Releases: solinode/homecloud
Releases · solinode/homecloud
Release list
HomeCloud v0.3.0
Every service in the console now speaks the AWS protocols, security groups filter traffic inside a VPC, and there's a demo console on the website.
AWS compatibility
- The AWS CLI, SDKs and Terraform now also work with API Gateway (HTTP APIs), Route 53, ACM, EFS, ElastiCache, CloudTrail, Cognito user pools and CloudFormation (stacks, change sets,
aws cloudformation deploy, exports, 60+ resource types). examples/terraform/shop: a full app (VPC, load balancer with HTTPS, ECS, RDS, S3, DynamoDB, SNS, SQS, Lambda, API Gateway, Route 53) that deploys on a fresh install with the standard AWS provider, re-plans clean and destroys cleanly.
Security
- Security groups filter traffic between resources inside a VPC, as on AWS: rules from CIDRs or other security groups, stateful replies, the default group allowing its own members. Covers instances, ECS tasks, RDS, ElastiCache, load balancers and Lambda functions in a VPC. Resources in different groups now need a rule between them.
- API Gateway checks the Lambda function's resource policy before invoking it.
Website
- Try the console without installing anything: https://homecloud.pages.dev/demo/
Fixed
- Security group rules whose source is another group were rejected when sent by the AWS SDKs and Terraform.
- Lambda event source mappings can be tagged, and Route 53 alias records keep
EvaluateTargetHealth, so Terraform plans stay clean. - API Gateway HTTP integrations escape path parameters and reject bodies over 10 MB.
HomeCloud v0.2.0
More services speak the AWS protocols, security groups and resource policies are enforced more strictly, and the console covers more of EC2, CloudWatch and EventBridge.
AWS compatibility
- The AWS CLI, SDKs and Terraform now also work with Elastic Load Balancing v2 (load balancers, target groups, listeners, rules), EC2 Auto Scaling and launch templates, ECS, ECR and RDS (instances, snapshots and restores, subnet and parameter groups, master passwords in Secrets Manager).
- Elastic IPs: allocate, associate, disassociate and release, in the AWS API, the native API and the console.
Security
- Security group changes apply to running instances (authorize/revoke, changing an instance's groups). Docker can't change a running container's ports, so the instance is recreated from its disk with the same ID and IP, and its processes restart.
- SQS queue policies, SNS topic policies and KMS key policies are enforced together with IAM policies; an explicit Deny wins. SNS and EventBridge deliveries are checked against the target's policy with
aws:SourceArn. - Condition keys in policies:
aws:SourceIp,aws:SecureTransport,aws:PrincipalArn,aws:username, S3 keys such ass3:prefixand object tags, and more. S3 bucket policies use the same evaluator as IAM.
Console
- EC2 key pairs (create, import, download), EBS snapshots, internet gateways and route tables, Elastic IPs.
- CloudWatch Logs Insights queries, metric filters and subscription filters, alarm history.
- EventBridge custom event buses and EventBridge Scheduler.
Fixed
homecloud upgradeand the install scripts download from solinode/homecloud instead of relying on GitHub's redirect from the old repository name.
HomeCloud v0.1.1
The first release of the rebuilt HomeCloud. It includes everything listed below, plus these fixes. (0.1.0 was withdrawn: S3 could not start on new installations.)
Fixed
- S3 failed to start on new installations: MinIO no longer publishes free images on Docker Hub or quay.io. HomeCloud now uses Chainguard's MinIO build (
cgr.dev/chainguard/minio), the same server built from source for amd64 and arm64. Existing installations keep their data. - Data races in the test harness and in Secrets Manager and SNS settings replaced at runtime; a rotation with no Lambda invoker now records an error instead of crashing.
Everything in this release
HomeCloud is rebuilt from a prototype CLI into a self-hosted cloud: one homecloud binary runs an authenticated REST API, the web console and around thirty AWS-style services on Docker.
Services
- Compute: EC2 instances (types, AMI catalog, capture-to-image, user data, run-command, browser terminal, live resize), EBS-style volumes, EFS shared file systems, EC2 Auto Scaling groups with target tracking.
- Containers: ECS services and tasks with rolling deployments and Secrets Manager injection, ECR private registry.
- Networking: VPCs and subnets with real IP allocation and private DNS, security groups, application load balancers with HTTP/HTTPS listeners, routing rules and health checks, Route 53 public and private hosted zones, ACM certificates from a private CA.
- Storage and databases: S3 (MinIO) with versioning, lifecycle, presigned URLs and static websites; RDS (PostgreSQL, MySQL, MariaDB), ElastiCache (Redis, Valkey, Memcached) and MongoDB with snapshots, restores, automated backups and a query editor; DynamoDB-style tables.
- Serverless and integration: Lambda (Python, Node.js) with function URLs, API Gateway with JWT authorizers, SQS, SNS, EventBridge schedules and patterns, Step Functions.
- Security and management: IAM (users, groups, JSON policies, access keys, simulator), Cognito user pools, KMS, Secrets Manager, Parameter Store, CloudWatch metrics/logs/alarms, CloudTrail, CloudFormation-style stacks.
AWS compatibility
- The API port speaks the AWS protocols (SigV4, awsJson, awsQuery, REST), so the AWS CLI, SDKs and Terraform work against HomeCloud with IAM enforced: STS, IAM, S3, Lambda, DynamoDB, SQS, SNS, Secrets Manager, Parameter Store, KMS, CloudWatch, CloudWatch Logs, EventBridge (and Scheduler) and Step Functions. See docs/aws-compat.md.
- IAM roles with trust policies and temporary credentials; functions receive role credentials.
- ARNs use the
awspartition and the default region isus-east-1; existing installations are migrated at startup (with a backup). - Lambda runs on AWS's official runtime images: warm environments, Go/Java/Ruby/.NET/custom runtimes, container images, versions, aliases, layers, async invocation with destinations, concurrency limits.
Tooling
homecloud aws-env,service install,backup/restoreandupgrade.- New CLI covering every service (
homecloud <service> ...),homecloud serve,configure,doctor, andapifor raw calls. - Web console with pages for every service, embedded in the binary.
- Cross-compiled releases for Linux, macOS and Windows (amd64/arm64), CI with unit, race and end-to-end tests, arch-aware install scripts.
Fixed (from 0.0.1)
- The Windows release archive contained a macOS binary.
- S3 commands used credentials that did not match the MinIO container, only the bare
s3command started MinIO, and it could attach to other projects' MinIO containers. - Compute state was written to whatever directory the CLI ran in.
HomeCloud CLI 0.0.1
What's Next:
- We're just getting started! Future releases will include more features like database management, IAM, and serverless functions.
What's Changed
- Compute (using docker, switch to kvm) by @drk1rd in #2
- cla check by @drk1rd in #4
- transfer complete. by @drk1rd in #7
- refactored for modularity by @drk1rd in #9
- refactoring missed md by @drk1rd in #10
- renewed module by @drk1rd in #12
- cc changed by @drk1rd in #13
- s3 initial by @drk1rd in #15
- s3 deletion fix by @drk1rd in #16
- Update README.md by @drk1rd in #17
- 0.0.1 cli release by @drk1rd in #19
New Contributors
Full Changelog: https://github.com/homecloudhq/homecloud/commits/0.0.1