floci-io/floci
52.1
Weak · 6 August 2026
182.5k
lines of production code
Java
primary language
3
measurements over time
What this system is
Floci is a comprehensive local AWS emulator that replicates the behavior of over 50 AWS services, including compute, storage, databases, and networking. It enables local development and testing by providing in-memory or containerized backends for services like S3, Lambda, DynamoDB, and EC2, while also supporting infrastructure-as-code tools such as Terraform, CDK, and OpenTofu. The system enforces IAM policies, manages resource lifecycles, and ensures SDK compatibility through extensive integration testing.
Features
API Gateway: support LocalStack-compatible execute and custom domain routing
Added new controllers and filters to support LocalStack-compatible execute endpoints (/\_aws/execute-api/ and /\_user\request\/) and custom domain routing via Host header matching. This enables compatibility with tooling that relies on these alternative URL formats. Additionally, a new VTL template engine and AWS service router were introduced to handle VTL mapping templates and dispatch AWS integration requests to the correct internal service handlers.
src/main/java/io/github/hectorvent/floci/services/apigateway · high confidence
Add AMI image build tool for generating Ubuntu AMI guest images
A new Java-based tool (AmiImageTool) is introduced to manage the lifecycle of Ubuntu AMI guest images. It supports planning, resolving, generating, and building Docker images from AMI specifications, as well as updating the EC2 image catalog. This enables users to build and manage AMI-based images with consistent metadata and provenance tracking.
src/main/java/io/github/hectorvent/floci/tools · high confidence
Add AWS ACM (Certificate Manager) emulation support
The emulator now supports the AWS Certificate Manager (ACM) API, allowing users to request, import, export, list, and manage X.509 certificates locally. This includes generating self-signed certificates for HTTPS support, handling certificate lifecycle states, and supporting domain validation methods, effectively emulating the AWS ACM service for local development.
src/main/java/io/github/hectorvent/floci/services/acm · high confidence
Add AWS AppSync emulator support for GraphQL APIs, schemas, and VTL resolvers
Users can now create, update, and delete GraphQL APIs, manage schemas, and configure data sources via the AppSync emulator. This includes a new REST API for managing GraphQL APIs and data sources, a schema registry with async compilation, and a VTL (Velocity Template Language) engine for processing resolvers. The implementation adds support for AWS-specific GraphQL scalars (e.g., AWSJSON, AWSDateTime) and directives (e.g., @aws\_api\_key, @aws\_iam), enabling users to define and test AppSync-style GraphQL schemas and resolvers locally.
src/main/java/io/github/hectorvent/floci/services/appsync · high confidence
Add AWS BCM Data Exports management plane
Introduces the management-plane implementation for AWS Billing and Cost Management (BCM) Data Exports. The new BcmDataExportsService and BcmDataExportsJsonHandler provide the CreateExport, GetExport, ListExports, UpdateExport, DeleteExport, ListExecutions, and GetExecution operations. The service persists export and execution records in storage backends, validates inputs (e.g., PARQUET format, SYNCHRONOUS frequency), and coordinates with the CurEmissionScheduler to emit data for new or updated exports. Model classes (Export, ExportExecution, DataQuery, DestinationConfiguration, RefreshCadence) are added to support these operations.
src/main/java/io/github/hectorvent/floci/services/bcmdataexports · high confidence
Add AWS Batch service support
The emulator now supports the AWS Batch API, allowing users to create and manage compute environments, job queues, and job definitions, as well as submit and track batch jobs. This includes a new REST controller, a service layer for state management, a Docker-based job runner, and the necessary data models.
src/main/java/io/github/hectorvent/floci/services/batch · high confidence
Add AWS CLI compatibility test suite
A new compatibility test suite for the AWS CLI is introduced, providing a Dockerized environment to run BATS-based tests against the Floci emulator. The suite covers services including S3, SQS, SNS, DynamoDB, IAM, STS, SES, Secrets Manager, KMS, Cognito, and S3 notifications. The test runner is configured to disable within-file parallelism to prevent race conditions in shared state, while preserving cross-file parallelism for faster execution.
compatibility-tests/sdk-test-awscli · high confidence
Add AWS Cloud Map (Service Discovery) support
The application now supports AWS Cloud Map (servicediscovery) operations, allowing users to create, list, and delete HTTP, Public DNS, and Private DNS namespaces, as well as manage services and instances within them. This includes endpoints for all standard Cloud Map API actions such as CreateNamespace, GetNamespace, ListNamespaces, CreateService, RegisterInstance, and DiscoverInstances, backed by in-memory storage and async operation tracking.
src/main/java/io/github/hectorvent/floci/services/cloudmap · high confidence
Add AWS CodeBuild emulator with full project, build, and credential management
The CodeBuild service now supports managing projects, report groups, and source credentials, and executing builds in Docker containers. Users can create, update, and delete projects and report groups, import and manage source credentials, and start, stop, or retry builds. The emulator parses buildspec files, runs build phases (install, pre\_build, build, post\_build) in isolated containers, and persists project, report group, and credential state to storage.
src/main/java/io/github/hectorvent/floci/services/codebuild · high confidence
Add AWS CodePipeline emulation
The application now supports emulating the AWS CodePipeline service. This change introduces new Java classes in the \io.github.hectorvent.floci.services.codepipeline\ package, including \CodePipelineService\ and \CodePipelineJsonHandler\, along with model classes for pipeline definitions, executions, and stored items. This enables users to interact with a simulated CodePipeline environment within the platform.
src/main/java/io/github/hectorvent/floci/services/codepipeline · medium confidence
Add AWS Config service emulation
Added an emulation of the AWS Config service, including the core service implementation, JSON request handlers, and model classes for config rules, conformance packs, configuration recorders, and delivery channels.
src/main/java/io/github/hectorvent/floci/services/configservice · high confidence
Add AWS Cost Explorer service emulation
The Cost Explorer service is now available, allowing users to query cost and usage data for AWS services like EC2, Lambda, and S3. The service synthesizes cost data from Floci's internal resource state, applying pricing rates from the bundled pricing snapshot. It supports filtering by dimensions, tags, and cost categories, and provides aggregated results by time, dimension, or tag. A monthly credit is also applied to reduce the total cost.
src/main/java/io/github/hectorvent/floci/services/ce · high confidence
Add AWS Lightsail emulation support
The application now includes a new emulation layer for Amazon Lightsail, implemented via LightsailService and LightsailJsonHandler. This adds support for managing EC2-like resources—specifically instances, disks, static IPs, and key pairs—by routing JSON API requests to local storage-backed service methods. Users can now create, start, stop, and delete instances, as well as manage associated resources, within the emulated environment.
src/main/java/io/github/hectorvent/floci/services/lightsail · high confidence
Add AWS Price List Service support
The application now supports the AWS Price List Service API, allowing users to query pricing data for AWS services. This includes operations such as DescribeServices, GetAttributeValues, GetProducts, ListPriceLists, and GetPriceListFileUrl. The service is backed by a bundled static snapshot of pricing data, which can be overridden at runtime via configuration.
src/main/java/io/github/hectorvent/floci/services/pricing · high confidence
Add AWS Transfer Family management-plane API
The application now supports the AWS Transfer Family management-plane API, allowing users to create, update, and delete SFTP, FTPS, and FTP servers, as well as manage associated users, SSH public keys, and resource tags. This new capability is implemented via the \TransferHandler\ and \TransferService\ classes, which route requests to backend storage and handle server and user lifecycle operations.
src/main/java/io/github/hectorvent/floci/services/transfer · high confidence
Add AWS WAF v2 management API support
The application now supports the AWS WAF v2 management plane. This change introduces a new handler and service layer that exposes endpoints for creating, reading, updating, and deleting Web ACLs, IP sets, regex pattern sets, and rule groups. Users can now manage these WAF v2 resources through the application's API, with the backend storing resource metadata and configuration in a storage backend.
src/main/java/io/github/hectorvent/floci/services/wafv2 · high confidence
Add Amazon EMR management API (Phase 1)
Users can now manage Amazon EMR clusters through the emulator. This change introduces the core domain models (EmrCluster, EmrStep, EmrInstanceGroup, EmrInstanceFleet, SecurityConfiguration) and the corresponding handler and service classes. The API supports creating, describing, listing, and terminating job flows, as well as managing steps, instance groups, and security configurations. The implementation simulates cluster lifecycle states (STARTING, RUNNING, WAITING, TERMINATED) and step states (PENDING, RUNNING, COMPLETED) with immediate state transitions for deterministic behavior.
src/main/java/io/github/hectorvent/floci/services/emr · high confidence
Add Amazon MQ broker control plane backed by RabbitMQ
Introduces a new Amazon MQ service implementation that manages RabbitMQ-based brokers. The change adds a REST controller (AmazonMqController) and a backend service (AmazonMqService) that handle broker lifecycle operations including create, list, describe, delete, and reboot, as well as user management (create, describe, list, delete). The service orchestrates the creation and management of Docker containers running RabbitMQ, handling container lifecycle, readiness polling, and storage of broker state. A new model package includes Broker, BrokerInstance, BrokerState, and MqUser classes to represent broker data and user configurations.
