Repository navigation
-
HomeCloud as a drop-in AWS for tests (docs/integrations.md): a GitHub Action (
integrations/github-action) that installs a checksum-verified release, starts the server and exportsAWS_ENDPOINT_URLand credentials, and testcontainers modules for Go (integrations/testcontainers-go) and Python (integrations/testcontainers-python) that run the HomeCloud image and clean up every container it started. -
Official container image
ghcr.io/solinode/homecloud(linux/amd64 and linux/arm64, published by the release workflow as:<version>and:latest):docker run -d --name homecloud -p 127.0.0.1:8080:8080 -v /var/run/docker.sock:/var/run/docker.sock -v homecloud-data:/data ghcr.io/solinode/homecloud. Running in a container on the Docker host it manages, HomeCloud joins every VPC at a reserved address (the third-to-last of the range, never allocated) so workloads reach the API there throughhost.docker.internal, and reaches MinIO, the registry, DNS and function environments over Docker networks instead of loopback ports. ECS tasks now gethost.docker.internaltoo.homecloudinside the container calls the local server, and the install script installs the CLI without Docker (with a note) instead of stopping. A new Install test workflow (manual, weekly and on release tags) checks the install script on Ubuntu, Debian and macOS and the image. -
Terraform compatibility suite (
compat/run.sh, nightly workflow, docs/compatibility.md): 17 scenarios built from popularterraform-aws-modulesmodules (VPC, S3, SQS/SNS, DynamoDB, Lambda, RDS, ECS + ALB, security groups, IAM, KMS, Secrets Manager, SSM, CloudWatch, EventBridge, API Gateway, Route 53, ACM) apply, re-plan clean and destroy on a fresh install with the AWS provider 6.x. Fixes found by it: CloudWatch speaks Smithy RPC v2 CBOR (the protocol of current SDKs) and has composite alarms; EC2 NAT gateways, network ACLs, security group rule tags andDescribeAddressesAttribute; Application Auto Scaling (records); CloudWatch Logs query definitions and log delivery records; DynamoDB warm throughput; S3 lifecycle rules withAbortIncompleteMultipartUpload; RDS accepts the engine's port for private databases and lower-cases maintenance windows; ACM keeps the transparency logging preference; Cognito reportsbirthdatelike AWS; KMS reports rotation off for asymmetric keys. -
KMS supports imported key material (
create-key --origin EXTERNAL,get-parameters-for-import,import-key-materialwithRSAES_OAEP_SHA_1/256andRSA_AES_KEY_WRAP_SHA_1/256,ValidToexpiry,delete-imported-key-material; only the same material can be imported again) and multi-Region primary keys (--multi-region,mrk-ids).ReplicateKeyandUpdatePrimaryRegionreturnUnsupportedOperationExceptionbecause HomeCloud runs a single region. -
homecloud configureaccepts--ca-fileand--region, and keeps the region andca_filealready in the credentials file when it rewrites it (#79). -
With
--addr 0.0.0.0:8080(or[::]) the credentials file records127.0.0.1(or the public URL) as the endpoint instead of0.0.0.0; an existing file is repaired at the next start (#79). -
New
--public-url(configpublic_url): API Gateway endpoints, function URLs, queue URLs, Cognito issuers and website links use it, and function URLs and queue URLs now follow the API's scheme (https with built-in TLS). Unset, links are unchanged (#79). -
New
--trusted-proxies(CIDR list, default none): behind a trusted proxy,X-Forwarded-For(rightmost untrusted entry) andX-Forwarded-Protofeedaws:SourceIp,aws:SecureTransport, the audit trail and the sign-in throttle (#79). -
With built-in TLS, functions, tasks and instances reach the API over a plain-HTTP endpoint bound only to the Docker bridge (loopback on Docker Desktop) instead of
https://host.docker.internal, whose name no certificate covers (#79). -
MinIO, its console and the DNS server are published on
127.0.0.1by default, since Docker bypasses ufw;--s3-bindand--dns-bindexpose them. Existing containers are recreated at the next start, and presigned URLs from the console are served through the API under/_s3/(#79). -
