Skip to content

feat(ci): migrate demo-localstack to Floci (rename to demo-floci) - #2599

Merged
Andriy Knysh (aknysh) merged 10 commits into
mainfrom
osterman/demo-floci
Jun 11, 2026
Merged

Andriy Knysh (aknysh) merged 10 commits into
mainfrom
osterman/demo-floci

Conversation

@osterman

@osterman Erik Osterman (Cloud Posse) (osterman) commented Jun 10, 2026 •

Copy link
Copy Markdown
Member

what

  • Replace the LocalStack image with Floci (floci/floci:1.5.23, pinned) for the AWS-emulator demo
  • Rename the example examples/demo-localstack → examples/demo-floci, and the CI job [localstack] demo-localstack → [floci] demo-floci
  • Rename all emulator-facing names inside the example: mixin (stacks/mixins/floci.yaml), YAML anchor (&floci_url), auth identity (floci-superuser), custom commands (atmos floci up|down|restart|reset|status), compose service/container
  • Decouple the vendor-globs test from this demo: it vendors **/demo-localstack/* from origin/main at test time, so a rename would break it in this PR (main has no demo-floci yet) and on every unmerged branch afterward. It now targets examples/demo-helmfile (identical root file set), keeping it green before and after merge
  • Drop LocalStack-specific service-container config Floci doesn't need (SERVICES, DEBUG, docker.sock mount, 4510-4559 port range — this demo only touches STS/IAM/S3)
  • Update devcontainer bootstrap, examples index, and website file-browser plugin references

why

LocalStack EOL'd Community Edition: the OSS repo was archived in March 2026, the unified image now requires an account + auth token, and hosted infrastructure is being dismantled — the localhost.localstack.cloud DNS breakage fixed in #2598 was collateral from that wind-down. Staying on the unpatched 2023-era localstack:1.4.0 image means depending on a dead project whose vendor is actively turning things off.

Floci is the community's drop-in replacement (MIT, no auth token, same 4566 edge port and credential pattern) and is already used by the Terraform DAG scheduler integration tests (tests/terraform_floci_dag_test.go).

merge checklist (branch protection)

[localstack] demo-localstack is a required status check on main. Merge order:

  1. Merge fix(ci): use localhost endpoints in LocalStack demo to avoid DNS hangs #2598 first (under the current rule)
  2. Update the required check on main: [localstack] demo-localstack → [floci] demo-floci
  3. Merge this PR
  4. Other branches pick everything up by merging main (which they already need for the fix(ci): use localhost endpoints in LocalStack demo to avoid DNS hangs #2598 DNS fix)

verification

  • CI: the Floci-backed demo job passed in 1m50s (vs LocalStack's ~3m; Floci's native binary boots in ~26ms vs ~15s)
  • Local: full atmos test (validate + plan/apply/destroy × 3 stacks) passed against floci/floci:1.5.23 under podman
  • vendor-globs CLI test executed for real against remote main (not skipped) with the new demo-helmfile glob — passed

references

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features

    • Added demo-floci example and Atmos CLI commands to manage the Floci emulator (start/stop/restart/reset/status).
  • Documentation

    • Updated example READMEs and compose guidance with Floci setup, port/credentials, and Terraform tips.
  • CI

    • CI workflows switched demo coverage from LocalStack to Floci.
  • Tests

    • Added offline test for demo-floci and updated demo-related test expectations.
  • Chores

    • Updated local demo startup script, demo manifests, and website tags to use Floci.

The demo-localstack CI job began timing out at the 20-minute limit across
all branches on 2026-06-10. Root cause: the provider endpoints used
https://localhost.localstack.cloud:4566, a public DNS record hosted by
LocalStack. After LocalStack EOL'd Community Edition, their DNS zone was
restructured on 2026-06-08 (localhost.localstack.cloud re-delegated to a
new Route53 subzone), and GitHub's Azure runners now intermittently fail
to resolve it. The AWS provider treats DNS failure as retryable and backs
off past the job timeout, hanging silently before its first API call.