src/main/java/io/github/hectorvent/floci/services/amazonmq · high confidence
Add Amazon MSK service with Redpanda orchestration
Introduces a new Amazon MSK service implementation that manages Redpanda containers to emulate AWS MSK clusters. The change adds MskController and MskService classes that expose REST endpoints for creating, listing, describing, and deleting clusters, along with a RedpandaManager to handle container lifecycle, readiness polling, and bootstrap broker address resolution.
src/main/java/io/github/hectorvent/floci/services/msk · high confidence
Add Amazon MWAA emulation backed by a real Airflow (LocalExecutor) environment
The application now supports creating and managing Amazon MWAA environments using a real Apache Airflow instance running inside Docker containers. This feature introduces a new service layer (MwaaController, MwaaService, MwaaEnvironmentManager) that provisions Postgres and Airflow containers, manages their lifecycle, and exposes a REST-JSON API mirroring the actual AWS MWAA API (e.g., PUT for CreateEnvironment, PATCH for UpdateEnvironment). The implementation includes a web proxy to forward traffic to the running Airflow webserver and handles CLI token validation for executing Airflow commands.
src/main/java/io/github/hectorvent/floci/services/mwaa · high confidence
Add Amazon Transcribe service support
Users can now use the Amazon Transcribe API to manage transcription jobs and vocabularies. The new TranscribeService and TranscribeJsonHandler handle StartTranscriptionJob, GetTranscriptionJob, ListTranscriptionJobs, DeleteTranscriptionJob, CreateVocabulary, GetVocabulary, ListVocabularies, and DeleteVocabulary operations. Transcription jobs are transient and cleared on restart, while vocabularies are persisted to storage for durability.
src/main/java/io/github/hectorvent/floci/services/transcribe · high confidence
Add Bedrock Runtime API stub and proxy backend
The Bedrock Runtime service now supports Converse and InvokeModel endpoints with two backend implementations: a StubBackend that returns dummy responses for testing, and a ProxyBackend that forwards requests to an OpenAI-compatible API. The Converse endpoint translates Bedrock's request format to OpenAI's Chat Completions API, while InvokeModel is currently unsupported in the proxy backend. This change enables users to test Bedrock Runtime integrations locally or connect to real LLM providers via the proxy.
src/main/java/io/github/hectorvent/floci/services/bedrockruntime · high confidence
Add CDK compatibility test suite for AWS resource provisioning
The \compatibility-tests/compat-cdk\ directory now contains a full CDK-based test stack that provisions S3 buckets, SQS queues, DynamoDB tables (including GSIs and LSIs), Secrets Manager secrets, Docker-based Lambda functions, and EC2 VPCs with internal ALBs. The suite uses BATS to validate that CloudFormation correctly creates these resources in the emulated environment, ensuring that EC2 VPC/subnet creation and ECR image handling work end-to-end.
compatibility-tests/compat-cdk · high confidence
Add CloudFormation StackSets and custom resource response handling
The CloudFormation service now supports StackSets, allowing users to deploy stacks across multiple accounts and regions. A new CfnResponseController and CustomResourceResponseStore enable the handling of custom resource Lambda callbacks, which are required for certain resource types. Additionally, the handler now supports UpdateTerminationProtection, DeleteChangeSet, and ListExports API actions.
src/main/java/io/github/hectorvent/floci/services/cloudformation · high confidence
Add CloudFormation model classes for StackSets and StackInstances
The CloudFormation service now supports StackSets, introducing new model classes for StackSet, StackInstance, and StackSetOperation to represent multi-account and multi-region deployments. The existing Stack model has been extended with fields for termination protection, exports, and output export names, while all model classes are annotated for Quarkus reflection and Jackson serialization.
src/main/java/io/github/hectorvent/floci/services/cloudformation/model · high confidence
Add CloudWatch Logs Insights query support and improve log event ordering
The CloudWatch Logs service now supports Logs Insights queries via the StartQuery, GetQueryResults, and StopQuery operations, allowing users to run and retrieve query results. Additionally, log events are now sorted by timestamp and then by ingestion sequence to preserve the order of events with the same timestamp, and pagination for GetLogEvents and FilterLogEvents has been updated to use stable cursor tokens.
src/main/java/io/github/hectorvent/floci/services/cloudwatch/logs · high confidence
Add CloudWatch RUM app-monitor service
The application now supports managing CloudWatch RUM app monitors. A new REST controller and service layer handle creating, reading, updating, deleting, and listing app monitors, storing data in the configured storage backend. This enables the CDK custom resource to interact with RUM via JSON responses instead of falling through to an XML error.
src/main/java/io/github/hectorvent/floci/services/rum · high confidence
Add CodeDeploy service with persistence for applications, deployment groups, configs, and on-premises instances
The CodeDeploy service now persists applications, deployment groups, deployment configs, tags, and on-premises instances to storage, ensuring that these resources survive restarts. This change introduces the \CodeDeployService\ and \CodeDeployJsonHandler\ along with their associated model classes, enabling the platform to manage and recall CodeDeploy resources reliably.
src/main/java/io/github/hectorvent/floci/services/codedeploy · high confidence
Add Cognito authentication flows, OAuth endpoints, and user pool management
The Cognito service now supports the full USER\_SRP\_AUTH, USER\_PASSWORD\_AUTH, REFRESH\_TOKEN\_AUTH, and CUSTOM\_AUTH authentication flows, including challenge responses and token issuance. A new OAuth2 controller exposes the /oauth2/token and /oauth2/userInfo endpoints, enabling OIDC-compliant token exchange and user info retrieval. Additionally, the service implements user pool and client management operations, including tag management, group management, and custom attribute handling, providing a more complete emulation of AWS Cognito's identity and access management capabilities.
src/main/java/io/github/hectorvent/floci/services/cognito · high confidence
Add Cost and Usage Report (CUR) and BCM Data Exports emission pipeline
Users can now generate Parquet artifacts for AWS Cost and Usage Reports and BCM Data Exports. The change introduces a new emission pipeline that collects usage lines, projects them into the FOCUS 1.2/ CUR 2.0 columnar format, and writes the resulting Parquet files to S3. The system supports both synchronous emission on every mutation and a daily scheduled emission mode, with the scheduler running outside the request scope to correctly attribute reports to the owning account.
src/main/java/io/github/hectorvent/floci/services/cur · high confidence
Add ECR model classes for image and repository data
New Java model classes have been added to the ECR service layer, introducing data structures for AWS ECR resources. This includes \AuthorizationData\ for short-lived credentials, \Image\ and \ImageDetail\ for image metadata and manifests, \ImageFailure\ for batch operation errors, \ImageIdentifier\ for tag/digest references, \ImageMetadata\ for internal push timestamps, and \Repository\ for mutable repository entities with encryption, lifecycle, and tag support. These models enable the application to serialize and deserialize ECR API responses and manage repository state.
src/main/java/io/github/hectorvent/floci/services/ecr/model · high confidence
Add ECS model classes for task, service, and cluster resources
New Java model classes are introduced in the ECS service layer to represent AWS ECS resources, including EcsTask, EcsServiceModel, TaskDefinition, ContainerDefinition, and supporting types like NetworkConfiguration and EfsVolumeConfiguration. These models enable the application to track and manage ECS tasks, services, and clusters, supporting features such as container overrides, EFS volume mounts, and network configuration.
src/main/java/io/github/hectorvent/floci/services/ecs/model · high confidence
Add EKS model classes for cluster, node group, and Fargate profile data
The EKS service now includes a complete set of Java model classes to represent EKS resources, including Cluster, Nodegroup, FargateProfile, and their associated configuration and status enums. These models support serialization and reflection for the EKS API, enabling the service to create and manage clusters, node groups, and Fargate profiles.
src/main/java/io/github/hectorvent/floci/services/eks/model · high confidence
Add Elastic Beanstalk query API support with persistent storage
The application now supports querying and managing AWS Elastic Beanstalk resources (applications, versions, and environments) through a new query handler. This change introduces a new \ElasticBeanstalkService\ that manages the lifecycle of these resources and persists their state to disk via \StorageBackedMap\, ensuring that applications, versions, and environments are retained across application restarts.
src/main/java/io/github/hectorvent/floci/services/elasticbeanstalk · high confidence
Add EventBridge Pipes support with Kafka source, filtering, and enrichment
Introduced a new EventBridge Pipes implementation, including a REST controller, service layer, and poller that supports SQS, Kinesis, DynamoDB Streams, and Kafka sources. The update adds Kafka-specific components (consumer manager, native image support) and a filter matcher that applies source filter criteria to records. It also implements enrichment logic for Lambda functions and supports input templates, batch sizes, and dead-letter queue routing for pipe targets.
