @Zordrak.
  • DynamoDB Streams — no-op writes and closed streams — a write that changed nothing produced a MODIFY record, and a disabled or deleted stream vanished. No record is written now, and a closed stream stays readable for 24 hours as DISABLED. Contributed by @DimQ1.
  • IoT — the gateway certificate names the DescribeEndpoint hosts — https://<endpointAddress> failed hostname verification under USE_SSL=1; the certificate now carries the IoT data and credentials hosts. Contributed by @iot-rocket.
  • Kinesis — SubscribeToShard keeps its position across retention pruning — removing expired records could skip newly appended ones. Contributed by @AdrianAcala.
  • Lambda — one request ID per Docker invocation — RIE logs carried a second START/END/REPORT set under a different RequestId; MiniStack's ID now reaches RIE and the logs are saved once. Contributed by @gakuto-cw21.
  • Lambda — invoked_function_arn keeps the alias or version invoked. Contributed by @jayjanssen.
  • Lambda — event source mappings pick up new work at once — a new SQS message, Kinesis record or DynamoDB stream record waited for the poller's idle tick; it now wakes the poller. Contributed by @antonie-popovic.
  • RDS — global cluster tags — CreateGlobalCluster dropped Tags; they are now stored and returned in TagList. Contributed by @jayjanssen.
  • RDS Data API — MySQL generatedFields — it was always empty; it now holds the AUTO_INCREMENT id. Contributed by @skialpine.
  • S3 — cross-account replication — the destination bucket was looked up only in the caller's account, so every replica FAILED; it is now found in its owner's account, and its bucket policy must grant the replication role. Contributed by @pingedbrain.
  • S3 — re-creating a bucket you own — outside us-east-1 it returned 200; it now returns BucketAlreadyOwnedByYou (409). Contributed by @DimQ1.
  • S3 — truncated uploads — a body shorter than Content-Length or a malformed aws-chunked upload was stored as a partial object; it now returns IncompleteBody (400). Contributed by @DimQ1.
  • SES — SendEmail validation — an address without a domain returns InvalidParameterValue "Missing final '@Domain'", and an unknown configuration set returns ConfigurationSetDoesNotExist. Contributed by @DimQ1.
  • SES — SendRawEmail relay sends one Message-ID — a client Message-ID was kept next to MiniStack's. Contributed by @kjdev.
  • SNS — published messages are no longer retained — every publish was kept on its topic and persisted. Contributed by @DimQ1.
  • SQS — FIFO delays and MaxNumberOfMessages — FIFO queues ignored DelaySeconds and accepted per-message delays, and MaxNumberOfMessages was clamped. A FIFO message now waits the queue delay, a nonzero per-message delay returns InvalidParameterValue, and MaxNumberOfMessages outside 1–10 returns InvalidParameterValue. Contributed by @DimQ1.
  • SQS — queue DelaySeconds applies to messages from other services — deliveries from SNS, EventBridge, S3 notifications and Lambda were visible at once. Contributed by @DimQ1.
  • SSM — PutParameter validation — a parameter without Type, a name starting with aws or ssm, and Tags with Overwrite were accepted; they are now refused, and an overwrite without Type keeps the stored type. Contributed by @fabio-andre-rodrigues. Reported by @jin-gizmo.
  • Step Functions — $$.State.RetryCount — it resolved to null; it now counts a state's retries, and a Task's Parameters are evaluated for each attempt. Contributed by @skialpine.
  • Step Functions — the first matching retrier decides — a retrier that had used its MaxAttempts was skipped, so a later States.ALL retried anyway. Contributed by @skialpine.
  • Step Functions — StopExecution keeps its error and cause — DescribeExecution returned neither; it now returns both. Contributed by @skialpine.
  • Step Functions — a retried StopExecution succeeds — stopping an already-aborted execution returned ValidationException; it now returns the original stopDate. Contributed by @jayjanssen.
  • TLS — the generated certificate works with rustls — it was a CA certificate, which rustls refuses as a server's; it is now a server certificate. Contributed by @antonie-popovic.

Don't miss a new ministack release

NewReleases is sending notifications on new releases.