Switch all endpoints to http://localhost:4566 (the port the GitHub Actions
service container actually exposes), enable path-style S3 so bucket
operations don't depend on wildcard *.localhost.localstack.cloud DNS/TLS,
and skip the account-id lookup during provider configure.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
LocalStack EOL'd Community Edition (repo archived March 2026, image
consolidation now requires an auth token), and its hosted infrastructure
is being dismantled — the localhost.localstack.cloud DNS breakage that
took out CI was collateral from that wind-down. Move the demo to Floci
(floci/floci), the free, MIT-licensed drop-in replacement we already use
in the terraform DAG scheduler tests: same 4566 edge port, same test
credentials, covers the STS/IAM/S3 surface this demo touches.

- Swap the CI service container and example docker-compose image to a
  pinned floci/floci:1.5.23
- Rename the emulator-facing names inside the example (mixin file,
  anchor, auth identity, atmos custom command group, container name)
  from localstack to floci
- Keep the example directory name and the "[localstack]" job name:
  "[localstack] demo-localstack" is a required status check in branch
  protection on main, and external fixtures/globs reference the
  directory path

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@osterman Erik Osterman (Cloud Posse) (osterman) added the no-release Do not create a new release (wait for additional code changes) label Jun 10, 2026
@atmos-pro

atmos-pro Bot commented Jun 10, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@github-actions github-actions Bot added the size/m Medium size PR label Jun 10, 2026
@github-actions

github-actions Bot commented Jun 10, 2026 •

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues found.

Scanned Files

None

@mergify

mergify Bot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

Important

Cloud Posse Engineering Team Review Required

This pull request modifies files that require Cloud Posse's review. Please be patient, and a core maintainer will review your changes.

To expedite this process, reach out to us on Slack in the #pr-reviews channel.

@mergify mergify Bot added the needs-cloudposse Needs Cloud Posse assistance label Jun 10, 2026
@osterman
Erik Osterman (Cloud Posse) (osterman) marked this pull request as ready for review June 10, 2026 20:50
@coderabbitai

coderabbitai Bot commented Jun 10, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

📝 Walkthrough

Walkthrough

This PR migrates the project from LocalStack to Floci as the AWS emulator: CI and devcontainer use Floci, demo-localstack artifacts are converted, a new demo-floci example and mixin are added, and related tests, fixtures, docs, and website metadata are updated.

Changes

LocalStack to Floci Migration

Layer / File(s) Summary
CI and development environment setup
.devcontainer/post-create.sh, .github/workflows/test.yml
Devcontainer post-create and GitHub Actions workflow switch from LocalStack to Floci, updating startup commands, service container image, ports, job/matrix demo-folder entries, and job dependencies.
Examples directory index
examples/README.md
Top-level examples README replaces demo-localstack with demo-floci and updates the description to reference Floci.
Demo-localstack conversion to Floci
examples/demo-localstack/README.md, examples/demo-localstack/docker-compose.yml
demo-localstack README and docker-compose are updated to describe and run Floci (endpoint, credentials, Terraform S3/path-style notes) and add CLI snippets for emulator lifecycle.
New demo-floci example setup
examples/demo-floci/README.md, examples/demo-floci/atmos.yaml, examples/demo-floci/docker-compose.yml, examples/demo-floci/stacks/mixins/floci.yaml, examples/demo-floci/stacks/deploy/*/demo.yaml
Adds demo-floci with README, Atmos auth identity and floci command group (up/down/restart/reset/status), docker-compose service for floci/floci:1.5.23, a Floci mixin pointing AWS provider endpoints to localhost:4566 (S3 path-style), and deployment manifests importing the Floci mixin.
Tests, fixtures, and website metadata
internal/exec/copy_glob_test.go, tests/fixtures/scenarios/vendor-globs/vendor.yaml, tests/test-cases/demo-globs.yaml, tests/test-cases/demo-floci.yaml, website/plugins/file-browser/index.js
Adjust test shallow-patterns and vendor globs to reference demo-helmfile, update demo-globs expectations, add an offline demo-floci test-case, and tag demo-floci with DX in the site file-browser plugin.
Package README reference update
pkg/auth/cloud/aws/README.md
Update custom endpoint resolver example link from the demo-localstack Atmos file to the demo-floci Atmos file.

