This document lists every service and operation available in CloudEmu across all three cloud providers.
Every operation here is served from an in-memory backend by default. Selected data-plane services (relational database, cache, functions, compute, containers, object storage) can additionally be backed by opt-in real engines for real SQL/Redis/function execution.
| # | Service Category | AWS | Azure | GCP |
|---|---|---|---|---|
| 1 | Storage | s3 |
blobstorage |
gcs |
| 2 | Compute | ec2 |
virtualmachines |
compute |
| 3 | Database | dynamodb |
cosmosdb |
firestore |
| 4 | Serverless | lambda |
functions |
cloudfunctions |
| 5 | Networking | vpc (+ AWS-specific: Transit Gateway, VPN, DHCP options, prefix lists, egress-only IGW, endpoint services, Client VPN, Traffic Mirroring, Network Insights, VPC Block Public Access) |
vnet |
vpc |
| 5a | Network Firewall | network-firewall |
— | — |
| 6 | Monitoring | cloudwatch |
monitor |
monitoring |
| 7 | IAM | iam |
iam |
iam |
| 8 | DNS | route53 |
dns |
clouddns |
| 9 | Load Balancer | elb |
loadbalancer |
loadbalancer |
| 10 | Message Queue | sqs |
servicebus |
pubsub |
| 11 | Cache | elasticache |
cache |
memorystore |
| 12 | Secrets | secretsmanager |
keyvault |
secretmanager |
| 13 | Logging | cloudwatchlogs |
loganalytics |
cloudlogging |
| 14 | Notification | sns |
notificationhubs |
fcm |
| 15 | Container Registry | ecr |
acr |
artifactregistry |
| 16 | Event Bus | eventbridge |
eventgrid |
eventarc |
| 17 | Relational Database | rds (+ Aurora/Neptune/DocumentDB engines), redshift |
sql, postgresflex, mysqlflex |
cloudsql, alloydb |
| 17a | In-memory Database (Redis/Valkey) | memorydb |
— | — |
| 17b | Wide-column (Cassandra) | keyspaces |
managedcassandra |
— |
| 17c | Wide-column (Bigtable) | — | — | bigtable |
| 17d | Distributed PostgreSQL (Citus) | — | cosmospostgresql |
— |
| 18 | Kubernetes | eks + shared services/kubernetes/ |
aks + shared services/kubernetes/ |
gke + shared services/kubernetes/ |
| 19 | Resource Discovery | resourceexplorer2 + resourcegroupstaggingapi |
resourcegraph |
cloudasset |
| 20 | Generative AI | bedrock (+ bedrock-runtime), bedrock-agent (+ bedrock-agent-runtime) |
— | — |
| 21 | Databricks | — | databricks |
— |
| 22 | Machine Learning | sagemaker (+ sagemaker-runtime) |
ai (CognitiveServices + MachineLearningServices) |
vertexai |
| 23 | AI Search | — | search (Microsoft.Search) |
— |
| 24 | Container Orchestration | ecs |
— | — |
| 25 | DNS Resolver | route53resolver |
— | — |
| 26 | Application Networking | vpclattice |
— | — |
| 27 | Key Management | kms |
— | — |
| 28 | File System | efs |
— | — |
| 29 | Certificate Manager | acm |
— | — |
| 30 | Email Service | sesv2 |
— | — |
| 31 | Web Application Firewall | wafv2 |
— | — |
| 32 | Data Streams | kinesis |
— | — |
| 33 | Workflow Orchestration | sfn |
— | — |
| 34 | Search & Analytics | opensearch |
— | — |
| 35 | Audit Logging | cloudtrail |
— | — |
| 36 | Configuration Management | configservice |
— | — |
| 37 | Data Integration (ETL / Data Catalog) | glue |
— | — |
| 38 | Threat Detection | guardduty |
— | — |
| 39 | Streaming (Managed Kafka) | kafka |
— | — |
Driver interface: services/storage/driver/driver.go
AWS: S3 | Azure: Blob Storage | GCP: GCS
| Operation | Signature |
|---|---|
CreateBucket |
(ctx, name) error |
DeleteBucket |
(ctx, name) error |
ListBuckets |
(ctx) ([]BucketInfo, error) |
| Operation | Signature |
|---|---|
PutObject |
(ctx, bucket, key, data, contentType, metadata) error |
GetObject |
(ctx, bucket, key) (*Object, error) |
DeleteObject |
(ctx, bucket, key) error |
HeadObject |
(ctx, bucket, key) (*ObjectInfo, error) |
ListObjects |
(ctx, bucket, opts) (*ListResult, error) |
CopyObject |
(ctx, dstBucket, dstKey, src) error |
| Operation | Signature |
|---|---|
GeneratePresignedURL |
(ctx, req) (*PresignedURL, error) |
| Operation | Signature |
|---|---|
PutLifecycleConfig |
(ctx, bucket, config) error |
GetLifecycleConfig |
(ctx, bucket) (*LifecycleConfig, error) |
EvaluateLifecycle |
(ctx, bucket) ([]string, error) |
| Operation | Signature |
|---|---|
CreateMultipartUpload |
(ctx, bucket, key, contentType) (*MultipartUpload, error) |
UploadPart |
(ctx, bucket, key, uploadID, partNumber, data) (*UploadPart, error) |
CompleteMultipartUpload |
(ctx, bucket, key, uploadID, parts) error |
AbortMultipartUpload |
(ctx, bucket, key, uploadID) error |
ListMultipartUploads |
(ctx, bucket) ([]MultipartUpload, error) |
| Operation | Signature |
|---|---|
SetBucketVersioning |
(ctx, bucket, enabled) error |
GetBucketVersioning |
(ctx, bucket) (bool, error) |
| Operation | Signature |
|---|---|
PutBucketPolicy |
(ctx, bucket, policy) error |
GetBucketPolicy |
(ctx, bucket) (*BucketPolicy, error) |
DeleteBucketPolicy |
(ctx, bucket) error |
| Operation | Signature |
|---|---|
PutCORSConfig |
(ctx, bucket, config) error |
GetCORSConfig |
(ctx, bucket) (*CORSConfig, error) |
DeleteCORSConfig |
(ctx, bucket) error |
| Operation | Signature |
|---|---|
PutEncryptionConfig |
(ctx, bucket, config) error |
GetEncryptionConfig |
(ctx, bucket) (*EncryptionConfig, error) |
| Operation | Signature |
|---|---|
PutObjectTagging |
(ctx, bucket, key, tags) error |
GetObjectTagging |
(ctx, bucket, key) (map[string]string, error) |
DeleteObjectTagging |
(ctx, bucket, key) error |
| Operation | Signature |
|---|---|
PutBucketTagging |
(ctx, bucket, tags) error |
GetBucketTagging |
(ctx, bucket) (map[string]string, error) |
DeleteBucketTagging |
(ctx, bucket) error |
Total: 33 operations
Driver interface: services/compute/driver/driver.go
AWS: EC2 | Azure: Virtual Machines | GCP: GCE
| Operation | Signature |
|---|---|
RunInstances |
(ctx, config, count) ([]Instance, error) |
StartInstances |
(ctx, instanceIDs) error |
StopInstances |
(ctx, instanceIDs) error |
RebootInstances |
(ctx, instanceIDs) error |
TerminateInstances |
(ctx, instanceIDs) error |
DescribeInstances |
(ctx, instanceIDs, filters, ...opts) ([]Instance, error) |
ModifyInstance |
(ctx, instanceID, input) error |
EC2 emulates AWS managed resources — instances an AWS service (e.g. ECS Managed
Instances, EKS Auto Mode) provisions on the account's behalf. A managed instance
carries an Operator block (Managed=true, Principal) and is hidden from
DescribeInstances by default once the account's visibility is set to hidden,
reappearing only when the caller opts in with IncludeManagedResources=true.
