DirectorySecurity AdvisoriesPricing
Sign in
Directory
floci logoHELM

floci

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:

1
# The digest below is the contract with the image factory. CI (release-floci.yml)
2
# rewrites it from the image-published dispatch after every green image build, and
3
# the tracker pins the REAL digest here after the Floci image CI is green. It is
4
# never a tag. ---> PIN THE DIGEST HERE (image.digest, line 6). <---
5
image:
6
repository: chainreg.biz/chainguard-private/floci
7
# Human-readable tag for reference only; the pod is pulled by digest, not this.
8
tag: 2.2.0-r0
9
digest: sha256:58bf6901ed640b8e7958cfee5a89b3713d6b55f85421985a1c21a1e57cfa4443
10
pullPolicy: IfNotPresent
11
nameOverride: ""
12
# Floci's in-process emulator holds all state in RAM by default (FLOCI_STORAGE_MODE:
13
# memory), so it is stateless: a Deployment, not a StatefulSet. A single replica is
14
# the only correct topology for the default memory mode -- two replicas would each
15
# hold their own disjoint S3/DynamoDB/SQS/SNS/IAM state behind one Service. Enable
16
# persistence (below) only for single-replica durability across restarts; it is NOT
17
# a path to horizontal scale.
18
replicaCount: 1
19
# The image entrypoint runs the Floci (Quarkus) server directly; no command/args
20
# override is needed. Configure Floci through environment variables (env below).
21
command: []
22
args: []
23
# ---------------------------------------------------------------------------
24
# HARDENED SCOPE (READ THIS)
25
# ---------------------------------------------------------------------------
26
# Floci emulates 65 AWS services. This chart supports the 55 that run entirely
27
# inside the single nonroot Java process with no external dependencies: S3,
28
# DynamoDB, SQS, SNS, SES, IAM, STS, KMS, Secrets Manager, SSM, API Gateway,
29
# Cognito, Kinesis, CloudFormation, Step Functions, EventBridge, CloudWatch,
30
# CloudTrail, Config, Route53, CloudFront, ACM, Glue, Athena, ELBv2, Auto
31
# Scaling, Batch, WAF v2, AppConfig, AppSync, Bedrock Runtime, and more.
32
#
33
# The other 10 are DOCKER-BACKED (Lambda, RDS, ElastiCache, MSK, ECS, EKS,
34
# OpenSearch, ECR, DocumentDB, Neptune): they spin up real containers and REQUIRE
35
# the host Docker socket (/var/run/docker.sock) plus root. That is fundamentally
36
# incompatible with this hardened image (nonroot uid 1001, no docker.sock,
37
# read-only root filesystem) and is therefore NOT SUPPORTED here. Do not try to
38
# mount the Docker socket into this pod. If you need the Docker-backed services,
39
# run Floci on a Docker host outside Kubernetes.
40
#
41
# LocalStack API parity is disabled (LOCALSTACK_PARITY=false): clients target
42
# Floci's own endpoint on port 4566, which is LocalStack-wire-compatible for the
43
# in-process services above.
44
# ---------------------------------------------------------------------------
45
46
# Floci server configuration, surfaced as environment variables. Anything not
47
# listed here can be added via extraEnvVars.
48
floci:
49
# -------------------------------------------------------------------------
50
# MODE (hardened | full)
51
# -------------------------------------------------------------------------
52
# hardened (DEFAULT): the hardened `floci` image above -- nonroot uid 1001,
53
# no Docker socket, read-only root filesystem. Supports the 55 in-process
54
# AWS services only. This is the safe, recommended default; leave it alone.
55
#
56
# full (OPT-IN, NOT HARDENED): the separate `floci-full` image (below), run as
57
# ROOT with the host Docker socket (/var/run/docker.sock) mounted in. This
58
# enables ALL 65 services including the 10 Docker-backed ones (Lambda, RDS,
59
# ElastiCache, MSK, ECS, EKS, OpenSearch, ECR, DocumentDB, Neptune). A mounted
60
# host Docker socket is a node-root / container-escape surface: DO NOT use on
61
# shared or multi-tenant clusters. Requires floci.full.acknowledgeRisk=true or
62
# the chart refuses to render.
63
mode: hardened
64
# Settings that apply only when mode=full.
65
full:
66
# Explicit acknowledgement that full mode runs root + mounts the host Docker
67
# socket. The chart FAILS to render in full mode unless this is true.
68
acknowledgeRisk: false
69
# The floci-full image (root, Docker-backed services). Multi-arch,
70
# cosign-signed, 0-CVE, pinned by digest -- never a tag. Only used when
71
# mode=full.
72
image:
73
repository: chainreg.biz/chainguard-private/floci
74
# Human-readable tag for reference only; the pod is pulled by digest.
75