Estimated code review effort

🎯 3 (Moderate) | ⏱️ ~20 minutes

Possibly related PRs

Suggested labels

minor

Suggested reviewers

  • aknysh
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title accurately summarizes the main changeset: migrating from LocalStack to Floci and renaming the demo directory accordingly.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch osterman/demo-floci

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

coderabbitai[bot]
coderabbitai Bot previously approved these changes Jun 10, 2026
@codecov

codecov Bot commented Jun 10, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 79.05%. Comparing base (6094799) to head (27fdaee).

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##             main    #2599      +/-   ##
==========================================
+ Coverage   79.02%   79.05%   +0.03%     
==========================================
  Files        1211     1211              
  Lines      117291   117291              
==========================================
+ Hits        92690    92729      +39     
+ Misses      19523    19487      -36     
+ Partials     5078     5075       -3     
Flag Coverage Δ
unittests 79.05% <ø> (+0.03%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.
see 9 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Finish the migration by renaming the example directory and the CI job so
nothing refers to LocalStack anymore:

- examples/demo-localstack -> examples/demo-floci
- workflow job "localstack" / "[localstack] demo-localstack" ->
  "floci" / "[floci] demo-floci" (branch protection required check must
  be updated to the new context when this merges)
- decouple the vendor-globs scenario from this demo: the shallow-glob
  test vendors from origin/main at test time, so it now targets
  examples/demo-helmfile (same root file set), keeping the test green
  both before and after this PR merges
- update devcontainer bootstrap, examples index, and website
  file-browser plugin references

Verified locally: go build, copy_glob unit tests, atmos validate stacks
in the renamed example, and the vendor-globs CLI test run for real
against remote main (38s, not skipped).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@osterman Erik Osterman (Cloud Posse) (osterman) changed the title feat(ci): migrate demo-localstack from LocalStack to Floci feat(ci): migrate demo-localstack to Floci (rename to demo-floci) Jun 10, 2026
coderabbitai[bot]
coderabbitai Bot previously approved these changes Jun 10, 2026
The release job's needs list still referenced the old "localstack" job id,
which invalidated the workflow file, and the [validate] matrix still
pointed at the old demo-localstack folder.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@mergify

mergify Bot commented Jun 10, 2026

Copy link
Copy Markdown
Contributor

💥 This pull request now has conflicts. Could you fix it Erik Osterman (Cloud Posse) (@osterman)? 🙏

@mergify mergify Bot added the conflict This PR has conflicts label Jun 10, 2026

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
.github/workflows/test.yml (1)

542-605: ⚠️ Potential issue | 🟠 Major | ⚡ Quick win

Add golangci-lint to PR CI in this workflow.

This workflow runs tflint, but there’s no golangci-lint step/job for pull requests, which misses the repo CI requirement.

Suggested addition
+  golangci-lint:
+    name: "[lint] golangci-lint"
+    needs: build
+    runs-on: ubuntu-latest
+    steps:
+      - name: Check out code
+        uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
+        with:
+          persist-credentials: false
+      - name: Set up Go
+        uses: actions/setup-go@v6
+        with:
+          go-version-file: "go.mod"
+      - name: Run golangci-lint
+        uses: golangci/golangci-lint-action@v8
+        with:
+          version: latest

As per coding guidelines, .github/workflows/*.{yml,yaml} must run unit tests, integration tests, golangci-lint, and coverage reporting on all pull requests.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In @.github/workflows/test.yml around lines 542 - 605, The workflow is missing a
golangci-lint run for pull requests; add a golangci-lint step or a separate job
alongside the existing "lint" job (which currently runs tflint via the step
"Lint examples/${{ matrix.demo-folder }}/components/terraform" using
reviewdog/action-tflint@v1) so that golangci-lint executes for the same matrix
entries on PRs; implement by invoking golangci-lint (or reviewdog with
golangci-lint), enabling caching of $GOCACHE and $GOMODCACHE, installing the
golangci-lint binary at the start of the job, running `golangci-lint run` with
the repo config and failing the job on issues, and ensure the new step/job has
permissions and runs under the same matrix/needs/timeout so it covers all pull
requests.