Non-managed instances are always returned.
cloud := cloudemu.NewAWS()
cloud.EC2.RunInstances(ctx, computedriver.InstanceConfig{
InstanceType: "m5.large",
Managed: true, // Operator.Managed = true
Principal: "ecs.amazonaws.com", // Operator.Principal
Tags: map[string]string{"aws:ec2:managed-launch": "ecs-managed-instances"},
}, 1)
cloud.EC2.SetManagedResourceVisibility("hidden")
// Go API
cloud.EC2.DescribeInstances(ctx, nil, nil) // managed instance omitted
cloud.EC2.DescribeInstances(ctx, nil, nil, computedriver.DescribeInstancesOptions{IncludeManagedResources: true}) // included
// SDK-compat: real aws-sdk-go-v2 ec2.Client
client.DescribeInstances(ctx, &ec2.DescribeInstancesInput{}) // omits managed
client.DescribeInstances(ctx, &ec2.DescribeInstancesInput{IncludeManagedResources: aws.Bool(true)}) // includes managed| Operation | Signature |
|---|---|
CreateAutoScalingGroup |
(ctx, config) (*AutoScalingGroup, error) |
DeleteAutoScalingGroup |
(ctx, name, forceDelete) error |
GetAutoScalingGroup |
(ctx, name) (*AutoScalingGroup, error) |
ListAutoScalingGroups |
(ctx) ([]AutoScalingGroup, error) |
UpdateAutoScalingGroup |
(ctx, name, desired, minSize, maxSize) error |
SetDesiredCapacity |
(ctx, name, desired) error |
| Operation | Signature |
|---|---|
PutScalingPolicy |
(ctx, policy) error |
DeleteScalingPolicy |
(ctx, asgName, policyName) error |
ExecuteScalingPolicy |
(ctx, asgName, policyName) error |
| Operation | Signature |
|---|---|
RequestSpotInstances |
(ctx, config) ([]SpotInstanceRequest, error) |
CancelSpotRequests |
(ctx, requestIDs) error |
DescribeSpotRequests |
(ctx, requestIDs) ([]SpotInstanceRequest, error) |
| Operation | Signature |
|---|---|
CreateLaunchTemplate |
(ctx, config) (*LaunchTemplate, error) |
DeleteLaunchTemplate |
(ctx, name) error |
GetLaunchTemplate |
(ctx, name) (*LaunchTemplate, error) |
ListLaunchTemplates |
(ctx) ([]LaunchTemplate, error) |
| Operation | Signature |
|---|---|
CreateVolume |
(ctx, config) (*VolumeInfo, error) |
DeleteVolume |
(ctx, id) error |
DescribeVolumes |
(ctx, ids) ([]VolumeInfo, error) |
AttachVolume |
(ctx, volumeID, instanceID, device) error |
DetachVolume |
(ctx, volumeID) error |
| Operation | Signature |
|---|---|
CreateSnapshot |
(ctx, config) (*SnapshotInfo, error) |
DeleteSnapshot |
(ctx, id) error |
DescribeSnapshots |
(ctx, ids) ([]SnapshotInfo, error) |
| Operation | Signature |
|---|---|
CreateImage |
(ctx, config) (*ImageInfo, error) |
DeregisterImage |
(ctx, id) error |
DescribeImages |
(ctx, ids) ([]ImageInfo, error) |
| Operation | Signature |
|---|---|
CreateKeyPair |
(ctx, config) (*KeyPairInfo, error) |
DeleteKeyPair |
(ctx, name) error |
DescribeKeyPairs |
(ctx, names) ([]KeyPairInfo, error) |
Total: 35 operations
Driver interface: services/database/driver/driver.go
AWS: DynamoDB | Azure: Cosmos DB | GCP: Firestore
| Operation | Signature |
|---|---|
CreateTable |
(ctx, config) error |
DeleteTable |
(ctx, name) error |
DescribeTable |
(ctx, name) (*TableConfig, error) |
ListTables |
(ctx) ([]string, error) |
| Operation | Signature |
|---|---|
PutItem |
(ctx, table, item) error |
GetItem |
(ctx, table, key) (map[string]any, error) |
UpdateItem |
(ctx, input) (map[string]any, error) |
DeleteItem |
(ctx, table, key) error |
Query |
(ctx, input) (*QueryResult, error) |
Scan |
(ctx, input) (*QueryResult, error) |
| Operation | Signature |
|---|---|
BatchPutItems |
(ctx, table, items) error |
BatchGetItems |
(ctx, table, keys) ([]map[string]any, error) |
| Operation | Signature |
|---|---|
UpdateTTL |
(ctx, table, config) error |
DescribeTTL |
(ctx, table) (*TTLConfig, error) |
| Operation | Signature |
|---|---|
UpdateStreamConfig |
(ctx, table, config) error |
GetStreamRecords |
(ctx, table, limit, token) (*StreamIterator, error) |
| Operation | Signature |
|---|---|
TransactWriteItems |
(ctx, table, puts, deletes) error |
| Operation | Signature |
|---|---|
CreateIndex |
(ctx, table, config) (*IndexInfo, error) |
DeleteIndex |
(ctx, table, indexName) error |
DescribeIndex |
(ctx, table, indexName) (*IndexInfo, error) |
ListIndexes |
(ctx, table) ([]IndexInfo, error) |
Total: 21 operations
Driver interface: services/serverless/driver/driver.go
AWS: Lambda | Azure: Functions | GCP: Cloud Functions
| Operation | Signature |
|---|---|
CreateFunction |
(ctx, config) (*FunctionInfo, error) |
DeleteFunction |
(ctx, name) error |
GetFunction |
(ctx, name) (*FunctionInfo, error) |
ListFunctions |
(ctx) ([]FunctionInfo, error) |
UpdateFunction |
(ctx, name, config) (*FunctionInfo, error) |
Invoke |
(ctx, input) (*InvokeOutput, error) |
RegisterHandler |
(name, handler) |
| Operation | Signature |
|---|---|
PublishVersion |
(ctx, functionName, description) (*FunctionVersion, error) |
ListVersions |
(ctx, functionName) ([]FunctionVersion, error) |
| Operation | Signature |
|---|---|
CreateAlias |
(ctx, config) (*Alias, error) |
UpdateAlias |
(ctx, config) (*Alias, error) |
DeleteAlias |
(ctx, functionName, aliasName) error |
GetAlias |
(ctx, functionName, aliasName) (*Alias, error) |
ListAliases |
(ctx, functionName) ([]Alias, error) |
| Operation | Signature |
|---|---|
PublishLayerVersion |
(ctx, config) (*LayerVersion, error) |
GetLayerVersion |
(ctx, name, version) (*LayerVersion, error) |
ListLayerVersions |
(ctx, name) ([]LayerVersion, error) |
DeleteLayerVersion |
(ctx, name, version) error |
ListLayers |
(ctx) ([]LayerVersion, error) |
| Operation | Signature |
|---|---|
PutFunctionConcurrency |
(ctx, config) error |
GetFunctionConcurrency |
(ctx, functionName) (*ConcurrencyConfig, error) |
DeleteFunctionConcurrency |
(ctx, functionName) error |
| Operation | Signature |
|---|---|
CreateEventSourceMapping |
(ctx, config) (*EventSourceMappingInfo, error) |
DeleteEventSourceMapping |
(ctx, uuid) error |
GetEventSourceMapping |
(ctx, uuid) (*EventSourceMappingInfo, error) |
ListEventSourceMappings |
(ctx, functionName) ([]EventSourceMappingInfo, error) |
UpdateEventSourceMapping |
(ctx, uuid, config) (*EventSourceMappingInfo, error) |
Total: 26 operations
Driver interface: services/networking/driver/driver.go
AWS: VPC | Azure: VNet | GCP: GCP VPC | OCI: VCN (security lists map to network ACLs; service gateways to VPC endpoints; public IPs to elastic IPs; a connected pair of local peering gateways to a peering connection — DRGs, DRG attachments and remote peering connections are not emulated)
| Operation | Signature |
|---|---|
CreateVPC |
(ctx, config) (*VPCInfo, error) |
DeleteVPC |
(ctx, id) error |
DescribeVPCs |
(ctx, ids) ([]VPCInfo, error) |
| Operation | Signature |
|---|---|
CreateSubnet |
(ctx, config) (*SubnetInfo, error) |
DeleteSubnet |
(ctx, id) error |
DescribeSubnets |
(ctx, ids) ([]SubnetInfo, error) |
| Operation | Signature |
|---|---|
CreateSecurityGroup |
(ctx, config) (*SecurityGroupInfo, error) |
DeleteSecurityGroup |
(ctx, id) error |
DescribeSecurityGroups |
(ctx, ids) ([]SecurityGroupInfo, error) |
AddIngressRule |
(ctx, groupID, rule) error |
AddEgressRule |
(ctx, groupID, rule) error |
RemoveIngressRule |
(ctx, groupID, rule) error |
RemoveEgressRule |
(ctx, groupID, rule) error |
| Operation | Signature |
|---|---|
CreatePeeringConnection |
(ctx, config) (*PeeringConnection, error) |
AcceptPeeringConnection |
(ctx, peeringID) error |
RejectPeeringConnection |
(ctx, peeringID) error |
DeletePeeringConnection |
(ctx, peeringID) error |
DescribePeeringConnections |
(ctx, ids) ([]PeeringConnection, error) |
| Operation | Signature |
|---|---|
CreateNATGateway |
(ctx, config) (*NATGateway, error) |
DeleteNATGateway |
(ctx, id) error |
DescribeNATGateways |
(ctx, ids) ([]NATGateway, error) |
| Operation | Signature |
|---|---|
CreateFlowLog |
(ctx, config) (*FlowLog, error) |
DeleteFlowLog |
(ctx, id) error |
DescribeFlowLogs |
(ctx, ids) ([]FlowLog, error) |
GetFlowLogRecords |
(ctx, flowLogID, limit) ([]FlowLogRecord, error) |
| Operation | Signature |
|---|---|
CreateRouteTable |
(ctx, config) (*RouteTable, error) |
DeleteRouteTable |
(ctx, id) error |
DescribeRouteTables |
(ctx, ids) ([]RouteTable, error) |
CreateRoute |
(ctx, routeTableID, destinationCIDR, targetID, targetType) error |
DeleteRoute |
(ctx, routeTableID, destinationCIDR) error |
| Operation | Signature |
|---|---|
CreateNetworkACL |
(ctx, vpcID, tags) (*NetworkACL, error) |
DeleteNetworkACL |
(ctx, id) error |
DescribeNetworkACLs |
(ctx, ids) ([]NetworkACL, error) |
AddNetworkACLRule |
(ctx, aclID, rule) error |
RemoveNetworkACLRule |
(ctx, aclID, ruleNumber, egress) error |
| Operation | Signature |
|---|---|
CreateInternetGateway |
(ctx, config) (*InternetGateway, error) |
DeleteInternetGateway |
(ctx, id) error |
DescribeInternetGateways |
(ctx, ids) ([]InternetGateway, error) |
AttachInternetGateway |
(ctx, igwID, vpcID) error |
DetachInternetGateway |
(ctx, igwID, vpcID) error |
| Operation | Signature |
|---|---|
AllocateAddress |
(ctx, config) (*ElasticIP, error) |
ReleaseAddress |
(ctx, allocationID) error |
DescribeAddresses |
(ctx, ids) ([]ElasticIP, error) |
AssociateAddress |
(ctx, allocationID, instanceID) (string, error) |
DisassociateAddress |
(ctx, associationID) error |
| Operation | Signature |
|---|---|
AssociateRouteTable |
(ctx, routeTableID, subnetID) (*RouteTableAssociation, error) |
DisassociateRouteTable |
(ctx, associationID) error |
Every VPC is created with a main route table, carrying the local route and an
association with Main: true and no subnet. It cannot be deleted or
disassociated on its own and disappears with the VPC. A subnet with no explicit
association is governed by it.
