Dev News Daily ENDE

Rails stops forcing public-read ACLs on S3 and adds maintenance_database

The weekly Rails changelog published on 9 October collects a handful of changes from the Rails main branch, two of which fix real deployment failures.

Active Storage and S3 buckets without ACLs. AWS now uses "bucket owner enforced" as the default and recommended object-ownership setting, and such buckets reject any request that specifies an ACL. Active Storage services configured with public: true always attached a public-read ACL to uploads, with no opt-out — so uploading to a modern bucket through a public service failed outright. Rails now stops setting that ACL; the intended route is to grant public read through a bucket policy. Buckets that still use ACLs can restore the old behaviour per service by setting the acl option explicitly in its upload configuration.

PostgreSQL maintenance_database. Rails database tasks connect to the postgres database by default. Some managed PostgreSQL services — the changelog names DigitalOcean — do not provide one, so those tasks failed. The new maintenance_database adapter option sets the database to connect to instead, the equivalent of psql --maintenance-db.

Rails stops forcing public-read ACLs on S3 and adds maintenance_database
Rails stops forcing public-read ACLs on S3 and adds maintenance_database — Dev News Daily

Smaller changes worth knowing:

  • has_one_attached and has_many_attached now forward other options, so has_one_attached :avatar, deprecated: true works.
  • Events emitted by ActiveSupport::EventReporter are frozen: a subscriber can no longer modify the event seen by later subscribers, and in-place changes now raise FrozenError — dup first. Code that enriched events in place will start failing.
  • rails.deprecation structured events were never emitted with config.active_support.deprecation = :notify, because the subscriber class was never required; fixed.
  • Migrations declared as version 5.1 or earlier now honor table_name_prefix and table_name_suffix in change_column; SQLite references in 6.0 migrations honor an explicit type:.

What to do. If you saw Active Storage uploads failing with an ACL error after creating a new S3 bucket, this is the fix — and the bucket policy is the place to grant public reads. If you have EventReporter subscribers, search them for in-place mutation before upgrading. The changelog counted 30 contributors for the week.

Source: Ruby on Rails, "This Week in Rails: Better ACL S3 control and more", 9 October 2026 — https://rubyonrails.org/2026/10/9/this-week-in-rails