src/main/java/io/github/hectorvent/floci/services/pipes · high confidence
Add EventBridge Scheduler service with schedule dispatching and target invocation
The EventBridge Scheduler service is now available, allowing you to create and manage schedule groups and schedules. The system will automatically dispatch scheduled events to supported targets, including SQS, Lambda, SNS, EventBridge, and ECS RunTask. The dispatcher runs on a configurable tick interval, evaluating schedule expressions (at, rate, cron) and invoking targets when due. Universal AWS SDK targets (such as sns:publish and sqs:sendMessage) are also supported, allowing for flexible message routing. Schedule groups support tagging and untagging operations.
src/main/java/io/github/hectorvent/floci/services/scheduler · high confidence
Add Go SDK compatibility test utilities
Added a new Go SDK compatibility test suite located in the \compatibility-tests/sdk-test-go/internal/testutil\ directory. This includes a \fixtures.go\ file that provides shared test utilities and AWS client factories for services such as S3, DynamoDB, Lambda, RDS, and others, enabling automated compatibility testing against AWS SDK implementations.
compatibility-tests/sdk-test-go/internal · high confidence
Add KMS grant, key spec, and key usage models with expanded KMS API support
The KMS service now supports a broader range of AWS KMS operations, including CreateGrant, ListGrants, ListRetirableGrants, RevokeGrant, RetireGrant, GenerateRandom, GetPublicKey, GenerateMac, VerifyMac, GetKeyPolicy, PutKeyPolicy, ListKeyPolicies, UpdateKeyDescription, GetKeyRotationStatus, EnableKeyRotation, DisableKeyRotation, EnableKey, DisableKey, and RotateKeyOnDemand. This is enabled by new model classes (KmsGrant, KmsKeySpec, KmsKeyUsage, KmsMessageType) and updated KmsService/KmsJsonHandler implementations that handle these actions, including key creation with explicit key usage, key spec, and policy parameters.
src/main/java/io/github/hectorvent/floci/services/kms · high confidence
Add Memcached cluster support and improve ElastiCache error handling
Users can now create, describe, and delete Memcached cache clusters via the new ElastiCacheMemcachedService, which manages containerized Memcached instances backed by the StorageFactory. The ElastiCacheQueryHandler routes CreateCacheCluster, DescribeCacheClusters, and DeleteCacheCluster actions to this new service. Additionally, the ElastiCacheService now uses the StorageFactory for persistence instead of InMemoryStorage, and implements rollback logic to stop proxies and containers if cluster provisioning fails. The handler also adds support for ModifyReplicationGroup, and returns empty results for DescribeCacheSubnetGroups and DescribeCacheParameterGroups to satisfy SDK clients. Finally, password validation for replication groups is scoped to the group's associated users, preventing cross-group credential leakage.
src/main/java/io/github/hectorvent/floci/services/elasticache · high confidence
Add MemoryDB service with mock mode
The MemoryDB service is now available, allowing users to create and manage clusters, users, and ACLs. The implementation includes a new handler, service layer, and supporting model classes (Acl, AuthMode, Cluster, User) to support these operations. Additionally, the service supports a mock mode for development, where backend containers are not started, and a TCP proxy handles authentication and traffic routing.
src/main/java/io/github/hectorvent/floci/services/memorydb · high confidence
Add OpenTofu compatibility test suite
A new OpenTofu compatibility test suite has been added to the repository. This includes a Dockerfile to build a test environment with OpenTofu and Bats, a Terraform configuration (main.tf) that provisions a comprehensive set of AWS resources (S3, SQS, SNS, DynamoDB, IAM, SSM, Secrets Manager, VPC, Route53, Cognito, and Firehose), a provider configuration, and Bats test scripts that validate the creation and attributes of these resources. The tests verify that OpenTofu can successfully initialize, plan, and apply against the localstack-like endpoint, ensuring compatibility for these specific AWS services.
compatibility-tests/compat-opentofu · high confidence
Add RDS Data API support for PostgreSQL and MySQL
The application now implements the RDS Data API, exposing endpoints for executing SQL statements, managing transactions, and handling field mappings. This new service layer allows users to interact with local RDS instances (MySQL, MariaDB, and PostgreSQL) via the Data API interface, including support for connection pooling, transaction lifecycle management, and data type conversion.
src/main/java/io/github/hectorvent/floci/services/rdsdata · high confidence
Add S3 Vectors service support
Introduced a new S3 Vectors service, exposing REST endpoints to create, retrieve, list, and delete vector buckets and indexes, as well as to store, retrieve, and query vector data. The implementation includes a controller, service layer, and model classes to manage vector storage and retrieval operations.
src/main/java/io/github/hectorvent/floci/services/s3vectors · high confidence
Add SQS inspection endpoint and support for binary message attributes and permissions
A new REST endpoint at /\_aws/sqs/messages provides a non-destructive way to peek at all messages in a queue for testing and debugging. The SQS service now supports AddPermission and RemovePermission operations, allowing queue access control lists to be managed. Message attributes can now be binary (Base64-encoded), and the AWSTraceHeader system attribute is captured and returned in ReceiveMessage responses. Additionally, the message queue implementation has been refactored to use a thread-safe wrapper for atomic operations, and move task cancellation is now supported.
src/main/java/io/github/hectorvent/floci/services/sqs · high confidence
Add Textract service support and integration tests
The application now includes a new Textract service implementation that provides a mock/stubbed interface for Amazon Textract API operations. This includes a JSON handler (TextractJsonHandler) that routes requests for operations like DetectDocumentText, AnalyzeDocument, and their asynchronous counterparts (StartDocumentTextDetection, GetDocumentTextDetection, StartDocumentAnalysis, GetDocumentAnalysis) to the TextractService. The service returns fixed, AWS-compatible JSON responses containing stub blocks (PAGE, LINE, WORD) with geometry and confidence scores, simulating the behavior of the real AWS Textract service for testing and development purposes.
src/main/java/io/github/hectorvent/floci/services/textract · high confidence
Add WebSocket data-plane support for API Gateway v2
Introduces a new WebSocket data-plane implementation for API Gateway v2, enabling real-time bidirectional communication. The update adds a suite of new components in the \apigatewayv2.websocket\ package: a \WebSocketHandler\ to manage the HTTP upgrade and connection lifecycle; a \WebSocketConnectionManager\ to track active connections and metadata; a \WebSocketAuthorizerService\ to invoke and evaluate Lambda-based REQUEST authorizers for the \$connect\ route; a \RouteSelectionEvaluator\ to parse route selection expressions from message bodies; a \WebSocketRouteResolver\ to match incoming messages to configured routes; a \WebSocketIntegrationInvoker\ to dispatch messages to Lambda, HTTP, or MOCK integrations; and a \WebSocketProxyEventBuilder\ to construct AWS-compatible proxy events for CONNECT, MESSAGE, and DISCONNECT events. This feature allows users to build and manage WebSocket-based applications with custom routing, authorization, and integration targets.
src/main/java/io/github/hectorvent/floci/services/apigatewayv2/websocket · high confidence
Add comprehensive SES emulation with v1/v2 API support and event publishing
The Simple Email Service (SES) emulation is now fully implemented, introducing a new REST JSON controller for the AWS SES V2 API alongside the existing V1 Query protocol handler. This update adds support for managing email identities, templates, configuration sets, and suppression lists via both API versions. It also introduces the ability to publish email events to SNS, Kinesis Firehose, EventBridge, and CloudWatch, while providing a local inspection endpoint to view sent emails for testing.
src/main/java/io/github/hectorvent/floci/services/ses · high confidence
Add embedded DNS server for container name resolution
Introduces an embedded DNS server that runs inside the Floci container, allowing spawned containers (such as Lambda, RDS, and ElastiCache) to resolve internal hostnames and virtual-hosted S3 URLs (e.g., my-bucket.floci:4566) by mapping them to the Floci Docker network IP. The server handles queries for configured suffixes (like localhost.floci.io and localhost.localstack.cloud) and forwards all other queries to upstream resolvers, ensuring public hostnames still resolve correctly.
src/main/java/io/github/hectorvent/floci/core/common/dns · high confidence
Add health, init, and UI management endpoints
New controllers provide a /health endpoint for service status, an /init endpoint to inspect and manage initialization hooks (boot, start, ready, shutdown), and a /ui interface to launch and monitor the floci-ui console. The /state/reset and /state/nuke endpoints allow resetting or nuking emulator state.
src/main/java/io/github/hectorvent/floci/lifecycle · high confidence
Add in-process CloudTrail emulation with S3 data event emission
The CloudTrail service now supports creating, updating, and deleting trails, managing event selectors, and starting or stopping logging. The system captures S3 data events in-memory and periodically flushes them as gzipped JSON log files to the configured S3 bucket, following the standard AWS CloudTrail key layout. This enables local development and testing of CloudTrail-based workflows without external dependencies.
src/main/java/io/github/hectorvent/floci/services/cloudtrail · high confidence
Add inspection endpoints and models for SNS SMS and mobile push notifications
Added REST controllers (SnsInspectionController, SnsPushInspectionController) and supporting model classes (SentSms, PushNotification, PlatformApplication, PlatformEndpoint) to expose captured SMS and mobile push notification data for testing and debugging. The SnsService now tracks sent SMS and mock push notifications in memory, allowing test helpers to retrieve and assert on these messages via new GET/DELETE endpoints.
