September 30, 2026 · v1.5.19
v1.5.19 adds CloudFormation drift detection and RollbackStack, Kinesis SubscribeToShard for enhanced fan-out consumers, and IAM database login for MySQL and Aurora MySQL. It also brings KMS grants, resource policies for CloudWatch Logs and Bedrock AgentCore, and a round of CloudFormation, IAM, Lambda, RDS and IoT fixes.
SubscribeToShard. Enhanced fan-out: a registered consumer receives the shard's records as SubscribeToShardEvents over an event stream (HTTP/1.1 or HTTP/2) for up to 5 minutes, from any StartingPosition, with ContinuationSequenceNumber for resuming and ChildShards when the shard is split or merged. A second call for the same consumer and shard within 5 seconds is a ResourceInUseException; a later one takes the subscription over.PutResourcePolicy, DescribeResourcePolicies and DeleteResourcePolicy, account-scoped (up to 10) or scoped to one log group through resourceArn, with expectedRevisionId checks. AWS::Logs::ResourcePolicy stacks now create real policies. Contributed by @fabio-andre-rodrigues.RollbackStack. Rolls a stack left CREATE_FAILED or UPDATE_FAILED with rollback disabled back to its last stable state: a failed create ends ROLLBACK_COMPLETE, a failed update reverts its changes, deletes what it added and ends UPDATE_ROLLBACK_COMPLETE. RetainExceptOnCreate is honoured. Contributed by @fabio-andre-rodrigues.DetectStackDrift, DescribeStackDriftDetectionStatus, DetectStackResourceDrift and DescribeStackResourceDrifts compare the properties a template sets, plus stack-level tags, with the service's current record (IN_SYNC, MODIFIED with PropertyDifferences, DELETED); stacks and resources report DriftInformation. Contributed by @fabio-andre-rodrigues.PutResourcePolicy, GetResourcePolicy and DeleteResourcePolicy persist policies for runtimes and endpoints. With AUTH=true, runtime invocation evaluates caller principals, explicit denies and the runtime-plus-endpoint policy requirement for cross-account calls. This emulates the documented AgentCore policy contract locally; it does not validate behavior against AWS. Contributed by @pingedbrain.CreateGrant, RevokeGrant and RetireGrant; ListGrants now returns the grants they create, filtered by GrantId / GranteePrincipal and paged with Limit / Marker. CreateGrant follows the key state, rejects operations the key type cannot perform, and is idempotent for a named grant. Grants persist with the key and are not evaluated for authorization. Contributed by @DaviReisVieira.IDENTIFIED WITH AWSAuthenticationPlugin AS 'RDS' log in with an SDK-generated token over mysql_clear_password, as on AWS. The instance or cluster must have IAMDatabaseAuthenticationEnabled; with AUTH=true the token and the rds-db:connect policy are verified too. ModifyDBInstance accepts EnableIAMDatabaseAuthentication. Contributed by @Areson.CreateAgentRuntime returned …:agent/{uuid}:{version} and endpoints …:agentEndpoint/{uuid}, so identity and resource policies written for AWS never matched and every update changed the runtime ARN. Runtimes are now …:runtime/{agentRuntimeId}, stable across updates, endpoints are …:runtime/{agentRuntimeId}/runtime-endpoint/{name}, and the DEFAULT endpoint is created with the runtime and follows its latest version. Saved state moves to the new ARNs on restore.InvokeAgentRuntime enforces IAM policies. With AUTH=true, a runtime invocation resolves to bedrock-agentcore:InvokeAgentRuntime and is authorized against both the runtime ARN and its runtime-endpoint ARN (the qualifier, or DEFAULT), as AWS requires, so a policy can allow one runtime and deny another. Before, the action was not extracted and the invocation skipped policy evaluation. Contributed by @pingedbrain.Deny guarded by StringNotEquals, StringNotLike, ArnNotLike, NotIpAddress or another negated operator never applied to a request without that key. AWS evaluates such a condition as true and denies. The single-valued negated operators now do the same, while ForAnyValue and the affirmative operators still fail on an absent key. Contributed by @iot-rocket.BatchGetSecretValue returns only the secrets the caller may read. Under AUTH=true a grant on secretsmanager:BatchGetSecretValue alone returned every secret in the request, and Filters were ignored, so a filtered call returned the whole store. Each secret now needs secretsmanager:GetSecretValue and lands in Errors as AccessDeniedException without it, a call by Filters also