Repository navigation
Conversation
Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ck SyncType on DeleteResourceDataSync LastModifiedUser/CreatedBy/LastModifiedBy now come from the request's resolved IAM principal (awsmeta.CallerArn), omitted when unresolved. items_still_open adjudicated: 14 moved to structural_gaps, 7 left open. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…Events Entity keys, filter ListJobs by namespace items_still_open adjudicated in both PARITY.md files. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… details, SDK-valid VariantStatus - list pagination uses pkgs/page tokens instead of integer offsets - CreatedBy/LastModifiedBy IamIdentity on model package groups, packages, projects - UpdateProject applies provisioning and template-provider updates - DescribeProject TemplateProviderDetails used the create-side key; SDK decoded empty entries - VariantStatus used InService, which the SDK enum lacks; now Creating/Updating with StartTime - DescribeFeatureGroup OnlineStoreTotalSizeBytes from stored records Snapshot golden also carries the cloudwatchlogs/iot additive rows. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e, state machine TimeoutSeconds redshift: - Tags on parameter groups, snapshots, event subscriptions and IdC apps; TagKeys/TagValues filters on their describes - DescribeTags returned the bare cluster id as ResourceName; SDK expects the ARN - CopyClusterSnapshot kept the source ARN on the copy - ModifyCluster NewClusterIdentifier re-keys the cluster and its references - IdC application ServiceIntegrations; GetReservedNodeExchangeConfigurationOptions validation stepfunctions: top-level TimeoutSeconds was ignored; executions now end TIMED_OUT with States.Timeout, and RedriveExecution accepts them. cloudformation: PARITY.md adjudication only. Snapshot golden rows land with the rds commit. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…uster restore inheritance, receiver configs docdb: - CreateDBCluster GlobalClusterIdentifier was ignored; now joins as secondary - ReadReplicaIdentifiers was never serialized - CertificateDetails from the CA catalog; orderable options emit Vpc rds: - Failover/SwitchoverGlobalCluster move the writer; non-member targets rejected - CreateDBInstanceReadReplica honors SourceDBClusterIdentifier - cluster restores inherit engine/KMS/master user/retention from source - DBClusterSnapshot records MasterUsername, Port, storage and IAM auth cleanrooms: - receiverConfigurations on protected query/job summaries - request-only type key dropped from ProtectedJob responses - ability-change types derived for existing members Snapshot golden includes the redshift rows from da52afb. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…tIds, OpenZFS volume config, domain-owner checks fsx: - ClientRequestToken honored on create/copy/restore/update ops; changed params return IncompatibleParameterError - SubnetIds required with per-deployment-type counts - OpenZFS volume config stored, updated and enforced on delete/restore/copy - DRA S3 auto-import/export, file cache DRAs, self-managed AD config - UpdateFileCache accepted an invented StorageCapacityGiB member; removed - CopyBackup SourceRegion codeartifact: failedVersions carry errorMessage; domain-owner validated. bedrockruntime: PARITY.md adjudication only. Snapshot golden fsx rows land with the next commit. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…fig, shard metrics, DryRun s3: - PutObject x-amz-write-offset-bytes appends on directory buckets - GetBucketMetadataConfiguration returns a computed result, not the create body - request-metrics tag filters and FirstByteLatency - list ops emit RestoreStatus when requested - PutObject Size populated for notifications; ListObjectVersions no longer hardcodes STANDARD kinesis: - shard-level enhanced metrics; stream OutgoingRecords/Bytes were missing - DryRun returns DryRunOperationException without side effects - unflushed channel buffers persist across restarts xray: insight detection honors per-group FilterExpression. quicksight: asset bundle import overrides echoed; KnowledgeBase PrimaryOwnerUsername. Snapshot golden also carries the fsx rows from a29457c. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ake aggregates, conformance pack params codepipeline: Custom-owner actions now create real jobs that block the run until PutJobSuccess/FailureResult; continuation tokens queue follow-ups. cloudtrail: StartQuery by QueryAlias resolves the dashboard widget; dashboard refresh starts per-widget queries; lake SQL SUM/AVG/MIN/MAX/HAVING. awsconfig: conformance pack input parameters substituted; ListDiscoveredResources IncludeDeletedResources via tombstones; EvaluationTimeout range-checked. appsync: internal apiId/tags no longer leak onto the wire. Snapshot golden rows land with the next commit. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… Splunk failures, replicator Apache Kafka clusters firehose: - deliverToSplunk swallowed failures and always reported success - PutRecord/Batch, backup and per-destination delivery metrics - Elasticsearch/OpenSearch VpcConfiguration validated against EC2 kafka: - channels transition CREATING/UPDATING/DELETING - replicators keep apacheKafkaCluster and ReplicationInfo cluster ids (previously dropped, and an empty amazonMskCluster was always emitted) verifiedpermissions: policy store EncryptionState; Cedar entity Tags converted. workspaces: IdC ApplicationArn; enum validation on image/application filters. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nt settings, aggregations, remaining filters ec2: - Filter.N on peering, route-search, multicast, capacity blocks and more - DescribeInstanceImageMetadata reported the caller as every image owner - peering/capacity-block/secondary-interface wire fields - ModifyReservedInstances mints replacements; CreateFleet ValidUntil enforced - AssociateVpcCidrBlock applies the VPC user guide restriction matrix - Docker compute usage metrics dms: all 18 engine settings blocks round-trip (credentials stripped); CDC window. elasticbeanstalk: ComposeEnvironments was a stub listing environments; now reads env.yaml from bundles. RequestId no longer a fixed literal. inspector2: 12/15 aggregation types, AccountIds, ClientToken replay, CIS sorting, coverage metadata, ECS GetClustersForImage. Snapshot golden also carries rows from 49fa96b and 3a5dba6. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nfigs, AppBlockArn checks, finding filters athena: Identity Center, managed results and S3 access-grant workgroup configs; UpdateWorkGroup Remove* flags were silently ignored; EngineConfiguration validated; ImportNotebook reads NotebookS3LocationUri. appstream: AppBlockArn must exist on Create/UpdateApplication. accessanalyzer: resourceOwnerAccount/error/resourceControlPolicyRestriction filters no longer match everything. vpclattice: required txtMethodConfig members were missing; isManagedAssociation emitted. workmail: PARITY.md adjudication only. Snapshot golden athena row lands with the next commit. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…icky task lists, V2 filters, session expiry swf: decision and activity timeouts enforced; sticky task lists route and revert; pending task queues persist; empty registrationStatus rejected. securityhub: GetResourcesV2 ignored its filters; trends/statistics apply Filters; ListMembers OnlyAssociated defaults true per SDK; BatchUpdateFindings limits; CreateTicketV2 ClientToken; metadata.uid resolvable. neptune: SnapshotType public/shared always returned nothing; FailoverState echoed. redshiftdata: sessions expire after SessionKeepAliveSeconds. opsworks: ELB VpcId/SubnetIds/AZs derived; errors carry the JSON 1.1 content type. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… token revocation, port ranges, async states cognitoidp: ClientMetadata reaches every trigger; ConfirmForgotPassword fires PostConfirmation; RevokeToken invalidates derived access tokens; refresh RetryGracePeriodSeconds; case-insensitive/alias sign-in; ForceAliasCreation. ecs: StopServiceDeployment returned a wrapped object, SDK expects the bare ARN; ROLLBACK stop type; containerPortRange allocation; placement retries on port collision; resourceManagementType and daemonName filters. directoryservice: async trust/snapshot/share/setting states; updated settings stuck in Requested forever; replica Region resolves to the owner directory. eks: RollbackConfig.TimeoutMinutes validated. Snapshot golden also carries rows from earlier commits on this branch. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…-catalog settings, org feature stats glue: StartWorkflowRun RunProperties, IncludeGraph, blueprint include flags, GetPartitions Segment/ExcludeColumnSchema, SearchTables sort, real TaskRunProperties shape, session tags, ClientToken on glossaries and DQ runs, UpdateSchema checkpoint, partition CatalogId. lakeformation: ListPermissions IncludeRelated; Grant/Revoke CatalogId defaults the resource catalog; data lake settings per catalog. guardduty: countByFeature and free-trial days from member features. datasync: ScheduleDetails after a user disables a schedule. kinesisanalyticsv2: PARITY.md adjudication only. Snapshot golden rows land with the next commit. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… qualified function URLs, PITR restore lambda: AWS/Lambda Invocations/Errors/Duration/Throttles emitted; function URLs scoped by Qualifier; DeleteFunction leaked URL listeners and ports; qualifier-level event invoke config for async retries; UpdateFunctionCode DryRun; ESM tuning validation per SDK; TenancyConfig/CapacityProviderConfig stored. lightsail: point-in-time database restore; ApplyImmediately defers changes to the maintenance window; RotateMasterUserPassword was ignored; omitted PubliclyAccessible reset to false; certificate DomainValidationRecords. medialive: DeleteReservation keeps DELETED with TTL; busy-channel guards on DeleteCluster/DeleteNode; UsedChannelEngineVersions. memorydb: DescribeSnapshots ShowDetail; resharding PendingUpdates; multi-region ShardCount propagates. mediatailor: ListAlerts requires resourceArn. Snapshot golden rows land with the next commit; metrics emitter wiring in cli follows. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…e jobs, flow validation, WS metrics batch: array jobs spawn children with SEQUENTIAL/N_TO_N deps and cascade; multi-node node jobs and nodeOverrides; ListJobs arrayJobId/multiNodeJobId; eks/ecs property overrides; env/resource overrides merge by key. NodeRangeProperty used containerProperties where the SDK uses container (legacy key aliased in UnmarshalJSON). bedrockagent: ValidateFlowDefinition covers cycles, reachability, connections, conditions and loops; PrepareFlow fails on findings; ClientToken replay survives restart and covers KB document ingest/delete. apigatewayv2: HTTP DataProcessed, WS IntegrationError, route-level detailed metrics; WS routing uses the stage's deployment snapshot. account: region enable/disable and primary email update are async. acm: ACME domain validation settles VALIDATING to VALID. Snapshot golden rows land with the next commit. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…dentials, outpost bucket ARNs, SelectColumn metadata s3control: GetDataAccess was a stub returning empty credentials for any target; it now matches access grants and returns 403 when none covers the target. CreateBucket uses X-Amz-Outpost-Id in the ARN; MfaDelete and ManifestGenerator stored and echoed. timestreamquery: PrepareQuery Columns use the SelectColumn shape. sts, ses, servicediscovery, rolesanywhere: PARITY.md adjudication only. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…etrics and DLQ attributes, per-database SQLite, Ethereum nodes eventbridge: PutEvents and invocation metrics; DLQ messages carry ERROR_MESSAGE/EXHAUSTED_RETRY_CONDITION/RETRY_ATTEMPTS and the documented ERROR_FROM_TARGET code instead of an invented one; DLQ send checks the queue policy. rdsdata: Database selects a distinct SQLite database; ExecuteSql reaches the real engine; continueAfterTimeout on docker clusters; 1 MB response cap. networkmanager: attachment updates transition through UPDATING; route analysis follows TGW peerings (resolver wiring follows). managedblockchain: Ethereum mainnet nodes; framework attributes were dropped on clone. mq, mediastoredata: PARITY.md adjudication only. Refs: gopherstack-9x62.1 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ective): replication-group topology, domain processing windows, endpoint devices - elasticache: replication groups own real member clusters per node group; Create/Modify cluster, RG, global-datastore and snapshot parameter families implemented (placement, scaling, shard changes, failover); NoOperationFault/NodeGroupNotFoundFault; StorageEncryptionType and EffectiveDurability derived. - elasticsearch: package association details, domain processing windows and per-field OptionStatus, SubnetResolver hook for VPC options. - directconnect: AwsDevice/AwsDeviceV2/AwsLogicalDeviceId, same-endpoint LAG association rule, VirtualGatewayRegion, MACsec secret creator hook. - comprehend: training status vocabulary fix, VpcConfig/RedactionConfig and DocumentReaderConfig validation, flywheel iterations train models. - codedeploy: legacy String revision type. - detective: remaining items reclassified as structural. Snapshot golden rows land with the next commit. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s, ECS health and metrics, SWF Lambda tasks - lambda: handler wired into wireServiceMetrics; S3ObjectVersion code fetch through a versioned S3 adapter. - docdb/rds: ManageMasterUserPassword creates, rotates and deletes a real Secrets Manager secret. - iam: delegation request OwnerId/ApproverId from the caller ARN. - docdb/neptune/medialive: VpcId, SupportedNetworkTypes and channel ENIs resolved from EC2 subnets; NetworkTypeNotSupported on DUAL mismatch. - ecs: CPU/Memory utilization metrics from container stats, ELB-unhealthy task replacement, capacity-provider ASG validation. - swf: ScheduleLambdaFunction decisions invoke Lambda. - cleanrooms: association schemas from Glue tables; awsconfig conformance pack templates from S3/SSM; appsync wafWebAclArn from wafv2; workmail DeleteDirectory removes the Directory Service directory. Includes snapshot golden rows for earlier batches. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ices, cost drivers, job summary aggregation, CSR passthrough - codebuild: build-matrix batch expansion; RetryBuildBatch state rules, RETRY_FAILED_BUILDS carry-forward and PriorBuildSummaryList. - ce: GetCostComparisonDrivers from the cost ledger; DimensionalValueCount for TAG and COST_CATEGORY monitors. - backup: AggregationPeriod bucketing on job summaries; scan result status. - acmpca: CSRPassthrough templates, issuer path-length enforcement, EXPIRED CA status. - wafv2: Scope/Vendor/Name validation on managed catalog ops. - transcribe: MedicalScribeContext. - ssoadmin: primary Region listed and protected from RemoveRegion. Snapshot golden rows land with the next commit. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…sis, MQ RAM shares, Logs target authz - eventbridge: root authz tests attach the events.amazonaws.com sqs:SendMessage policy that AWS requires on a DLQ; CloudWatch Logs targets authorize logs:PutLogEvents against the log-group resource policy and now create the log stream before delivering. - directconnect: MACsec CAK/CKN keys stored as real Secrets Manager secrets. - elasticsearch: VPCOptions VPCId and AvailabilityZones from EC2 subnets. - networkmanager: route analysis walks transit gateway peering attachments in both directions. - mq: DescribeSharedResources reports RAM shares and their resources. - mediastoredata: ContainerNotFoundException for unknown containers. - comprehend: training-status test moved to an internal test file. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…,resourcegroupstaggingapi,sqs): live resource queries, delegation endpoints, invoke target validation - resourcegroups: TAG_FILTERS_1_0 and CLOUDFORMATION_STACK_1_0 queries evaluate live with stack QueryErrors. - resourcegroupstaggingapi: ListRequiredTags reads the Organizations effective TAG_POLICY. - route53resolver: HostVPCId from EC2 subnets; INBOUND_DELEGATION endpoints and DELEGATE rules. - sesv2: EndpointId and identity ARN validation on SendEmail. - sagemakerruntime: InferenceComponentName and TargetContainerHostname validation. - rekognition: video job NotificationChannel publishes completion to SNS. - sqs: remaining items reclassified. Includes snapshot golden rows for earlier batches. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…sion promote, run options, XKS keys, owning service - ram: PromoteResourceShareCreatedFromPolicy requires a matching promoted permission (UnmatchedPolicyPermissionException); ClientToken replay on 13 more ops. The Glue RAM wiring test now promotes the permission first, as the SDK documents. - omics: StartRun configurationName/runId, batch filters and failed submissions, outputBucketOwnerId, upload ClientToken, workflow owner checks, read set creationType. - kms: XksKeyId on CreateKey; ALL_KEY_MATERIAL rotations for EXTERNAL keys. - secretsmanager: OwningService from managed names; owning-service and primary-region filters. - iotdataplane: GetConnection after DeleteConnection reports the disconnect. - mwaa: CreateWebLoginToken IamIdentity from the caller. - outposts, organizations, mgn: items reclassified. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s, target group attribute defaults, foreign registry checks - dynamodb: vector indexes on CreateTable/UpdateTable/DescribeTable and restore overrides; SearchVectors scores COSINE/EUCLIDEAN/DOT_PRODUCT with filters and topK; GSI capacity and transaction metrics. - elbv2: CreateTargetGroup seeds the documented attribute defaults per load balancer family and target type. - ecr: foreign registryId rejected on repository-scoped ops. - efs: DescribeTags Marker/MaxItems paging; IpAddressInUse. - forecast: predictor and forecast lineage fields and DatasetGroupArn filters. - iotanalytics, fis, cloudcontrol: items reclassified. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…...): template versions, Select SQL expressions, vault policy enforcement, JWT OpenID tokens - pinpoint: template versions keep content; ?version= on Get/Update/Delete; UpdateTemplateActiveVersion pins a version; version numbers no longer reused after the trim. - glacier: Select SQL parentheses/NOT/BETWEEN/IN/LIKE/arithmetic/CAST/ COALESCE/NULLIF; vault lock and access policy Deny enforced on data ops with principal and condition matching. - databrew: CreatedBy/LastModifiedBy/PublishedBy/StartedBy from the caller instead of a literal; required-member validation. - cognitoidentity: OpenID tokens are JWTs with expiry and principal tags. - iotwireless: single import tasks keyed by Id with stored fields; WirelessDeviceType validation; ClientRequestToken replay persisted. - grafana: license removal chaos path; SSO grants across identity stores. - elb: CreateLoadBalancer checks security groups and subnets in EC2. - codeconnections: sync blocker contexts. codecommit: file/folder merge conflict resolution. cloudwatch: ApplyOnTransformedLogs on insight rules. - mediaconvert, identitystore: items reclassified. Snapshot golden rows land with the next commit. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ponse cache, real TestInvokeAuthorizer, translation jobs over S3, AZ ids - apigateway: embed=methods/apisummary; stage response cache with CacheHitCount/CacheMissCount and FlushStageCache; GetExport Accept and extensions; GetSdk required parameters; CloneFrom; TestInvokeAuthorizer runs the real authorizer instead of returning a fixed principal; TestInvokeMethod stage variables, path parameters, client certificates. - translate: terminology CSV/TSV/TMX parsing with skipped counts; parallel data statistics from S3; translation jobs translate S3 input documents; EncryptionKey validation. - autoscaling: LaunchInstances placement, AvailabilityZoneIds, IncludeDeletedGroups, InstanceId-derived launch settings. - applicationautoscaling: ResourceId shape validation per dimension. - bedrock: automated reasoning test case bodies, client token replay, KMS key checks, OfferType validation. - sns: AuthenticateOnUnsubscribe; SMS and application outcome metrics. - shield: LockedSubscriptionException outside the renewal window. - waf: tag ops require an existing resource. - appconfig, textract: items reclassified. Snapshot golden rows land with the next commit. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…# cron tokens fire, function LIVE stage, deep spec validation - scheduler: L, LW, L-n, nW, nL and n#m cron tokens now match instead of being accepted and never firing; day-of-week L-n rejected. - cloudfront: Stage on Get/Describe(Connection)Function with a LIVE snapshot taken at publish; distribution tenant ManagedCertificateRequest stored and reflected in GetManagedCertificateDetails. - appmesh: virtual node, route, gateway and gateway route specs validated (required members, unions, enums, ranges). - s3tables: CreateTable Iceberg Metadata validated and stored. - apprunner: CreateVpcIngressConnection requires an existing service. - amplify, transfer, support, appconfigdata, timestreamwrite: items reclassified. Includes snapshot golden rows for earlier batches. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…mination, probe VpcId from EC2, import source resolution test - emr: AutoTerminationPolicy.IdleTimeout terminates idle WAITING clusters. - networkmonitor: Probe.VpcId resolved from the source subnet via EC2. - resiliencehub: ImportResourcesToDraftAppVersion source resolution tested. - polly: ValidationException wire code covered on remaining ops. - apigatewaymanagementapi: dead constant removed. - pipes, opensearch, dax, emrserverless, codestarconnections, mediastore, kinesisanalytics: items reclassified. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…o S3 Completed async jobs used to leave nothing at their output location, so a start -> wait -> download flow found no object. Each service now writes its output through the S3 backend (resolved from the app config like translate) when the job completes: - polly: synthesized audio or speech-mark JSON at OutputS3BucketName/OutputS3KeyPrefix<TaskId>.<ext>. - transcribe: transcript JSON for transcription, medical and call analytics jobs at the job's output location; TranscriptFileUri appends <JobName>.json for an OutputKey ending in "/". - textract: <S3Prefix>/<JobId>/ output objects when OutputConfig is set. - comprehend: output.tar.gz under <S3Uri>/<acct>-<CODE>-<jobid>/output/. A failed write fails the job. Without an S3 backend behaviour is unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… realism pass; AI-service lifecycle knobs - iotdataplane: shadow version-conflict bodies carried a numeric "code" that the SDK decodes as a string, so every conflict failed to deserialize client-side; documented shadow error texts; bodies without a message fixed; topic slash limit. - iotwireless: CreateDestination rejects duplicates (it overwrote) and validates fields; multicast session ops on unknown groups are not found (they succeeded or 500'd); paging validation; opt-in FUOTA progression. - iotanalytics: opt-in CREATING->ACTIVE and dataset content CREATING->SUCCEEDED; bad nextToken/maxResults rejected. - mediastore: policy/CORS/lifecycle ops are ContainerInUseException while a container is not ACTIVE; modeled InternalServerError code. - mediastoredata: empty path segments rejected (they created nameless folders); clean messages. - Lifecycle knobs for comprehend, rekognition, textract, translate, polly, transcribe, iotanalytics and iotwireless. Includes snapshot golden rows for earlier batches. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
| return w.body.Write(b) | ||
| } | ||
|
|
||
| return w.ResponseWriter.Write(b) |