src/main/java/io/github/hectorvent/floci/services/sns · high confidence
Add model classes for AWS EventBridge Pipes
Introduced new data models for the EventBridge Pipes service, including the Pipe class which represents a pipe configuration with properties such as name, ARN, source, target, and state, and the DesiredState and PipeState enums to track pipe lifecycle states. These classes are annotated for JSON serialization and reflection, enabling the service to manage pipe resources.
src/main/java/io/github/hectorvent/floci/services/pipes/model · high confidence
Add real-mode EKS cluster support with k3s containers
Introduced a new EKS service implementation that manages real-mode EKS clusters using k3s containers. The change adds an EksClusterManager to handle the Docker lifecycle of k3s containers, including port allocation, readiness polling, and endpoint resolution. An EksController exposes REST-JSON endpoints for creating, listing, describing, and deleting clusters, node groups, and Fargate profiles. A new EksTokenWebhookController handles Kubernetes token authentication, mapping AWS IAM tokens to cluster-admin access. The service also supports disabling the bundled CNI and uses named Docker volumes for k3s data directories to ensure compatibility with macOS hosts.
src/main/java/io/github/hectorvent/floci/services/eks · high confidence
Add support for Kinesis stream mode, enhanced monitoring, and retention period updates
The Kinesis service now supports creating streams with a specified mode (PROVISIONED or ON\_DEMAND) and updating stream mode via the UpdateStreamMode API. Additionally, the service implements EnableEnhancedMonitoring and DisableEnhancedMonitoring to manage shard-level metrics, and supports increasing or decreasing stream retention periods. The handler also resolves stream names from StreamARNs where applicable, and returns real ShardIds in PutRecord responses.
src/main/java/io/github/hectorvent/floci/services/kinesis · medium confidence
Add support for emulating Amazon Neptune graph database clusters
Users can now create and manage Neptune DB clusters and instances, with the backend engine configurable via the NEPTUNE\_DB\_TYPE setting to use either a TinkerPop Gremlin Server or a Neo4j container. The new NeptuneQueryHandler routes AWS RDS-style API calls to the appropriate service, while the NeptuneService manages container and proxy lifecycles, including automatic rollback of resources if provisioning fails.
src/main/java/io/github/hectorvent/floci/services/neptune · high confidence
Add verification code subsystem for Cognito
Users can now receive and verify one-time codes for sign-up confirmation, password reset, MFA, and attribute verification. The new VerificationCodeService generates, stores, and validates these codes, while CognitoMessageDispatcher handles sending them via email (SES) or SMS (SNS).
src/main/java/io/github/hectorvent/floci/services/cognito/verification · high confidence
Added Amazon DocumentDB service emulation
The emulator now supports Amazon DocumentDB. A new service layer in src/main/java/io/github/hectorvent/floci/services/docdb provides emulation for DB clusters and instances, including CreateDBCluster, DescribeDBClusters, DeleteDBCluster, ModifyDBCluster, CreateDBInstance, DescribeDBInstances, DeleteDBInstance, and ModifyDBInstance. The implementation uses containerized MongoDB backends (or mock mode) and exposes the corresponding AWS RDS-style XML API responses.
src/main/java/io/github/hectorvent/floci/services/docdb · high confidence
Added Cloud Control service to list local resources
Users can now query a unified list of local resources (S3 buckets, EC2 VPCs, subnets, security groups, IAM roles, and users) through the Cloud Control service. The new CloudControlService aggregates data from existing local services, and the CloudControlJsonHandler exposes a ListResources endpoint that returns resource identifiers and properties, including EC2 resource tags for VPCs, subnets, and security groups.
src/main/java/io/github/hectorvent/floci/services/cloudcontrol · high confidence
Added ECR registry management and garbage collection endpoints
Introduced new Java classes to manage the lifecycle of the shared Docker registry container that backs the emulated ECR. EcrRegistryManager handles starting, stopping, and adopting the registry container, while EcrGcController exposes a new POST endpoint at \_floci/ecr/gc to trigger garbage collection on the backing registry to reclaim disk space. RegistryHttpClient provides the low-level HTTP interactions with the registry API.
src/main/java/io/github/hectorvent/floci/services/ecr/registry · high confidence
Added ECR service implementation for container registry operations
Users can now interact with Amazon ECR through the emulator, which provides a new backend for managing container image repositories. The change introduces the EcrService and EcrJsonHandler classes, implementing read and write APIs for repository management (create, describe, delete), image listing and inspection, and authentication token retrieval. This enables tools like Steampipe to collect ECR resource data and allows users to simulate ECR workflows locally.
src/main/java/io/github/hectorvent/floci/services/ecr · high confidence
Added IoT service with REST and MQTT endpoints
Introduced a new IoT service implementation featuring REST controllers for managing IoT resources (things, certificates, policies, jobs, shadows, and rules) and an embedded MQTT broker for handling direct message publishing, subscriptions, and retained messages. The service includes model classes for all core IoT entities and integrates with existing storage backends and other cloud service emulators (SQS, SNS, S3, Kinesis, DynamoDB, Lambda) to provide a functional IoT simulation environment.
src/main/java/io/github/hectorvent/floci/services/iot · high confidence
Added Maven Wrapper for consistent builds
The project now includes a Maven Wrapper, allowing developers to build the project without having Maven installed locally. The wrapper is configured to use Maven version 3.9.9, ensuring consistent build environments across all users.
.mvn · high confidence
Added awslocal development script
A new executable script named 'awslocal' has been added to the bin directory. This script configures environment variables to point the AWS CLI to a local endpoint (defaulting to http://localhost:4566) with test credentials, allowing developers to easily test against a local AWS-compatible service like Floci. It also provides an 'env' subcommand to print the necessary export commands for shell configuration.
bin · high confidence
Added compatibility test suite for Floci
The repository now includes a dedicated \compatibility-tests\ directory containing a full test suite for the Floci local AWS emulator. This suite verifies that standard AWS tooling (SDKs for Python, TypeScript, Java, Go, and AWS CLI, as well as CDK, Terraform, and OpenTofu) works correctly against the emulator without modification. The tests are orchestrated via a \justfile\ and produce JUnit XML reports for CI integration.
compatibility-tests · high confidence
Added emulation of AWS Route53 API for managing hosted zones and resource record sets
Users can now create, list, and delete hosted zones, as well as modify resource record sets, using the Route53 emulation layer. This includes support for zone creation with private/public settings, listing zones with pagination, and updating DNS records, all handled via the new \Route53Controller\ and \Route53Service\ classes backed by a JSON-based storage layer.
src/main/java/io/github/hectorvent/floci/services/route53 · high confidence
Amazon Kinesis Firehose service implementation
Added a new implementation of the Amazon Kinesis Firehose service, enabling the creation, update, and deletion of delivery streams, as well as data ingestion via PutRecord and PutRecordBatch. The update also adds support for managing stream tags (TagDeliveryStream, UntagDeliveryStream, ListTagsForDeliveryStream) and updating S3 destinations (UpdateDestination, DescribeDeliveryStream, ListDeliveryStreams). This provides a functional, in-memory backed Firehose service for local development and testing.
src/main/java/io/github/hectorvent/floci/services/firehose · high confidence
Core infrastructure for multi-account routing, protocol claiming, and IAM enforcement
The emulator now resolves the calling account from AWS Authorization headers and presigned URL credentials, enabling multi-account isolation. A new request pipeline claims the wire protocol (REST, JSON, or CBOR) and enforces IAM policies on every request, with CloudTrail logging for denied S3 actions. Additionally, global CORS headers are added to all responses, and request IDs are injected into response headers for SDK compatibility.
src/main/java/io/github/hectorvent/floci/core/common · high confidence
Docker image build and entrypoint overhaul for LocalStack compatibility
The Docker build system was restructured into four distinct image variants: a standard JVM image (Dockerfile), a native binary image (Dockerfile.native), a minimal native package (Dockerfile.native-package), and a compatibility image (Dockerfile.compat) that includes AWS CLI and boto3. The entrypoint script was rewritten to handle Docker socket group ownership for host compatibility, implement a fallback to the default command when no arguments are provided, and enforce write permissions on the data directory. Additionally, a new localstack-parity.sh script maps LocalStack environment variables (such as PERSISTENCE, EDGE\_PORT, and DEBUG) to Floci equivalents, and unit tests were added to verify the entrypoint and parity logic.
