1# The digest below is the contract with the image factory. CI (release-floci.yml)
2# rewrites it from the image-published dispatch after every green image build, and
3# the tracker pins the REAL digest here after the Floci image CI is green. It is
4# never a tag. ---> PIN THE DIGEST HERE (image.digest, line 6). <---
6 repository: chainreg.biz/chainguard-private/floci
7 # Human-readable tag for reference only; the pod is pulled by digest, not this.
9 digest: sha256:58bf6901ed640b8e7958cfee5a89b3713d6b55f85421985a1c21a1e57cfa4443
10 pullPolicy: IfNotPresent
12# Floci's in-process emulator holds all state in RAM by default (FLOCI_STORAGE_MODE:
13# memory), so it is stateless: a Deployment, not a StatefulSet. A single replica is
14# the only correct topology for the default memory mode -- two replicas would each
15# hold their own disjoint S3/DynamoDB/SQS/SNS/IAM state behind one Service. Enable
16# persistence (below) only for single-replica durability across restarts; it is NOT
17# a path to horizontal scale.
19# The image entrypoint runs the Floci (Quarkus) server directly; no command/args
20# override is needed. Configure Floci through environment variables (env below).
23# ---------------------------------------------------------------------------
24# HARDENED SCOPE (READ THIS)
25# ---------------------------------------------------------------------------
26# Floci emulates 65 AWS services. This chart supports the 55 that run entirely
27# inside the single nonroot Java process with no external dependencies: S3,
28# DynamoDB, SQS, SNS, SES, IAM, STS, KMS, Secrets Manager, SSM, API Gateway,
29# Cognito, Kinesis, CloudFormation, Step Functions, EventBridge, CloudWatch,
30# CloudTrail, Config, Route53, CloudFront, ACM, Glue, Athena, ELBv2, Auto
31# Scaling, Batch, WAF v2, AppConfig, AppSync, Bedrock Runtime, and more.
33# The other 10 are DOCKER-BACKED (Lambda, RDS, ElastiCache, MSK, ECS, EKS,
34# OpenSearch, ECR, DocumentDB, Neptune): they spin up real containers and REQUIRE
35# the host Docker socket (/var/run/docker.sock) plus root. That is fundamentally
36# incompatible with this hardened image (nonroot uid 1001, no docker.sock,
37# read-only root filesystem) and is therefore NOT SUPPORTED here. Do not try to
38# mount the Docker socket into this pod. If you need the Docker-backed services,
39# run Floci on a Docker host outside Kubernetes.
41# LocalStack API parity is disabled (LOCALSTACK_PARITY=false): clients target
42# Floci's own endpoint on port 4566, which is LocalStack-wire-compatible for the
43# in-process services above.
44# ---------------------------------------------------------------------------
46# Floci server configuration, surfaced as environment variables. Anything not
47# listed here can be added via extraEnvVars.
49 # -------------------------------------------------------------------------
50 # MODE (hardened | full)
51 # -------------------------------------------------------------------------
52 # hardened (DEFAULT): the hardened `floci` image above -- nonroot uid 1001,
53 # no Docker socket, read-only root filesystem. Supports the 55 in-process
54 # AWS services only. This is the safe, recommended default; leave it alone.
56 # full (OPT-IN, NOT HARDENED): the separate `floci-full` image (below), run as
57 # ROOT with the host Docker socket (/var/run/docker.sock) mounted in. This
58 # enables ALL 65 services including the 10 Docker-backed ones (Lambda, RDS,
59 # ElastiCache, MSK, ECS, EKS, OpenSearch, ECR, DocumentDB, Neptune). A mounted
60 # host Docker socket is a node-root / container-escape surface: DO NOT use on
61 # shared or multi-tenant clusters. Requires floci.full.acknowledgeRisk=true or
62 # the chart refuses to render.
64 # Settings that apply only when mode=full.
66 # Explicit acknowledgement that full mode runs root + mounts the host Docker
67 # socket. The chart FAILS to render in full mode unless this is true.
68 acknowledgeRisk: false
69 # The floci-full image (root, Docker-backed services). Multi-arch,
70 # cosign-signed, 0-CVE, pinned by digest -- never a tag. Only used when
73 repository: chainreg.biz/chainguard-private/floci
74 # Human-readable tag for reference only; the pod is pulled by digest.
76 digest: sha256:58bf6901ed640b8e7958cfee5a89b3713d6b55f85421985a1c21a1e57cfa4443
77 pullPolicy: IfNotPresent
78 # Edge/API port. Must match service.port and containerPort. LocalStack clients
79 # point their endpoint URL at this port.
81 # Default AWS region and account id used by the emulated services.
82 defaultRegion: us-east-1
83 defaultAccountId: "000000000000"
84 # LocalStack API-parity emulation. Kept false for the hardened build.
85 localstackParity: false
86 # Storage/persistence for the in-process services.
87 # memory - all state in RAM, lost on restart (default; needs no volume,
88 # works on the read-only root filesystem)
89 # persistent - flush every write to disk (needs persistence.enabled)
90 # hybrid - async flush every ~5s to disk (needs persistence.enabled)
91 # wal - write-ahead log for durability (needs persistence.enabled)
92 # Anything other than "memory" requires persistence.enabled=true so a writable
93 # volume is mounted at storage.path (the root filesystem is read-only).
97# Best-effort single-replica persistence for the in-process services. This is a
98# convenience for keeping S3/DynamoDB/SQS/SNS/IAM state across pod restarts on ONE
99# replica; it is NOT a way to scale out (each replica keeps its own state). Leave
100# disabled for the default in-memory, ephemeral emulator. When enabled, set
101# floci.storage.mode to persistent/hybrid/wal and a PVC is mounted at
112 requests: {cpu: 250m, memory: 512Mi}
113 limits: {cpu: "1", memory: 1Gi}
116 # Floci serves the LocalStack-compatible edge/API (and the /_floci/health
117 # endpoint) on a single port.
119# Optional horizontal autoscaling. NOTE: only meaningful if Floci is fronting a
120# shared external backend; with the default in-process memory/persistent storage,
121# each replica holds its own state, so keep replicaCount: 1 and this disabled.
126 targetCPUUtilizationPercentage: 80
127# --- Common production knobs, wired through quench-common (all optional) ---
133topologySpreadConstraints: []
136terminationGracePeriodSeconds: 30
138# Extra environment variables (e.g. per-service config such as
139# FLOCI_SERVICES_*). Merged after the floci.* env above.
142extraEnvVarsSecret: ""
143# A writable /tmp for the read-only root filesystem. Quarkus/JVM temp files land
144# here. The persistence volume (when enabled) is mounted separately at
155podSecurityContext: {}
156containerSecurityContext: {}
159customLivenessProbe: {}
160customReadinessProbe: {}
161customStartupProbe: {}
168# Floci is a developer/test emulator usually consumed from within the namespace
169# (or by CI pods). Restrict ingress to the namespace by default; set
170# allowExternal=true to open it to the whole cluster.
177# Optional Ingress (HTTP only). Disabled by default, so enabling it is an explicit
178# operator decision and this chart's behaviour is unchanged until then.
181 # IngressClass to claim this Ingress. Empty -> the cluster default applies.
184 # Service port to route to. Unset -> resolved from service.port, then
185 # service.ports.http / .https.
187 # e.g. [{host: app.example.com, paths: [{path: /, pathType: Prefix}]}]
188 # `paths` may be omitted for the common "/" Prefix case.
190 # Standard Ingress TLS list, e.g. [{hosts: [app.example.com], secretName: app-tls}]