needs secretsmanager:ListSecrets, and the filters select the secrets as in ListSecrets. Contributed by @iot-rocket.Add and Remove changes carried Replacement: False, a Remove had no physical id, PolicyAction was never sent and a Metadata or policy detail had no RequiresRecreation. Remove and Modify now name the physical resource, a Remove answers PolicyAction: Delete and a replacing Modify ReplaceAndDelete unless the resource retains or snapshots, and attribute details answer Never. PolicyAction also reports Retain, Snapshot and their ReplaceAnd forms from the resource's policy. Contributed by @iot-rocket.AWS::SQS::Queue applies every queue property. RedrivePolicy, RedriveAllowPolicy, KmsMasterKeyId, KmsDataKeyReusePeriodSeconds, SqsManagedSseEnabled, DeduplicationScope and FifoThroughputLimit were dropped on create and update, so a dead-letter queue declared in a template never received messages, and a value SQS refuses now fails the resource instead of being stored. A queue from a template also defaults to a 1 MiB MaximumMessageSize and SSE-SQS encryption, as on AWS. Contributed by @iot-rocket.Timeout to AWS RIE through AWS_LAMBDA_FUNCTION_TIMEOUT, preventing its default 300-second limit from ending longer invocations early. Timeout updates recycle warm containers so the RIE deadline follows the new configuration. Contributed by @gakuto-cw21.Retain or Snapshot DeletionPolicy is kept or snapshotted first, as on AWS. Contributed by @iot-rocket.KeyMaterialId. GenerateDataKey, GenerateDataKeyWithoutPlaintext, GenerateDataKeyPair, GenerateDataKeyPairWithoutPlaintext, Decrypt, ImportKeyMaterial and DeleteImportedKeyMaterial return the identifier of the key material they used, and DescribeKey reports it as CurrentKeyMaterialId for symmetric keys. The identifier stays the same until the key material changes. Contributed by @zlberto.VpcId. CreateFunction, GetFunction, GetFunctionConfiguration, and UpdateFunctionConfiguration now report the VPC of the configured subnets. Previously, VPC-attached functions returned only subnet and security group IDs. Contributed by @jayjanssen.Task timed out reply was returned as a successful payload, so Step Functions recorded TaskSucceeded and skipped Catch. Contributed by @drakeo338. Reported by @gakuto-cw21.Endpoint.Port kept the old one.true. PendingModifiedValues wrote Python True/False, which the SDKs parse as false.OnFailure and OnStackFailure are honoured. CreateStack OnFailure and CreateChangeSet OnStackFailure take DO_NOTHING, ROLLBACK or DELETE (roll back, then delete the stack). OnFailure with DisableRollback, or OnStackFailure=DELETE on a non-CREATE change set, is a ValidationError. ExecuteChangeSet now honours DisableRollback=true. Contributed by @fabio-andre-rodrigues.DeleteStack DeletionMode=FORCE_DELETE_STACK. On a DELETE_FAILED stack, resources that fail to delete and their dependencies are retained as DELETE_SKIPPED and the stack reaches DELETE_COMPLETE; on any other status it is a ValidationError. Contributed by @fabio-andre-rodrigues.GetTemplate TemplateStage and ChangeSetName. Processed, now the default, returns the template after its transforms; Original returns it as sent. StagesAvailable is reported, and ChangeSetName returns a change set's template (ChangeSetNotFound when unknown). Contributed by @fabio-andre-rodrigues.ClientRequestToken. Every event of CreateStack, UpdateStack, DeleteStack, ExecuteChangeSet, ContinueUpdateRollback, CancelUpdateStack and RollbackStack carries that call's token. Contributed by @fabio-andre-rodrigues.available under MINISTACK_RDS_PUBLIC_ENDPOINT=1 in a container. Database containers were left off MiniStack's network, so readiness never connected and the instance stayed creating. They now join the network for readiness and internal wiring, and DescribeDBInstances / DescribeDBClusters still report {MINISTACK_HOST, host_port}. Contributed by @skialpine.RegisterCACertificate checks the verification certificate. DEFAULT mode requires a verificationCertificate signed by the CA with the registration code as its CN, and SNI_ONLY refuses one, each with its own error; AWS::IoT::CACertificate fails the same way. Contributed by @iot-rocket.docker pull ministackorg/ministack:1.5.19 docker run -d -p 4566:4566 ministackorg/ministack:1.5.19
Or pin in compose.yaml:
services:
ministack:
image: ministackorg/ministack:1.5.19
ports:
- "4566:4566"
Issues and PRs welcome on GitHub. Discussion on r/ministack.