Repository navigation
feat(ci): migrate demo-localstack to Floci (rename to demo-floci) - #2599
Conversation
The demo-localstack CI job began timing out at the 20-minute limit across all branches on 2026-06-10. Root cause: the provider endpoints used https://localhost.localstack.cloud:4566, a public DNS record hosted by LocalStack. After LocalStack EOL'd Community Edition, their DNS zone was restructured on 2026-06-08 (localhost.localstack.cloud re-delegated to a new Route53 subzone), and GitHub's Azure runners now intermittently fail to resolve it. The AWS provider treats DNS failure as retryable and backs off past the job timeout, hanging silently before its first API call. Switch all endpoints to http://localhost:4566 (the port the GitHub Actions service container actually exposes), enable path-style S3 so bucket operations don't depend on wildcard *.localhost.localstack.cloud DNS/TLS, and skip the account-id lookup during provider configure. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
LocalStack EOL'd Community Edition (repo archived March 2026, image consolidation now requires an auth token), and its hosted infrastructure is being dismantled — the localhost.localstack.cloud DNS breakage that took out CI was collateral from that wind-down. Move the demo to Floci (floci/floci), the free, MIT-licensed drop-in replacement we already use in the terraform DAG scheduler tests: same 4566 edge port, same test credentials, covers the STS/IAM/S3 surface this demo touches. - Swap the CI service container and example docker-compose image to a pinned floci/floci:1.5.23 - Rename the emulator-facing names inside the example (mixin file, anchor, auth identity, atmos custom command group, container name) from localstack to floci - Keep the example directory name and the "[localstack]" job name: "[localstack] demo-localstack" is a required status check in branch protection on main, and external fixtures/globs reference the directory path Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Tip Atmos Pro
No affected stacks workflow was detected for this pull request. |
Dependency Review✅ No vulnerabilities or license issues found.Scanned FilesNone |
|
Important Cloud Posse Engineering Team Review RequiredThis pull request modifies files that require Cloud Posse's review. Please be patient, and a core maintainer will review your changes. To expedite this process, reach out to us on Slack in the |
📝 WalkthroughWalkthroughThis PR migrates the project from LocalStack to Floci as the AWS emulator: CI and devcontainer use Floci, demo-localstack artifacts are converted, a new demo-floci example and mixin are added, and related tests, fixtures, docs, and website metadata are updated. ChangesLocalStack to Floci Migration
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related PRs
Suggested labels
Suggested reviewers
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2599 +/- ##
==========================================
+ Coverage 79.02% 79.05% +0.03%
==========================================
Files 1211 1211
Lines 117291 117291
==========================================
+ Hits 92690 92729 +39
+ Misses 19523 19487 -36
+ Partials 5078 5075 -3
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
Finish the migration by renaming the example directory and the CI job so nothing refers to LocalStack anymore: - examples/demo-localstack -> examples/demo-floci - workflow job "localstack" / "[localstack] demo-localstack" -> "floci" / "[floci] demo-floci" (branch protection required check must be updated to the new context when this merges) - decouple the vendor-globs scenario from this demo: the shallow-glob test vendors from origin/main at test time, so it now targets examples/demo-helmfile (same root file set), keeping the test green both before and after this PR merges - update devcontainer bootstrap, examples index, and website file-browser plugin references Verified locally: go build, copy_glob unit tests, atmos validate stacks in the renamed example, and the vendor-globs CLI test run for real against remote main (38s, not skipped). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The release job's needs list still referenced the old "localstack" job id, which invalidated the workflow file, and the [validate] matrix still pointed at the old demo-localstack folder. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
💥 This pull request now has conflicts. Could you fix it Erik Osterman (Cloud Posse) (@osterman)? 🙏 |
There was a problem hiding this comment.
Caution
Some comments are outside the diff and can’t be posted inline due to platform limitations.
⚠️ Outside diff range comments (1)
.github/workflows/test.yml (1)
542-605:⚠️ Potential issue | 🟠 Major | ⚡ Quick winAdd
golangci-lintto PR CI in this workflow.This workflow runs
tflint, but there’s nogolangci-lintstep/job for pull requests, which misses the repo CI requirement.Suggested addition
+ golangci-lint: + name: "[lint] golangci-lint" + needs: build + runs-on: ubuntu-latest + steps: + - name: Check out code + uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + persist-credentials: false + - name: Set up Go + uses: actions/setup-go@v6 + with: + go-version-file: "go.mod" + - name: Run golangci-lint + uses: golangci/golangci-lint-action@v8 + with: + version: latestAs per coding guidelines,
.github/workflows/*.{yml,yaml}must run unit tests, integration tests, golangci-lint, and coverage reporting on all pull requests.🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the rest with a brief reason, keep changes minimal, and validate. In @.github/workflows/test.yml around lines 542 - 605, The workflow is missing a golangci-lint run for pull requests; add a golangci-lint step or a separate job alongside the existing "lint" job (which currently runs tflint via the step "Lint examples/${{ matrix.demo-folder }}/components/terraform" using reviewdog/action-tflint@v1) so that golangci-lint executes for the same matrix entries on PRs; implement by invoking golangci-lint (or reviewdog with golangci-lint), enabling caching of $GOCACHE and $GOMODCACHE, installing the golangci-lint binary at the start of the job, running `golangci-lint run` with the repo config and failing the job on issues, and ensure the new step/job has permissions and runs under the same matrix/needs/timeout so it covers all pull requests.Source: Coding guidelines
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Outside diff comments:
In @.github/workflows/test.yml:
- Around line 542-605: The workflow is missing a golangci-lint run for pull
requests; add a golangci-lint step or a separate job alongside the existing
"lint" job (which currently runs tflint via the step "Lint examples/${{
matrix.demo-folder }}/components/terraform" using reviewdog/action-tflint@v1) so
that golangci-lint executes for the same matrix entries on PRs; implement by
invoking golangci-lint (or reviewdog with golangci-lint), enabling caching of
$GOCACHE and $GOMODCACHE, installing the golangci-lint binary at the start of
the job, running `golangci-lint run` with the repo config and failing the job on
issues, and ensure the new step/job has permissions and runs under the same
matrix/needs/timeout so it covers all pull requests.