DescribeRouteTables populates RouteTable.Associations; it is the only way a
caller can discover an association ID in order to disassociate.
| Operation | Signature |
|---|---|
DescribeNetworkInterfaces |
(ctx, ids) ([]NetworkInterface, error) |
DetachNetworkInterface |
(ctx, attachmentID, force) error |
DeleteNetworkInterface |
(ctx, id) error |
Managed resources attach interfaces of their own — a NAT gateway holds one for as long as it lives. An attached interface cannot be deleted, which is how a caller draining a VPC before deleting it learns the drain is not finished.
| Operation | Signature |
|---|---|
ModifyVPCAttribute |
(ctx, id, enableDNSSupport, enableDNSHostnames) error |
Both attributes are pointers: nil leaves that attribute unchanged, matching an
API that accepts one attribute per call. New VPCs default to DNS support on and
DNS hostnames off.
| Operation | Signature |
|---|---|
CreateVPCEndpoint |
(ctx, config) (*VPCEndpoint, error) |
DeleteVPCEndpoint |
(ctx, id) error |
DescribeVPCEndpoints |
(ctx, ids) ([]VPCEndpoint, error) |
ModifyVPCEndpoint |
(ctx, id, config) (*VPCEndpoint, error) |
Total: 47 operations
AWS models several networking resources that don't map cleanly across clouds.
These are AWS-only optional capability interfaces (discovered by type
assertion, like NetworkInterfaces/VPCAttributes) implemented by
providers/aws/vpc and served by the EC2 handler — no Azure/GCP stubs.
| Capability | Operations |
|---|---|
| Transit Gateway | CreateTransitGateway, DeleteTransitGateway, DescribeTransitGateways; VPC attachments (Create/Delete/Describe); route tables (Create/Delete/Describe); routes (Create/Delete/Search); route-table Associate + Enable/DisableRouteTablePropagation |
| VPN | CustomerGateway (Create/Delete/Describe); VpnGateway (Create/Delete/Describe/Attach/Detach); VpnConnection (Create/Delete/Describe/ModifyVpnConnection); VpnConnectionRoute (Create/Delete) |
| DHCP option sets | Create, Delete, Describe, Associate |
| Managed prefix lists | Create, Delete, Describe, GetEntries, Modify |
| Egress-only internet gateways | Create, Delete, Describe |
| VPC endpoint services (PrivateLink) | Create, Delete, Describe; ModifyPermissions, DescribePermissions |
| Client VPN | CreateEndpoint, DeleteEndpoint, DescribeEndpoints, Associate/DisassociateTargetNetwork, DescribeTargetNetworks; Authorize/RevokeIngress, DescribeAuthorizationRules; Route (Create/Delete/Describe) |
| Traffic Mirroring | Target (Create/Delete/Describe); Filter (Create/Delete/Describe) + ModifyFilterNetworkServices; FilterRule (Create/Modify/Delete/Describe); Session (Create/Modify/Delete/Describe) |
| Network Insights — Reachability Analyzer | Path (Create/Delete/Describe); Analysis (Start/Delete/Describe) |
| Network Insights — Network Access Analyzer | AccessScope (Create/Delete/Describe) + GetContent; AccessScopeAnalysis (Start/Delete/Describe) + GetAnalysisFindings |
| VPC Block Public Access | Options (Describe/Modify); Exclusion (Create/Modify/Delete/Describe) |
| IPAM (IP Address Manager) — full | Ipam/Scope/Pool CRUD+Modify; Cidr Provision/Deprovision/Get; Allocation Allocate/Release/Get/Modify; ResourceCidrs (Get/Modify) + AddressHistory; ResourceDiscovery CRUD + Associate/Disassociate + Discovered Accounts/ResourceCidrs/PublicAddresses; BYOASN (Provision/Deprovision/Associate/Disassociate/Describe); BYOIP (Move/Provision/Deprovision/Describe/Advertise/Withdraw); PrefixListResolver + Targets + Versions/Rules/Entries; ExternalResourceVerificationToken (Create/Delete/Describe); Policy (Create/Delete/Describe/Enable/Disable/GetEnabled/AllocationRules/OrgTargets) + OrganizationAdminAccount (Enable/Disable) |
AWS-specific total: 162 operations
IPAM is fully covered (~69 operations). Cross-account/organization and live-network features (Resource Discovery, discovered accounts/resources/public addresses, BYOASN/BYOIP, policies, org-admin) are modeled against the emulator's own single-account state: discovered resources are derived from the stored VPCs/subnets/EIPs, and organization targets resolve to the configured account.
IPAM publishes derived metrics through the CloudWatch service (ListMetrics / GetMetricStatistics): TotalActiveIpCount; pool PercentAllocated/PercentAssigned/PercentAvailable/Compliant/NoncompliantResourceCidrs; scope Managed/Unmanaged/Overlapping/Compliant/NoncompliantResourceCidrs; public-IP insight counts; and resource utilization VpcIPUsage/SubnetIPUsage. Values are computed live from IPAM + VPC/subnet/EIP state.
Driver interface: services/monitoring/driver/driver.go
AWS: CloudWatch | Azure: Azure Monitor | GCP: Cloud Monitoring
| Operation | Signature |
|---|---|
PutMetricData |
(ctx, data) error |
GetMetricData |
(ctx, input) (*MetricDataResult, error) |
ListMetrics |
(ctx, namespace) ([]string, error) |
| Operation | Signature |
|---|---|
CreateAlarm |
(ctx, config) error |
DeleteAlarm |
(ctx, name) error |
DescribeAlarms |
(ctx, names) ([]AlarmInfo, error) |
SetAlarmState |
(ctx, name, state, reason) error |
| Operation | Signature |
|---|---|
CreateNotificationChannel |
(ctx, config) (*NotificationChannelInfo, error) |
DeleteNotificationChannel |
(ctx, id) error |
GetNotificationChannel |
(ctx, id) (*NotificationChannelInfo, error) |
ListNotificationChannels |
(ctx) ([]NotificationChannelInfo, error) |
| Operation | Signature |
|---|---|
GetAlarmHistory |
(ctx, alarmName, limit) ([]AlarmHistoryEntry, error) |
Total: 12 operations
Optional capability: server/oci/monitoring.Extras — OCI scopes metrics
and alarms to a compartment and identifies alarms by OCID, neither of which the
portable model carries. Its value types live in providers/oci/monitoring.
