Skip to content
CAI
Software that uses CAICheck a score

k1LoW/awspec

60.0

Adequate · 20 September 2026

17.5k

lines of production code

Ruby

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

Awspec is a Ruby testing library that enables RSpec-based assertions for AWS infrastructure resources. It provides a comprehensive suite of matchers, stubs, and generators to verify the configuration and state of services such as EC2, Lambda, and VPCs without requiring live credentials. The system supports automated spec scaffolding and includes robust error handling for API throttling, allowing developers to validate cloud environments locally.

Features

Add \`awspec generate\` command for creating spec files

Users can now use the \awspec generate\ subcommand to automatically generate spec files for various AWS resources. The command supports generating specs for VPC-based resources (like EC2, RDS, ELB, ALB, NLB, and subnets) using a VPC ID, domain-specific resources like Route53 hosted zones and S3 buckets, parameter groups, clusters, and WAFv2 IP sets. It also supports generating specs for all instances of resources such as IAM users, roles, policies, CloudWatch alarms, Lambda functions, and EBS volumes. The command accepts optional \--profile\, \--region\, and \--secrets\_path\ options to configure AWS credentials and region.

lib/awspec/command · high confidence

Added development and setup CLI tools

New executable scripts have been added to the bin directory to streamline local development workflows. The setup script now automates dependency installation via bundle install, while the console script provides an interactive Ruby environment pre-loaded with awspec and pry for debugging and testing. Additionally, a new toolbox script has been introduced to launch the Awspec toolbox interface.

bin · high confidence

Awspec v1.36.0: New matchers, generators, and configuration system

This release introduces a comprehensive set of new matchers for AWS resources, including \have\_tag\, \have\_network\_interface\, \be\_allowed\_action\ for IAM, \have\_rule\ for ALB listeners, and \have\_env\_vars\ for Lambda. It also adds a new \awspec generate\ command to scaffold spec files for resources like EC2, RDS, VPC, and IAM, alongside a new centralized \Awspec::Config\ singleton for managing client backoff and iteration settings. The setup process now generates a \.rspec\ file and uses \awsecrets\ for credential loading, while the version is bumped to 1.36.0.

lib/awspec · high confidence

Comprehensive expansion of AWS resource type matchers

The \lib/awspec/type\ directory has been significantly expanded to support a wide array of new AWS resources and matchers, enabling users to verify the configuration of services such as ECS clusters and services, ALB/NLB listeners and target groups, EKS clusters and node groups, RDS DB clusters, and various networking components like VPC endpoints and transit gateways. This update introduces new type classes for resources including ACM, CloudFormation stacks, CloudFront distributions, CodeBuild, CodeDeploy, DynamoDB tables, EFS, ECR repositories, ElastiCache, ElastiSearch, EMR, Kinesis, Lambda, Route53, S3 buckets, SQS, and more. Users can now write specifications to check resource states, tags, security group associations, subnet placements, and specific configuration attributes (such as ALB listener rules, CloudFront origins, and RDS parameter groups) across these newly supported services.

lib/awspec/type · high confidence

Expanded AWS resource spec generation coverage

The \awspec generate\ command now supports a significantly wider range of AWS resources, allowing users to automatically generate RSpec test files for infrastructure components that were previously missing. This update adds generator implementations for Application Load Balancers (ALB) and their listeners, Network Load Balancers (NLB) and their listeners, Auto Scaling Groups, CloudWatch Alarms, CloudWatch Events, CloudWatch Logs, CodeBuild projects, CodePipelines, Direct Connect virtual interfaces, Elastic Block Store (EBS) volumes, EC2 instances, Elastic File System (EFS), Elastic IPs, ElastiCache clusters, Elasticsearch domains, Classic ELBs, IAM groups/policies/roles/users, Internet Gateways, KMS keys, Lambda functions, Managed Prefix Lists, NAT Gateways, Network ACLs, Network Interfaces, RDS instances, Route Tables, Subnets, and VPCs. Users can now run \awspec generate\ commands for these resources to produce comprehensive test suites that verify existence, configuration, and relationships.

lib/awspec/generator/spec · high confidence

Expanded AWSpec matchers for security, IAM, networking, and resource associations

