Skip to content
Release Radar

Floci

Testing

Light and free AWS local emulator, a LocalStack alternative

2.1.014 days after 2.0.1
View on GitHub

Release history

2.1.0

CompareGitHub

2.1.0 (2026-09-15)

Bug Fixes

  • acm: reflect the requested ValidationDomain in DescribeCertificate (#3264) (922eb0b)
  • acm: reject RequestCertificate key algorithms real ACM does not support (#3044) (db6c419), closes #3027
  • acm: report SUCCESS domain validation once a certificate is issued (#3112) (9b28388)
  • acm: stop hex-shaped names becoming bogus IP address SANs (#3335) (7a7531a)
  • amazonmq: add configuration for AMQP and console host port ranges (#3315) (2d5a8f7)
  • apigateway: add missing authorizer arg to two VtlContext test calls (38056a0), closes #3560
  • apigateway: allow idempotent custom-id tags (#3430) (eb62225)
  • apigateway: answer an unmatched REST request with 403, not 404/405 (#3547) (fb82fb2)
  • apigateway: decode the ~0 JSON Pointer escape in stage method-settings patch paths (#3526) (bc44fc9)
  • apigateway: enforce ApiKeyRequired on REST API methods (#3537) (3b31c5a), closes #3507 #3507
  • apigateway: enforce AWS_IAM authorization on the execute-api data plane (#2895) (06349c8), closes #2810
  • apigateway: expose VTL authorizer and parameter maps (#3538) (2290247)
  • apigateway: fall back to a parameterised sibling on method mismatch (#3399) (f03a716)
  • apigateway: implement MOCK integration response selection based on status code (#3327) (8d011cb)
  • apigateway: import x-amazon-apigateway-any-method on OpenAPI import (#2876) (b85dd2b)
  • apigateway: include apiKeyId in the REQUEST authorizer identity context (#3143) (dced3e7)
  • apigateway: only emit the greedy path parameter for greedy resources (#3397) (547090b)
  • apigateway: prefer path parameters in VTL lookups (#3560) (166b13a)
  • apigateway: report rootResourceId and the API key defaults (#3269) (c57b8ff)
  • apigateway: return the full integration configuration on read-back (#3432) (a91d7be)
  • apigateway: take the last value of a repeated query string parameter (#3548) (e8edc3d)
  • apigatewayv2: provision integration, route and stage on quick create (#2877) (2a637d3), closes #1902
  • appconfigdata: honor requested poll interval (#3092) (8686651)
  • appconfigdata: return empty payload on repeat polls (#3295) (47d96f6)
  • appsync: verify JWT signatures and SigV4 requests for GraphQL auth (#3541) (f38a384)
  • athena: project the column names the Glue table declares (#3414) (ebe9cf2)
  • athena: read a projecting table's partition paths, not its whole location (#3415) (6d6940b)
  • athena: register every Glue database as a DuckDB schema so <db>.<table> resolves (#2993) (0ab9979)
  • autoscaling: round-trip launch configuration InstanceMonitoring and BlockDeviceMappings (#3174) (4cc850e)
  • autoscaling: round-trip the dropped Auto Scaling group fields (#3494) (cebb011)
  • autoscaling: validate monitoring booleans (#3219) (84a7ce6)
  • bound CloudTrail delivery retries (#3298) (d44a3fe)
  • build: publish arm64 baseline release image (#3461) (e0d4318)
  • cdk: parse CDK endpoint URLs safely (#3352) (c5e1a7f)
  • cloudcontrol: reject ListResources for unsupported resource types instead of returning empty (#3141) (5cf10ec), closes #2043
  • cloudcontrol: scope resources by caller account (#3244) (b6080ea)
  • cloudformation: apply AWS::SQS::Queue tags from the template (#3532) (a5045d3), closes #2985
  • cloudformation: delete AWS::IAM::User on stack deletion (#3076) (7b5c6e2), closes #2490
  • cloudformation: expand AWS::Serverless::StateMachine, and reject every unresolvable DefinitionUri on both StateMachine and HttpApi (#2885) (f2b4c08)
  • cloudformation: expose the RDS resource-id GetAtt attributes (#3527) (b618fa9)
  • cloudformation: identify unsupported SAM Cognito authorizers (#3535) (809ce40)
  • cloudformation: keep a generated physical name across stack updates (#2788) (1528c65)
  • cloudformation: keep generated names across updates for Sche

…(truncated)

2.0.0 (2026-09-01)

  • fix(stepfunctions)!: reject JSONata top-level references at definition time (#2699) (5534460)

Bug Fixes

  • acm: correct wildcard validation record names (#2575) (88bf0a2)
  • apigateway: match measured JWT claim wire format and enforce route authorizationScopes (#2011) (4980210)
  • apigateway: pass RequestContext to ApiGatewayExecuteController in trailing-slash tests (#2394) (41953d8), closes #2377
  • apigateway: project HTTP API v2 cookies (#2391) (48880aa)
  • apigateway: report RestApi as available (#2816) (62dbd9d)
  • apigateway: route CORS preflight (OPTIONS) to deployed API integ… (#1955) (0e3391c), closes #1928
  • apigateway: support AWS type Lambda integration and fix duplicate Content-Type header (#2049) (72dfa63)
  • apigateway: support underscores in v2 path parameters (#2721) (c18af5b)
  • apigatewayv2: CloudFormation AuthorizationScopes pass-through and scope-ingestion hardening (follow-up to #2011) (#2431) (d0a96d8)
  • apigatewayv2: preserve trailing slash in HTTP API event path (#2367) (6469637), closes #1863 #2136
  • apigatewayv2: propagate Lambda REQUEST authorizer context to HTTP API backends (#2715) (908d70d), closes #1011 #812 #581
  • apigatewayv2: return stage tags across protocols (#2413) (5744082)
  • apigatewayv2: route requests to API-owning account (#2377) (ba9ce84)
  • apply S3 Vectors metadata filters (#2417) (bd8d99b), closes #2160
  • appsync: honor configured base URL in API URIs (#2457) (86e1c01)
  • appsync: use ApiKey.id as the API key value (#2645) (2932500)
  • appsync: wait for schema creation in SDK test (#2456) (43e5e90)
  • athena: route database DDL to Glue (#2757) (2480daa)
  • bedrock-agentcore: allow maxResults up to 1000 (#2487) (9792198)
  • bedrock-agentcore: support memory tagging and dropped fields (#2501) (feb669d), closes #2316
  • build: resolve the JSON schema library from Maven Central (#2811) (66d910c)
  • ci: replace setup-java's broken maven cache with actions/cache (#2503) (a68bfc4)
  • cloudformation: adopt managed policy on stack update (#2717) (51edcca)
  • cloudformation: fail the stack when Lambda S3 code cannot be read (#2650) (231c097), closes #2648
  • cloudformation: keep a rolled-back stack's diagnostics until the next redeploy (#2365) (c54f8dd), closes #2207 Stack#changeSets #2419
  • cloudformation: no-op stack update for unchanged fixed-name resources (#2385) (5864ff6), closes lex00/floci#16
  • cloudformation: reconcile DynamoDB streams declared by StreamSpecification (#2411) (c4597f2)
  • cloudformation: resolve IAM assume role policy intrinsics (#2630) (6a1d86e)
  • cloudformation: tolerate missing stack resources during deletion (#2039) (12b8ddd)
  • cloudfront: include terraform-required distribution fields (#1940) (8ac23de), closes #1930
  • cloudfront: separate DEVELOPMENT and LIVE function stages (#2622) (0dfec3c)
  • cloudwatch: decompress gzipped cbor bodies. (#2379) (f952fff)
  • cloudwatch: evaluate alarms over CloudWatch's wider evaluation range (#2771) (cfe8566), closes #2700
  • cognito: AWS-accurate UsernameAttributes pools β€” UUID username, alias sign-in, and token/revocation parity (#1849) (1ca19c7)
  • cognito: enforce user pool password policies (#2070) (3aaf745), closes #2066 #2066
  • cognito: reject self-managed verification status (#2532) (f8597bd)
  • docdb: give a record without an ARN the one it should have had (#2425) (7602002)
  • docdb: refuse an engine version a live account does not list (#2682) (46d2f4e), closes #2681
  • docdb: scope cluster and instance identifiers per region (#2440) ([3887a6c](https://github.co

