What's Changed
New Contributors
- @mayuriphad made their first contribution in #2113
- @xPTM1219 made their first contribution in #1715
[1.5.25] — 2026-10-10
Added
- CloudFormation —
AWS::IAM::User— templates with an IAM user now provision it withPath,Groups,ManagedPolicyArns, inlinePolicies,LoginProfile,PermissionsBoundaryandTags; every property updates in place exceptUserName, which replaces the user.Refreturns the user name andFn::GetAttreturnsArn. IAM gainsPutUserPermissionsBoundaryandDeleteUserPermissionsBoundary, andCreateUserandGetUsercarry the boundary. Reported by @gakuto-cw21. - DocumentDB — a new service for the
docdbAPI:CreateDBCluster,CreateDBInstance,DescribeDBClusters,DescribeDBInstances,ModifyDBCluster,ModifyDBInstance,RebootDBInstance,StartDBCluster,StopDBCluster,FailoverDBCluster,DeleteDBCluster,DeleteDBInstanceand the tag operations. Each cluster runs adocumentdb-localcontainer serving the MongoDB protocol over TLS. Defaults follow AWS: engine8.0.0, port27017, thedefault.docdb8.0parameter group anddocdb.amazonaws.comendpoints. Thedocdbclient reaches it on the normal endpoint, and an unfilteredDescribeDBClustersorDescribeDBInstanceslists RDS and DocumentDB together, as on AWS. Subnet and parameter groups are shared with RDS. CloudFormation provisionsAWS::DocDB::DBCluster,DBInstance,DBSubnetGroupandDBClusterParameterGroup, andAWS::SecretsManager::SecretTargetAttachmentaccepts DocumentDB targets. Contributed by @xPTM1219. - CloudFormation —
AWS::Logs::MetricFilter— templates with a metric filter failed withUnrecognized resource types; the filter now provisions, updates in place and is replaced on aFilterNameorLogGroupNamechange. Contributed by @iot-rocket. - DynamoDB — vector search —
CreateTableacceptsVectorIndexes,UpdateTabletakesVectorIndexUpdates(resource allocation, then backfilling, thenACTIVE), andDescribeTablereports them.SearchVectorsscores withCOSINE,EUCLIDEANorDOT_PRODUCTat 32-bit float precision and filters on theSearchSchema. Writes are checked against each vector index,INDEXEScapacity reportsVectorWriteRequestByteson single, batch and transactional writes, and a PartiQLSELECTorScanon a vector index returns "Scan operation not supported on this index type". Backups record the indexes inSourceTableFeatureDetails,RestoreTableFromBackupandRestoreTableToPointInTimerestore them or applyVectorIndexOverride, andImportTablecreates them fromTableCreationParameters. Reported by @hicksy and the paritysuite.org project. - S3 Tables — bucket and table configuration — table bucket encryption, maintenance, policy, storage class and metrics; table encryption, maintenance, maintenance job status, policy and storage class;
RenameTable; andTagResource,UntagResourceandListTagsForResource. Unset configurations return the documented defaults: SSE-S3,STANDARD, unreferenced file removal after 3 and 10 days, compaction at 512 MB with theautostrategy, and snapshot management keeping 1 snapshot for 120 hours. - IoT — job and job execution events — completed, canceled and deleted jobs and finished, removed or deleted executions publish to
$aws/events/job/...and$aws/events/jobExecution/...whenUpdateEventConfigurationsenables them. Contributed by @iot-rocket. - IoT —
UpdateJob—PATCH /jobs/{jobId}updates anIN_PROGRESSjob's description, presigned URL, rollout, abort, timeout and retry configuration with AWS's checks; running executions keep their timeout.CreateJobrefuses a bad timeout with the same message. Contributed by @iot-rocket. - Signer — real signatures on the IoT platform — when ACM holds the key of the profile's certificate,
StartSigningJobonAWSIoTDeviceManagement-SHA256-ECDSAwrites AWS's signed document instead of a JSON receipt, and an RSA key fails the job. Without a key the receipt stays and a warning is logged. Contributed by @iot-rocket.
