October 5, 2026 · v1.5.22
v1.5.22 adds two services, AWS Budgets and OpenSearch Serverless (collections, security and access policies, and a proxied collection endpoint), and the Bedrock AgentCore Memory data plane: the event log, long-term records and RetrieveMemoryRecords. CloudFormation gains AWS::RDS::DBSubnetGroup, both RDS parameter group types and AWS::SecretsManager::SecretTargetAttachment, so CDK rds.DatabaseInstance and rds.DatabaseCluster stacks deploy; MySQL instances now apply their DB parameter group; Aurora DSQL supports partial indexes; IoT publishes lifecycle events and lists certificates by CA; and Cognito stores hosted UI customization. A round of Cognito, IoT, RDS, Lambda, Step Functions, SES and API Gateway fixes rounds it out.
bedrock-agentcore data-plane endpoint now serves the short-term event log (CreateEvent, GetEvent, ListEvents, DeleteEvent, ListActors, ListSessions), the long-term record store (BatchCreateMemoryRecords, BatchUpdateMemoryRecords, BatchDeleteMemoryRecords, GetMemoryRecord, ListMemoryRecords, DeleteMemoryRecord) and RetrieveMemoryRecords (token-overlap scoring, no embeddings); extraction does not run so StartMemoryExtractionJob returns ResourceNotFoundException; a cross-account memory ARN is refused AccessDeniedException under AUTH=true. Shapes verified against botocore bedrock-agentcore. Contributed by @pingedbrain.CreateBudget, DescribeBudget, DescribeBudgets, UpdateBudget, DeleteBudget, CreateNotification, UpdateNotification, DeleteNotification, DescribeNotificationsForBudget, CreateSubscriber, UpdateSubscriber, DeleteSubscriber, DescribeSubscribersForNotification, TagResource, UntagResource and ListTagsForResource. Account-scoped JSON 1.1 service; omitted TimePeriod.Start defaults to the period start, omitted End to 06/15/87 00:00 UTC and omitted ThresholdType to PERCENTAGE; the 10-notification/budget and 11-subscriber/notification limits are enforced with CreationLimitExceededException; deleting the last subscriber of a notification deletes it. Budget Actions and DescribeBudgetPerformanceHistory are out of scope. Contributed by @skialpine.CreateCollection, BatchGetCollection, ListCollections, UpdateCollection, DeleteCollection; Create/Get/Update/Delete/ListSecurityPolicy (encryption, network); Create/Get/Update/Delete/ListAccessPolicy (data); GetPoliciesStats; tag operations; enough for Terraform's aws_opensearchserverless_collection, _security_policy and _access_policy to apply and destroy; a collection requires a matching encryption policy (exact name or prefix*), an update must name the current policyVersion, a data policy refuses empty or wildcard principals, TIMESERIES collections refuse custom ids and updates, and with OPENSEARCH_DATAPLANE=1 each collection is backed by an OpenSearch container on a named Docker volume, otherwise 503; data access and network policies are stored but not enforced. Contributed by @skialpine.AWS::RDS::DBSubnetGroup, AWS::RDS::DBParameterGroup, AWS::RDS::DBClusterParameterGroup and AWS::SecretsManager::SecretTargetAttachment. these CDK rds.DatabaseInstance/rds.DatabaseCluster types were refused as Unrecognized resource types; they now create, update and delete via the RDS and Secrets Manager APIs. Ref returns the group name or the secret ARN; Fn::GetAtt gives DBSubnetGroupArn, DBParameterGroupName and DBParameterGroupArn; a parameter requiring a reboot goes pending-reboot; the attachment writes engine, host, port and dbname into the secret JSON and removes them on delete. Reported by @fabio-andre-rodrigues.CREATE INDEX ASYNC ... WHERE predicate was refused 0A000; the predicate now reaches the backend (unique partial indexes scope uniqueness to covered rows). A volatile-function predicate fails 42P17 and a subquery fails 0A000 at submit time, in the order the live service checks (eu-central-1, 2026-10-04). Contributed by @vivedo.dsql.enable_batched_nestloop and the reserved dsql. prefix. the setting shows on by default, RESET returns to on, and a non-Boolean value or value list is refused 22023; any other dsql.