…(truncated)

πŸŽ‰ Highlights

This release is one of the largest in Floci's history: nine new services including Bedrock AgentCore, Lambda MicroVMs, CloudHSM v2, GuardDuty, SWF, S3 Tables, Managed Service for Apache Flink, Application Auto Scaling, and transit gateways. AppSync Phase 6 closes the six-release build-out. CloudFront serves real content from S3 and custom origins. EKS gains IRSA with real OIDC. Massive CloudFormation resource push (11 new resource types plus new intrinsics). IAM seeds the full AWS managed policy catalog. Following 1.6.0's platform-additions bump, 1.7.0 is a maturity-and-breadth release.

πŸ†• Nine new services

  • Bedrock AgentCore β€” AgentCore control plane and InvokeAgentRuntime stub, extending the Bedrock story from 1.6.0 (#2316)
  • Lambda MicroVMs β€” service module and CloudFormation types for the new Lambda MicroVMs compute model (#2079)
  • CloudHSM v2 β€” hardware security module emulation (#1776)
  • GuardDuty β€” detector and organization configuration emulation (#2346)
  • SWF β€” Simple Workflow Service emulation (#2257)
  • S3 Tables β€” metadata service emulation (#2322)
  • Managed Service for Apache Flink (Kinesis Analytics V2) β€” real-time stream processing (#1914)
  • Application Auto Scaling β€” control plane for scalable resource targets (#2159)
  • EC2 Transit Gateways β€” cross-VPC networking (#2329)

🧩 AppSync Phase 6: Query Execution + HTTP Endpoint

The AppSync journey completes across six phases with Phase 6 (#1884): Query Execution and HTTP Endpoint support. From Phase 1 in 1.5.22 through Phase 6 here, AppSync went from a management-API stub to a working GraphQL service that executes queries against real data sources. Genuine end-to-end GraphQL emulation is now available.

☁️ CloudFront: real content serving

CloudFront moves from configuration-only support to actually serving distribution requests from S3 and custom origins (#1820), with signed private content enforcement (#1831). Real CDN patterns β€” origin routing, cache behaviors, signed URLs β€” now work end to end.

☸️ EKS: IRSA with real OIDC issuer

IAM Roles for Service Accounts (IRSA) now works with a real OIDC issuer and JWT validation (#2108). This is the specific EKS pattern that most production Kubernetes workloads use for AWS credential access, and previously required real EKS. Combined with managed node groups (1.5.24), Fargate profiles (1.5.33), and host-reachable clusters (1.5.22), EKS on Floci is now genuinely production-shaped.

🧱 CloudFormation: massive resource-provisioning push

Eleven new resource types plus significant behavior improvements:

  • AWS::EC2::VPCEndpoint (#1995)
  • AWS::EC2::FlowLog, AWS::ApiGateway::Account, AWS::AutoScaling::LifecycleHook (#2003)
  • AWS::ECS::CapacityProvider and ClusterCapacityProviderAssociations (#1999)
  • AWS::Events::EventBus as a real custom bus (#1807)
  • AWS::Lambda::Permission with Version and Alias update fixes (#1997)
  • Network ACL family (#2001)

Plus:

  • AWS::Serverless::HttpApi expanded via SAM transform (#2146)
  • SAM AutoPublishAlias expanded into Version + Alias (#1961)
  • Resource-level DeletionPolicy honored (#2167)
  • Resource-level conditions honored (#2255)
  • GetTemplateSummary implemented (#2148)
  • Dynamic references in RDS credentials resolved (#1809)
  • Nested stacks and removed resources physically deleted on update (#2345)

πŸ” IAM: full managed policy catalog

IAM now seeds the full AWS managed policy catalog (#2194). Every AWS-managed policy that real workloads reference is now present, closing the last major "why doesn't this CDK/Terraform stack work" gap around managed-policy attachments. Also lands: service-linked roles (#2179), account aliases (#2103), OIDC identity providers (#2106), account summary (#1986), long-term access keys routed to owning accounts (#2319).

πŸ” Cognito: refresh token hardening

Three coordinated security fixes for Cognito refresh tokens:

  • Refresh tokens expire and are scoped to their pool in REFRESH_TOKEN_AUTH (#2135)
  • Refresh tokens HMAC-signed to prevent forgery (#2139)
  • Invalid refresh tokens rejected in InitiateAuth (#2132)

These close real security gaps where forged or reused tokens could have been accepted. Also lands: AdminLinkProviderForUser (#2166), GetUserAttributeVerificationCode (#1898), contact attribute verification on ConfirmSignUp (#1881).

πŸ”’ Multi-account isolation

Three coordinated isolation improvements:

  • DynamoDB: item storage and locks isolated between accounts (#2240)
  • S3: object byte storage isolated between accounts (#2241)
  • Core: shared pagination helper, maxResults=0 rejected (#2343)

Combined with the cross-account IAM assumed-role routing from 1.5.29 and STS session policies from 1.5.30, multi-account testing on Floci is now genuinely correct rather than approximate.

🚌 EventBridge to event-bus targets

EventBridge can now deliver events to event-bus targets (#1814). Cross-bus event routing patterns work locally.

🌊 Firehose: BufferingHints

Firehose now honors BufferingHints with both time and size based flushing (#2314). Real-world Firehose patterns that depend on batching behavior now match production semantics.