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: 3347fecc-ae96-4621-a928-77bf91ac5740
📒 Files selected for processing (1)
.github/workflows/test.yml
Resolve modify/delete conflicts on the renamed example: main #2598 ("use localhost endpoints in LocalStack demo to avoid DNS hangs") modified examples/demo-localstack/README.md and stacks/mixins/localstack.yaml, which this branch deleted as part of renaming demo-localstack -> demo-floci. Resolved by keeping the deletions: the same fixes (s3_use_path_style: true, skip_requesting_account_id: true, http://localhost:4566 path-style endpoints, and the expected-warning note) already exist in the renamed files examples/demo-floci/stacks/mixins/floci.yaml and examples/demo-floci/README.md, so nothing from #2598 is lost. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The demo-floci migration added a new example with no Go/CLI test coverage (it is exercised only by the CI workflow job, which requires the Floci emulator). Add a test-case that runs `atmos validate stacks` against examples/demo-floci, which works offline (it does not trigger the emulator-backed auth chain that list/ describe do), guarding the new example's stack manifests against config regressions. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Complete the demo-localstack -> demo-floci rename: the AWS cloud auth README linked to /examples/demo-localstack/atmos.yaml, a path removed by this branch. Update the section to reference /examples/demo-floci/atmos.yaml. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
There was a problem hiding this comment.
Actionable comments posted: 1
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@tests/test-cases/demo-floci.yaml`:
- Line 10: The YAML `enabled` flag is ignored because the TestCase struct lacks
an Enabled field and the runner doesn't check it; add an exported Enabled bool
`yaml:"enabled"` field to the TestCase struct (e.g., in the TestCase type used
by loadTestCases/ParseTestCase), ensure YAML unmarshalling populates it, and
update the test runner function (e.g., RunTestCase or
TestRunner.Run/ExecuteTestCase) to skip/mark tests when TestCase.Enabled is
false (treat missing field as true if desired); also update any defaults or docs
accordingly.
🪄 Autofix (Beta)
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro
Run ID: 073a0457-4e13-4743-91c4-70e370a9ecb2
📒 Files selected for processing (2)
pkg/auth/cloud/aws/README.mdtests/test-cases/demo-floci.yaml
✅ Files skipped from review due to trivial changes (1)
- pkg/auth/cloud/aws/README.md
|
Tip Atmos Pro
No affected stacks workflow was detected for this pull request. |
|
These changes were released in v1.221.1. |
what
floci/floci:1.5.23, pinned) for the AWS-emulator demoexamples/demo-localstack→examples/demo-floci, and the CI job[localstack] demo-localstack→[floci] demo-flocistacks/mixins/floci.yaml), YAML anchor (&floci_url), auth identity (floci-superuser), custom commands (atmos floci up|down|restart|reset|status), compose service/containervendor-globstest from this demo: it vendors**/demo-localstack/*from origin/main at test time, so a rename would break it in this PR (main has nodemo-flociyet) and on every unmerged branch afterward. It now targetsexamples/demo-helmfile(identical root file set), keeping it green before and after mergeSERVICES,DEBUG, docker.sock mount, 4510-4559 port range — this demo only touches STS/IAM/S3)why
LocalStack EOL'd Community Edition: the OSS repo was archived in March 2026, the unified image now requires an account + auth token, and hosted infrastructure is being dismantled — the
localhost.localstack.cloudDNS breakage fixed in #2598 was collateral from that wind-down. Staying on the unpatched 2023-eralocalstack:1.4.0image means depending on a dead project whose vendor is actively turning things off.Floci is the community's drop-in replacement (MIT, no auth token, same 4566 edge port and credential pattern) and is already used by the Terraform DAG scheduler integration tests (
tests/terraform_floci_dag_test.go).merge checklist (branch protection)
[localstack] demo-localstackis a required status check onmain. Merge order:main:[localstack] demo-localstack→[floci] demo-flocimain(which they already need for the fix(ci): use localhost endpoints in LocalStack demo to avoid DNS hangs #2598 DNS fix)verification
atmos test(validate + plan/apply/destroy × 3 stacks) passed againstfloci/floci:1.5.23under podmanvendor-globsCLI test executed for real against remotemain(not skipped) with the newdemo-helmfileglob — passedreferences
🤖 Generated with Claude Code
Summary by CodeRabbit
New Features
Documentation
CI
Tests
Chores