Provider: providers/oci/monitoring | Wire: server/oci/monitoring
| Operation | Route |
|---|---|
PostMetricData |
POST /20180401/metrics |
ListMetrics |
POST /20180401/metrics/actions/listMetrics |
SummarizeMetricsData |
POST /20180401/metrics/actions/summarizeMetricsData |
CreateAlarm |
POST /20180401/alarms |
ListAlarms |
GET /20180401/alarms |
ListAlarmsStatus |
GET /20180401/alarms/status |
GetAlarm |
GET /20180401/alarms/{alarmId} |
UpdateAlarm |
PUT /20180401/alarms/{alarmId} |
DeleteAlarm |
DELETE /20180401/alarms/{alarmId} |
GetAlarmHistory |
GET /20180401/alarms/{alarmId}/history |
Every list route requires compartmentId and paginates with limit / page,
returning the cursor as opc-next-page. Alarm mutations are synchronous in real
OCI Monitoring, so none of them returns a work request.
Queries are read in MQL's single-metric threshold form plus the optional
dimension predicate that scopes an alarm to one series —
CpuUtilization[1m]{resourceId = "ocid1.instance…"}.mean() > 80. The predicate
supports = and !=; the pattern operators =~ and !~ are rejected rather
than answered with a false "no data". A resolution finer than OCI's 1m
minimum is rejected; richer MQL is stored verbatim and never fires.
An alarm fires only once its condition has held for pendingDuration, read as
an ISO-8601 duration such as PT5M; the portable EvaluationPeriods maps onto
it. Unset, it fires on the first breaching datapoint — evaluation runs on
PostMetricData rather than on a timer, so OCI's PT1M default would never
elapse on its own. Alarm suppression and overrides are rejected rather than
accepted and dropped.
PostMetricData enforces OCI's batch limit of 50 metricData entries and its
namespace, metric name and dimension formats. The per-request datapoint cap,
metadata limits and the ingestion time window are not enforced.
Driver interface: services/iam/driver/driver.go
AWS: IAM | Azure: Azure IAM | GCP: GCP IAM | OCI: Identity
| Operation | Signature |
|---|---|
CreateUser |
(ctx, config) (*UserInfo, error) |
DeleteUser |
(ctx, name) error |
GetUser |
(ctx, name) (*UserInfo, error) |
ListUsers |
(ctx) ([]UserInfo, error) |
| Operation | Signature |
|---|---|
CreateRole |
(ctx, config) (*RoleInfo, error) |
DeleteRole |
(ctx, name) error |
GetRole |
(ctx, name) (*RoleInfo, error) |
ListRoles |
(ctx) ([]RoleInfo, error) |
| Operation | Signature |
|---|---|
CreatePolicy |
(ctx, config) (*PolicyInfo, error) |
DeletePolicy |
(ctx, arn) error |
GetPolicy |
(ctx, arn) (*PolicyInfo, error) |
ListPolicies |
(ctx) ([]PolicyInfo, error) |
| Operation | Signature |
|---|---|
AttachUserPolicy |
(ctx, userName, policyARN) error |
DetachUserPolicy |
(ctx, userName, policyARN) error |
AttachRolePolicy |
(ctx, roleName, policyARN) error |
DetachRolePolicy |
(ctx, roleName, policyARN) error |
ListAttachedUserPolicies |
(ctx, userName) ([]string, error) |
ListAttachedRolePolicies |
(ctx, roleName) ([]string, error) |
| Operation | Signature |
|---|---|
CheckPermission |
(ctx, principal, action, resource) (bool, error) |
| Operation | Signature |
|---|---|
CreateGroup |
(ctx, config) (*GroupInfo, error) |
DeleteGroup |
(ctx, name) error |
GetGroup |
(ctx, name) (*GroupInfo, error) |
ListGroups |
(ctx) ([]GroupInfo, error) |
AddUserToGroup |
(ctx, userName, groupName) error |
RemoveUserFromGroup |
(ctx, userName, groupName) error |
ListGroupsForUser |
(ctx, userName) ([]GroupInfo, error) |
| Operation | Signature |
|---|---|
CreateAccessKey |
(ctx, config) (*AccessKeyInfo, error) |
DeleteAccessKey |
(ctx, userName, accessKeyID) error |
ListAccessKeys |
(ctx, userName) ([]AccessKeyInfo, error) |
| Operation | Signature |
|---|---|
CreateInstanceProfile |
(ctx, config) (*InstanceProfileInfo, error) |
DeleteInstanceProfile |
(ctx, name) error |
GetInstanceProfile |
(ctx, name) (*InstanceProfileInfo, error) |
ListInstanceProfiles |
(ctx) ([]InstanceProfileInfo, error) |
AddRoleToInstanceProfile |
(ctx, profileName, roleName) error |
RemoveRoleFromInstanceProfile |
(ctx, profileName, roleName) error |
Total: 35 operations
Declared by the wire handler and discovered by type assertion, with their
value types in providers/oci/identity. OCI addresses identity resources by
OCID, scopes them to a compartment, and writes policies as English-like
statements, none of which the portable interface expresses. Only
providers/oci/identity implements them; the OCI provider answers
Unimplemented for policy attachment and instance profiles, which have no OCI
equivalent.
| Capability | Operations |
|---|---|
Compartments |
Create/Get/List/Update/DeleteCompartment; ListCompartments descends the tree when inSubtree is set |
OCIIdentity |
Create/Get/List/Update/Delete OCIUser and OCIGroup; Create/Get/List/Delete OCIGroupMembership |
StatementPolicies |
Create/Get/List/Update/DeleteStatementPolicy; Evaluate resolves a statement against the compartment tree |
Statements round-trip verbatim, but two things Evaluate cannot decide report
themselves as Unimplemented rather than granting the whole verb: a where
condition, and a resource family outside the modeled set. MoveCompartment and
the Quotas API (/20181025/quotas) answer 501 for the same reason.
Driver interface: services/dns/driver/driver.go
AWS: Route 53 | Azure: Azure DNS | GCP: Cloud DNS
| Operation | Signature |
|---|---|
CreateZone |
(ctx, config) (*ZoneInfo, error) |
DeleteZone |
(ctx, id) error |
GetZone |
(ctx, id) (*ZoneInfo, error) |
ListZones |
(ctx) ([]ZoneInfo, error) |
| Operation | Signature |
|---|---|
CreateRecord |
(ctx, config) (*RecordInfo, error) |
DeleteRecord |
(ctx, zoneID, name, recordType) error |
GetRecord |
(ctx, zoneID, name, recordType) (*RecordInfo, error) |
ListRecords |
(ctx, zoneID) ([]RecordInfo, error) |
UpdateRecord |
(ctx, config) (*RecordInfo, error) |
| Operation | Signature |
|---|---|
CreateHealthCheck |
(ctx, config) (*HealthCheckInfo, error) |
DeleteHealthCheck |
(ctx, id) error |
GetHealthCheck |
(ctx, id) (*HealthCheckInfo, error) |
ListHealthChecks |
(ctx) ([]HealthCheckInfo, error) |
UpdateHealthCheck |
(ctx, id, config) (*HealthCheckInfo, error) |
SetHealthCheckStatus |
(ctx, id, status) error |
Total: 15 operations
Driver interface: services/loadbalancer/driver/driver.go
AWS: ELB | Azure: Azure LB | GCP: GCP LB
| Operation | Signature |
|---|---|
CreateLoadBalancer |
(ctx, config) (*LBInfo, error) |
DeleteLoadBalancer |
(ctx, arn) error |
DescribeLoadBalancers |
(ctx, arns) ([]LBInfo, error) |
| Operation | Signature |
|---|---|
CreateTargetGroup |
(ctx, config) (*TargetGroupInfo, error) |
DeleteTargetGroup |
(ctx, arn) error |
DescribeTargetGroups |
(ctx, arns) ([]TargetGroupInfo, error) |
| Operation | Signature |
|---|---|
CreateListener |
(ctx, config) (*ListenerInfo, error) |
DeleteListener |
(ctx, arn) error |
DescribeListeners |
(ctx, lbARN) ([]ListenerInfo, error) |
ModifyListener |
(ctx, input) error |
| Operation | Signature |
|---|---|
CreateRule |
(ctx, config) (*RuleInfo, error) |
DeleteRule |
(ctx, ruleARN) error |
DescribeRules |
(ctx, listenerARN) ([]RuleInfo, error) |
| Operation | Signature |
|---|---|
GetLBAttributes |
(ctx, lbARN) (*LBAttributes, error) |
PutLBAttributes |
(ctx, lbARN, attrs) error |
These two were always in the driver; they are listed here because the ELBv2 handler now exposes them as ModifyLoadBalancerAttributes and DescribeLoadBalancerAttributes.
| Operation | Signature |
|---|---|
RegisterTargets |
(ctx, targetGroupARN, targets) error |
DeregisterTargets |
(ctx, targetGroupARN, targets) error |
DescribeTargetHealth |
(ctx, targetGroupARN) ([]TargetHealth, error) |
SetTargetHealth |
(ctx, targetGroupARN, targetID, state) error |
| Operation | Signature |
|---|---|
GetLBAttributes |
(ctx, lbARN) (*LBAttributes, error) |
PutLBAttributes |
(ctx, lbARN, attrs) error |
These two were always in the driver; they are listed here because the ELBv2 handler now exposes them as ModifyLoadBalancerAttributes and DescribeLoadBalancerAttributes.
LBAttributes.Extra carries attributes outside the typed set, keyed by their
provider attribute name (load_balancing.cross_zone.enabled and friends).
Providers model attributes as open key/value pairs and add new ones over time, so
a fixed struct would silently drop whatever it had not been taught.
Total: 21 operations
Driver interface: services/messagequeue/driver/driver.go
AWS: SQS | Azure: Service Bus | GCP: Pub/Sub
| Operation | Signature |
|---|---|
CreateQueue |
(ctx, config) (*QueueInfo, error) |
DeleteQueue |
(ctx, url) error |
GetQueueInfo |
(ctx, url) (*QueueInfo, error) |
ListQueues |
(ctx, prefix) ([]QueueInfo, error) |
| Operation | Signature |
|---|---|
SendMessage |
(ctx, input) (*SendMessageOutput, error) |
ReceiveMessages |
(ctx, input) ([]Message, error) |
DeleteMessage |
(ctx, queueURL, receiptHandle) error |
ChangeVisibility |
(ctx, queueURL, receiptHandle, timeout) error |
| Operation | Signature |
|---|---|
SendMessageBatch |
(ctx, queue, entries) (*BatchSendResult, error) |
DeleteMessageBatch |
(ctx, queue, entries) (*BatchDeleteResult, error) |
| Operation | Signature |
|---|---|
ReceiveMessagesWithOptions |
(ctx, queue, opts) ([]Message, error) |
| Operation | Signature |
|---|---|
GetQueueAttributes |
(ctx, queue) (*QueueAttributes, error) |
SetQueueAttributes |
(ctx, queue, attrs) error |
| Operation | Signature |
|---|---|
PurgeQueue |
(ctx, queue) error |
Total: 14 operations
Driver interface: services/cache/driver/driver.go
AWS: ElastiCache | Azure: Azure Cache | GCP: Memorystore
| Operation | Signature |
|---|---|
CreateCache |
(ctx, config) (*CacheInfo, error) |
DeleteCache |
(ctx, name) error |
GetCache |
(ctx, name) (*CacheInfo, error) |
ListCaches |
(ctx) ([]CacheInfo, error) |
| Operation | Signature |
|---|---|
Set |
(ctx, cacheName, key, value, ttl) error |
Get |
(ctx, cacheName, key) (*Item, error) |
Delete |
(ctx, cacheName, key) error |
Keys |
(ctx, cacheName, pattern) ([]string, error) |
FlushAll |
(ctx, cacheName) error |
| Operation | Signature |
|---|---|
Expire |
(ctx, cacheName, key, ttl) error |
GetTTL |
(ctx, cacheName, key) (time.Duration, error) |
Persist |
(ctx, cacheName, key) error |
| Operation | Signature |
|---|---|
Incr |
(ctx, cacheName, key) (int64, error) |
IncrBy |
(ctx, cacheName, key, delta) (int64, error) |
Decr |
(ctx, cacheName, key) (int64, error) |
DecrBy |
(ctx, cacheName, key, delta) (int64, error) |
| Operation | Signature |
|---|---|
CreateCacheSubnetGroup |
(ctx, SubnetGroupConfig) (*SubnetGroup, error) |
DescribeCacheSubnetGroups |
(ctx, names) ([]SubnetGroup, error) |
DeleteCacheSubnetGroup |
(ctx, name) error |
A primary node plus replicas, addressed through one primary endpoint. Callers build a connection string from it, so the endpoint is always populated — a group without one is indistinguishable from a broken provision.
| Operation | Signature |
|---|---|
CreateReplicationGroup |
(ctx, ReplicationGroupConfig) (*ReplicationGroup, error) |
DescribeReplicationGroups |
(ctx, ids) ([]ReplicationGroup, error) |
ModifyReplicationGroup |
(ctx, id, numCacheNodes) (*ReplicationGroup, error) |
DeleteReplicationGroup |
(ctx, id) error |
Both interfaces are AWS-only concepts, discovered by type assertion.
Total: 16 operations (+7 optional)
Driver interface: services/memorydb/driver/driver.go
AWS: MemoryDB for Redis/Valkey | Azure: — | GCP: —
A durable, in-VPC Redis/Valkey cluster service. Unlike Cache, MemoryDB is a
control-plane-only surface (no Set/Get data plane), so it has its own driver
rather than reusing services/cache. Served as AWS JSON 1.1 on the
AmazonMemoryDB. target prefix (server/aws/memorydb), so a real
aws-sdk-go-v2/service/memorydb client with a custom endpoint works unchanged.
| Operation | Signature |
|---|---|
CreateCluster |
(ctx, CreateClusterConfig) (*Cluster, error) |
DescribeClusters |
(ctx, names) ([]Cluster, error) |
UpdateCluster |
(ctx, UpdateClusterConfig) (*Cluster, error) |
DeleteCluster |
(ctx, name, finalSnapshotName) (*Cluster, error) |
FailoverShard |
(ctx, clusterName, shardName) (*Cluster, error) |
ListAllowedNodeTypeUpdates |
(ctx, clusterName) (scaleUp, scaleDown []string, error) |
| Operation | Signature |
|---|---|
CreateACL |
(ctx, name, userNames, tags) (*ACL, error) |
DescribeACLs |
(ctx, names) ([]ACL, error) |
UpdateACL |
(ctx, name, add, remove) (*ACL, error) |
DeleteACL |
(ctx, name) (*ACL, error) |
CreateUser |
(ctx, CreateUserConfig) (*User, error) |
DescribeUsers |
(ctx, names) ([]User, error) |
UpdateUser |
(ctx, UpdateUserConfig) (*User, error) |
DeleteUser |
(ctx, name) (*User, error) |
| Operation | Signature |
|---|---|
CreateParameterGroup |
(ctx, name, family, description, tags) (*ParameterGroup, error) |
DescribeParameterGroups |
(ctx, names) ([]ParameterGroup, error) |
UpdateParameterGroup |
(ctx, name, params) (*ParameterGroup, error) |
ResetParameterGroup |
(ctx, name, all, names) (*ParameterGroup, error) |
DeleteParameterGroup |
(ctx, name) (*ParameterGroup, error) |
DescribeParameters |
(ctx, groupName) ([]Parameter, error) |
| Operation | Signature |
|---|---|
CreateSubnetGroup |
(ctx, CreateSubnetGroupConfig) (*SubnetGroup, error) |
DescribeSubnetGroups |
(ctx, names) ([]SubnetGroup, error) |
UpdateSubnetGroup |
(ctx, UpdateSubnetGroupConfig) (*SubnetGroup, error) |
DeleteSubnetGroup |
(ctx, name) (*SubnetGroup, error) |
| Operation | Signature |
|---|---|
CreateSnapshot |
(ctx, CreateSnapshotConfig) (*Snapshot, error) |
DescribeSnapshots |
(ctx, names, clusterName) ([]Snapshot, error) |
CopySnapshot |
(ctx, CopySnapshotConfig) (*Snapshot, error) |
DeleteSnapshot |
(ctx, name) (*Snapshot, error) |
| Operation | Signature |
|---|---|
TagResource |
(ctx, arn, tags) ([]Tag, error) |
UntagResource |
(ctx, arn, keys) ([]Tag, error) |
ListTags |
(ctx, arn) ([]Tag, error) |
DescribeEngineVersions |
(ctx, engine, version) ([]EngineVersionInfo, error) |
DescribeEvents |
(ctx) ([]Event, error) |
| Operation | Signature |
|---|---|
CreateMultiRegionCluster |
(ctx, CreateMultiRegionClusterConfig) (*MultiRegionCluster, error) |
DescribeMultiRegionClusters |
(ctx, names) ([]MultiRegionCluster, error) |
UpdateMultiRegionCluster |
(ctx, name, nodeType, engineVersion, shardCount) (*MultiRegionCluster, error) |
DeleteMultiRegionCluster |
(ctx, name) (*MultiRegionCluster, error) |
ListAllowedMultiRegionClusterUpdates |
(ctx, name) ([]string, error) |
DescribeMultiRegionParameterGroups |
(ctx, names) ([]MultiRegionParameterGroup, error) |
DescribeMultiRegionParameters |
(ctx, groupName) ([]Parameter, error) |
| Operation | Signature |
|---|---|
DescribeReservedNodes |
(ctx) ([]ReservedNode, error) |
DescribeReservedNodesOfferings |
(ctx) ([]ReservedNodesOffering, error) |
PurchaseReservedNodesOffering |
(ctx, offeringID, reservationID, count) (*ReservedNode, error) |
| Operation | Signature |
|---|---|
DescribeServiceUpdates |
(ctx, serviceUpdateName, clusterNames, status) ([]ServiceUpdate, error) |
BatchUpdateCluster |
(ctx, clusterNames, serviceUpdateName) (processed []Cluster, unprocessed []UnprocessedCluster, error) |
BatchUpdateCluster applies a service update to each named cluster; a name that
does not exist is returned in unprocessed (with ClusterNotFoundFault) rather
than failing the whole batch — matching AWS's partial-success semantics.
The three optional interfaces are AWS-only concepts, discovered by type assertion.
Pagination: every Describe* operation honors MaxResults/NextToken.
The server pages the deterministic (sorted) result set and returns an opaque
base64 offset token; a malformed token yields InvalidParameterValueException.
Total: 33 operations (+13 optional)
Driver interface: services/keyspaces/driver/driver.go
AWS: Amazon Keyspaces (for Apache Cassandra) | Azure: — | GCP: —
A managed, Cassandra-compatible wide-column service. Control-plane only (CQL
data operations are out of scope), so it has its own driver rather than reusing
the relational/cache drivers. Served as AWS JSON 1.0 on the KeyspacesService.
target prefix (server/aws/keyspaces); a real
aws-sdk-go-v2/service/keyspaces client with a custom endpoint works unchanged.
Because Keyspaces models its members in lowerCamelCase, the server lowercases
response keys so the SDK's case-sensitive deserializer decodes them.
| Operation | Signature |
|---|---|
CreateKeyspace |
(ctx, CreateKeyspaceConfig) (*Keyspace, error) |
GetKeyspace |
(ctx, name) (*Keyspace, error) |
ListKeyspaces |
(ctx) ([]Keyspace, error) |
UpdateKeyspace |
(ctx, name, addRegions) (*Keyspace, error) |
DeleteKeyspace |
(ctx, name) error |
Single- or multi-region replication (ReplicationSpecification); a keyspace
must be empty to delete.
| Operation | Signature |
|---|---|
CreateTable |
(ctx, CreateTableConfig) (*Table, error) |
GetTable |
(ctx, keyspace, table) (*Table, error) |
ListTables |
(ctx, keyspace) ([]Table, error) |
UpdateTable |
(ctx, UpdateTableConfig) (*Table, error) |
DeleteTable |
(ctx, keyspace, table) error |
RestoreTable |
(ctx, RestoreTableConfig) (*Table, error) |
Full SchemaDefinition (partition/clustering keys, static & regular columns),
CapacitySpecification (PAY_PER_REQUEST / PROVISIONED + RCU/WCU), encryption,
point-in-time recovery, TTL, client-side timestamps, CDC, comment, and
multi-region replica specs. RestoreTable is point-in-time recovery into a new
table.
| Operation | Signature |
|---|---|
CreateType |
(ctx, keyspace, name, fields) (*UDT, error) |
GetType |
(ctx, keyspace, name) (*UDT, error) |
ListTypes |
(ctx, keyspace) ([]UDT, error) |
DeleteType |
(ctx, keyspace, name) (*UDT, error) |
| Operation | Signature |
|---|---|
TagResource |
(ctx, arn, tags) error |
UntagResource |
(ctx, arn, keys) error |
ListTagsForResource |
(ctx, arn) ([]Tag, error) |
| Operation | Signature |
|---|---|
GetTableAutoScalingSettings |
(ctx, keyspace, table) (*Table, error) |
Target-tracking auto scaling for PROVISIONED tables, discovered by type assertion; errors for PAY_PER_REQUEST tables (matching AWS).
Pagination: ListKeyspaces/ListTables/ListTypes/ListTagsForResource
honor MaxResults/NextToken (server-side opaque base64 offset token over the
deterministic result set; a malformed token yields ValidationException).
Total: 18 operations (+1 optional)
Driver interface: services/managedcassandra/driver/driver.go
AWS: — | Azure: Azure Managed Instance for Apache Cassandra | GCP: —
A managed, Cassandra-compatible cluster service under Cosmos DB. Control-plane
only (CQL is out of scope), so it has its own driver. Served as ARM REST/JSON
under Microsoft.DocumentDB/cassandraClusters (server/azure/managedcassandra);
a real armcosmos CassandraClusters/CassandraDataCenters client with a
custom endpoint works unchanged. Mutating ops complete synchronously so the
SDK's LRO pollers terminate on the first response (create/patch return the
resource; delete → 204; deallocate/start → 202 + Azure-AsyncOperation;
invokeCommand → 202 + Location returning the command output).
| Operation | Signature |
|---|---|
CreateOrUpdateCluster |
(ctx, CreateClusterConfig) (*Cluster, error) |
GetCluster |
(ctx, resourceGroup, name) (*Cluster, error) |
ListClustersByResourceGroup |
(ctx, resourceGroup) ([]Cluster, error) |
ListClustersBySubscription |
(ctx) ([]Cluster, error) |
UpdateCluster |
(ctx, resourceGroup, name, ClusterPatch) (*Cluster, error) |
DeleteCluster |
(ctx, resourceGroup, name) error |
DeallocateCluster |
(ctx, resourceGroup, name) (*Cluster, error) |
StartCluster |
(ctx, resourceGroup, name) (*Cluster, error) |
InvokeCommand |
(ctx, resourceGroup, name, command, host) (string, error) |
ClusterStatus |
(ctx, resourceGroup, name) (*ClusterStatus, error) |
Single/multi-region-capable clusters with cassandra version, delegated subnet,
authentication method, repair, backups, seed/gossip/client certs, and a
deallocate/start lifecycle. ClusterStatus reports per-node health;
InvokeCommand runs a maintenance command (e.g. nodetool).
| Operation | Signature |
|---|---|
CreateOrUpdateDataCenter |
(ctx, CreateDataCenterConfig) (*DataCenter, error) |
GetDataCenter |
(ctx, resourceGroup, cluster, name) (*DataCenter, error) |
ListDataCenters |
(ctx, resourceGroup, cluster) ([]DataCenter, error) |
UpdateDataCenter |
(ctx, resourceGroup, cluster, name, DataCenterPatch) (*DataCenter, error) |
DeleteDataCenter |
(ctx, resourceGroup, cluster, name) error |
Datacenters live under a cluster (node count, disk capacity, SKU, availability zone, delegated subnet, seed nodes). Deleting a cluster cascade-deletes its datacenters; creating a datacenter validates the parent cluster exists; deallocate/start propagate to all datacenters.
Total: 15 operations
Driver interface: services/bigtable/driver/driver.go
AWS: — | Azure: — | GCP: Cloud Bigtable
A wide-column NoSQL database. Control-plane only (the data plane is out of
scope), so it has its own driver. Served as GCP REST/JSON under /v2/...
(server/gcp/bigtable); a real google.golang.org/api/bigtableadmin/v2 client
with a custom endpoint works unchanged. The wire layer uses the SDK's own types
for exact fidelity. Long-running RPCs return a Google Operation{done:true}
carrying the resulting resource, and operations.get returns a done Operation,
so SDK LRO waits complete.
| Operation | Signature |
|---|---|
CreateInstance |
(ctx, CreateInstanceConfig) (*Instance, *Operation, error) |
GetInstance |
(ctx, name) (*Instance, error) |
ListInstances |
(ctx, project) ([]Instance, error) |
UpdateInstance |
(ctx, name, cfg) (*Instance, error) |
PartialUpdateInstance |
(ctx, name, cfg) (*Instance, *Operation, error) |
DeleteInstance |
(ctx, name) error |
| Operation | Signature |
|---|---|
CreateCluster |
(ctx, CreateClusterConfig) (*Cluster, *Operation, error) |
GetCluster |
(ctx, name) (*Cluster, error) |
ListClusters |
(ctx, instance) ([]Cluster, error) |
UpdateCluster |
(ctx, name, serveNodes, autoscaling) (*Cluster, *Operation, error) |
DeleteCluster |
(ctx, name) error |
GetClusterMemoryLayer |
(ctx, name) error |
| Operation | Signature |
|---|---|
CreateTable |
(ctx, CreateTableConfig) (*Table, error) |
GetTable / ListTables |
(ctx, name) / (ctx, instance) |
UpdateTable |
(ctx, name, deletionProtection) (*Table, *Operation, error) |
DeleteTable / UndeleteTable |
(ctx, name) (soft-delete + restore) |
ModifyColumnFamilies |
(ctx, name, mods) (*Table, error) |
DropRowRange / GenerateConsistencyToken / CheckConsistency |
data-consistency helpers |
RestoreTable |
(ctx, parent, tableID, backup) (*Table, *Operation, error) |
Column families carry recursive GC rules (maxNumVersions / maxAge /
union / intersection).
| Operation | Signature |
|---|---|
CreateAppProfile / GetAppProfile / ListAppProfiles |
routing-policy CRUD |
UpdateAppProfile |
(ctx, name, cfg) (*AppProfile, *Operation, error) |
DeleteAppProfile |
(ctx, name) error |
| Operation | Signature |
|---|---|
CreateBackup |
(ctx, CreateBackupConfig) (*Backup, *Operation, error) |
GetBackup / ListBackups / UpdateBackup / DeleteBackup |
backup CRUD |
CopyBackup |
(ctx, CopyBackupConfig) (*Backup, *Operation, error) |
GetOperation (LRO poll) plus per-resource IAM on instances, tables, and
backups: GetIamPolicy, SetIamPolicy, TestIamPermissions.