🎯 API Gateway: execute-api hostnames + WebSocket

  • execute-api hostnames routed for HTTP APIs (#2054)
  • execute-api hosts route to WebSocket $connect and @connections (#2188)
  • JWT authorizer claims verified and propagated for HTTP API v2 (#2353)

✨ New Features

New services

  • feat(bedrockagentcore): emulate the AgentCore control plane and InvokeAgentRuntime stub (#2316)
  • feat(lambdamicrovms): AWS Lambda MicroVMs service module and CloudFormation types (#2079)
  • feat(cloudhsmv2): implement CloudHSM v2 service (#1776)
  • feat(guardduty): add GuardDuty detector and organization configuration emulation (#2346)
  • feat(swf): add Simple Workflow Service emulation (#2257)
  • feat(s3tables): emulate metadata service (#2322)
  • feat(kinesisanalytics): add Managed Service for Apache Flink (Kinesis Analytics V2) (#1914)
  • feat(applicationautoscaling): add Application Auto Scaling control plane (#2159)
  • feat(ec2): support transit gateways (#2329)

AppSync / CloudFront / EKS

  • feat(appsync): Phase 6 β€” Query Execution + HTTP Endpoint (#1884)
  • feat(cloudfront): serve distribution requests from S3 and custom origins (#1820)
  • feat(cloudfront): enforce signed private content (#1831)
  • feat(eks): support IRSA with a real OIDC issuer and JWT validation (#2108)

CloudFormation

  • feat(cloudformation): provision AWS::EC2::VPCEndpoint (#1995)
  • feat(cloudformation): provision ApiGateway::Account, AutoScaling::LifecycleHook, EC2::FlowLog (#2003)
  • feat(cloudformation): provision AWS::ECS::CapacityProvider and ClusterCapacityProviderAssociations (#1999)
  • feat(cloudformation): provision AWS::Events::EventBus as a real custom bus (#1807)
  • feat(cloudformation): provision AWS::Lambda::Permission and fix Version and Alias updates (#1997)
  • feat(cloudformation): provision the network ACL family (#2001)
  • feat(cloudformation): honor resource-level DeletionPolicy (#2167)
  • feat(cloudformation): implement GetTemplateSummary (#2148)
  • feat(cloudformation): resolve dynamic references in RDS credentials (#1809)

IAM

  • feat(iam): seed the full AWS managed policy catalog (#2194)
  • feat(iam): add service-linked role create, delete, and deletion status (#2179)
  • feat(iam): support account aliases (#2103)
  • feat(iam): support OIDC identity providers (#2106)
  • feat(iam): add GetAccountSummary support (#1986)

EC2

  • feat(ec2): add ReplaceRoute (#2178)
  • feat(ec2): allow security group rules to take a prefix list as source (#2271)
  • feat(ec2): config toggle to report the AWS-faithful private IP (#2024)
  • feat(ec2): DescribeImages synthesizes an AMI for wildcard lookups (#2009)
  • feat(ec2): DescribeVpcEndpointServices returns common interface services with AZs (#2007)
  • feat(ec2): support CreateImage (create AMI from instance) (#1979)
  • feat(ec2): support managed prefix lists (#2105)

API Gateway

  • feat(apigateway): API key management β€” UpdateApiKey, DeleteApiKey, UsagePlan custom-id, generateDistinctId (#1883)
  • feat(apigateway): derive SQS QueueUrl from path-style integration URI when absent from template (#1903)
  • feat(apigateway): route execute-api hostnames for HTTP APIs (#2054)
  • feat(apigatewayv2): route execute-api hosts to WebSocket $connect and @connections (#2188)

Cognito / SES

  • feat(cognito): add AdminLinkProviderForUser (#2166)
  • feat(cognito): add GetUserAttributeVerificationCode support (#1898)
  • feat(ses): add DKIM actions with domain-inherited email DKIM (#1904)
  • feat(ses): honor ConfigurationSetName on CreateEmailIdentity (v2) (#1812)
  • feat(ses): implement custom verification email templates for v1 and v2 (#1840)
  • feat(ses): implement PutAccountVdmAttributes and return VdmAttributes from GetAccount (v2) (#2265)
  • feat(ses): implement SendCustomVerificationEmail for v1 and v2 (#2191)
  • feat(ses): implement SendEmail ListManagementOptions suppression and unsubscribe (v2) (#1875)
  • feat(ses): implement v1 receipt rule set actions (stored-but-inert) (#2128)

Step Functions

  • feat(stepfunctions): add UpdateStateMachine and update in place on stack updates (#1867)
  • feat(stepfunctions): emulate distributed Map ResultWriter (S3 export + manifest) (#1823)
  • feat(stepfunctions): run Map iterat

…(truncated)

πŸŽ‰ Highlights

This release adds three new services β€” Amazon MWAA, CloudWatch RUM, and Bedrock with real LLM proxy β€” brings the Lambda Extensions API, lands a substantial CloudFormation resource expansion, and ships the one-button release cut with ECR Public versioned publishing infrastructure. This is the first release in the 1.6.x series, and the version bump reflects the depth of platform additions: real LLMs via a proxy backend, real Airflow, and Lambda extensions collectively unlock service categories that previously required real AWS accounts.

πŸ†• Amazon MWAA backed by real Airflow

Amazon MWAA (Managed Workflows for Apache Airflow) emulation lands (#2086), backed by a real Airflow LocalExecutor. Data engineering workflows that depend on Airflow DAG scheduling can now be exercised locally without provisioning real MWAA environments. Continues the real-Docker-backed pattern (Postgres, Redis, k3s, RabbitMQ, Redpanda, Valkey).

πŸ†• CloudWatch RUM

CloudWatch RUM app-monitor service (#1797) enables local testing of real-user monitoring workflows. Front-end observability instrumentation and app monitor configurations can now be exercised without sending data to real CloudWatch.

πŸ€– Bedrock: proxy backend for real LLM responses

Bedrock gains a proxy backend for real LLM responses via an OpenAI-compatible API (#1789). This is a meaningful capability: Bedrock-backed applications can now be tested with real LLM inference by routing through any OpenAI-compatible endpoint (OpenAI, local models via Ollama/LM Studio, or other compatible providers), rather than mocked responses. Combined with the Bedrock managed policies added in this release (#2034), the Bedrock story is much more complete for AI/ML workloads.

🧩 Lambda Extensions API

The Lambda Extensions API (#1773) is now implemented. Applications using Lambda layers that ship as extensions β€” observability, secrets management, auth β€” can now be tested locally end to end. Combined with /etc/hosts support for launched containers (#2073), Lambda's environment story is meaningfully more realistic.

🧱 CloudFormation resource expansion

Six new CloudFormation resource types plus one intrinsic improvement:

  • AWS::EC2::LaunchTemplate (#1973)
  • AWS::EC2::VPCGatewayAttachment (#1972)
  • AWS::SecretsManager::SecretTargetAttachment (#1804)
  • AWS::Events::EventBus and EventBusPolicy (#1794)
  • AWS::ApiGatewayV2::Authorizer with Route.AuthorizerId wiring (#1760)
  • AWS::IAM::ManagedPolicy exposes PolicyArn for Fn::GetAtt (#2056)
  • Fn::GetAtt [Vpc, DefaultSecurityGroup] resolves (#1977)
  • Delete-of-already-removed DynamoDB tables and Lambda functions is idempotent (#1803)
  • Uniqueness suffix preserved when truncating generated resource names (#1802)
  • Subnet public IP setting preserved on updates (#2031)

Real IaC that provisions launch templates, event buses, and complex API Gateway v2 setups now deploys correctly.