* name is refused 42602 "reserved prefix"; work_mem, statement_timeout and default_statistics_target can no longer be set (0A000), as on the live service. Plans remain Postgres-shaped. Contributed by @vivedo.CREATE STATISTICS on a table fails 54000 "more than 5 extended statistics per table are not allowed"; targets above 100 are refused 22023; ALTER TABLE ... ALTER COLUMN ... SET STATISTICS is refused 0A000, as on the live service. Contributed by @vivedo.ListCertificatesByCA. GET /certificates-by-ca/{caCertificateId} answered Unsupported IoT path; it now lists device certificates under the CA in every status, newest first (or ascending with isAscendingOrder=true), with pageSize (1–250) and nextMarker pagination; an unknown CA returns an empty list; invalid page sizes, ids or markers return InvalidRequestException. Contributed by @iot-rocket.$aws/events/presence/connected|disconnected/{clientId} and $aws/events/subscriptions/subscribed|unsubscribed/{clientId} with the AWS payload (sessionIdentifier, principalIdentifier, versionNumber, disconnectReason, clientInitiatedDisconnect); rules or subscriptions with a #/+ prefix filter do not receive $aws/events messages, and client ids containing # or + get none. Contributed by @iot-rocket.SetUICustomization and GetUICustomization. store and return the hosted UI CSS per user pool or per app client (client falls back to pool default); the pool needs a domain first, as on AWS. ImageFile is accepted but not stored. Supports Terraform's aws_cognito_user_pool_ui_customization. Contributed by @antonie-popovic.GenerateSecret=true clients now require a valid SecretHash on signup, confirmation, password recovery and auth; missing/wrong hashes return NotAuthorizedException before any user change. Clients without a secret reject a hash on self-service and initial auth; refresh/challenge ignore it. Refresh auth verifies the token owner and custom challenges cannot be answered through a different client. Applies under AUTH=true. Contributed by @AdrianAcala./oauth2/token refreshes tokens issued by the API. the refresh_token grant answered invalid_grant for tokens from InitiateAuth, AdminInitiateAuth, RespondToAuthChallenge or federated sign-in; it now validates them as REFRESH_TOKEN_AUTH does, refusing revoked, signed-out or wrong-client tokens with invalid_grant and returning new ID and access tokens. A missing or wrong client secret or unknown client returns invalid_client. Contributed by @Pintouch.ListFoundationModelAgreementOffers returned an empty list, so there was no offerToken for CreateFoundationModelAgreement; it now returns one offer for third-party models (Amazon models have none), CreateFoundationModelAgreement requires offerToken and returns ResourceNotFoundException for an unknown model, and GetFoundationModelAvailability reports AVAILABLE only while an agreement exists, so the Terraform aws_bedrock_foundation_model_agreement resource can be destroyed. Reported by @wparad.SMTP_HOST set, a relay that drops packets held every service request for the OS connect timeout (~2 min). The relay now runs in the background with a 10-second timeout after SES returns the MessageId; Cognito email delivery uses the same relay. Reported by @bawdo.ModifyDBParameterGroup with ApplyMethod=immediate runs SET GLOBAL on running instances; ResetDBParameterGroup restores engine defaults; a static parameter with immediate is refused InvalidParameterCombination; a pending-reboot change shows ParameterApplyStatus: pending-reboot until next start. Names, values and formula values are not validated. Contributed by @skialpine.CreateDBParameterGroup and CreateDBClusterParameterGroup with a name already in use replaced the group with an empty one, dropping its parameters; they now return DBParameterGroupAlreadyExists, as AWS does. Contributed by @skialpine.BackupRetentionPeriod=0 turns binary logging off; MiniStack's MySQL 8.0/8.4 instances kept the image default, binary logging on. Such an instance now starts with binary logging off. Contributed by @skialpine.ModifyDBInstance settings that are not pending modifications apply immediately. without