Source: Coding guidelines

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In @.github/workflows/test.yml:
- Around line 542-605: The workflow is missing a golangci-lint run for pull
requests; add a golangci-lint step or a separate job alongside the existing
"lint" job (which currently runs tflint via the step "Lint examples/${{
matrix.demo-folder }}/components/terraform" using reviewdog/action-tflint@v1) so
that golangci-lint executes for the same matrix entries on PRs; implement by
invoking golangci-lint (or reviewdog with golangci-lint), enabling caching of
$GOCACHE and $GOMODCACHE, installing the golangci-lint binary at the start of
the job, running `golangci-lint run` with the repo config and failing the job on
issues, and ensure the new step/job has permissions and runs under the same
matrix/needs/timeout so it covers all pull requests.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 3347fecc-ae96-4621-a928-77bf91ac5740

📥 Commits

Reviewing files that changed from the base of the PR and between 83828e8 and 24ed7cd.

📒 Files selected for processing (1)
  • .github/workflows/test.yml

coderabbitai[bot]
coderabbitai Bot previously approved these changes Jun 10, 2026
Andriy Knysh (aknysh) and others added 3 commits June 10, 2026 20:48
Resolve modify/delete conflicts on the renamed example:

main #2598 ("use localhost endpoints in LocalStack demo to avoid DNS hangs")
modified examples/demo-localstack/README.md and stacks/mixins/localstack.yaml,
which this branch deleted as part of renaming demo-localstack -> demo-floci.

Resolved by keeping the deletions: the same fixes (s3_use_path_style: true,
skip_requesting_account_id: true, http://localhost:4566 path-style endpoints,
and the expected-warning note) already exist in the renamed files
examples/demo-floci/stacks/mixins/floci.yaml and examples/demo-floci/README.md,
so nothing from #2598 is lost.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The demo-floci migration added a new example with no Go/CLI test coverage (it is
exercised only by the CI workflow job, which requires the Floci emulator). Add a
test-case that runs `atmos validate stacks` against examples/demo-floci, which
works offline (it does not trigger the emulator-backed auth chain that list/
describe do), guarding the new example's stack manifests against config regressions.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Complete the demo-localstack -> demo-floci rename: the AWS cloud auth README
linked to /examples/demo-localstack/atmos.yaml, a path removed by this branch.
Update the section to reference /examples/demo-floci/atmos.yaml.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@tests/test-cases/demo-floci.yaml`:
- Line 10: The YAML `enabled` flag is ignored because the TestCase struct lacks
an Enabled field and the runner doesn't check it; add an exported Enabled bool
`yaml:"enabled"` field to the TestCase struct (e.g., in the TestCase type used
by loadTestCases/ParseTestCase), ensure YAML unmarshalling populates it, and
update the test runner function (e.g., RunTestCase or
TestRunner.Run/ExecuteTestCase) to skip/mark tests when TestCase.Enabled is
false (treat missing field as true if desired); also update any defaults or docs
accordingly.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 073a0457-4e13-4743-91c4-70e370a9ecb2

📥 Commits

Reviewing files that changed from the base of the PR and between 24ed7cd and d471e1b.

📒 Files selected for processing (2)
  • pkg/auth/cloud/aws/README.md
  • tests/test-cases/demo-floci.yaml
✅ Files skipped from review due to trivial changes (1)
  • pkg/auth/cloud/aws/README.md

Comment thread tests/test-cases/demo-floci.yaml
@aknysh
Andriy Knysh (aknysh) merged commit 1100815 into main Jun 11, 2026
61 checks passed
@aknysh
Andriy Knysh (aknysh) deleted the osterman/demo-floci branch June 11, 2026 20:48
@mergify mergify Bot removed the needs-cloudposse Needs Cloud Posse assistance label Jun 11, 2026
@atmos-pro

atmos-pro Bot commented Jun 11, 2026 •

Copy link
Copy Markdown
Contributor

Tip

Atmos Pro  

No affected stacks workflow was detected for this pull request.
If this is expected, no action is needed.
Learn More. Ask AI.

@github-actions

Copy link
Copy Markdown

These changes were released in v1.221.1.

This branch was successfully deployed

1 active deployment
preview — 27fdaee6 Deployed Jun 11, 2026 by github-actions[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

no-release Do not create a new release (wait for additional code changes) size/m Medium size PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants