Skip to content

HomeCloud v0.4.0

Latest

Choose a tag to compare

@github-actions github-actions released this 07 Oct 17:13
· 34 commits to main since this release
1622bd2
  • HomeCloud as a drop-in AWS for tests (docs/integrations.md): a GitHub Action (integrations/github-action) that installs a checksum-verified release, starts the server and exports AWS_ENDPOINT_URL and credentials, and testcontainers modules for Go (integrations/testcontainers-go) and Python (integrations/testcontainers-python) that run the HomeCloud image and clean up every container it started.

  • Official container image ghcr.io/solinode/homecloud (linux/amd64 and linux/arm64, published by the release workflow as :<version> and :latest): docker run -d --name homecloud -p 127.0.0.1:8080:8080 -v /var/run/docker.sock:/var/run/docker.sock -v homecloud-data:/data ghcr.io/solinode/homecloud. Running in a container on the Docker host it manages, HomeCloud joins every VPC at a reserved address (the third-to-last of the range, never allocated) so workloads reach the API there through host.docker.internal, and reaches MinIO, the registry, DNS and function environments over Docker networks instead of loopback ports. ECS tasks now get host.docker.internal too. homecloud inside the container calls the local server, and the install script installs the CLI without Docker (with a note) instead of stopping. A new Install test workflow (manual, weekly and on release tags) checks the install script on Ubuntu, Debian and macOS and the image.

  • Terraform compatibility suite (compat/run.sh, nightly workflow, docs/compatibility.md): 17 scenarios built from popular terraform-aws-modules modules (VPC, S3, SQS/SNS, DynamoDB, Lambda, RDS, ECS + ALB, security groups, IAM, KMS, Secrets Manager, SSM, CloudWatch, EventBridge, API Gateway, Route 53, ACM) apply, re-plan clean and destroy on a fresh install with the AWS provider 6.x. Fixes found by it: CloudWatch speaks Smithy RPC v2 CBOR (the protocol of current SDKs) and has composite alarms; EC2 NAT gateways, network ACLs, security group rule tags and DescribeAddressesAttribute; Application Auto Scaling (records); CloudWatch Logs query definitions and log delivery records; DynamoDB warm throughput; S3 lifecycle rules with AbortIncompleteMultipartUpload; RDS accepts the engine's port for private databases and lower-cases maintenance windows; ACM keeps the transparency logging preference; Cognito reports birthdate like AWS; KMS reports rotation off for asymmetric keys.

  • KMS supports imported key material (create-key --origin EXTERNAL, get-parameters-for-import, import-key-material with RSAES_OAEP_SHA_1/256 and RSA_AES_KEY_WRAP_SHA_1/256, ValidTo expiry, delete-imported-key-material; only the same material can be imported again) and multi-Region primary keys (--multi-region, mrk- ids). ReplicateKey and UpdatePrimaryRegion return UnsupportedOperationException because HomeCloud runs a single region.

  • homecloud configure accepts --ca-file and --region, and keeps the region and ca_file already in the credentials file when it rewrites it (#79).

  • With --addr 0.0.0.0:8080 (or [::]) the credentials file records 127.0.0.1 (or the public URL) as the endpoint instead of 0.0.0.0; an existing file is repaired at the next start (#79).

  • New --public-url (config public_url): API Gateway endpoints, function URLs, queue URLs, Cognito issuers and website links use it, and function URLs and queue URLs now follow the API's scheme (https with built-in TLS). Unset, links are unchanged (#79).

  • New --trusted-proxies (CIDR list, default none): behind a trusted proxy, X-Forwarded-For (rightmost untrusted entry) and X-Forwarded-Proto feed aws:SourceIp, aws:SecureTransport, the audit trail and the sign-in throttle (#79).

  • With built-in TLS, functions, tasks and instances reach the API over a plain-HTTP endpoint bound only to the Docker bridge (loopback on Docker Desktop) instead of https://host.docker.internal, whose name no certificate covers (#79).