This update significantly broadens the testing capabilities of the library by introducing numerous new RSpec matchers and enhancing existing ones. Security and access control are strengthened with new \be\_allowed\ and \be\_denied\ matchers for security group rules, \be\_allowed\_action\ for IAM policy evaluation, and \be\_opened\_only\ for stricter security group validation. IAM testing now includes \have\_inline\_policy\ for users, groups, and roles. Networking capabilities are expanded with \be\_connected\_to\_vpc\ and \have\_vpc\_peering\_connection\ for VPCs, \have\_route\ with support for VPC peering targets in route tables, and \have\_network\_interface\ with \as\_eth\ chains. Resource association matchers have been added or extended to cover backups (\belong\_to\_backup\_plan\), ElastiCache (\belong\_to\_replication\_group\, \belong\_to\_cache\_subnet\_group\), and load balancers (\belong\_to\_alb\, \belong\_to\_nlb\). Additionally, Lambda environment variables can now be tested with \have\_env\_var\ and \have\_env\_var\_value\, and CloudFront distributions support \have\_origin\ and \have\_custom\_response\_error\_code\ checks.

lib/awspec/matcher · high confidence

Expanded stub coverage for AWS resources and services

The stub library now includes mock response data for a wide range of AWS services, enabling users to write tests for resources that were previously unsupported. New stubs cover account-level quotas and settings (EC2, RDS, Lambda, SES, STS), Application Load Balancer components (ALB, listeners, target groups), and core infrastructure (ACM, AMI, Auto Scaling Groups, CloudFormation, CloudFront, CloudTrail, CloudWatch Alarms/Events/Logs, CodeBuild). Additional support has been added for AWS Batch, Backup (plans, selections, vaults), API Gateway, and various networking resources (VPC endpoints, NAT Gateways, VPNs). This allows users to validate configurations and behaviors for these services without requiring live AWS credentials or network access.

lib/awspec/stub · high confidence

New template generator for AWSpec resource types

A new \Awspec::Generator::Template\ class has been added to automate the creation of scaffolding files for new AWS resource types. When invoked, it generates the corresponding type class (inheriting from either \ResourceBase\ or \AccountAttributeBase\), a stub file for AWS client mocking, a spec file with a basic existence check, and documentation files. This tool simplifies the process of adding support for new AWS services by providing a consistent starting point for implementation.

lib/awspec/generator · high confidence

Behavioural changes

Automated release workflow and parallelized test execution

The release process is now automated via the \tagpr\ tool, which manages versioning in \lib/awspec/version.rb\ and generates changelog entries, replacing the previous manual release steps. Additionally, the Rake test suite has been restructured to support parallel execution of spec tasks (types, account, core, generator, and helper specs) using the \parallel\ gem, significantly speeding up test runs, while the CI configuration has migrated from Travis CI to GitHub Actions.

(repo-wide) · high confidence

Executable relocated and Ruby linting fixed

The main executable has been moved from the bin directory to the exe directory, and the frozen string literal comment has been added to resolve a Rubocop warning.

exe · high confidence

Expanded AWS resource coverage and improved API resilience

Awspec now supports a significantly wider range of AWS resources, including ECS clusters, EKS clusters, RDS DB clusters, WAFv2, and many others, allowing users to write assertions against these services. The library also introduces a retry mechanism for API calls that hit throttling limits (RequestLimitExceeded or Throttling errors), automatically backing off to improve stability under load. Additionally, some resource types have been renamed (e.g., \auto\_scaling\_group\ to \autoscaling\_group\, \s3\ to \s3\_bucket\) with deprecation warnings provided for the old names to ensure a smooth transition.

lib/awspec/helper · high confidence

Library initialization and dependency restructuring

The main library entry point has been restructured to explicitly load several new internal components (config, ext, error, stub, generator, toolbox, resource\_reader, shared\_context) and external dependencies (dry/inflector, ipaddress, awsecrets). This change updates the runtime requirements and module loading order, introducing new capabilities for stubbing, resource reading, and configuration while replacing the previous string extension with the broader ext module.