πŸ” IAM: managed policies expansion

Three coordinated IAM improvements:

  • AWSCloudFormationReadOnlyAccess managed policy seeded (#2057)
  • Amazon Bedrock managed policies seeded (#2034)
  • CDK bootstrap managed policies seeded, and CDK scenario stacks attach correctly (#2064)
  • ListEntitiesForPolicy implemented (#1808)

The CDK bootstrap coverage is particularly meaningful β€” CDK-based IaC workflows depend on specific bootstrap policies existing, and this closes a repeated pain point.

πŸš€ Release infrastructure

One-button release cut from main with ECR Public versioned publishing (#2127) is now in place. Releases are more consistent, image tags on ECR Public are properly versioned, and cutting a release requires fewer manual steps.

🎯 API Gateway: floci:override-id

floci:override-id support for both v1 and v2 API Gateway (#2045). Tests that depend on stable, predictable API IDs (rather than randomly generated ones) can now specify their own. Closes a long-open feature request.

🌐 EC2 / SQS / Cognito

  • EC2 volume attach and detach support (#1787)
  • SQS: MessageGroupId retained on standard queue messages (#1891)
  • Cognito: ResendConfirmationCode implemented (#2071), unconfirmed users rejected in SRP auth (#2027)
  • KMS: ListKeyPolicies implemented (#2046)

✨ New Features

New services

  • feat(mwaa): add Amazon MWAA emulation backed by real Airflow (LocalExecutor) (#2086)
  • feat(rum): add CloudWatch RUM app-monitor service (#1797)

Bedrock / Lambda

  • feat(bedrock): add proxy backend for real LLM responses via OpenAI-compatible API (#1789)
  • feat(lambda): implement the Lambda Extensions API (#1773)
  • feat(lambda): support extra /etc/hosts entries on Lambda launch (#2073)

CloudFormation

  • feat(cloudformation): provision AWS::EC2::LaunchTemplate (#1973)
  • feat(cloudformation): provision AWS::EC2::VPCGatewayAttachment (#1972)
  • feat(cloudformation): provision AWS::SecretsManager::SecretTargetAttachment (#1804)
  • feat(cloudformation): support AWS::Events::EventBus and EventBusPolicy (#1794)

IAM

  • feat(iam): add AWSCloudFormationReadOnlyAccess managed policy (#2057)
  • feat(iam): seed Amazon Bedrock managed policies (#2034)
  • feat(iam): seed CDK bootstrap managed policies and attach on scenario stacks (#2064)
  • feat(iam): list entities attached to managed policies (#1808)

API Gateway / EC2 / KMS / Cognito / SQS / Cloud Control

  • feat(apigateway): support floci:override-id for v1 and v2 (#2045)
  • feat(ec2): volume attach and detach support (#1787)
  • feat(ec2): return an empty set for DescribeVpnGateways (#1975)
  • feat(kms): implement ListKeyPolicies (#2046)
  • feat(cognito): implement ResendConfirmationCode (#2071)
  • feat(sqs): retain MessageGroupId on standard queue messages (#1891)
  • feat(cloudcontrol): include EC2 resource tags (#1933)

Release infrastructure

  • feat(release): one-button release cut from main and ECR Public versioned publishing (#2127)

πŸ› Bug Fixes

CloudFormation

  • fix(cloudformation): AWS::IAM::ManagedPolicy exposes PolicyArn for Fn::GetAtt (#2056)
  • fix(cloudformation): keep uniqueness suffix when truncating generated resource names (#1802)
  • fix(cloudformation): preserve subnet public IP setting (#2031)
  • fix(cloudformation): provision AWS::ApiGatewayV2::Authorizer and wire Route.AuthorizerId (#1760)
  • fix(cloudformation): resolve Fn::GetAtt [Vpc, DefaultSecurityGroup] (#1977)
  • fix(cloudformation): idempotent delete of DynamoDB tables and Lambda functions (#1803)

API Gateway

  • fix(apigateway): fall through to less specific resources on method miss (#1630)
  • fix(apigateway): import authorizers and security requirements from OpenAPI (#1798)
  • fix(apigateway): use last duplicate header value (#1806)

S3

…(truncated)

πŸŽ‰ Highlights

This release adds in-process CloudTrail with S3 data event emission, brings Step Functions HTTP invoke and the States.JsonMerge intrinsic, ships SES identity policies for authorization, and lands provenance and SBOM attestations on published container images. Cognito hostname handling, CloudFormation IAM inline policies, and DynamoDB expression parsing all see meaningful conformance work. Welcome to the 7 first-time contributors.

πŸ” CloudTrail: in-process with S3 data event emission

In-process CloudTrail with S3 data event emission lands (#1460). CloudTrail moves from lifecycle-only support to actually capturing and emitting events, so audit-log workflows that depend on CloudTrail data events can now be exercised end to end locally.

🧩 Step Functions: HTTP invoke + JsonMerge

Two coordinated Step Functions capabilities:

  • HTTP invoke step (#1503) β€” external HTTP endpoints callable directly from state machines
  • States.JsonMerge intrinsic (#1662) β€” the JSONata merge operation now works in payload templates

Combined with the JSONata Assign support in 1.5.33, Step Functions expression coverage keeps expanding.

πŸ” SES: identity (sending authorization) policies

Identity sending authorization policies for both v1 and v2 SES (#1750). Cross-account sending patterns and policy-controlled email delivery that couldn't previously be exercised locally now work.

πŸ”’ CI: provenance + SBOM attestations

Published container images now include provenance and SBOM attestations (#2032). This is a meaningful supply-chain-security move: users can now cryptographically verify the images they pull match what was built from source, and enumerate the software bill of materials without external tooling. Enterprise procurement and compliance teams care about this specifically.

🧱 CloudFormation: AWS::IAM::Policy as inline

AWS::IAM::Policy is now correctly modeled as an inline policy (#1800, fixes #1531), matching real CloudFormation behavior. IAM patterns that use inline policies attached to roles or users now provision correctly.

πŸ› Error handling improvements

Two coordinated error-handling fixes:

  • 4xx client errors returned instead of 500 for malformed JSON-protocol input (#1926)
  • Firehose ResourceInUseException and ResourceNotFoundException properly returned instead of generic errors (#1738)

Meaningful for SDK client libraries that switch behavior based on error class (retry on 5xx, fail-fast on 4xx).