  • MinIO, its console and the DNS server are published on 127.0.0.1 by default, since Docker bypasses ufw; --s3-bind and --dns-bind expose them. Existing containers are recreated at the next start, and presigned URLs from the console are served through the API under /_s3/ (#79).

  • --dns-port 53 is supported and documented for real delegation; if the port is taken the server says so and how to free it (#79).

  • homecloud service install under sudo defaults --data-dir to the invoking user's home, not root's (#79).

  • New homecloud admin set-root-password sets the root console password to a value read from the terminal or stdin (never an argument), with the server stopped (#79).

  • CloudWatch anomaly detection: PutAnomalyDetector, DescribeAnomalyDetectors, DeleteAnomalyDetector, ANOMALY_DETECTION_BAND(m, stddevs) in GetMetricData (upper and lower series) and anomaly alarms (ThresholdMetricId with LessThanLowerOrGreaterThanUpperThreshold, LessThanLowerThreshold, GreaterThanUpperThreshold; the detector is created automatically). The band is mean +/- k standard deviations of the metric's last 14 days, by hour of week, hour of day or a rolling window depending on how much history exists, and is absent below 10 datapoints or one hour of history; it is not AWS's machine learning model. FILL(m, LINEAR) interpolates between neighbouring datapoints.

  • Secrets Manager CreateSecret with AddReplicaRegions and ReplicateSecretToRegions now fail with a clear error (HomeCloud serves a single region) instead of being accepted and ignored; the other replication calls (RemoveRegionsFromReplication, StopReplicationToReplica) are recognised.

  • Cognito user pools support USER_SRP_AUTH (Amplify, amazon-cognito-identity-js, pycognito), ForgotPassword/ConfirmForgotPassword and AdminResetUserPassword. Existing users need their password set again (or one USER_PASSWORD_AUTH sign-in) before SRP works.

  • CloudFormation updates behave like AWS: queues, topics, parameters, functions, roles, tables, alarms and other resources change in place, replacements create the new resource before deleting the old one, and a failed update rolls back to the previous template (UPDATE_ROLLBACK_COMPLETE, ContinueUpdateRollback, DisableRollback). A replacement that keeps a custom resource name now fails, as in AWS.

EC2

  • VM instances: ami-ubuntu-24-04-vm and ami-debian-12-vm boot the official cloud image as a QEMU virtual machine with its own kernel, systemd and cloud-init. The VM runs inside a container attached to the instance's VPC network with its private IP, so DNS, the metadata service, security groups and published ports work as for container instances; passt gives the guest the container's address and forwards inbound ports. Key pairs, user data (scripts and #cloud-config), the root block device size, stop/start/reboot, console output and terminate work through the same EC2 API, CLI, console and Terraform.
  • Guests use KVM when the Docker host has /dev/kvm and are emulated (slower) otherwise; instances report virtualization: "kvm" or "emulated". DescribeImages and DescribeInstances report Hypervisor: kvm for VM images and instances. Cloud images are pinned to a release, verified by checksum and downloaded once into a Docker volume; the runner image is built locally on first use.
  • VM disks: extra EBS volumes (BlockDeviceMappings, AttachVolume, DetachVolume) are virtio disks in the guest; attaching or detaching reboots the guest because Docker cannot add mounts to a running container. CreateSnapshot and CreateImage flatten a VM's root disk into a standalone copy, instances launch from such images, and homecloud backup archives a VM's root disk as a standalone image. After a restore, a VM instance whose container is gone is recreated from its disk and left stopped.
  • VM containers use Docker's default seccomp profile plus unshare, mount, umount2 and pivot_root (what passt's sandbox needs) instead of an unconfined one; AppArmor is unconfined (HC_VM_APPARMOR names a profile instead).
  • VM instances have run-command (through qemu-guest-agent, installed by cloud-init), the browser terminal (the guest's serial console; log in with a password set by user data) and CloudWatch HC/EC2 metrics measured inside the guest (CPU, memory, network, disk, process count), all under the same IAM actions as container instances.
  • CI boots a VM with KVM on every change.