docker · high confidence
DynamoDB service receives comprehensive implementation and validation support
The DynamoDB service implementation is significantly expanded with new files that add critical functionality and correctness checks. A new PartiQL parser and handler (\DynamoDbPartiQLParser\, \DynamoDbPartiQLHandler\) enable execution of SQL-like queries (SELECT, INSERT, UPDATE, DELETE) against DynamoDB tables. Number validation and normalization are handled by \DynamoDbNumberUtils\, ensuring values conform to DynamoDB's precision and range constraints. Item size validation is enforced via \DynamoDbItemSize\, rejecting items exceeding the 400KB limit. A reserved words checker (\DynamoDbReservedWords\) prevents the use of SQL/DynamoDB keywords as bare attribute names. Table name resolution (\DynamoDbTableNames\) now supports both short names and full ARNs. Finally, \DynamoDbResponses\ adds the \X-Amz-Crc32\ header to JSON protocol responses, improving compatibility with AWS SDK clients that verify checksums. These changes collectively improve conformance, validation, and feature parity for the DynamoDB mock service.
src/main/java/io/github/hectorvent/floci/services/dynamodb · high confidence
EC2 instance emulation via Docker containers
EC2 instances are now emulated as isolated Docker containers, enabling real guest OS execution with SSH, UserData, and IMDS support. This change introduces an image resolution system that maps AMI IDs to Docker images, a metadata server that mimics the AWS Instance Metadata Service (IMDS) for credential and instance data, and a container manager that handles the full lifecycle of each instance. The implementation persists EC2 state to storage so that CloudFormation references and other resources survive restarts.
src/main/java/io/github/hectorvent/floci/services/ec2 · high confidence
Emulate AWS CloudFront service for local testing
Added a new CloudFront service emulation layer, including a REST controller and backend service that manage distributions, cache policies, origin request policies, and other CloudFront resources in memory. This enables local development and testing of CloudFront-related functionality without requiring a live AWS account.
src/main/java/io/github/hectorvent/floci/services/cloudfront · high confidence
Emulated OpenSearch service with real container support and metadata
Added an emulated OpenSearch service that supports both mock and real Docker-based execution. The new OpenSearchController exposes REST endpoints for domain creation, description, and configuration updates, while OpenSearchService manages domain state and lifecycle. For real-mode domains, OpenSearchDomainManager starts isolated Docker containers, handling image resolution, port allocation, and readiness checks. A new OpenSearchVersions catalog maps engine versions (including OpenSearch 3.x and Elasticsearch 7.10 OSS) to specific Docker images. Additionally, OpenSearchInstanceTypes provides per-family instance type metadata (storage type, volume limits, feature flags) so SDK clients see accurate limits for each instance class.
src/main/java/io/github/hectorvent/floci/services/opensearch · high confidence
Enable optional TLS/HTTPS support with self-signed certificate generation
Floci now supports optional TLS/HTTPS on the same port as HTTP, matching LocalStack's dual-protocol behavior. When enabled, a TCP proxy inspects incoming connections to route TLS and HTTP traffic to separate internal backends. A new configuration source generates and persists self-signed certificates, tracking hostnames and version to detect configuration changes and regenerate certificates when needed. The proxy listens on the public port and an optional AWS HTTPS port (default 443) for CloudFormation callbacks.
src/main/java/io/github/hectorvent/floci/config · high confidence
Enforce IAM policies for all supported AWS services
The IAM service now enforces identity-based, resource-based, session, and permission boundary policies for a wide range of AWS services including S3, Lambda, DynamoDB, RDS Data API, API Gateway, Kinesis, SQS, SNS, KMS, and Secrets Manager. This is achieved by introducing new components: an \IamPolicyEvaluator\ that implements the full AWS policy evaluation algorithm (phases 1-4), an \AssumeRolePolicyEvaluator\ for trust policy checks, an \IamActionRegistry\ that maps HTTP requests to IAM actions, and a \ResourceArnBuilder\ that constructs resource ARNs for policy matching. Additionally, a catalog of 60+ AWS managed policies is seeded at startup to support common use cases. The \IamQueryHandler\ has been updated to pass authorization context to enforcement logic, and new handlers for permission boundaries and entity listing have been added.
src/main/java/io/github/hectorvent/floci/services/iam · high confidence
EventBridge: Add scheduled rules, event replay, and target invocation infrastructure
The EventBridge service now supports scheduled rules, event replay, and event delivery to multiple targets. A new \RuleScheduler\ uses a cron/rate expression parser to trigger rules on a schedule, while a \ReplayDispatcher\ handles asynchronous replay of archived events to a destination bus. The \EventBridgeInvoker\ routes events to Lambda, SQS, SNS, AWS Batch, and Firehose targets, applying input path and transformer logic. The \EventBridgeHandler\ exposes new API actions including \UpdateEventBus\, \TestEventPattern\, \TagResource\/\UntagResource\, \PutPermission\/\RemovePermission\, and full Archive/Replay lifecycle operations.
src/main/java/io/github/hectorvent/floci/services/eventbridge · medium confidence
Expanded API Gateway v2 model support for advanced routing and integration features
The API Gateway v2 service models have been updated to support more granular configuration of API resources. New model classes (IntegrationResponse, Model, RouteResponse, VpcLink) and expanded fields in existing models (Api, Authorizer, Integration, Route, Stage) now allow users to configure route selection expressions, CORS settings, authorizer TTL, connection types, and stage variables. This enables more complex API gateway setups, including WebSocket support, ALB listener forwarding, and detailed response templating.
src/main/java/io/github/hectorvent/floci/services/apigatewayv2/model · medium confidence
Expanded Cognito model support for groups, resource servers, and client configuration
The Cognito service now supports managing user groups, resource servers with scopes, and token revocation tracking via new model classes (CognitoGroup, ResourceServer, ResourceServerScope, RevokedTokenInfo, UserPoolClientSecret). Existing models have been enriched: CognitoUser now includes group membership and SRP-6a authentication fields; UserPool exposes comprehensive configuration options (MFA, lambda hooks, policies, tags, etc.); and UserPoolClient now supports OAuth flows, token validity, refresh token rotation, and client secret management.
src/main/java/io/github/hectorvent/floci/services/cognito/model · high confidence
Expanded EventBridge model support for archives, replays, and advanced target parameters
The EventBridge service now supports managing event archives and replays, with new \Archive\ and \Replay\ model classes that expose fields such as \retentionDays\, \eventPattern\, \eventStartTime\, and \destinationArn\. Additionally, the \Target\ model now includes \InputTransformer\, \SqsParameters\ (including \MessageGroupId\ for FIFO queues), and \BatchParameters\ (supporting job definitions, names, array properties, and retry strategies). The \EventBus\ model has been extended with \policy\, \kmsKeyIdentifier\, \deadLetterConfig\, and \logConfig\ fields, while the \Rule\ model now exposes \accountId\ and a computed \region\ derived from the ARN.
src/main/java/io/github/hectorvent/floci/services/eventbridge/model · medium confidence
Expanded S3 model support for notifications, checksums, and object attributes
The S3 service model now includes new classes for handling S3-to-Lambda notifications, object attributes (ETag, checksums, storage class, size, and parts), and filter rules for event notifications. Additionally, the S3Object and MultipartUpload models now support checksum algorithms, content headers (Cache-Control, Content-Disposition, Content-Encoding), and storage class settings, enabling more complete S3 API compatibility.
src/main/java/io/github/hectorvent/floci/services/s3/model · high confidence
HTTP API v2 HTTP\_PROXY integration with request parameter mapping
Added support for HTTP\_PROXY integration in API Gateway v2, allowing HTTP API requests to be forwarded through an ALB listener. The change introduces a new proxying layer (ContextValueResolver, HttpProxyInvoker, PathTemplateResolver, ProxyRequestBuilder, ProxyResult, RequestContext, and RequestParameterMapper) that resolves request parameters and context values (such as headers, query strings, path parameters, and authorizer claims) to construct and forward backend requests. This enables dynamic header, query, and path manipulation based on incoming request data.
src/main/java/io/github/hectorvent/floci/services/apigatewayv2/proxy · medium confidence
Implement core AWS Athena API emulation for query execution and workgroup management
Added a new \AthenaService\ and \AthenaJsonHandler\ to emulate AWS Athena behavior locally. The service now supports starting, stopping, and listing query executions, as well as creating, retrieving, and deleting workgroups. The handler routes JSON requests for actions like \StartQueryExecution\, \GetQueryExecution\, \ListQueryExecutions\, \StopQueryExecution\, \GetWorkGroup\, \ListWorkGroups\, and \DeleteWorkGroup\ to the service layer. Model classes for query states, result configurations, and workgroup configurations have been introduced to support these operations.
src/main/java/io/github/hectorvent/floci/services/athena · high confidence
Introduce AWS Backup management-plane API
The application now supports the AWS Backup management-plane API, allowing users to create, describe, update, and delete backup vaults, backup plans, and backup selections. This includes endpoints for managing backup vaults, creating and updating backup plans with rules, and defining resource selections for those plans.
src/main/java/io/github/hectorvent/floci/services/backup · high confidence
Introduce EC2 Auto Scaling service with stateful group reconciliation and instance refresh support
Added a new Auto Scaling service that provides a stateful, in-memory (with optional persistent storage) implementation of the AWS EC2 Auto Scaling API. This includes full CRUD operations for launch configurations, auto scaling groups, scaling policies, lifecycle hooks, and scaling activities. A background reconciler continuously synchronizes the internal state with actual EC2 instances, handling instance lifecycle transitions (Pending to InService), removing stale or terminated instances, and managing load balancer target group registrations. The service also supports instance refresh operations, allowing users to update the desired configuration of their auto scaling groups and track the progress of rolling updates.