🌐 Core routing improvements

Unknown-service REST requests no longer fall through to S3 (#1967). Previously, requests for unrecognized services could be silently routed to S3, producing confusing errors. Now they fail correctly, which makes debugging routing issues much easier.

☸️ EKS: option to disable bundled CNI

EKS gains an option to disable k3s's bundled CNI (#1793), useful for testing setups that provide their own network plugin or want to exercise CNI-less patterns.

✨ New Features

CloudTrail / Step Functions / SES

Firehose / EKS

πŸ› Bug Fixes

DynamoDB / S3

Cognito

CloudFormation / EC2 / ELBv2 / Neptune

Core / Storage

Step Functions

πŸ§ͺ Tests

🧰 CI

πŸ‘‹ New Contributors

A warm welcome to everyone making their first contribution to Floci:

Full Changelog: https://github.com/floci-io/floci/compare/1.5.33...1.5.34

πŸŽ‰ Highlights

This release adds EKS Fargate profiles, brings Step Functions JSONata workflow variables, expands Cognito with GlobalSignOut and RevokeToken, and lands substantial S3 conformance work on ACLs, replication, encryption defaults, and error handling. IAM gets S3 list condition context, and lifecycle management improves for process-bound containers. Welcome to the 7 first-time contributors.

☸️ EKS Fargate profiles

EKS Fargate profiles support lands (#1523), extending the EKS + managed node groups story from 1.5.24. Real EKS provisioning patterns that use Fargate for serverless container execution now work locally.

🧩 Step Functions: JSONata Assign

Step Functions now supports JSONata workflow variables via the Assign field (#1824). Recent AWS additions to Step Functions expression language now work locally β€” state machines using JSONata syntax for variable manipulation can be tested end to end.

πŸ” Cognito: sign-out completion

Two coordinated Cognito additions:

  • GlobalSignOut implemented (#1701)
  • jti / origin_jti claims emitted with RevokeToken support (#1705)

Combined with the earlier AdminUserGlobalSignOut token revocation from 1.5.27, Cognito's session-invalidation story is now genuinely complete. Applications relying on token revocation for security-sensitive flows now behave correctly.

πŸͺ£ S3 conformance pass

Five coordinated S3 improvements land this cycle:

  • DeleteBucketReplication handled correctly instead of deleting the whole bucket (@MariusVolkhart, #1837)
  • GetBucketEncryption returns default SSE-S3 instead of 404 (#1838)
  • ACL headers and explicit grants honored (@kmahadevan-bidgely, #1768)
  • Fail-fast on unwritable data root instead of opaque 500s (#1868)
  • IAM S3 list condition context passed to IAM enforcement (#1748)

Between these and the S3 auth enforcement from 1.5.32, S3's security and correctness posture is meaningfully more realistic.

🧱 CloudFormation: SAM refinements

  • SAM function PackageType carried through expansion (#1772), so SAM templates that reference container images vs zips are handled correctly
  • Secrets parsed in ContainerDefinitions for ECS resource provisioning (#1874)

πŸ”„ Lifecycle: process-bound container teardown

Process-bound containers are now torn down properly on shutdown (#1869). Combined with the shutdown-flush work from 1.5.29, Floci's shutdown story continues to improve β€” no more orphan containers left behind after clean shutdowns.

🌐 EC2 / RDS conformance

  • EC2: ImportKeyPair rejects duplicate names (@ankit1324, #1848)
  • RDS: DescribeDBSubnetGroups returns DBSubnetGroupNotFoundFault for missing groups (@Leandro-ft, #1870)
  • Scheduler: MessageAttributes forwarded in universal sns:publish target (#1706)

✨ New Features

EKS / Step Functions / Cognito

CloudFormation

πŸ› Bug Fixes

S3

EC2 / RDS / ELBv2 / Scheduler

CloudFormation / EKS / Lifecycle

πŸ§ͺ Tests

πŸ‘‹ New Contributors

A warm welcome to everyone making their first contribution to Floci:

Full Changelog: https://github.com/floci-io/floci/compare/1.5.32...1.5.33

πŸŽ‰ Highlights

This release adds AWS Lightsail, brings AppSync Phase 5 completing the four-release AppSync build-out, lands EventBridge Pipes enrichment, and ships a substantial ECS conformance push with EFS ownership, secrets resolution, and awsvpc port allocation. S3 gains auth enforcement, Step Functions payload templates get more capable, and a CloudFormation architectural refactor kicks off. Welcome to the 2 first-time contributors.

πŸ†• New: AWS Lightsail

AWS Lightsail emulation lands (#1583). Simple compute workloads that use Lightsail rather than EC2 can now be tested locally, extending Floci's compute coverage beyond the enterprise-tier services.

🧩 AppSync Phase 5 (complete build-out)

The AppSync journey completes with Phase 5 (#1590): Management API coverage expansion, AWS behavior alignment, and async schema creation. Across five phases (Phase 1 β†’ 5 spanning 1.5.22 through this release), AppSync has grown from a management-API stub to a working GraphQL emulator with schema registry, $util runtime, VTL engine, and AWS-aligned behavior. This is one of the most complete phased service build-outs Floci has done.

🚒 ECS conformance push

Four coordinated ECS improvements land this cycle:

  • EFS access point POSIX ownership applied to shared local volumes (@abanna, #1686)
  • containerDefinitions[].secrets resolved from SSM and Secrets Manager (@hampsterx, #1687)
  • AWS SDK baseline env injected into launched task containers (@abanna, #1697)
  • awsvpc tasks assigned dynamic host ports to avoid collisions (#1785)

Together these unblock realistic ECS deployment patterns: EFS-backed stateful services, tasks that read secrets at startup, applications that expect AWS SDK defaults to be present, and multiple awsvpc tasks running side by side.

πŸ“¨ EventBridge Pipes: enrichment

Pipes now apply enrichment before target delivery (#1658). The full source-filter-enrichment-target flow for Pipes is now testable end to end.

πŸ”’ S3 auth enforcement

S3 now supports auth enforcement (#1689). Applications that depend on presigned URLs, IAM-authorized access, or bucket policy denial paths now behave more like real S3 rather than a permissive endpoint.

🧱 CloudFormation: per-service provisioner registry

An architectural refactor extracts a per-service provisioner registry, migrating SQS as the first service (#1825). Groundwork for cleaner CloudFormation provisioning across the growing catalog. Also lands: UpdateTerminationProtection support (#1692).

🌐 EC2: create-time tag round-trip + concurrent mutation safety

Two important EC2 correctness fixes:

  • Create-time tags and route/security-group-rule attributes round-trip properly (#1763)
  • Concurrent mutations of shared resources serialized per resource (#1786)

The concurrency fix is the kind of change that eliminates a class of subtle test flakiness.

🧩 Step Functions: template expressions

Payload template resolution now handles .$ inside arrays and $$ context in intrinsic args (@abanna, #1691). Real state machine definitions that use these expression patterns now work correctly.