Modeling: instances own clusters/tables/app-profiles (parent linkage, cascade delete); backups live under a cluster and restore into a new table; serve-node counts are bounded; clone-on-read on every path.
Total: 38 operations
Driver interface: services/cosmospostgresql/driver/driver.go
Azure: Cosmos DB for PostgreSQL (Citus) — Microsoft.DBforPostgreSQL/serverGroupsv2
Real armcosmosforpostgresql clients configured with a custom endpoint hit the
ARM handler (server/azure/cosmospostgresql) the same way they hit
management.azure.com. Create/update RPCs return the resource inline with a
terminal provisioningState; the cluster start/stop/restart/promote actions
reply 202 + Location and the poller reads a terminal status from the
operationStatuses URL.
| Operation | Signature |
|---|---|
CreateOrUpdateCluster |
(ctx, CreateClusterConfig) (*Cluster, error) |
GetCluster / ListClustersByResourceGroup / ListClustersBySubscription |
cluster reads |
UpdateCluster |
(ctx, rg, name, ClusterPatch) (*Cluster, error) (PATCH) |
DeleteCluster |
(ctx, rg, name) error |
RestartCluster / StartCluster / StopCluster |
lifecycle actions (LRO) |
PromoteReadReplica |
(ctx, rg, name) error — detach a replica |
CheckNameAvailability |
(ctx, name, type) (*NameAvailability, error) |
| Operation | Signature |
|---|---|
CreateOrUpdateFirewallRule / GetFirewallRule / ListFirewallRules / DeleteFirewallRule |
IP allow-list CRUD |
CreateRole / GetRole / ListRoles / DeleteRole |
Postgres role CRUD |
| Operation | Signature |
|---|---|
GetServer / ListServers |
read-only derived nodes (coordinator + workers) |
ListConfigurations / GetConfiguration |
cluster-wide server parameters (per-role values) |
GetCoordinatorConfiguration / GetNodeConfiguration / ListServerConfigurations |
server-scoped parameter reads |
UpdateCoordinatorConfiguration / UpdateNodeConfiguration |
per-role parameter updates (LRO) |
CreateOrUpdatePrivateEndpointConnection / GetPrivateEndpointConnection / ListPrivateEndpointConnections / DeletePrivateEndpointConnection |
private-endpoint CRUD |
GetPrivateLinkResource / ListPrivateLinkResources |
private-link resource reads |
Modeling: a cluster owns its firewall rules, roles, configurations, and private-endpoint connections (parent linkage, cascade delete); nodes are derived from the cluster shape (one coordinator + N workers); read replicas link back to a source cluster and detach on promote; clone-on-read on every path.
Total: 34 operations
Driver interface: services/secrets/driver/driver.go
AWS: Secrets Manager | Azure: Key Vault | GCP: Secret Manager
| Operation | Signature |
|---|---|
CreateSecret |
(ctx, config, value) (*SecretInfo, error) |
DeleteSecret |
(ctx, name) error |
GetSecret |
(ctx, name) (*SecretInfo, error) |
ListSecrets |
(ctx) ([]SecretInfo, error) |
| Operation | Signature |
|---|---|
PutSecretValue |
(ctx, name, value) (*SecretVersion, error) |
GetSecretValue |
(ctx, name, versionID) (*SecretVersion, error) |
ListSecretVersions |
(ctx, name) ([]SecretVersion, error) |
Total: 7 operations
Driver interface: services/logging/driver/driver.go
AWS: CloudWatch Logs | Azure: Log Analytics | GCP: Cloud Logging
| Operation | Signature |
|---|---|
CreateLogGroup |
(ctx, config) (*LogGroupInfo, error) |
DeleteLogGroup |
(ctx, name) error |
GetLogGroup |
(ctx, name) (*LogGroupInfo, error) |
ListLogGroups |
(ctx) ([]LogGroupInfo, error) |
| Operation | Signature |
|---|---|
CreateLogStream |
(ctx, logGroup, streamName) (*LogStreamInfo, error) |
DeleteLogStream |
(ctx, logGroup, streamName) error |
ListLogStreams |
(ctx, logGroup) ([]LogStreamInfo, error) |
| Operation | Signature |
|---|---|
PutLogEvents |
(ctx, logGroup, streamName, events) error |
GetLogEvents |
(ctx, input) ([]LogEvent, error) |
| Operation | Signature |
|---|---|
FilterLogEvents |
(ctx, input) ([]FilteredLogEvent, error) |
PutMetricFilter |
(ctx, config) error |
DeleteMetricFilter |
(ctx, logGroup, filterName) error |
DescribeMetricFilters |
(ctx, logGroup) ([]MetricFilterInfo, error) |
Total: 13 operations
Driver interface: services/notification/driver/driver.go
AWS: SNS | Azure: Notification Hubs | GCP: FCM
| Operation | Signature |
|---|---|
CreateTopic |
(ctx, config) (*TopicInfo, error) |
DeleteTopic |
(ctx, id) error |
GetTopic |
(ctx, id) (*TopicInfo, error) |
ListTopics |
(ctx) ([]TopicInfo, error) |
| Operation | Signature |
|---|---|
Subscribe |
(ctx, config) (*SubscriptionInfo, error) |
Unsubscribe |
(ctx, subscriptionID) error |
ListSubscriptions |
(ctx, topicID) ([]SubscriptionInfo, error) |
| Operation | Signature |
|---|---|
Publish |
(ctx, input) (*PublishOutput, error) |
Total: 8 operations
Driver interface: services/containerregistry/driver/driver.go
AWS: ECR | Azure: ACR | GCP: Artifact Registry
| Operation | Signature |
|---|---|
CreateRepository |
(ctx, config) (*Repository, error) |
DeleteRepository |
(ctx, name, force) error |
GetRepository |
(ctx, name) (*Repository, error) |
ListRepositories |
(ctx) ([]Repository, error) |
| Operation | Signature |
|---|---|
PutImage |
(ctx, manifest) (*ImageDetail, error) |
GetImage |
(ctx, repository, reference) (*ImageDetail, error) |
ListImages |
(ctx, repository) ([]ImageDetail, error) |
DeleteImage |
(ctx, repository, reference) error |
TagImage |
(ctx, repository, sourceRef, targetTag) error |
| Operation | Signature |
|---|---|
PutLifecyclePolicy |
(ctx, repository, policy) error |
GetLifecyclePolicy |
(ctx, repository) (*LifecyclePolicy, error) |
EvaluateLifecyclePolicy |
(ctx, repository) ([]string, error) |
| Operation | Signature |
|---|---|
StartImageScan |
(ctx, repository, reference) (*ScanResult, error) |
GetImageScanResults |
(ctx, repository, reference) (*ScanResult, error) |
Total: 14 operations
Driver interface: services/eventbus/driver/driver.go
AWS: EventBridge | Azure: Event Grid | GCP: Eventarc
| Operation | Signature |
|---|---|
CreateEventBus |
(ctx, config) (*EventBusInfo, error) |
DeleteEventBus |
(ctx, name) error |
GetEventBus |
(ctx, name) (*EventBusInfo, error) |
ListEventBuses |
(ctx) ([]EventBusInfo, error) |
| Operation | Signature |
|---|---|
PutRule |
(ctx, config) (*Rule, error) |
DeleteRule |
(ctx, eventBus, ruleName) error |
GetRule |
(ctx, eventBus, ruleName) (*Rule, error) |
ListRules |
(ctx, eventBus) ([]Rule, error) |
EnableRule |
(ctx, eventBus, ruleName) error |
DisableRule |
(ctx, eventBus, ruleName) error |
| Operation | Signature |
|---|---|
PutTargets |
(ctx, eventBus, ruleName, targets) error |
RemoveTargets |
(ctx, eventBus, ruleName, targetIDs) error |
ListTargets |
(ctx, eventBus, ruleName) ([]Target, error) |
| Operation | Signature |
|---|---|
PutEvents |
(ctx, events) (*PublishResult, error) |
| Operation | Signature |
|---|---|
GetEventHistory |
(ctx, eventBus, limit) ([]Event, error) |
Total: 15 operations
Driver interface: services/relationaldb/driver/driver.go
AWS: rds (covers Aurora, Neptune, and DocumentDB engines), redshift | Azure: sql, postgresflex, mysqlflex | GCP: cloudsql, alloydb
A single portable interface backs every RDBMS handler. Engine selection (MySQL / PostgreSQL / Aurora / Neptune / DocumentDB / Redshift / Cloud SQL / Azure SQL / AlloyDB / …) is a field on the input config, not a separate driver.