src/main/java/io/github/hectorvent/floci/services/autoscaling · high confidence
Introduce ECS service emulation with ELBv2 integration
Added the \EcsService\ and \EcsJsonHandler\ to emulate AWS ECS resources including clusters, task definitions, tasks, and services, with persistence via \StorageBackedMap\. The new \EcsLoadBalancerRegistrar\ automatically registers running task containers as targets in ELBv2 target groups when an ECS service declares a load balancer, and deregisters them on task stop or emulator shutdown.
src/main/java/io/github/hectorvent/floci/services/ecs · medium confidence
Introduce ECS task execution via Docker containers
Added EcsContainerManager, EcsTaskHandle, and SecretsManagerSelector to manage the lifecycle of Docker containers that emulate AWS ECS tasks. The new manager starts one container per task definition, handling port mappings, command overrides, environment variables, and log streaming. It also resolves AWS Secrets Manager values for task secrets and supports EFS volume mounting, allowing users to run ECS-style workloads locally.
src/main/java/io/github/hectorvent/floci/services/ecs/container · high confidence
Introduce ELBv2 service emulation
Added the core implementation for the Elastic Load Balancing v2 (ELBv2) service emulation. This includes the data plane for managing listeners and routing, a health checker for target groups, a query handler for AWS-style API actions, and the underlying service and model classes (LoadBalancer, Listener, Rule, TargetGroup, etc.) to support creating, describing, and deleting load balancers, target groups, listeners, and rules.
src/main/java/io/github/hectorvent/floci/services/elbv2 · high confidence
Introduce Resource Groups Tagging API implementation
Added the core service and JSON handler for the Resource Groups Tagging API, enabling users to tag, untag, and query resources by tags. The new \ResourceGroupsTaggingService\ persists resource-to-tag mappings in storage, ensuring that tag data survives restarts, while the \ResourceGroupsTaggingJsonHandler\ routes incoming JSON requests to the appropriate service methods.
src/main/java/io/github/hectorvent/floci/services/resourcegroupstagging · high confidence
Introduce local Glue catalog and schema registry emulation
Added new Java classes to emulate AWS Glue catalog operations and schema registry functionality, including model classes for databases, tables, partitions, and user-defined functions, alongside a GlueService for core catalog operations and a GlueSchemaRegistryService for managing schemas and registries. The implementation supports creating, updating, and deleting databases, tables, and partitions, as well as schema versioning and compatibility checking for Avro, JSON, and Protobuf formats.
src/main/java/io/github/hectorvent/floci/services/glue · high confidence
Lambda model layer adds support for extensions, image config, and event source mapping enhancements
The lambda model package introduces new data classes to support the Lambda Extensions API (ExtensionEvent, RegisteredExtension), image configuration (ImageConfig fields in LambdaFunction), and enhanced EventSourceMapping (ScalingConfig, DestinationConfig, functionResponseTypes). It also adds LambdaLayerVersion for layer management, FunctionEventInvokeConfig for retry and destination settings, and updates InvokeResult to report the executed version. These changes enable the service to track extension lifecycle events, configure image-based functions, manage layer versions, and handle advanced event source mapping configurations.
src/main/java/io/github/hectorvent/floci/services/lambda/model · high confidence
Native image build and runtime configuration overhaul
The application's native image build and runtime configuration has been significantly expanded to support new services and fix existing issues. The \reflect-config.json\ is updated with extensive GraalVM reflection entries for BouncyCastle (RSA, EC, SHA, AES, PBKDF2) and Apache Velocity, while \resource-config.json\ is added to bundle pricing snapshots, EC2 image catalogs, and Velocity properties. The \application.yml\ is updated to include these resources, add a custom log format, and configure shutdown hooks to run before the HTTP server stops. Additionally, a new \TlsConfigSource\ is registered for MicroProfile Config, and a default banner and UI landing page are added to the resources.
src/main/resources · high confidence
New Lambda management endpoints for concurrency, event invoke config, layers, tags, and code signing
Added new REST controllers and supporting classes to expose AWS Lambda management operations. This includes LambdaConcurrencyController for managing reserved and unreserved concurrency limits, LambdaEventInvokeController for configuring asynchronous event invocation settings, and LambdaLayerController with its service and store to support publishing, listing, and deleting layer versions. Additionally, LambdaTagController implements tag management, and LambdaCodeSigningController provides the code-signing configuration endpoint. A new LambdaArnUtils class centralizes parsing of function names and ARNs, and the DynamoDbStreamsEventSourcePoller was updated to reset volatile checkpoints on restart.
src/main/java/io/github/hectorvent/floci/services/lambda · high confidence
New floci-duck sidecar client and UI manager components
Added new Java classes to manage the floci-duck sidecar and the Floci UI container. FlociDuckClient and FlociDuckManager handle HTTP communication and lifecycle management for the DuckDB-based sidecar, including health checks and SQL execution. FlociUiManager and UiPages manage the Floci UI container's lifecycle, logging, and serve embedded HTML pages for the web console and interstitial states.
src/main/java/io/github/hectorvent/floci/services/floci · high confidence
Per-account storage isolation and improved storage reliability
Storage backends are now wrapped in an AccountAwareStorageBackend that automatically prefixes keys with the current account ID, providing per-account resource isolation. The storage factory reuses backends by file path to prevent duplicate in-memory stores that could clobber persisted state. Additionally, PersistentStorage now quarantines unreadable files instead of silently dropping data, and the scan() method returns a mutable list to allow callers to sort or filter without affecting the underlying store.
src/main/java/io/github/hectorvent/floci/core/storage · high confidence
RDS: Persistence, subnet groups, and new API support
RDS state is now persisted across storage-backed restarts, ensuring that DB instances, clusters, and parameter groups survive emulator restarts. The service now supports DBSubnetGroup, DBClusterParameterGroup, and tag management (Add/List/RemoveTags) operations. Additionally, the DescribeOrderableDBInstanceOptions API is implemented, and the handler routes actions with a region parameter to support multi-region emulation.
src/main/java/io/github/hectorvent/floci/services/rds · high confidence
Refactor ElastiCache container management to use a shared Docker lifecycle abstraction
The ElastiCache container managers for both Memcached and Valkey have been refactored to use a new shared Docker lifecycle abstraction (ContainerBuilder, ContainerLifecycleManager, ContainerDetector) instead of direct Docker client calls. This change simplifies container creation, port binding, and log streaming, and ensures consistent behavior across different runtime environments (native vs. Docker).
src/main/java/io/github/hectorvent/floci/services/elasticache/container · high confidence
Refactored Docker container management into a shared common module
The Docker container management logic has been refactored into a new common module under \src/main/java/io/github/hectorvent/floci/core/common/docker\. This introduces a new \ContainerBuilder\ for constructing container specifications, a \ContainerDetector\ to detect if the application is running inside a container, and a \ContainerLifecycleManager\ to handle container creation, starting, and removal. Additionally, a \ContainerLogStreamer\ is introduced to forward container logs to CloudWatch Logs, and a \ContainerStorageHelper\ is added to manage named volumes and host paths for child containers. The \DockerHostResolver\ has been moved to this new package and updated to use the new \ContainerDetector\ and \CurrentContainerNetworkResolver\ to determine the correct host address for container-to-host communication.
src/main/java/io/github/hectorvent/floci/core/common/docker · high confidence
Repository tooling and configuration overhaul
The repository has been updated with a Maven wrapper (mvnw) and a Makefile to standardize the build and documentation generation workflows. Git and Docker build configurations have been significantly restructured: .gitignore and .dockerignore have been expanded to exclude more files and include specific build artifacts, while .gitattributes enforces consistent line endings. The project has also adopted AGENTS.md for AI coding agent guidance, and the release automation has been updated to exclude Dockerfile.native from version control.