✨ New Features

New service

AppSync

ECS

Pipes / S3 / Step Functions / CloudFormation

SES / KMS

πŸ› Bug Fixes

ECS

EC2

Lambda

S3 / SES / Secrets Manager

ELBv2 / Auto Scaling / RDS / Neptune / Scheduler / IAM / TLS

Core

🧰 Refactors

πŸ“š Documentation

πŸ‘‹ New Contributors

A warm welcome to everyone making their first contribution to Floci:

Full Changelog: https://github.com/floci-io/floci/compare/1.5.31...1.5.32

πŸŽ‰ Highlights

This release brings CloudWatch Logs Insights, adds RDS Data API for PostgreSQL, introduces RDS mock mode and read-only Cloud Control APIs, and lands substantial persistence and performance work. Lambda cold starts speed up with read-only code mounting, and multiple services join the durable-state family. Welcome to the 2 first-time contributors.

πŸ” CloudWatch Logs Insights

Logs Insights query support lands (#1448), enabling local execution of the query DSL for log analysis workflows. This closes one of the more requested CloudWatch Logs gaps.

🐘 RDS Data API for PostgreSQL

The RDS Data API now supports PostgreSQL (#1720), extending the MySQL-backed Data API added in 1.5.25. Serverless SQL workflows against both engines now work locally.

🎭 RDS mock mode

Mock mode for RDS lets clusters and instances be created without Docker (#1655). Useful for CI environments that don't have Docker-in-Docker, or for fast unit-style tests where the real engine isn't needed.

🌐 Cloud Control API

list_resources from local services now works via the Cloud Control API (#1602), and read-only describe/list APIs for resource collection are broadly implemented (#1581). Combined with the Steampipe support in 1.5.28, tools that use unified resource-discovery APIs against AWS can now target Floci.

πŸ’Ύ Persistence expansion

Three more services join the durable-state family:

  • Elastic Beanstalk: applications, versions, and environments persist across restart (#1729)
  • Lambda: version counters and event-invoke configs persist (#1730)
  • API Gateway: API key tags persist, plus GetApiKey route (#1677)

πŸš€ Lambda cold-start performance

Lambda cold starts get meaningfully faster: function code now mounts from a read-only volume rather than being copied per cold start (#1673). Combined with the base64 round-trip removal in 1.5.30, Lambda's warm-up story is significantly improved.

πŸ–₯️ EC2: image and metadata catalogs

Two coordinated EC2 improvements from @jvanzyl:

  • Instance metadata catalog with architecture parity (#1596)
  • Registered images and snapshots support (#1601)

Real IaC that references specific instance types or manages custom AMIs behaves much closer to actual AWS.

πŸ“¨ EventBridge to Firehose

EventBridge can now deliver events to Firehose delivery stream targets (#1739), closing an integration gap for event-streaming architectures that fan out to analytics pipelines.

🧩 Step Functions extensions

Two more Step Functions capabilities land:

  • Map ItemReader for S3-backed JSON datasets (#1588), enabling large-scale distributed map patterns
  • Qualified Lambda function ARNs resolved in lambda:invoke (#1660)

πŸ“š Docs: auto-generated Supported Actions

Documentation now generates Supported Actions tables from handler source (#1641). Drift between docs and code is structurally addressed, so the service pages stay accurate as new actions land.

✨ New Features

CloudWatch / RDS Data / Cloud Control

EC2 / EventBridge / Scheduler / CloudFormation

Step Functions / Secrets Manager

API Gateway

Core / Docs

πŸ› Bug Fixes

Persistence

RDS / Auto Scaling / EC2 / EKS

SQS / S3 / Step Functions

CloudWatch / EMR / Storage / Docker

πŸš€ Performance

🧰 Tests

πŸ“š Documentation

πŸ‘‹ New Contributors

A warm welcome to everyone making their first contribution to Floci:

Full Changelog: https://github.com/floci-io/floci/compare/1.5.30...1.5.31

πŸŽ‰ Highlights

This release adds Amazon MQ and VPC Flow Logs, brings a major Step Functions feature push (state machine versions, ECS integrations, ResultSelector, cross-account execution), lands CloudFormation StackSets with account-aware provisioning, and ships HTTPS on port 443 with Lambda cert trust. IAM gains AssumeRole trust policy enforcement and STS session policies. Service count is now officially 68. Welcome to the 4 first-time contributors.

πŸ†• New: Amazon MQ

Amazon MQ broker control plane lands (#1642), backed by RabbitMQ. Messaging workloads that depend on Amazon MQ can now be exercised locally with a real message broker rather than a mock, continuing the real-Docker-backed pattern from RDS, ElastiCache, MSK, and OpenSearch.

🌐 New: VPC Flow Logs

EC2 gains VPC Flow Logs support (#1611), enabling local testing of network observability pipelines that consume flow logs from VPCs, subnets, or ENIs.

🧩 Step Functions: major feature push

Six coordinated Step Functions improvements land this cycle:

  • State machine version APIs (PublishStateMachineVersion, List, Delete) (#1562)
  • Executions run under the execution's account (#1566)
  • ResultSelector, Pass Parameters, ArrayContains, wildcard projection, plus IsPresent fix for absent paths (#1558)
  • aws-sdk CloudFormation and EC2 integrations (already in 1.5.29)
  • ecs:runTask service integration (#1564)
  • Compilation repair after semantic conflict between #1558 and #1564 (#1694)

Together this makes Step Functions substantially more capable for real workflow orchestration, particularly for patterns that fan out to ECS tasks or coordinate CloudFormation stack operations.

🧱 CloudFormation StackSets

StackSets with account-aware provisioning (#1551) unlock multi-account CloudFormation patterns, previously blocked entirely. Combined with the IAM cross-account routing from 1.5.29, enterprise-style multi-account IaC now runs locally.

πŸ” IAM: trust policies + STS session policies

Two meaningful identity improvements:

  • AssumeRole trust policies enforced when enforcement is enabled (#1552), opt-in for now but a real capability
  • STS session policies enforced (#1636), completing the STS story

Together these give IAM a much more realistic policy-enforcement surface, useful for teams testing security posture locally.

πŸ”’ HTTPS on port 443

Floci now serves HTTPS on port 443 and Lambda containers trust Floci's certificate (#1595). SDK code that expects to reach Floci over HTTPS, or Lambda handlers that make AWS calls back into Floci over HTTPS, now work without cert workarounds.

πŸ”₯ Firehose improvements

Firehose gains:

  • ExtendedS3DestinationDescription returned from describe operations (#1710)
  • UpdateDestination support (#1710)

πŸ“Š Service count: officially 68

Documentation now reflects the accurate 68 services (#1716), with IoT Core and S3 Vectors pages added to catch up to recent additions.