…): realism pass on monitoring and scaling services - cloudwatch: PutMetricAlarm on an existing alarm no longer resets it to INSUFFICIENT_DATA (the SDK says state is unchanged); AWS-style state reasons, StateReasonData and history; SetAlarmState on an unknown alarm is ResourceNotFound 404; paging, enum, period, time-range, datapoint, unit and dimension validation; composite TRUE/FALSE rules. - applicationautoscaling: scheduled actions now fire (at/rate/cron with timezones and start/end), updating capacity, honouring suspension and recording activities; schedule and capacity validation; AWS not-found wording. - autoscaling: raising MinSize / lowering MaxSize adjusts desired capacity as documented instead of erroring; MaxSize=0 is a real bound; capacity changes record scaling activities; unknown launch configuration on CreateAutoScalingGroup fails; per-response request ids; ResourceInUse on delete; opt-in Pending launch delay. - eks: version updates go UPDATING with the update InProgress and apply the version on completion (it flipped instantly); restore re-arms in-flight transitions; nodegroup scaling defaults survive partial configs; name/version/role/scaling/upgrade-step validation; UUID update ids; opt-in DELETING dwell. - dynamodbstreams: malformed JSON is SerializationException; Limit bounds. - Error messages no longer repeat the error code across these services. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…g, eks and more lifecycle knobs - redshift: NumberOfNodes and ClusterType were dropped so every cluster had one node; node count/type/catalog rules; pause/resume/resize state checks with InvalidClusterState; deleting status and double-delete guard. - redshiftdata: statements progress SUBMITTED->STARTED->FINISHED over an opt-in delay; cancel aborts sub-statements; sessions report BUSY; WaitTimeSeconds enforced (it was dropped); results on unfinished statements rejected. - swf: faults are HTTP 400; unknown domains/executions are UnknownResourceFault instead of empty bodies; name validation; paging validation; ScheduleActivityTask uses the type's default task list and fails for unregistered or deprecated types. - pinpoint: export/import jobs progress to COMPLETED (they stayed CREATED); definitions echo their segment/import members; format, S3, schedule and journey state validation; 400s instead of 500s. - dax: IAM role ARN and maintenance window validation; windows crossing midnight roll the end day. - Lifecycle knobs: autoscaling, eks, redshiftdata, dax, pinpoint. Includes snapshot golden rows for earlier batches. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…isabled streams stay readable; realism pass - dynamodb/dynamodbstreams: disabling a stream used to drop it immediately; it now stays listed and describable as DISABLING then DISABLED with closed shards, readable via GetShardIterator/GetRecords, for 24 hours; re-enabling creates a new stream ARN and label; iterators carry their stream ARN; disable resets the table's stream records and sequence. - lightsail: StopInstance/StartInstance pass through stopping/pending (they were instant) with state guards; multi-name creates no longer leak earlier names when a later one is a duplicate; AZ and name rules; CreateBucket returns the bucket. - elb: identical CreateLoadBalancer is idempotent; duplicate listener ports, foreign AZs and bad tags rejected without leaving a partial load balancer; PageSize/Marker validation; PolicyNotFound; AWS wording. - kinesisvideo: media type, device, storage tier, KMS, tag, channel, TTL, retention and APIName validation; paging validation. - ecrpublic: ECR wording, policy JSON, catalog data, tag and batch limits. - Error messages no longer repeat the error code across these services. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…): realism pass; lifecycle knobs - verifiedpermissions: STRICT validation mode is enforced on CreatePolicy/UpdatePolicy (no schema rejects static policies; principal, resource and action types must be declared); paging validation. - vpclattice: documented name rules and id-prefix exclusions; port and rule priority ranges with unique priorities; forward actions to unknown target groups are ResourceNotFound; opt-in CREATE/DELETE_IN_PROGRESS and target INITIAL->HEALTHY / DRAINING; not-found names the resource. - kafkaconnect: MCU, worker, autoscaling, role and name validation on create and update; base64 worker config; paging validation. - elasticsearch: instance type/count, dedicated master and EBS validation; upgrades require a known newer version. - grafana: workspace name and enum validation; paging validation. - Lifecycle knobs: --lifecycle-vpclattice, -kafkaconnect, -grafana. Includes snapshot golden rows for earlier batches. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…essanalyzer, appstream, dlm, fis - Janitors started their worker group inside `go janitor.Run(ctx)`, so the ticker goroutine could appear after a goleak baseline and be reported as a leak (TestSiblingJanitorStopsWithSibling/restore flaked in CI). Start now builds the group and starts tickers before returning; callers wait in a goroutine. Applied to apigatewaymanagementapi, lambda, cloudwatch, appsync, bedrock and bedrockruntime. - acmpca: key and signing algorithm enum and family checks (mismatches like RSA keys with ECDSA signing were accepted); NextToken validation; opt-in audit report CREATING dwell. - appstream: ComputeCapacityStatus reflects RUNNING fleets and in-use sessions (it was hard-coded); opt-in STARTING/STOPPING and image builder PENDING; fleet range validation. - dlm: policy state, resource type, schedule, interval, cron and retain rule validation (bogus states were stored); 17-hex policy ids. - accessanalyzer: analyzer name/type/configuration validation; unknown list tokens rejected; opt-in CREATING dwell. - fis: list paging validation; natural not-found messages; configurable lifecycle pause. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…productivity and ML-ops services - workmail: organization ids were m- plus 20 hex, below the 34-char minimum the AWS CLI enforces, so every CLI call on a created org failed; now m- plus 32 hex. Missing orgs return OrganizationNotFoundException (about 40 sites returned EntityNotFoundException); alias/name rules; opaque tokens; export job requirements; opt-in REQUESTED/CREATING lifecycle and export progress. - personalize: list pagination dropped one item at every page boundary; tokens now resume after the last returned item. Name, schema, filter expression and role validation; data deletion jobs end COMPLETED; minProvisionedTPS defaults to 1; opt-in CREATE PENDING/IN_PROGRESS. - opsworks: ResourceNotFound is 400 (was 404); CustomCookbooksSource and UseCustomCookbooks were dropped and now round-trip with secrets masked; stack/layer/hostname validation; opt-in instance boot progression. - outposts: name/description/notes bounds; rack property enums; configurable transition delay. - support: natural not-found messages; cc address validation; opt-in opened -> work-in-progress. Includes snapshot golden rows for earlier batches. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…ealism pass - elb: DescribeInstanceHealth reported every registered instance as InService; it now reads the EC2 instance state (running InService, pending/stopped/terminated OutOfService with the documented reason, missing Unknown) through a new EC2Resolver.InstanceStateName. - macie2: ONE_TIME classification jobs stayed RUNNING forever and now complete after a window; clientToken replay (it was ignored); job, allow list and filter validation (bad regexes and BOGUS actions were accepted); bad list tokens rejected; member ARNs include member/<id>; sentinel messages carry documented wording. - dsql: 26-char identifier validation; paging, tag and policy validation; not-found carries the resource; configurable lifecycle windows. - detective: graph ARN validation; MaxResults ceilings; new graphs start with DETECTIVE_CORE ingest; opt-in investigation RUNNING window. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…s, dsql, macie2, detective, workmail, personalize, opsworks, outposts, support Each --lifecycle-<service> flag (with its env var) falls back to the global --lifecycle-delay and defaults to 0; services with non-zero built-in windows (fis, dsql, macie2, outposts) are only overridden when set. The wiring harness covers the knobs whose default settles instantly. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…: realism pass on data planes; resolve cross-service lookups lazily - sagemakerruntime: the endpoint existence/InService check never ran in a real server because Provider.Init read GetSageMakerHandler() before the CLI stores handlers, so unknown endpoints returned 200; lookups now resolve per call. Unknown TargetVariant rejected; header constraints (CustomAttributes, InferenceId, InputLocation, TTL, timeout, session). - bedrockruntime: Converse role order/alternation, content, inference config and toolConfig validation; guardrail references resolved against the bedrock registry (lazily, same Init-ordering fix); model id format; ListAsyncInvokes paging validation. - s3tables: list limits, bucket type, policy JSON, encryption and maintenance status validation; clean messages. - cloudfrontkeyvaluestore: required Key/Value enforced (empty values were stored); malformed NextToken rejected; backend codes no longer leak into messages. - appconfigdata: probed session token rotation and polling; no deviations. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…rn-conformant guardrail ids - cloudwatchlogs: Provider.Init captured GetS3Handler() before the CLI stores sibling handlers, so in a real server the export sink was never set and CreateExportTask stayed PENDING without writing to S3. The sink now resolves the S3 backend per PutObject. - bedrock: guardrail ids were bedrock-guardrail-0000001; they are now 10-char [a-z0-9] ids (deterministic per counter) as real guardrails use. - TestSiblingLookupsAreLiveInRealServer drives sagemakerruntime, bedrockruntime and cloudwatchlogs cross-service lookups through the full server stack. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nobs - omics: import/export/activation jobs completed instantly and now go SUBMITTED->IN_PROGRESS->COMPLETED; runs and stores progress on an opt-in timer so Get and List agree; opaque tokens and bounds; workflow and run enum validation. - resiliencehub: appVersion "release" resolves to the latest published version (it was always not found); list token, bound and filter validation. - databrew: stopping a run no longer gets overwritten to SUCCEEDED by the completion timer; runs pass through RUNNING; format, sample and recipe version validation; opaque tokens; messages name the resource. - mwaa: SourceBucketArn/ExecutionRoleArn validated (notanarn was accepted); tag rules; opaque tokens; opt-in CREATING/UPDATING/DELETING. - mgn: replication and launch configuration enum validation; bad tokens. - Lifecycle knobs: mwaa, omics, resiliencehub, databrew, mgn. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…n): realism pass - cleanrooms: StartProtectedQuery dropped sqlParameters analysisTemplateArn/parameters; they are stored and echoed. SQL, result configuration and target status validation; opt-in SUBMITTED->STARTED-> SUCCESS progression for protected queries and jobs. - forecast: resource names accepted hyphens and leading digits (real rule ^[a-zA-Z][a-zA-Z0-9_]*$, max 63); S3 path, format, schema, frequency, backtest window and MaxResults validation; opt-in CREATE_PENDING-> CREATE_IN_PROGRESS->ACTIVE with ResourceInUse on early delete. - managedblockchain: ids were UUIDs and now use the real prefix plus 26 base32 chars; admin password complexity, voting policy and name validation; opt-in CREATING with ResourceNotReadyException. - networkmonitor: probe destinations must be IP addresses; opt-in PENDING. - rolesanywhere: name, duration, role ARN, policy ARN, CRL size and notification validation from the botocore model. - All five: error messages no longer repeat the exception code. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Several REST matchers claimed paths that other services share, so
correctly signed requests reached the wrong backend:
- databrew /schedules* went to Scheduler (CreateSchedule/ListSchedules
returned ResourceNotFound from the CLI)
- detective, macie2 and securityhub /invitation* went to GuardDuty
- macie2 /usage/statistics went to Inspector2
- securityhub /administrator* and /master* went to Macie2
- networkmanager /resource-policy went to Bedrock and
/organizations/service-access to SecurityHub
- resourcegroups /resources/{arn}/tags could reach Backup
- signin /v1/token went to Batch
Each matcher now declines when httputils.SignedForOtherService reports
a SigV4 scope (header or presigned) for a different service; unsigned
requests behave as before and no MatchPriority changed.
