September 28, 2026 · v1.5.18
v1.5.18 adds S3 object annotations, runs a Bedrock AgentCore runtime's own container on InvokeAgentRuntime, and lets an unmodified OIDC client follow a Cognito token's real issuer host to MiniStack. SQS and SNS resource policies are now enforced under AUTH=true, and DynamoDB accepts a table ARN wherever TableName is.
InvokeAgentRuntime runs the runtime's container. With Docker available (full image), the runtime's containerConfiguration.containerUri image is started, checked on /ping, and invocations are forwarded to its /invocations on port 8080; container failures answer RuntimeClientError (424). Without Docker, or for a code artifact, the deterministic echo remains. Contributed by @pingedbrain.PutDeliveryDestinationPolicy, GetDeliveryDestinationPolicy and DeleteDeliveryDestinationPolicy, so a delivery that needs a destination policy can be created. Contributed by @fabio-andre-rodrigues.USE_SSL=1). The generated certificate covers cognito-idp.<region>.amazonaws.com for every region and Lambda containers resolve those hosts to MiniStack and trust it. With an /etc/hosts entry and the certificate trusted, an unmodified client follows the token's iss to MiniStack while iss stays exactly as AWS issues it. Reported by @epcap90.ListGrants. It answered InvalidAction. It now lists the key's grants (empty, since grants are not modelled) and answers NotFoundException for an unknown key. Reported by @DaviReisVieira.PutObjectAnnotation, GetObjectAnnotation, ListObjectAnnotations and DeleteObjectAnnotation: up to 1,000 UTF-8 payloads per object version, carried by CopyObject unless the directive is EXCLUDE, removed with their version, and announced with s3:ObjectAnnotation:* events. Under AUTH=true, Object Lock refuses annotation writes with 403 AccessDenied. Contributed by @BoLaMN.AddPermission and RemovePermission. They add and remove labelled statements in the topic's Policy; a duplicate label answers InvalidParameter. Contributed by @AdrianAcala.requestContext.identity. An authorizer reading sourceIp or userAgent crashed; both are now present, as in the AWS_PROXY event. Contributed by @yosriady.TableName is. Item, query, scan, batch, transaction and table operations answered ValidationException or ResourceNotFoundException for the table's ARN. Batch responses keep the key form the request used. Contributed by @valeryan.ListAliases entries carry CreationDate and LastUpdatedDate. Both were missing; UpdateAlias moves LastUpdatedDate and keeps CreationDate. Reported by @DaviReisVieira.ReservedConcurrentExecutions is shared across versions. $LATEST and published versions each counted separately and could exceed the reservation together. Contributed by @jgrumboe.versionId and a growing sequencer are set, eventVersion is 2.6, a delete marker is ObjectRemoved:DeleteMarkerCreated, and DeleteObjects sends one event per object it removes. Contributed by @BoLaMN.AUTH=true, PutBucketNotificationConfiguration fails with InvalidArgument when an SQS/SNS destination's policy does not let S3 publish; cross-account destinations are accepted. Contributed by @AdrianAcala.AUTH=true. They were stored but never evaluated. Cross-account calls need an explicit Allow (AccessDenied for SQS, AuthorizationError for SNS), and S3 and SNS deliveries need the destination policy to allow them. With AUTH=false nothing changes. Contributed by @AdrianAcala.GetCallerIdentity resolves IAM-user callers. Keys from CreateAccessKey reported root; they now return the user's ARN and ID. Contributed by @AdrianAcala.InvalidClientTokenId. Under AUTH=true, STS answered UnrecognizedClientException.docker pull ministackorg/ministack:1.5.18 docker run -d -p 4566:4566 ministackorg/ministack:1.5.18
Or pin in compose.yaml:
services:
ministack:
image: ministackorg/ministack:1.5.18
ports:
- "4566:4566"
Issues and PRs welcome on GitHub. Discussion on r/ministack.