github ministackorg/ministack v1.5.25

6 hours ago

What's Changed

New Contributors

[1.5.25] — 2026-10-10

Added

  • CloudFormation — AWS::IAM::User — templates with an IAM user now provision it with Path, Groups, ManagedPolicyArns, inline Policies, LoginProfile, PermissionsBoundary and Tags; every property updates in place except UserName, which replaces the user. Ref returns the user name and Fn::GetAtt returns Arn. IAM gains PutUserPermissionsBoundary and DeleteUserPermissionsBoundary, and CreateUser and GetUser carry the boundary. Reported by @gakuto-cw21.
  • DocumentDB — a new service for the docdb API: CreateDBCluster, CreateDBInstance, DescribeDBClusters, DescribeDBInstances, ModifyDBCluster, ModifyDBInstance, RebootDBInstance, StartDBCluster, StopDBCluster, FailoverDBCluster, DeleteDBCluster, DeleteDBInstance and the tag operations. Each cluster runs a documentdb-local container serving the MongoDB protocol over TLS. Defaults follow AWS: engine 8.0.0, port 27017, the default.docdb8.0 parameter group and docdb.amazonaws.com endpoints. The docdb client reaches it on the normal endpoint, and an unfiltered DescribeDBClusters or DescribeDBInstances lists RDS and DocumentDB together, as on AWS. Subnet and parameter groups are shared with RDS. CloudFormation provisions AWS::DocDB::DBCluster, DBInstance, DBSubnetGroup and DBClusterParameterGroup, and AWS::SecretsManager::SecretTargetAttachment accepts DocumentDB targets. Contributed by @xPTM1219.
  • CloudFormation — AWS::Logs::MetricFilter — templates with a metric filter failed with Unrecognized resource types; the filter now provisions, updates in place and is replaced on a FilterName or LogGroupName change. Contributed by @iot-rocket.
  • DynamoDB — vector search — CreateTable accepts VectorIndexes, UpdateTable takes VectorIndexUpdates (resource allocation, then backfilling, then ACTIVE), and DescribeTable reports them. SearchVectors scores with COSINE, EUCLIDEAN or DOT_PRODUCT at 32-bit float precision and filters on the SearchSchema. Writes are checked against each vector index, INDEXES capacity reports VectorWriteRequestBytes on single, batch and transactional writes, and a PartiQL SELECT or Scan on a vector index returns "Scan operation not supported on this index type". Backups record the indexes in SourceTableFeatureDetails, RestoreTableFromBackup and RestoreTableToPointInTime restore them or apply VectorIndexOverride, and ImportTable creates them from TableCreationParameters. Reported by @hicksy and the paritysuite.org project.
  • S3 Tables — bucket and table configuration — table bucket encryption, maintenance, policy, storage class and metrics; table encryption, maintenance, maintenance job status, policy and storage class; RenameTable; and TagResource, UntagResource and ListTagsForResource. Unset configurations return the documented defaults: SSE-S3, STANDARD, unreferenced file removal after 3 and 10 days, compaction at 512 MB with the auto strategy, and snapshot management keeping 1 snapshot for 120 hours.
  • IoT — job and job execution events — completed, canceled and deleted jobs and finished, removed or deleted executions publish to $aws/events/job/... and $aws/events/jobExecution/... when UpdateEventConfigurations enables them. Contributed by @iot-rocket.
  • IoT — UpdateJob — PATCH /jobs/{jobId} updates an IN_PROGRESS job's description, presigned URL, rollout, abort, timeout and retry configuration with AWS's checks; running executions keep their timeout. CreateJob refuses a bad timeout with the same message. Contributed by @iot-rocket.
  • Signer — real signatures on the IoT platform — when ACM holds the key of the profile's certificate, StartSigningJob on AWSIoTDeviceManagement-SHA256-ECDSA writes AWS's signed document instead of a JSON receipt, and an RSA key fails the job. Without a key the receipt stays and a warning is logged. Contributed by @iot-rocket.