Fixed
- ELBv2 —
http-headerrule conditions keep theirHttpHeaderConfig— the header name and values were dropped when a rule was created, modified or provisioned through CloudFormation, soDescribeRulesreturned an empty condition and requests never matched. Matching follows AWS: the header name and values compare case-insensitively,*and?are the only wildcards, and a request without the header does not match. Reported by @kinoh. - Firehose — dynamic partitioning and Parquet conversion on S3 delivery —
PutRecord,PutRecordBatchand Kinesis-sourced records ignoredDynamicPartitioningConfigurationandDataFormatConversionConfiguration. ThePrefixandErrorOutputPrefixnow evaluate!{timestamp:...},!{firehose:random-string},!{firehose:error-output-type},!{partitionKeyFromQuery:...}(JQMetadataExtraction) and!{partitionKeyFromLambda:...}(Lambdametadata.partitionKeys), withyyyy/MM/dd/HH/appended when the prefix has no timestamp. Records convert to Parquet against the Glue table schema with the configured compression and land as<stream>-<version>-<timestamp>-<uuid>.parquetor theFileExtension. Failed records go to the error prefix as AWS's error document underprocessing-failedorformat-conversion-failed. Parquet output needs DuckDB (the full image); ORC is not supported. Reported by @mintel-hgli. - CloudWatch Logs —
DescribeMetricFiltersby metric —metricNameandmetricNamespacenow select the filters that publish that metric,filterNamePrefixapplies only withlogGroupName, andDeleteLogGroupremoves the group's filters. Contributed by @iot-rocket. - Cognito —
Usernameis thesubin pools withUsernameAttributes—AdminCreateUserandSignUpnow use thesubas theUsername, keep the email or phone number as an alias, and refuse aUsernamethat is not a sign-in attribute, a differing email or phone attribute and a caller-suppliedsub. Contributed by @iot-rocket. - Athena — S3 Tables, Glue table data and result shapes — queries reach S3 Tables as
"s3tablescatalog/<bucket>".<namespace>.<table>or throughQueryExecutionContext.Catalog. Glue tables read every object under theirLOCATIONfrom the S3 store withoutS3_PERSIST, skipping files and folders that start with_or.; CSV columns map to the Glue schema by position with the SerDe delimiter andskip.header.line.count, and Avro tables are readable.StartQueryExecutionwithout a result location returnsInvalidRequestException, andGetQueryResultsreturnsNULLas aDatumwithoutVarCharValue. - Athena — partitioned Glue tables and qualified columns — partition columns take their Glue types instead of the types DuckDB inferred from the path, and
db.table.columnreferences resolve. Contributed by @mayuriphad. Reported by @mintel-hgli. - Error responses use each protocol's
Content-Type—application/x-amz-json-1.1or1.0for JSON services by theirjsonVersion,text/xmlfor query services (text/xml;charset=UTF-8for EC2),application/jsonfor rest-json except SESv2 (application/x-amz-json-1.1), andtext/xmlfor rest-xml except S3 (application/xml). Errors are normalized at dispatch from the botocore service model. Contributed by @pingedbrain. - Unimplemented services no longer answered by S3 — a request signed for a service MiniStack does not implement (for example Glacier or Pinpoint) fell through to S3 and returned
NoSuchBucket; it now returnsUnsupported service: <name>. Contributed by @pingedbrain. - CloudFormation — error namespace —
ErrorResponseuseshttp://cloudformation.amazonaws.com/doc/2010-05-15/, the botocore API version, instead of2010-05-08. Contributed by @pingedbrain. - EC2 —
DescribeInstanceschecks the ID format first — a malformedInstanceIdreturnsInvalidInstanceID.Malformed; a well-formed unknown ID still returnsInvalidInstanceID.NotFound. Contributed by @pingedbrain. - ELBv2 —
DescribeLoadBalancerschecks name length first — aNamesentry over 32 characters returnsValidationError. Contributed by @pingedbrain. - WAFv2 —
GetWebACLchecks theIdfirst — anIdthat is not a UUID or is longer than 36 characters returnsValidationExceptionlisting the failed constraints; a well-formed unknown ID still returnsWAFNonexistentItemException. Contributed by @pingedbrain. - Docker images fall back to public mirrors — when a Docker Hub pull fails, MiniStack retries from ECR Public and then
mirror.gcr.ioand tags the image with the requested name, so a Docker Hub rate limit no longer stops RDS, ElastiCache, ECS and the other container-backed services. - Step Functions — optimized DynamoDB error names — conditional failures and other service errors now use the
DynamoDB.prefix so exactCatchandRetryhandlers match AWS. Contributed by @jayjanssen. - Step Functions — Lambda
GetFunctionSDK integration — workflows can read function configuration, code metadata and tags throughaws-sdk:lambda:getFunction, including qualified reads. Contributed by @jayjanssen. - Secrets Manager — force delete of a secret scheduled for deletion —
DeleteSecretwithForceDeleteWithoutRecoveryreturnedInvalidRequestExceptionfor a secret already scheduled for deletion. It now deletes the secret permanently. Contributed by @fabio-andre-rodrigues. - DynamoDB —
RestoreTableToPointInTimekeeps secondary indexes — the restored table now carries the source table's GSIs and LSIs, orGlobalSecondaryIndexOverride/LocalSecondaryIndexOverridewhen given. - DynamoDB — item size limits per operation — numbers are sized as base-100 digit pairs, so the 400 KB limit is exact to the byte.
UpdateItemcounts only the attributes it writes plus a cost per clause and answers "Item size to update has exceeded the maximum allowed size". PartiQLINSERTandUPDATEnow enforce the limit, and an oversized transactedUpdatecancels the transaction. Reported by @hicksy and the paritysuite.org project. - DynamoDB — nesting depth and key length — values nested beyond 32 levels return "Nesting Levels have exceeded supported limits: Attributes in the item have nested levels beyond supported limit", including in
UpdateItemandTransactWriteItemsexpression values. Over-long keys are refused on reads too. Reported by @hicksy and the paritysuite.org project. - DynamoDB — validation messages — overlapping
ProjectionExpressionpaths are refused onGetItem,Query,ScanandBatchGetItem. EmptyRequestItems,Select,Limit,Segment,ExclusiveStartKey,CreateTable, PartiQL and transaction errors use AWS's wording, andUpdateItemreports only the first invalid enum. Reported by @hicksy and the paritysuite.org project.