lib · high confidence

Refactor documentation generation into a dedicated Type module

The documentation generation logic has been extracted from the previous monolithic script into a new \Awspec::Generator::Doc::Type\ module. This change restructures how resource types and account attributes are processed, explicitly separating the generation of standard resource links from account-specific attributes and their corresponding documentation sections.

lib/awspec/generator/doc · high confidence

Refactor string inflection to use dry-inflector and add utility extensions

String inflection methods (camelize, pluralize, underscore, demodulize) now rely on the dry-inflector library instead of the previous custom implementation, changing the underlying behavior for these transformations. Additionally, new extension methods have been added to core classes: Array\#single\_resource raises an error if the array contains more than one item, Hash\#to\_struct converts hashes into Struct objects, and Struct\#tag\_name extracts the value of the 'Name' tag.

lib/awspec/ext · high confidence

Refactored resource lookup logic into a modular finder helper

The resource lookup logic has been moved from the resource types into a new, modular helper structure under \lib/awspec/helper/finder\. This change introduces dedicated finder modules for each AWS service (e.g., \Ec2\, \Alb\, \Rds\, \Iam\), centralizing how resources are fetched, paginated, and identified by ID or name. For users, this ensures consistent and reliable resource resolution across all supported AWS services, handling edge cases like duplicate names and API pagination uniformly.

lib/awspec/helper/finder · high confidence

Restructured AWS resource documentation generators

The documentation generation logic for AWSpec resources has been reorganized into a dedicated \lib/awspec/generator/doc/type\ directory. This change introduces a modular architecture with a shared \Base\ class and specific generator classes for each AWS resource type (such as EC2, ALB, RDS, and ECS), ensuring that documentation for these resources is generated consistently and is easier to maintain.

lib/awspec/generator/doc/type · high confidence

Test coverage

Added tests for AWSpec generator specs; Added tests for Awspec::Helper::ClientWrap initialization and retry logic; Added tests for configuration management, shared context, and resource type validation; Added tests for the documentation generator; Expanded test coverage for AWS resource types; Simplify spec helper configuration and update Ruby style.

Dependencies

Upgrade to AWS SDK v3 and require Ruby 3.0

The awspec gem now requires Ruby 3.0 or higher and upgrades its core dependency from AWS SDK v2 to v3. This change replaces several legacy dependencies with modern alternatives: \active\_support/inflector\ is replaced by \dry-inflector\, \IPAddr\ by the \ipaddress\ gem, and \ox\ is added as a conditional runtime dependency for Ruby 3.0+. Development dependencies have also been updated, including raising the Rake version requirement to \~\> 12.0 and adding \octorelease\, \parallel\, and \pry\.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 60.

Lenses

  • Code Health 99
  • Architecture 99
  • Maturity 54
  • Readiness 48
  • Security 77

Changes since last survey

  • 300 commits — 237 feature/other, 63 fixes

By area

  • doc/resource_types.md — 98 commits
  • lib/awspec — 83 commits
  • (repo) — 72 commits
  • (root) — 30 commits
  • doc/_resource_types — 8 commits
  • spec/type — 5 commits
  • .github/workflows — 3 commits
  • .github/release.yml — 1 commit

Notable commits

  • fix: Fix
  • fix: Fix
  • fix: Fix ALB & NLB have_subnet
  • fix: Fix ECR Repository document
  • fix: Fix IAM date tests
  • fix: Fix aws cli example
  • fix: Fix find vpc_endpoint by Name
  • fix: Fix finding Gateway VPC Endpoints by id
  • fix: Fix group
  • fix: Fix linter error
  • fix: Fix rubocop issues
  • fix: Fix rubocop warn Style/ClassEqualityComparison
  • fix: Fix rubocop warn Style/ConditionalAssignment
  • fix: Fix rubocop warn Style/FrozenStringLiteralComment
  • fix: Fix rubocop warn Style/GlobalStdStream
  • fix: Fix rubocop warn Style/HashTransformKeys
  • fix: Fix rubocop warn Style/KeywordParametersOrder
  • fix: Fix rubocop warn Style/MultilineWhenThen
  • fix: Fix rubocop warn Style/MutableConstant
  • fix: Fix rubocop warn Style/PercentLiteralDelimiters
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

k1LoW/awspec was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit ca746f2ac8619967c5c5a473ea4796393fd6ee18 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.