routing_signing_scope_test.go drives each pair through the production
registry with the real SDK; the routing corpus golden is regenerated.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…,apigatewaymanagementapi): realism pass - resourcegroups: ListGroups maxResults/nextToken travel in the query string and were dropped, so paginators never paged; opaque tokens and bounds; resource query shape validation; opt-in UPDATING configuration. - serverlessrepo: versions sorted as strings (1.10.0 before 1.2.0) and accepted non-semver; templates and change sets for unknown versions are rejected; stack/change set names and policy principals validated; opt-in PREPARING templates. - codeconnections: 40-char connection names were accepted (limit 32); CreateConnection with only HostArn failed instead of inheriting the host's provider; tag limits; opt-in PENDING connections and hosts. - codestarconnections: list paging validation; opt-in handshake delay. - apigatewaymanagementapi: modeled error wording; no extra members. - All: error messages no longer repeat the exception code. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- cognitoidp: PasswordPolicy.PasswordHistorySize is stored and enforced on ChangePassword, ConfirmForgotPassword and NEW_PASSWORD_REQUIRED (PasswordHistoryPolicyViolationException). - ec2: CreateVolume without Size or SnapshotId is MissingParameter; RunInstances mints one reservation id per call, DescribeInstances groups by it and supports the reservation-id filter. - sagemaker: DeleteEndpoint passes through Deleting so the endpoint-deleted waiter works. - rdsdata: Postgres column origin metadata moved to structural gaps. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…kchain, cleanrooms, resourcegroups, serverlessrepo, codeconnections, codestarconnections Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- s3: the per-bucket key index was a flat sorted []string, so every new or deleted key shifted the whole slice (O(n) per write). It is now chunks of at most 512 keys with the same ordering and seek semantics. PutObject on a 100k-key bucket drops from ~55us to ~7us, DeleteObject from ~40us to ~7us, CopyObject from ~133us to ~24us. - dynamodb: BETWEEN unwraps and parses its operands once and comparisons stop unwrapping twice; a filtered Scan of 2000 items is ~17% faster. - Fix the complex Scan benchmark, which used the reserved word Source. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…; hand-written list XML - cosmosdb: queries evaluate stored documents with lazily added system properties, a parse cache, cached sorted docs and precomputed ORDER BY keys. A WHERE query over 10k docs drops from ~82ms/641k allocs to ~2ms/786 allocs; ListDocuments breaks equal ids by partition key. - azuretable (pkgs/odatatable): cached sorted entities and filter before clone; a $filter query over 10k entities drops from ~10.8ms to ~1.2ms. - azurequeue, azureservicebus: id index plus an in-flight scan hint, so get/peek/delete no longer scan thousands of locked messages (~117us to ~1.5us). Put/Send pay ~25% more for the index map. - azureblob, azurequeue: hand-written list XML (byte-identical to xml.Marshal, tested) via the new pkgs/xmlappend; GetBlob avoids a copy. Listing 10k blobs drops from ~31ms/10k allocs to ~7ms/50 allocs. - azurearm: per-type resource index and cheaper ARM ids. - azurestoragevhost: host parse without SplitN. Snapshot inventory rows updated for unexported, non-persisted index fields; no format change. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- EventBridge rules deliver to SSM Run Command (document ARN plus RunCommandParameters targets), SSM Automation (automation-definition ARN; payload as parameters, documented as an assumption) and AppSync (AppSyncParameters.GraphQLOperation executed with the event as variables, authorised as an IAM service invocation). Failed deliveries take the existing retry/DLQ path. - Pipes deliver to Timestream: single- and multi-measure mappings, dimension/time/version paths into JSON-string and base64 Kinesis bodies, epoch units and TIMESTAMP_FORMAT; any bad mapping fails the invocation without a partial write. - Inspector is not a rule or pipe target in the current APIs; recorded as structural. - Adapters resolve sibling backends per call; full-stack tests drive each target and its failure path through the SDK. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…mented ranges - CreateDBCluster returned an instantly available cluster; it now reports creating and the lifecycle reconciler flips it to available, as the Docker-engine path already did (the SDK cluster-available waiter now has something to wait for). - Describe* validate MaxRecords against each op's documented range (20..100 by default, 20..1000 orderable options, 1..200 serverless v2); in-repo tests that paged with 1 or 2 now page realistically. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…cloudformation): realism pass; wait for SageMaker endpoint deletion - cloudformation: stack delete waits (bounded) for the SageMaker endpoint to disappear now that DeleteEndpoint passes through Deleting, as real CloudFormation reports DELETE_COMPLETE only once the resource is gone. - cloudcontrol: clean not-found wording; bad NextToken rejected; opt-in IN_PROGRESS progress events with RetryAfter and CancelResourceRequest. - directconnect: bandwidth, gateway ASN and VLAN validation; unknown connection/LAG ids error instead of an empty list; LAG child connections progressed past requested (they never did). - kinesisanalytics: ResourceNotFoundException is 400 (was 404); ExclusiveStartApplicationName for an unknown name returned the full list and now continues after it. - mediapackage: harvest jobs stayed IN_PROGRESS forever and now succeed; ManifestName defaults to index; lowercase message key. - rdsdata: TransactionNotFoundException is 404; no code prefix. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… and mediapackage lifecycle knobs Cloud Control (in-process SDK client) and CloudFormation AWS::SQS::Queue created queues from requests with no Host, so the returned QueueUrl was http:///000000000000/q1 and unusable. The SQS backend now falls back to the server endpoint when a request supplies none; real requests still use their Host. Full-stack tests check the Cloud Control identifier and the CloudFormation Ref match GetQueueUrl and accept SendMessage. Adds --lifecycle-cloudcontrol and --lifecycle-mediapackage. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- s3: object lock headers and bucket default retention were ignored on PutObject/CopyObject/multipart, so locked buckets never locked; they apply now, with validation. Lock-enabled buckets turn on versioning and refuse suspension. Ranged GETs no longer return full-object checksums (the CLI/SDK validation failed). If-Match on a missing key is 404; CompleteMultipartUpload honours conditional headers. CORS header wildcards and Vary. A Date expiration now expires every matching object once the date passes (it only expired objects modified before the date). Lifecycle rules need an action. - dynamodb: PartiQL accepts the real dialect (bare names, IN lists, numeric/boolean/null literals, set/list/map literals, set_add, RETURNING, extra WHERE conditions as conditions, reserved names); BatchExecuteStatement uses the real error code enum. - sns: MessageBody filter policies with nested objects are accepted and matched. - kinesis: shard SequenceNumberRange derives from shard open/close time instead of "0" or the ring buffer position. - CI: the compression byte-identity test ignores the per-process memory stats header; the S3 lifecycle integration test uses a valid Date rule (Days=0 is rejected by AWS). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
… pass; integration fixes - ecs: UpdateService never replaced old tasks, so services-stable never succeeded; rolling deployments now honour MaximumPercent and MinimumHealthyPercent, and DescribeServices returns service events. - cloudformation: UpdateStack ignored property changes to existing resources; changes now apply in place (Lambda, SQS, Step Functions) or by replacement honouring UpdateReplacePolicy, with AWS's events and the custom-name replacement error. SQS create applies its attributes. - apigateway: mapping templates run a Velocity subset (#set, #foreach, #if, $input.params) instead of regex substitution; MOCK integrations, PassthroughBehavior, 502 on Lambda proxy failure, multiValueHeaders. - stepfunctions: redrive resumes at the failed state and keeps history (it restarted and re-ran succeeded states); Parallel/Map/retry history events with details. - lambda: SQS event sources with BatchSize over 10 never polled (SQS caps a receive at 10); alias routing, reserved concurrency floor, JSON payload and mapping validation. - secretsmanager: the rotation Lambda can write AWSPENDING over the placeholder RotateSecret creates. - test/integration: tests updated to the realistic flows the realism passes now require (InService endpoints, existing thing types and versions, valid ids and engine versions). Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Query result capacity no longer derives from the caller's $top, and States.ArrayPartition clones each chunk instead of sizing make() from an index subtraction. Results are unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Every AWS service's PARITY.md already claimed
overall: A. This PR makes those grades honest by working through the 685items_still_openentries across 152 services. Each item was handled in one of three ways:structural_gaps: it can never work in an emulator, for example because it needs a real ML engine, real hardware or billing data.685 open items are now 232, across 96 services. The remainder is tracked in a follow-up bd issue.
Highlights
Cross-service wiring (the
cli_*_wiring.gofiles), each covered by a root-level SDK test:Real bugs fixed along the way:
CreateEventBusreturned a 500 when Tags were given.CreateFunctiondefaulted toImageinstead ofZip.L,Wand#but never fired on them.GetConnection.Made-up data removed:
GetPositionEstimateno longer returns[0,0].PublishedBy="admin".TestInvokeAuthorizerno longer returns a fixed principal.Custom:Applicationschema.Engines added:
Behaviour changes worth a look
use_load_balancer_configuration.NumCacheNodes > 1is rejected, andDeleteGlobalReplicationGroupwithRetainPrimaryReplicationGroup=falsenow also deletes the primary replication group.GetExportrejects an unknown stage or export type.AutoRenewcan only change in the last 30 days of the commitment.AWS::DirectConnect::Lagis created with no connections.Verification
Run on the final tree:
go build ./...,go vet ./...andgo vet -tags e2e ./test/e2e/...go test -count=1 .for the root packageTestSnapshotVersionGuardand the full persistence packagegofmton all tracked Go filesgolangci-linton every touched packagego.modandgo.sumunchangedmake bd-audit, which found no trailer mismatchesNot run: the terraform and integration suites, which need Docker. Snapshot inventory changes are additive only, with no version bumps.
🤖 Generated with Claude Code