(repo-wide) · high confidence
SSM Run Command and EC2 container execution support
Added support for AWS Systems Manager (SSM) Run Command, allowing users to execute commands on EC2 instances via the \SendCommand\ API. This includes a new \SsmCommandService\ and \Ec2MessagesJsonHandler\ to manage command lifecycle, status, and agent communication. For EC2 instances with Docker containers, commands are executed directly in the container environment; otherwise, messages are queued for the SSM agent. Additionally, read-only support for Patch Manager was added, including \DescribePatchBaselines\ and \GetDefaultPatchBaseline\ to list and retrieve AWS-defined patch baselines.
src/main/java/io/github/hectorvent/floci/services/ssm · high confidence
Secrets Manager: New capabilities for password generation, batch retrieval, and versioning
Users can now generate random passwords via the GetRandomPassword API, retrieve multiple secrets in a single call with the BatchGetSecretValue API, and manage version stages during secret updates. The update operations now return the VersionId, and DescribeSecret includes KmsKeyId and rotation configuration details.
src/main/java/io/github/hectorvent/floci/services/secretsmanager · medium confidence
Step Functions: JSONata expression evaluation, sync execution, and state machine versioning
Users can now use JSONata expressions in Step Functions state machine definitions, enabling more powerful data transformation and query capabilities within workflows. The emulator also supports synchronous execution of EXPRESS state machines, allowing immediate retrieval of execution results. Additionally, state machine versioning is introduced, allowing users to publish, list, and delete versions of their state machines. The changes also include support for activity-based workflows and improved error handling in execution history.
src/main/java/io/github/hectorvent/floci/services/stepfunctions · high confidence
Behavioural changes
Add support for CloudWatch GetMetricData and resource tagging operations
The CloudWatch metrics handlers now support the GetMetricData API, allowing users to retrieve aggregated metric data over time ranges with full query and expression support. Additionally, the service now supports TagResource, UntagResource, and ListTagsForResource operations, enabling users to manage tags on CloudWatch alarms. The SetAlarmState operation now returns a proper ResourceNotFound error when an alarm does not exist, improving error handling consistency.
src/main/java/io/github/hectorvent/floci/services/cloudwatch/metrics · high confidence
Added website analytics via Umami
The site now includes a script to track page views using the Umami analytics service, which will record visitor data for the main page template.
overrides · high confidence
AppConfig service adds route filter to prevent path collision with S3 bucket named 'configuration'
The AppConfig service now includes a pre-matching route filter that distinguishes between AppConfigData's GetLatestConfiguration requests and S3 path-style requests to a bucket named 'configuration'. Requests carrying a 'configuration\_token' query parameter are rewritten to an internal path, ensuring that legitimate AppConfigData calls are not shadowed by an S3 bucket with the same name. This resolves a routing conflict where the bare '/configuration' path was incorrectly handled by the S3 route.
src/main/java/io/github/hectorvent/floci/services/appconfig · high confidence
Expanded API Gateway model support for REST APIs and method settings
The API Gateway service now supports a broader set of REST API configuration options. New model classes (Account, EndpointConfiguration, MethodSetting, Model, ThrottleSettings) and enum (EndpointType) have been added to represent API Gateway resources. Existing models have been extended: ApiKey now tracks tags, Authorizer supports Cognito User Pools via providerARNs, and Integration includes passthrough behavior and request parameters. MethodConfig gains request validation and model mapping, while Stage now persists method settings. All affected models are registered for native-image reflection to ensure runtime compatibility.
src/main/java/io/github/hectorvent/floci/services/apigateway/model · high confidence
Expanded API Gateway v2 management API support
The API Gateway v2 handler and service layer now support a broader set of management operations, including Update and Delete actions for APIs, routes, integrations, authorizers, stages, deployments, route responses, integration responses, and models, as well as Create/Get/Update/Delete for models and Tagging operations. The service layer also introduces storage backends for route responses, integration responses, models, and VPC links, and implements cascade deletion of child resources when an API is deleted. Additionally, the handler now uses a shared error response utility and lower-camel-case conversion for request maps.
src/main/java/io/github/hectorvent/floci/services/apigatewayv2 · high confidence
Expanded runtime support and improved image pull reliability
The emulator now supports additional runtimes including Java 25, Ruby 3.4, .NET 10/9/8/6, Go 1.x, and updated Node.js/Python versions. Image pulls are more resilient, retrying transient registry failures with exponential backoff and supporting private registry authentication. Additionally, the launcher now handles hot-reload containers, manages Lambda layer versions, and ensures proper container lifecycle management including fault detection and log stream handling.
src/main/java/io/github/hectorvent/floci/services/lambda/launcher · high confidence
Kinesis model updates for enhanced monitoring and native-image support
The Kinesis data models have been updated to support enhanced monitoring features and improve native-image compatibility. The KinesisStream model now includes fields for account ID and enhanced monitoring metrics, while the KinesisShard model's inner records are annotated for reflection in native-image builds.
src/main/java/io/github/hectorvent/floci/services/kinesis/model · high confidence
Refactor CloudFormation provisioning into a per-service registry
The CloudFormation resource provisioning logic has been refactored from a single monolithic class into a modular, per-service architecture. A new {@code CfnResourceProvisioner} interface and a {@code CloudFormationResourceRegistry} now manage resource type mappings via CDI, replacing the previous switch-based dispatch. This change extracts specific provisioners for EC2 (VPC, VPC Gateway Attachment, Launch Template) and SQS (Queue, Queue Policy), each handling their respective AWS resource types. Additionally, the {@code ProvisionContext} is extracted to handle common tasks like resolving intrinsic functions and generating physical names, ensuring consistent behavior across the new modular structure.
src/main/java/io/github/hectorvent/floci/services/cloudformation/provisioners · high confidence
Refactors RDS container management with a new Docker abstraction layer
The RDS container manager has been refactored to use a new, shared Docker infrastructure (ContainerBuilder, ContainerLifecycleManager, ContainerDetector) instead of direct Docker client calls. This change simplifies container lifecycle management, improves port binding logic for both native and Docker-in-Docker modes, and removes dependencies on legacy services like ImageCacheService and DockerHostResolver.
src/main/java/io/github/hectorvent/floci/services/rds/container · medium confidence
Secret model extended with rotation and attachment metadata
The Secret model now includes fields for automatic secret rotation and target attachment details. Specifically, it adds properties for rotation configuration (rotationLambdaArn, rotationRules, lastRotatedDate, nextRotationDate) and the target attachment owner, enabling the system to track and manage secret rotation states and associated resources.
src/main/java/io/github/hectorvent/floci/services/secretsmanager/model · high confidence
Warn on backslash separators in ZIP entries
The ZipExtractor now detects ZIP entries containing backslash characters (commonly produced by PowerShell's Compress-Archive) and logs a warning. This change ensures that malformed paths are flagged during local extraction, preventing broken packages from passing local checks while still allowing the deployment process to fail on AWS Lambda where these paths are not normalized.
src/main/java/io/github/hectorvent/floci/services/lambda/zip · medium confidence
Fixes
Enable reflection for Elasticache model classes
The model classes in the Elasticache service (CacheCluster, Endpoint, ReplicationGroup, AuthMode, and the status enums) are now annotated with @RegisterForReflection. This ensures these types are available for reflection at runtime, which is required for serialization, state persistence, and native-image compatibility.
src/main/java/io/github/hectorvent/floci/services/elasticache/model · medium confidence
Fix Lambda Runtime API server lifecycle and port management
The Lambda Runtime API server now properly manages its HTTP port lifecycle by releasing the port when startup fails, preventing port exhaustion. Additionally, the server now exposes a faulted state to signal when an extension reports an init or exit error, ensuring the container is not reused or pooled, which matches AWS behavior for condemned environments.
src/main/java/io/github/hectorvent/floci/services/lambda/runtime · high confidence
Fixes to RDS proxy authentication and logging
The RDS proxy now correctly handles authentication for non-master users by passing their credentials to the backend rather than rejecting them, and validates IAM tokens against the expected username. Additionally, the proxy now supports PostgreSQL SSL negotiation and logs port numbers without locale-specific grouping separators.
src/main/java/io/github/hectorvent/floci/services/rds/proxy · high confidence
Improved ElastiCache proxy reliability and authentication security
The ElastiCache proxy now uses platform daemon threads for client-to-backend relaying to prevent virtual-thread starvation and ensure timely delivery of backend responses like PING/PONG. Additionally, the IAM authentication flow now validates the username against the token's User parameter and uses a timing-safe comparison for signature verification to prevent timing attacks.
src/main/java/io/github/hectorvent/floci/services/elasticache/proxy · medium confidence
PortAllocator now supports port pooling and reuse
The PortAllocator has been refactored from a simple sequential counter to a reusable pool. It now tracks which ports are currently in use and allows callers to release ports back to the pool via a new \release\ method. This prevents port exhaustion errors when services are restarted or recycled, as previously used ports can be reclaimed and reused within the configured range.
src/main/java/io/github/hectorvent/floci/core/common/port · medium confidence
RDS model classes enhanced with missing metadata and reflection support
The RDS model classes (DbCluster, DbInstance, DbEndpoint, DatabaseEngine, DbInstanceStatus) now include previously missing fields for network placement, resource identifiers, and tags, enabling correct handling of AWS RDS attributes such as VPC ID, availability zone, multi-AZ status, subnet groups, and ARNs. Additionally, all model classes are annotated with @RegisterForReflection to ensure proper serialization and native-image compatibility.
src/main/java/io/github/hectorvent/floci/services/rds/model · high confidence
S3 service receives multiple bug fixes and new capabilities
The S3 service received numerous bug fixes and new capabilities. Key changes include: implementing S3 Control endpoints (ListTagsForResource, TagResource, UntagResource, ListAccessPoints) for Terraform compatibility; adding CORS header handling via a new filter; stripping charset from XML Content-Type headers; parsing and enforcing ACL policies; evaluating public access settings; parsing and validating pre-signed URL authorization; and emitting CloudTrail events for S3 operations. Additionally, the S3 Select feature was significantly expanded with a new AST-based evaluator supporting complex WHERE clauses, and various other fixes address header handling, error responses, and routing.