--dns-port 53is supported and documented for real delegation; if the port is taken the server says so and how to free it (#79). -
homecloud service installundersudodefaults--data-dirto the invoking user's home, not root's (#79). -
New
homecloud admin set-root-passwordsets the root console password to a value read from the terminal or stdin (never an argument), with the server stopped (#79). -
CloudWatch anomaly detection:
PutAnomalyDetector,DescribeAnomalyDetectors,DeleteAnomalyDetector,ANOMALY_DETECTION_BAND(m, stddevs)inGetMetricData(upper and lower series) and anomaly alarms (ThresholdMetricIdwithLessThanLowerOrGreaterThanUpperThreshold,LessThanLowerThreshold,GreaterThanUpperThreshold; the detector is created automatically). The band is mean +/- k standard deviations of the metric's last 14 days, by hour of week, hour of day or a rolling window depending on how much history exists, and is absent below 10 datapoints or one hour of history; it is not AWS's machine learning model.FILL(m, LINEAR)interpolates between neighbouring datapoints. -
Secrets Manager
CreateSecretwithAddReplicaRegionsandReplicateSecretToRegionsnow fail with a clear error (HomeCloud serves a single region) instead of being accepted and ignored; the other replication calls (RemoveRegionsFromReplication,StopReplicationToReplica) are recognised. -
Cognito user pools support
USER_SRP_AUTH(Amplify, amazon-cognito-identity-js, pycognito),ForgotPassword/ConfirmForgotPasswordandAdminResetUserPassword. Existing users need their password set again (or oneUSER_PASSWORD_AUTHsign-in) before SRP works. -
CloudFormation updates behave like AWS: queues, topics, parameters, functions, roles, tables, alarms and other resources change in place, replacements create the new resource before deleting the old one, and a failed update rolls back to the previous template (
UPDATE_ROLLBACK_COMPLETE,ContinueUpdateRollback,DisableRollback). A replacement that keeps a custom resource name now fails, as in AWS.
EC2
- VM instances:
ami-ubuntu-24-04-vmandami-debian-12-vmboot the official cloud image as a QEMU virtual machine with its own kernel, systemd and cloud-init. The VM runs inside a container attached to the instance's VPC network with its private IP, so DNS, the metadata service, security groups and published ports work as for container instances; passt gives the guest the container's address and forwards inbound ports. Key pairs, user data (scripts and#cloud-config), the root block device size, stop/start/reboot, console output and terminate work through the same EC2 API, CLI, console and Terraform. - Guests use KVM when the Docker host has
/dev/kvmand are emulated (slower) otherwise; instances reportvirtualization: "kvm"or"emulated".DescribeImagesandDescribeInstancesreportHypervisor: kvmfor VM images and instances. Cloud images are pinned to a release, verified by checksum and downloaded once into a Docker volume; the runner image is built locally on first use. - VM disks: extra EBS volumes (
BlockDeviceMappings,AttachVolume,DetachVolume) are virtio disks in the guest; attaching or detaching reboots the guest because Docker cannot add mounts to a running container.CreateSnapshotandCreateImageflatten a VM's root disk into a standalone copy, instances launch from such images, andhomecloud backuparchives a VM's root disk as a standalone image. After a restore, a VM instance whose container is gone is recreated from its disk and left stopped. - VM containers use Docker's default seccomp profile plus
unshare,mount,umount2andpivot_root(what passt's sandbox needs) instead of an unconfined one; AppArmor is unconfined (HC_VM_APPARMORnames a profile instead). - VM instances have run-command (through qemu-guest-agent, installed by cloud-init), the browser terminal (the guest's serial console; log in with a password set by user data) and CloudWatch
HC/EC2metrics measured inside the guest (CPU, memory, network, disk, process count), all under the same IAM actions as container instances. - CI boots a VM with KVM on every change.