ApplyImmediately, DeletionProtection, CopyTagsToSnapshot, PreferredBackupWindow, PreferredMaintenanceWindow, PubliclyAccessible, MaxAllocatedStorage, MonitoringInterval and MonitoringRoleArn were queued in PendingModifiedValues, which has no such members, and never applied. They now apply at once on every instance. Contributed by @AdrianAcala.ALL PRIVILEGES including SUPER and SYSTEM_VARIABLES_ADMIN, so SET GLOBAL/SET PERSIST worked where RDS denies them; an instance started in the background got no global grant at all. Every start path now grants the RDS/Aurora master user privileges for the engine and version WITH GRANT OPTION. Contributed by @skialpine.GetApiKeys filters by nameQuery. GetApiKeys ignored nameQuery and returned all the API keys, so a lookup by name could get the wrong key. It now returns only the keys whose names start with nameQuery. Contributed by @mishukdutta-cz.requestContext.authorizer.jwt.claims holds every claim as a string, as on AWS: numbers as digits, booleans as true/false and arrays as their items in brackets, e.g. [admin dev]. Typed event models (for example aws_lambda_events in Rust, or Go's map[string]string) parse the event. Contributed by @antonie-popovic.$connect with AWS_IAM. an unsigned handshake is refused with 403 Missing Authentication Token, and under AUTH=true the caller needs execute-api:Invoke on arn:aws:execute-api:<region>:<account>:<api-id>/<stage>/$connect. Contributed by @iot-rocket.Set-Cookie as a separate header, preserving cookie attributes and repeated fields even when their names use different casing; previously only the first value survived. Contributed by @AdrianAcala. Reported by @bawdo.CreateThingGroup on an existing name returns the group when nothing differs. a repeated CreateThingGroup always failed with ResourceAlreadyExistsException. It now returns the existing group's name, ARN and id when the description, attributes (in any order), parent and tags match, and answers 409 with AWS's message otherwise, leaving the group unchanged, as AWS does. An AWS::IoT::ThingGroup that names an existing group still fails its stack, with or without matching properties, now with AWS's name-conflict message. Contributed by @iot-rocket.SNI_ONLY mode. a device certificate signed by a CA registered with certificateMode SNI_ONLY and auto-registration enabled was refused on its first mTLS connect, so only DEFAULT CAs auto-registered. Such a CA now registers the certificate PENDING_ACTIVATION and publishes the registered event when the device's TLS ClientHello carries a server name, and does nothing without one. Under either mode, an endpoint name with another account's prefix auto-registers nothing. Contributed by @iot-rocket.RegisterCertificate links the CA that signed the certificate. a certificate registered without caCertificatePem carried no caCertificateId, even when a registered ACTIVE CA had signed it, so DescribeCertificate named no CA and ListCertificatesByCA left it out. It is now linked to that CA, as AWS does; when several registered CAs share a subject, the signature decides. Contributed by @iot-rocket.REMOVED; both publish jobs/notify(-next); notify-next omits thingName and empty statusDetails; and ListJobExecutionsForThing, DescribeJobExecution and jobProcessDetails include earlier executions. Contributed by @iot-rocket.# region no longer widens topic filters. a WebSocket session whose credential names # as its region received every message published under that region, whatever its filter, because filters were matched with the account and region prefix in front of them. Contributed by @iot-rocket.Sandbox.Timedout. functions past their Timeout returned Runtime.ExitError, so Step Functions Retry/Catch on Sandbox.Timedout never matched; all executors now return Sandbox.Timedout with Task timed out after N.00 seconds; a runtime that exits before responding still reports Runtime.ExitError. Contributed by @mishukdutta-cz.retryAfterSeconds is a string. a TooManyRequestsException returns retryAfterSeconds as a string, as the Lambda API model declares, so SDK clients such as the AWS SDK for Rust parse the response as a throttle. Contributed by @antonie-popovic.TimeoutSeconds applies to Lambda and service integration tasks. only .waitForTaskToken tasks respected TimeoutSeconds; Lambda and service integration tasks now fail States.Timeout after TimeoutSeconds; activity tasks and TimeoutSecondsPath unchanged. Contributed by @mishukdutta-cz.States.TaskFailed no longer matches States.Timeout. States.TaskFailed matched timeouts, so retries/catches ran where AWS doesn't; it now matches every error except States.Timeout. Contributed by @mishukdutta-cz.AppConfig.AllAtOnce, AppConfig.Linear50PercentEvery30Seconds, AppConfig.Canary10Percent20Minutes and AppConfig.Linear20PercentEvery6Minutes now exist in every account/region and cannot be updated or deleted; StartDeployment and AWS::AppConfig::Deployment fail ResourceNotFoundException for an unknown strategy id. Contributed by @koh-sh.54011 before the mode, key-expression and INCLUDE rules; the proxy reported those first, so a plain CREATE INDEX on nine columns drew "unsupported mode". sys.jobs.details is now NULL for a job that succeeded, where it was an empty string. Contributed by @vivedo.CALL sys.wait_for_job($1) with a bound job id. a bound job id went to the backing Postgres and failed 3F000; it now works for sys.wait_for_job and sys.jobs ... WHERE job_id = $1, CALL returns succeeded with the CALL tag (eu-central-1, 2026-10-04), and a malformed id is refused 22P02; CREATE INDEX ASYNC/ALTER TABLE ASYNC return the matching tags, sys.jobs declares oid and timestamptz columns, a constraint validation job carries class_id 2606, and a failing unique index reports the service's details. Contributed by @vivedo.TimeZone missing at startup. the proxy's startup greeting reported no TimeZone, so a driver that decodes timestamptz by it could stall on the first value; it now reports TimeZone, IntervalStyle and the rest of the parameters the live service does. Contributed by @vivedo.ministack-opensearch-<region>-<domain>, causing Docker name conflicts across accounts and erroneous cleanup; names now include an account and region hash, as RDS does. Contributed by @skialpine.CROSSSLOT; the container now runs as one cluster-mode shard holding all slots, and CLUSTER SLOTS reports the cache endpoint. Contributed by @skialpine.PutEventSelectors stores AdvancedEventSelectors and sets HasCustomEventSelectors. advanced selectors were dropped instead of stored; they are now stored in place of EventSelectors, a request with both kinds, neither, or an empty or oversized list fails InvalidEventSelectorsException, basic selectors fill in omitted members, and GetTrail/DescribeTrails report HasCustomEventSelectors: true when non-default selectors exist. Contributed by @iot-rocket.GetEventSelectors returns the default selector of a new trail. a trail that never had PutEventSelectors answered an empty EventSelectors list instead of the default selector that logs all read and write management events. Contributed by @iot-rocket.GetAccessKeyInfo answers the account that owns the key. it always returned the caller's account; it now returns the owning account for known keys, or decodes it from the key id for any AKIA/ASIA key as AWS does, and returns ValidationError for a key id that encodes no account or violates constraints. Contributed by @iot-rocket.GetAccessKeyInfo is authorized like other actions. under AUTH=true it was allowed like GetCallerIdentity and GetSessionToken, whatever the caller's policies said. It now needs an identity policy that allows it and no deny, and otherwise answers AccessDenied, as AWS does; the other two stay allowed. Contributed by @iot-rocket.CreateTopic keeps its tags. the handler read Tag.member.N where the API sends Tags.member.N, so tags given at creation were dropped. Contributed by @iot-rocket.docker pull ministackorg/ministack:1.5.22 docker run -d -p 4566:4566 ministackorg/ministack:1.5.22
Or pin in compose.yaml:
services:
ministack:
image: ministackorg/ministack:1.5.22
ports:
- "4566:4566"
Issues and PRs welcome on GitHub. Discussion on r/ministack.