src/main/java/io/github/hectorvent/floci/services/s3 · high confidence
Test coverage
Add Java SDK v2 compatibility test suite for Floci; Add Python SDK compatibility tests for AWS services; Add Terraform-based compatibility tests; Added ElastiCache integration and unit tests; Added Go SDK compatibility tests for ACM, CloudWatch, Cognito, DynamoDB, ECR, Glue, IAM, IoT, Kinesis, KMS, Lambda, Neptune, Pipes, and RDS Data; Added Node.js SDK compatibility tests for ACM, API Gateway, CloudFormation, CloudWatch, Cognito, and more; Added Python SDK compatibility tests for AWS services; Added Terraform compatibility tests for EC2, CloudWatch, and Route53; Added comprehensive test coverage for the ECS service implementation; Added comprehensive tests for CloudWatch metrics and alarms; Added integration and persistence tests for CodeBuild service; Added integration and persistence tests for CodeDeploy services; Added integration and persistence tests for the Amazon Transcribe service; Added integration and persistence tests for the Elastic Beanstalk service; Added integration and persistence tests for the Resource Groups Tagging API; Added integration and unit tests for AWS AppSync services; Added integration and unit tests for AWS Glue service and schema registry; Added integration and unit tests for DynamoDB CBOR protocol, concurrency, export, filter expressions, projection, and response handling; Added integration and unit tests for EventBridge features; Added integration and unit tests for Kinesis service; Added integration and unit tests for OpenSearch domain options and versioning; Added integration and unit tests for emulator lifecycle and info endpoints; Added integration and unit tests for the Auto Scaling service; Added integration and unit tests for the CloudWatch RUM app-monitor service; Added integration tests for API Gateway features; Added integration tests for AWS Backup management-plane API; Added integration tests for AWS Cloud Map service; Added integration tests for AWS CodePipeline emulation; Added integration tests for AWS Price List Service emulation; Added integration tests for AWS WAF v2 management API; Added integration tests for Amazon EMR cluster lifecycle; Added integration tests for Amazon Kinesis Firehose service; Added integration tests for Amazon Textract service; Added integration tests for Bedrock Runtime and proxy backend; Added integration tests for IoT core services; Added integration tests for Route53 emulation; Added integration tests for SES v1/v2 configuration set and bulk email operations; Added integration tests for the AppConfig service; Added integration tests for the S3 Vectors service; Added storage layer tests for reflection, path validation, and concurrency; Added test utilities for AWS JSON content type handling; Added test utilities for IAM and SigV4 token generation; Added tests for ACM service edge cases, idempotency, import/export, integration, pagination, and certificate generation; Added tests for AMI image generation and catalog updates; Added tests for API Gateway v2 proxy integration; Added tests for AWS Batch service support and CloudFormation resource provisioning; Added tests for AWS Config service emulation; Added tests for Amazon DocumentDB service emulation; Added tests for Amazon MQ broker support; Added tests for Amazon MSK service and Redpanda orchestration; Added tests for CUR and BCM Data Exports account isolation and emission; Added tests for CloudTrail service logic and integration; Added tests for EC2 service features and reliability; Added tests for ECR service and registry manager; Added tests for EKS service and cluster management; Added tests for ELBv2 health checking, integration, and target resolution; Added tests for Floci UI manager and landing page behavior; Added tests for IAM enforcement, concurrency safety, and policy resolution; Added tests for Lambda container launcher and image resolution; Added tests for Lambda service components; Added tests for MemoryDB service and handler; Added tests for Neptune graph database support; Added tests for PortAllocator checkout/release pool behavior; Added tests for RDS Data API service and controller; Added tests for RDS container management; Added tests for SNS HTTP delivery, mobile push, and PublishBatch partial failures; Added tests for SSM command execution and parameter management; Added tests for Secrets Manager random password generation, rotation, and version stage handling; Added tests for TLS certificate hostname handling and native image runtime initialization; Added tests for ZIP extraction behavior; Added tests for account context resolution, cross-account isolation, and protocol routing; Added tests for initialization hooks execution and lifecycle management; Added tests for the Cognito verification code subsystem; Added tests for the Cost Explorer service; Added tests for the Lambda Runtime API server; Added tests for the MWAA emulation service; Added tests for the Pipes service implementation; Added tests for the embedded DNS server; Added tests for the new EventBridge Scheduler service; Added unit tests for CloudFront domain suffix configuration; Added unit tests for Docker core components; Added unit tests for ECS container manager; Added unit tests for RDS proxy authentication and protocol handling; Added unit tests for RDS query handling and service logic; Added unit tests for SigV4Validator; Expanded AWS SDK compatibility tests for ACM, CloudFormation, Cognito, DynamoDB, ECR, Glue, IAM, KMS, Lambda, Neptune, and Pipes; Expanded KMS integration and unit test coverage; Expanded test coverage for AWS Cognito service; Expanded test coverage for Athena service operations; Expanded test coverage for CloudWatch Logs handlers and services; Expanded test coverage for S3 service behaviors; Expanded test coverage for SQS service and inspection endpoints; Step Functions emulator: expanded test coverage for ASL execution, intrinsics, and integrations.
Dependencies
Updated build dependencies and added new libraries for expanded service emulation
The project's build configuration has been updated to support new and existing service emulations. The main \pom.xml\ was upgraded to Quarkus 3.36.3 (from 3.32.3) and the project version to 1.6.0. New dependencies were added to support specific features: \vertx-mail-client\ and \apache-mime4j\ for the SES SMTP relay, \cron-utils\ for EventBridge schedule parsing, \kafka-clients\ for MSK/Kafka pipe polling, and \jsonata\ for Step Functions. Additionally, \bcprov\ and \bcpkix\ (BouncyCastle) were added for ACM certificate handling, \velocity-engine-core\ for API Gateway VTL, and \graphql\ libraries for AppSync. The \docker-java\ client was upgraded to 3.7.1, and \httpclient5\ was updated to 5.5.1. In the release tooling, \semantic-release\ and related plugins were updated to their latest versions. Compatibility test projects were also updated: the Java SDK test was upgraded to AWS SDK 2.44.14, the Node.js SDK test to AWS SDK 3.500.0, and the Python SDK test to boto3 1.37.1.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 52.
Lenses
- Code Health 89
- Architecture 100
- Maturity 76
- Readiness 33
- Security 65
- Accessibility 61
Changes since last survey
- 300 commits — 139 feature/other, 161 fixes
By area
- src/main — 191 commits
- src/test — 61 commits
- (root) — 18 commits
- .github/workflows — 10 commits
- docs/services — 6 commits
- compatibility-tests/sdk-test-java — 5 commits
- (repo) — 2 commits
- docs/configuration — 2 commits
- compatibility-tests/compat-opentofu — 1 commit
- compatibility-tests/sdk-test-awscli — 1 commit
- compatibility-tests/sdk-test-node — 1 commit
- compatibility-tests/sdk-test-rust — 1 commit
- docker/Dockerfile — 1 commit
Notable commits
- fix: fix(elasticache): roll back proxy port and container on failed provisioning (#1618)
- fix: Fix(s3)/1560 fix copy object (#1670)
- fix: chore(glue): fix GlueJsonHandlerEmptyListTest compile on main (#1764)
- fix: fix(1790): better populate describe alarm responses (#1792)
- fix: fix(apigateway): fall through to less specific resources on method mi… (#1630)
- fix: fix(apigateway): import authorizers and security requirements from OpenAPI (#1798)
- fix: fix(apigateway): use last duplicate header value (#1806)
- fix: fix(apigatewayv2): cascade-delete child resources and 404 references … (#1300)
- fix: fix(athena): report the result CSV object key as OutputLocation (#1895)
- fix: fix(athena): serialize timestamps as epoch seconds in GetWorkGroup and GetTableMetadata responses (#1524)
- fix: fix(autoscaling): align active instance refresh behavior (#1598)
- fix: fix(autoscaling): fail SSM commands for stale ASG instances (#1600)
- fix: fix(autoscaling): propagate ASG tags at launch (#1734)
- fix: fix(autoscaling): reject launch templates without image ids (#1451)
- fix: fix(cloudformation): AWS::IAM::ManagedPolicy exposes PolicyArn for Fn::GetAtt (#2056)
- fix: fix(cloudformation): carry PackageType through SAM Function expansion (#1772)
- fix: fix(cloudformation): fail stack delete when a managed resource cannot be deleted (#1554)
- fix: fix(cloudformation): idempotent ECS resource deletion on stack delete (#1645)
- fix: fix(cloudformation): keep uniqueness suffix when truncating generated resource names (#1802)
- fix: fix(cloudformation): model AWS::IAM::Policy as an inline policy (Fixes #1531) (#1800)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
floci-io/floci was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit e0aab2e27d896772847517a29cd4025203ddc4f8 — the exact code this score is about.
- Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer latest.