✨ New Features

New services

Step Functions

CloudFormation & IAM

Networking & TLS

Other services

πŸ› Bug Fixes

IAM / STS

EC2 / ELBv2 / Auto Scaling

CloudFormation

DynamoDB / SES / Cognito / KMS

CloudWatch Logs / ElastiCache / S3 & SNS / Step Functions

Docker / ECR / Persistence

πŸš€ Performance

🧰 Tests & CI

πŸ“š Documentation

πŸ“¦ Dependencies

πŸ‘‹ New Contributors

A warm welcome to everyone making their first contribution to Floci:

Full Changelog: https://github.com/floci-io/floci/compare/1.5.29...1.5.30

πŸŽ‰ Highlights

This release adds AppSync Phase 4 with a full VTL engine, lands cross-account assumed-role routing, ships state reset and nuke endpoints, and brings substantial ECS conformance improvements alongside persistence work for Transcribe vocabularies. Welcome to first-time contributor @dnlopes.

🧩 AppSync Phase 4: VTL Engine

The AppSync VTL story completes its build-out across four releases (Phase 1 through Phase 4). This release lands a full VTL Engine (#1288), evaluating template logic end to end. Combined with the Phase 3 $util runtime library, AppSync resolver templates now execute with real semantics rather than fixture responses.

πŸ” IAM: cross-account assumed-role credentials

A meaningful identity improvement: assumed-role credentials now route to the target account (#1549). Multi-account testing patterns that rely on sts:AssumeRole to switch contexts now behave correctly, which unlocks more realistic enterprise-style IAM workflows.

πŸ”„ State reset and nuke endpoints

floci-core gains state reset and nuke endpoints (#1482). Useful for CI suites that want a known-clean starting state without restarting the container, and for development workflows where wiping state mid-session is faster than a full restart.

🚒 ECS conformance pass

A coordinated ECS improvement set:

  • Task portMappings hostPort honored when launching containers (#1610)
  • Persisted model records registered for native-image reflection (#1606)
  • Idempotent ECS resource deletion on CloudFormation stack delete (#1645)

πŸ’Ύ Persistence improvements

Two notable persistence fixes:

  • Transcribe vocabularies now persist across restart (#1608)
  • Persisted state flushed before container teardown on shutdown (#1607)

The shutdown-flush fix is particularly important: it closes a small but real window where state changes immediately before shutdown could be lost.

🌐 ELBv2: resolvable local ALB DNS names

ALB DNS names are now resolvable locally (#1492). This addresses a common Terraform / SDK pattern where the ALB DNS name returned by DescribeLoadBalancers needs to actually resolve for the next test step to connect.

✨ New Features

πŸ› Bug Fixes

ECS / ELBv2

Persistence

SES / SSM / IoT

🧰 Tests

πŸ“š Documentation

πŸ‘‹ New Contributors

A warm welcome making their first contribution to Floci:

Full Changelog: https://github.com/floci-io/floci/compare/1.5.28...1.5.29

πŸŽ‰ Highlights

This release adds two new services (AWS IoT Core and Elastic Beanstalk Query API), brings AppSync Phase 3 with the $util runtime library, lands Kafka pipe sources for EventBridge Pipes, and ships Steampipe read API support. ECS gets EFS volumes, MemoryDB gets ACL-based auth, and there's substantial conformance work across Cognito, RDS, and Lambda. Welcome to the 7 first-time contributors.

πŸ†• Two new services

  • AWS IoT Core (#1359) β€” local testing of MQTT-based IoT workflows
  • AWS Elastic Beanstalk Query API (initial support) (#1362)

🧩 AppSync Phase 3: $util runtime for VTL

AppSync continues its phased build-out. Phase 3 lands the $util runtime library for VTL resolvers (#1223). Resolver templates that depend on $util.dynamodb, $util.qr, $util.error, and similar utilities now work, which closes one of the largest remaining gaps for real-world AppSync templates.

πŸ“¨ EventBridge Pipes: Kafka sources

Pipes gain Kafka source and polling support (#1260). Streaming workloads that funnel from Kafka through Pipes to other AWS targets can now be exercised end to end locally.

πŸ”Ž Steampipe read API coverage

A meaningful new audience-targeting capability: read APIs required by Steampipe resource collection are now implemented (#1538). Steampipe users can now point at Floci to introspect resources without a real AWS account.

🚒 ECS: EFS volumes

ECS now mounts efsVolumeConfiguration task volumes as shared local volumes (#1569). Stateful container workloads that depend on shared filesystems across tasks now behave correctly.

πŸ” MemoryDB: ACL-based auth

MemoryDB models auth via ACLs and users (#1478), bringing its security model closer to real AWS rather than running as an open Redis-style endpoint.

πŸ’Ύ CodeDeploy persistence

CodeDeploy joins the persistence story: applications, deployment groups, configs, on-prem instances, and tags now persist across restart (#1579). This continues the durable-state work from 1.5.27 (ECS, CodeBuild, Config, ACM).

🧱 Cognito alignment pass

A coordinated Cognito pass from @shrimptails-f:

  • Sign-up confirmation aligned with AWS behavior (#1488)
  • CUSTOM_AUTH trigger failures aligned with AWS (#1484)
  • AdminGetUser lookup aligned with pool sign-in settings (#1571)

✨ New Features

New services

Service expansions

Read APIs

πŸ› Bug Fixes

Cognito

Lambda

RDS / EC2 / IAM

S3 / SES / Secrets Manager

CloudFormation / CloudFront / CodeBuild / CodeDeploy

DynamoDB / Step Functions / Athena / ELBv2 / EventBridge / MSK / UI

🧰 CI

πŸ‘‹ New Contributors

A warm welcome to everyone making their first contribution to Floci:

Full Changelog: https://github.com/floci-io/floci/compare/1.5.27...1.5.28

πŸŽ‰ Highlights

This release adds four new services (S3 Vectors, MemoryDB, CodePipeline, EC2 Network ACLs), brings Neptune openCypher via neo4j, lands meaningful DynamoDB conformance work, and ships state persistence across restart for ECS, CodeBuild, and Config. SAM-driven CloudFormation patterns also get a substantial boost. Welcome to the 7 first-time contributors.

πŸ†• Four new services

  • AWS S3 Vectors β€” vector search service support (#1435)
  • Amazon MemoryDB β€” with mock mode (#1420)
  • AWS CodePipeline β€” emulation lands (#1469)
  • EC2 Network ACLs β€” VPC network ACL support (#1473)

πŸ•ΈοΈ Neptune: openCypher via neo4j

Neptune now supports a neo4j backend for openCypher queries, selectable via NEPTUNE_DB_TYPE (#1449). The existing Gremlin-via-TinkerGraph backend remains in place, so graph workloads using either query language work locally.

πŸͺ¨ DynamoDB conformance pass

A coordinated DynamoDB pass:

  • TableId, TableClass, and OnDemandThroughput support, plus deletion-protection error fix (#1457)
  • Expression validation: redundant parens rejected, contains() duplicate operands rejected, begins_with non-string rejected (#1442)
  • ExclusiveStartKey validated against the key schema (#1443)
  • Limit caps scanned items, index scans carry a full cursor (#1456)

πŸ’Ύ State persistence across restart

ECS, CodeBuild, and AWS Config now persist durable resources via StorageBackedMap (#1514, #1515, #1516). Combined with the 1.5.24 storage-backed maps foundation and the 1.5.26 EC2 state persistence, Floci's restart story is significantly stronger.