Fixed

  • ELBv2 — http-header rule conditions keep their HttpHeaderConfig — the header name and values were dropped when a rule was created, modified or provisioned through CloudFormation, so DescribeRules returned an empty condition and requests never matched. Matching follows AWS: the header name and values compare case-insensitively, * and ? are the only wildcards, and a request without the header does not match. Reported by @kinoh.
  • Firehose — dynamic partitioning and Parquet conversion on S3 delivery — PutRecord, PutRecordBatch and Kinesis-sourced records ignored DynamicPartitioningConfiguration and DataFormatConversionConfiguration. The Prefix and ErrorOutputPrefix now evaluate !{timestamp:...}, !{firehose:random-string}, !{firehose:error-output-type}, !{partitionKeyFromQuery:...} (JQ MetadataExtraction) and !{partitionKeyFromLambda:...} (Lambda metadata.partitionKeys), with yyyy/MM/dd/HH/ appended when the prefix has no timestamp. Records convert to Parquet against the Glue table schema with the configured compression and land as <stream>-<version>-<timestamp>-<uuid>.parquet or the FileExtension. Failed records go to the error prefix as AWS's error document under processing-failed or format-conversion-failed. Parquet output needs DuckDB (the full image); ORC is not supported. Reported by @mintel-hgli.
  • CloudWatch Logs — DescribeMetricFilters by metric — metricName and metricNamespace now select the filters that publish that metric, filterNamePrefix applies only with logGroupName, and DeleteLogGroup removes the group's filters. Contributed by @iot-rocket.
  • Cognito — Username is the sub in pools with UsernameAttributes — AdminCreateUser and SignUp now use the sub as the Username, keep the email or phone number as an alias, and refuse a Username that is not a sign-in attribute, a differing email or phone attribute and a caller-supplied sub. Contributed by @iot-rocket.
  • Athena — S3 Tables, Glue table data and result shapes — queries reach S3 Tables as "s3tablescatalog/<bucket>".<namespace>.<table> or through QueryExecutionContext.Catalog. Glue tables read every object under their LOCATION from the S3 store without S3_PERSIST, skipping files and folders that start with _ or .; CSV columns map to the Glue schema by position with the SerDe delimiter and skip.header.line.count, and Avro tables are readable. StartQueryExecution without a result location returns InvalidRequestException, and GetQueryResults returns NULL as a Datum without VarCharValue.
  • Athena — partitioned Glue tables and qualified columns — partition columns take their Glue types instead of the types DuckDB inferred from the path, and db.table.column references resolve. Contributed by @mayuriphad. Reported by @mintel-hgli.
  • Error responses use each protocol's Content-Type — application/x-amz-json-1.1 or 1.0 for JSON services by their jsonVersion, text/xml for query services (text/xml;charset=UTF-8 for EC2), application/json for rest-json except SESv2 (application/x-amz-json-1.1), and text/xml for rest-xml except S3 (application/xml). Errors are normalized at dispatch from the botocore service model. Contributed by @pingedbrain.
  • Unimplemented services no longer answered by S3 — a request signed for a service MiniStack does not implement (for example Glacier or Pinpoint) fell through to S3 and returned NoSuchBucket; it now returns Unsupported service: <name>. Contributed by @pingedbrain.
  • CloudFormation — error namespace — ErrorResponse uses http://cloudformation.amazonaws.com/doc/2010-05-15/, the botocore API version, instead of 2010-05-08. Contributed by @pingedbrain.
  • EC2 — DescribeInstances checks the ID format first — a malformed InstanceId returns InvalidInstanceID.Malformed; a well-formed unknown ID still returns InvalidInstanceID.NotFound. Contributed by @pingedbrain.
  • ELBv2 — DescribeLoadBalancers checks name length first — a Names entry over 32 characters returns ValidationError. Contributed by @pingedbrain.
  • WAFv2 — GetWebACL checks the Id first — an Id that is not a UUID or is longer than 36 characters returns ValidationException listing the failed constraints; a well-formed unknown ID still returns WAFNonexistentItemException. Contributed by @pingedbrain.
  • Docker images fall back to public mirrors — when a Docker Hub pull fails, MiniStack retries from ECR Public and then mirror.gcr.io and tags the image with the requested name, so a Docker Hub rate limit no longer stops RDS, ElastiCache, ECS and the other container-backed services.
  • Step Functions — optimized DynamoDB error names — conditional failures and other service errors now use the DynamoDB. prefix so exact Catch and Retry handlers match AWS. Contributed by @jayjanssen.
  • Step Functions — Lambda GetFunction SDK integration — workflows can read function configuration, code metadata and tags through aws-sdk:lambda:getFunction, including qualified reads. Contributed by @jayjanssen.
  • Secrets Manager — force delete of a secret scheduled for deletion — DeleteSecret with ForceDeleteWithoutRecovery returned InvalidRequestException for a secret already scheduled for deletion. It now deletes the secret permanently. Contributed by @fabio-andre-rodrigues.
  • DynamoDB — RestoreTableToPointInTime keeps secondary indexes — the restored table now carries the source table's GSIs and LSIs, or GlobalSecondaryIndexOverride / LocalSecondaryIndexOverride when given.
  • DynamoDB — item size limits per operation — numbers are sized as base-100 digit pairs, so the 400 KB limit is exact to the byte. UpdateItem counts only the attributes it writes plus a cost per clause and answers "Item size to update has exceeded the maximum allowed size". PartiQL INSERT and UPDATE now enforce the limit, and an oversized transacted Update cancels the transaction. Reported by @hicksy and the paritysuite.org project.
  • DynamoDB — nesting depth and key length — values nested beyond 32 levels return "Nesting Levels have exceeded supported limits: Attributes in the item have nested levels beyond supported limit", including in UpdateItem and TransactWriteItems expression values. Over-long keys are refused on reads too. Reported by @hicksy and the paritysuite.org project.
  • DynamoDB — validation messages — overlapping ProjectionExpression paths are refused on GetItem, Query, Scan and BatchGetItem. Empty RequestItems, Select, Limit, Segment, ExclusiveStartKey, CreateTable, PartiQL and transaction errors use AWS's wording, and UpdateItem reports only the first invalid enum. Reported by @hicksy and the paritysuite.org project.

Don't miss a new ministack release

NewReleases is sending notifications on new releases.