tag: 2.2.0-r0
76
digest: sha256:58bf6901ed640b8e7958cfee5a89b3713d6b55f85421985a1c21a1e57cfa4443
77
pullPolicy: IfNotPresent
78
# Edge/API port. Must match service.port and containerPort. LocalStack clients
79
# point their endpoint URL at this port.
80
port: 4566
81
# Default AWS region and account id used by the emulated services.
82
defaultRegion: us-east-1
83
defaultAccountId: "000000000000"
84
# LocalStack API-parity emulation. Kept false for the hardened build.
85
localstackParity: false
86
# Storage/persistence for the in-process services.
87
# memory - all state in RAM, lost on restart (default; needs no volume,
88
# works on the read-only root filesystem)
89
# persistent - flush every write to disk (needs persistence.enabled)
90
# hybrid - async flush every ~5s to disk (needs persistence.enabled)
91
# wal - write-ahead log for durability (needs persistence.enabled)
92
# Anything other than "memory" requires persistence.enabled=true so a writable
93
# volume is mounted at storage.path (the root filesystem is read-only).
94
storage:
95
mode: memory
96
path: /data
97
# Best-effort single-replica persistence for the in-process services. This is a
98
# convenience for keeping S3/DynamoDB/SQS/SNS/IAM state across pod restarts on ONE
99
# replica; it is NOT a way to scale out (each replica keeps its own state). Leave
100
# disabled for the default in-memory, ephemeral emulator. When enabled, set
101
# floci.storage.mode to persistent/hybrid/wal and a PVC is mounted at
102
# floci.storage.path.
103
persistence:
104
enabled: false
105
# existingClaim: ""
106
accessModes:
107
- ReadWriteOnce
108
size: 8Gi
109
storageClass: ""
110
annotations: {}
111
resources:
112
requests: {cpu: 250m, memory: 512Mi}
113
limits: {cpu: "1", memory: 1Gi}
114
service:
115
type: ClusterIP
116
# Floci serves the LocalStack-compatible edge/API (and the /_floci/health
117
# endpoint) on a single port.
118
port: 4566
119
# Optional horizontal autoscaling. NOTE: only meaningful if Floci is fronting a
120
# shared external backend; with the default in-process memory/persistent storage,
121
# each replica holds its own state, so keep replicaCount: 1 and this disabled.
122
autoscaling:
123
enabled: false
124
minReplicas: 1
125
maxReplicas: 5
126
targetCPUUtilizationPercentage: 80
127
# --- Common production knobs, wired through quench-common (all optional) ---
128
podLabels: {}
129
podAnnotations: {}
130
nodeSelector: {}
131
affinity: {}
132
tolerations: []
133
topologySpreadConstraints: []
134
priorityClassName: ""
135
schedulerName: ""
136
terminationGracePeriodSeconds: 30
137
updateStrategy: {}
138
# Extra environment variables (e.g. per-service config such as
139
# FLOCI_SERVICES_*). Merged after the floci.* env above.
140
extraEnvVars: []
141
extraEnvVarsCM: ""
142
extraEnvVarsSecret: ""
143
# A writable /tmp for the read-only root filesystem. Quarkus/JVM temp files land
144
# here. The persistence volume (when enabled) is mounted separately at
145
# floci.storage.path.
146
extraVolumes:
147
- name: tmp
148
emptyDir: {}
149
extraVolumeMounts:
150
- name: tmp
151
mountPath: /tmp
152
initContainers: []
153
sidecars: []
154
lifecycleHooks: {}
155
podSecurityContext: {}
156
containerSecurityContext: {}
157
livenessProbe: {}
158
readinessProbe: {}
159
customLivenessProbe: {}
160
customReadinessProbe: {}
161
customStartupProbe: {}
162
serviceAccount:
163
create: true
164
name: ""
165
annotations: {}
166
rbac:
167
create: false
168
# Floci is a developer/test emulator usually consumed from within the namespace
169
# (or by CI pods). Restrict ingress to the namespace by default; set
170
# allowExternal=true to open it to the whole cluster.
171
networkPolicy:
172
enabled: true
173
allowExternal: false
174
podDisruptionBudget:
175
enabled: false
176
minAvailable: 1
177
# Optional Ingress (HTTP only). Disabled by default, so enabling it is an explicit
178
# operator decision and this chart's behaviour is unchanged until then.
179
ingress:
180
enabled: false
181
# IngressClass to claim this Ingress. Empty -> the cluster default applies.
182
className: ""
183
annotations: {}
184
# Service port to route to. Unset -> resolved from service.port, then
185
# service.ports.http / .https.
186
servicePort: null
187
# e.g. [{host: app.example.com, paths: [{path: /, pathType: Prefix}]}]
188
# `paths` may be omitted for the common "/" Prefix case.
189
hosts: []
190
# Standard Ingress TLS list, e.g. [{hosts: [app.example.com], secretName: app-tls}]
191
tls: []
192

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.