🧱 CloudFormation: SAM improvements

Two notable SAM-related improvements:

  • Implicit API Gateway generated from SAM Api events (#1438)
  • SAM Globals merged into resource properties (#1427)

This brings SAM templates that rely on implicit APIs and global defaults much closer to real CloudFormation behavior.

πŸ” Cognito + Secrets Manager

  • Cognito: token revocation implemented for AdminUserGlobalSignOut (#1407)
  • Secrets Manager: automatic secret rotation lifecycle (#1467)

✨ New Features

New services

Service expansions

πŸ› Bug Fixes

DynamoDB

Persistence

CloudFormation

EC2 / DocDB / Neptune lifecycle

Cognito / Athena / RDS / API Gateway v2

Auto Scaling / SSM / UI

🧰 Refactors & Tests

πŸ‘‹ New Contributors

A warm welcome to everyone making their first contribution to Floci:

Full Changelog: https://github.com/floci-io/floci/compare/1.5.26...1.5.27

πŸŽ‰ Highlights

This release adds Amazon DocumentDB, brings a massive CloudFormation provisioning push covering nine resource types, lights up the floci-ui console on demand, and lands meaningful SSM, Auto Scaling, and Cognito improvements. Welcome to the 4 first-time contributors.

πŸ†• New service: Amazon DocumentDB

Amazon DocumentDB emulation lands (#1341), with docs included (#1386). Local testing of MongoDB-compatible workflows that depend on DocumentDB is now possible without standing up a real cluster.

🧱 CloudFormation: nine new resource types

Easily the biggest CloudFormation push to date. Templates can now provision:

  • EC2 instances (#1366)
  • EC2 VPC/subnet persistence so references survive restart (#1364)
  • RDS resources (#1367)
  • EKS clusters and node groups (#1368)
  • CloudWatch Logs log groups (#1369)
  • CloudWatch metric alarms (#1371)
  • Auto Scaling groups and launch configurations (#1372)
  • Kinesis data streams (#1370)
  • Kinesis Firehose delivery streams (#1399)

Plus the Fn::GetAZs and Fn::Cidr intrinsic functions (#1365) and stage creation from inline StageName on AWS::ApiGateway::Deployment (#1400). Real-world IaC stacks combining VPCs, EKS, RDS, Auto Scaling, and observability now deploy end to end.

πŸ–₯️ floci-ui console on demand

Floci now serves a landing page and launches the floci-ui console on demand (#1313). The console runs as a Docker sidecar tied to Floci's own lifecycle, so there's no separate process to manage. The UI groups under the new services.floci namespace alongside DuckDB (#1397).

πŸ› οΈ SSM run commands in EC2 containers

SSM SendCommand execution in EC2 containers now works (#1387). Patch baseline APIs (DescribePatchBaselines, GetDefaultPatchBaseline) are also supported (#1404).

πŸ” Auto Scaling maturity

Auto Scaling moves well beyond provisioning:

  • Group reconciliation and refresh (#1393)
  • Policy and mixed-instances parity preserved (#1437)
  • MixedInstancesPolicy launch template validation (#1439)

πŸ” Cognito alignment pass

A coordinated Cognito pass:

  • User pool client config APIs aligned with AWS (#1360)
  • Missing UserPoolClient validation added (#1394)
  • Password recovery flow aligned with AWS (#1415)

πŸ“Š Service catalog correction

The supported-services count is now 58 (#1398), with documentation pages added for EMR, WAF v2, and CloudTrail to catch up to the recent service-addition cadence.

✨ New Features

New service

CloudFormation provisioning

Console & UI

Service expansions

πŸ› Bug Fixes

CloudFormation

Auto Scaling / Cognito

KMS / SES / Secrets Manager

Lambda / SQS / RDS / RDS Data

EC2 / EventBridge Scheduler / API Gateway / ECS

CloudWatch / ElastiCache / Core / Auth

🧰 Refactors & CI

πŸ“š Documentation

πŸ‘‹ New Contributors

A warm welcome to everyone making their first contribution to Floci:

Full Changelog: https://github.com/floci-io/floci/compare/1.5.25...1.5.26

πŸŽ‰ Highlights

This release adds four new services (EMR, WAF v2, AWS Batch, RDS Data API), lands a substantial Glue partition and statistics pass, brings RDS provisioning support, and ships meaningful CloudFormation improvements with Lambda-backed custom resources and EC2 VPC/subnet provisioning. ELBv2, S3, SES, and ECS all see solid conformance work. Welcome to first-time contributor @LorenzoGalassi.

πŸ†• Four new services

  • Amazon EMR management API (Phase 1) (#1321)
  • AWS WAF v2 management API (Phase 1) (#1327)
  • AWS Batch service support (#1332)
  • RDS Data API (#1262)

That's a major catalog expansion in one release: from analytics (EMR) and edge security (WAF v2) to batch compute (Batch) and serverless SQL (RDS Data API).

πŸ—„οΈ RDS provisioning support

Beyond the existing real-Docker-backed RDS engines, provisioning lifecycle is now supported (#1253), so the full create / describe / modify / delete flow works as real AWS would handle it.

πŸͺ¨ Glue: partitions, statistics, and determinism

A coordinated Glue Data Catalog pass lands this cycle:

  • Partition APIs support (#1315)
  • Column statistics support (#1309)
  • Table statistics deletion (#1324)
  • Missing table deletes rejected (#1323)
  • Deterministic partition ordering from GetPartitions (#1335)

🧱 CloudFormation: custom resources + VPC/subnet provisioning

Two notable CloudFormation improvements:

  • Lambda-backed custom resources (AWS::CloudFormation::CustomResource) and layer versions now provision (#1146)
  • EC2 VPC and subnet resources provision via CloudFormation so cross-stack exports resolve correctly (#1342)

πŸ” STS session secret persistence

A subtle but important fix: STS session secret keys now persist (#1266), so IAM-token-based authentication against RDS and ElastiCache actually validates across requests.

🚨 SQS message size correction

MaximumMessageSize upper bound corrected from 256KB to the actual AWS maximum of 1MB (#1339). If your tests relied on Floci rejecting messages between 256KB and 1MB, those will now pass as they do in real AWS.

✨ New Features

New services

Service expansions

πŸ› Bug Fixes

Glue

S3

SQS / SES

ELBv2 / ECS / EC2

Cognito / Athena / AppConfig / MSK

CloudFormation / STS / Compat

🧰 Refactors & Tests

πŸ“š Documentation

πŸ‘‹ New Contributors

A warm welcome making their first contribution to Floci:

Full Changelog: https://github.com/floci-io/floci/compare/1.5.24...1.5.25