AlloyDB (GCP): a PostgreSQL-compatible managed database served on the alloydb.googleapis.com/v1 REST API (server/gcp/alloydb). It reuses the relational driver — AlloyDB clusters map to Cluster, instances (PRIMARY / READ_POOL / SECONDARY) to Instance, and cluster backups to ClusterSnapshot — plus the Users and Databases capabilities. AlloyDB-specific behavior (instance types, machine vCPU config, cross-region secondary clusters + promote, instance failover/restart, continuous/automated backup config) lives in the optional AlloyDB capability. Because AlloyDB's REST paths (/v1/projects/{p}/locations/{l}/clusters…) are identical to GKE's, the two cannot be multiplexed on one server; the combined GCP server leaves Drivers.AlloyDB nil and callers inject it in place of GKE.
| Operation | Signature |
|---|---|
CreateInstance |
(ctx, InstanceConfig) (*Instance, error) |
DescribeInstances |
(ctx, ids) ([]Instance, error) |
ModifyInstance |
(ctx, id, ModifyInstanceInput) (*Instance, error) |
DeleteInstance |
(ctx, id) error |
StartInstance |
(ctx, id) error |
StopInstance |
(ctx, id) error |
RebootInstance |
(ctx, id) error |
| Operation | Signature |
|---|---|
CreateCluster |
(ctx, ClusterConfig) (*Cluster, error) |
DescribeClusters |
(ctx, ids) ([]Cluster, error) |
ModifyCluster |
(ctx, id, ModifyInstanceInput) (*Cluster, error) |
DeleteCluster |
(ctx, id) error |
StartCluster |
(ctx, id) error |
StopCluster |
(ctx, id) error |
| Operation | Signature |
|---|---|
CreateSnapshot |
(ctx, SnapshotConfig) (*Snapshot, error) |
DescribeSnapshots |
(ctx, ids, instanceID) ([]Snapshot, error) |
DeleteSnapshot |
(ctx, id) error |
RestoreInstanceFromSnapshot |
(ctx, RestoreInstanceInput) (*Instance, error) |
| Operation | Signature |
|---|---|
CreateClusterSnapshot |
(ctx, ClusterSnapshotConfig) (*ClusterSnapshot, error) |
DescribeClusterSnapshots |
(ctx, ids, clusterID) ([]ClusterSnapshot, error) |
DeleteClusterSnapshot |
(ctx, id) error |
RestoreClusterFromSnapshot |
(ctx, RestoreClusterInput) (*Cluster, error) |
DB subnet groups are an AWS concept — Azure and GCP place managed databases with
vnet integration instead. The SubnetGroups interface is therefore kept out of
RelationalDB and discovered by type assertion; drivers that do not implement it
answer InvalidAction.
| Operation | Signature |
|---|---|
CreateDBSubnetGroup |
(ctx, SubnetGroupConfig) (*SubnetGroup, error) |
DescribeDBSubnetGroups |
(ctx, names) ([]SubnetGroup, error) |
DeleteDBSubnetGroup |
(ctx, name) error |
VPCID is derived from the member subnets rather than supplied by the caller,
matching the real service. Callers tearing down a VPC list subnet groups and
match on it.
DB and DB cluster parameter groups. Only user-set parameters are modeled;
the emulator does not fabricate the hundreds of engine defaults real AWS
returns. Real AWS reuses the DBParameterGroup* fault codes for the cluster
variants, so error mapping is shared.
| Operation | Signature |
|---|---|
CreateDBParameterGroup |
(ctx, ParameterGroupConfig) (*ParameterGroup, error) |
DescribeDBParameterGroups |
(ctx, names) ([]ParameterGroup, error) |
ModifyDBParameterGroup |
(ctx, name, []Parameter) (*ParameterGroup, error) |
DeleteDBParameterGroup |
(ctx, name) error |
DescribeDBParameters |
(ctx, name) ([]Parameter, error) |
ResetDBParameterGroup |
(ctx, name, params, resetAll) (*ParameterGroup, error) |
CopyDBParameterGroup |
(ctx, source, target, description) (*ParameterGroup, error) |
CreateDBClusterParameterGroup … CopyDBClusterParameterGroup |
cluster-scoped analogues (7) |
| Operation | Signature |
|---|---|
CreateOptionGroup |
(ctx, OptionGroupConfig) (*OptionGroup, error) |
DescribeOptionGroups |
(ctx, names, engineName) ([]OptionGroup, error) |
ModifyOptionGroup |
(ctx, name, include, remove) (*OptionGroup, error) |
DeleteOptionGroup |
(ctx, name) error |
CopyOptionGroup |
(ctx, source, target, description) (*OptionGroup, error) |
DescribeOptionGroupOptions |
(ctx, engineName, majorEngineVersion) ([]OptionGroupOption, error) |
DescribeOptionGroupOptions returns a representative per-engine catalog of
well-known option names, not AWS's exhaustive version-specific list.
| Operation | Signature |
|---|---|
CreateDBInstanceReadReplica |
(ctx, ReadReplicaConfig) (*Instance, error) |
PromoteReadReplica |
(ctx, id) (*Instance, error) |
A replica inherits its source's engine/version/storage; the source tracks its replica IDs and the replica records its source. Promotion detaches it.
| Operation | Signature |
|---|---|
CopyDBSnapshot |
(ctx, source, target, tags) (*Snapshot, error) |
CopyDBClusterSnapshot |
(ctx, source, target, tags) (*ClusterSnapshot, error) |
RestoreDBInstanceToPointInTime |
(ctx, RestoreInstanceToPointInTimeInput) (*Instance, error) |
RestoreDBClusterToPointInTime |
(ctx, RestoreClusterToPointInTimeInput) (*Cluster, error) |
The emulator retains no historical timeline, so PITR clones the source's
current spec; RestoreTime / UseLatestRestorableTime are accepted but not
replayed.
A proxy has a single implicit default target group; targets are RDS instances
(RDS_INSTANCE) or clusters (TRACKED_CLUSTER), validated on registration.
| Operation | Signature |
|---|---|
CreateDBProxy / DescribeDBProxies / ModifyDBProxy / DeleteDBProxy |
proxy lifecycle (4) |
RegisterDBProxyTargets / DeregisterDBProxyTargets / DescribeDBProxyTargets |
target membership (3) |
DescribeDBProxyTargetGroups |
(ctx, name) ([]ProxyTargetGroup, error) |
| Operation | Signature |
|---|---|
CreateEventSubscription / DescribeEventSubscriptions / ModifyEventSubscription / DeleteEventSubscription |
subscription CRUD (4) |
DescribeEvents |
(ctx, sourceType, sourceID, categories) ([]Event, error) — empty: no event timeline is retained |
DescribeEventCategories |
(ctx, sourceType) ([]EventCategoryGroup, error) |
ClusterEndpoints:CreateDBClusterEndpoint/DescribeDBClusterEndpoints/ModifyDBClusterEndpoint/DeleteDBClusterEndpoint(4).ClusterFailover:FailoverDBClusterpromotes the target member to writer, or rotates the first reader when no target is given (1).GlobalClusters:CreateGlobalCluster/DescribeGlobalClusters/ModifyGlobalCluster/DeleteGlobalCluster/RemoveFromGlobalCluster(5).
Metadata:DescribeDBEngineVersions,DescribeOrderableDBInstanceOptions— representative per-engine catalogs (2).Tagging:AddTagsToResource,RemoveTagsFromResource,ListTagsForResource— addressed by resource ARN over the tag-bearing stores (instances, clusters, instance/cluster snapshots) (3).
Each managed-SQL service also exposes its cloud's own child resources and
actions. Like the RDS capabilities above, these are kept out of the core
RelationalDB interface and discovered by type assertion, so a driver only
answers for the resources its cloud actually has; others return InvalidAction.
The server handlers reach them the way real SDK clients do (ARM sub-resource
routes for Azure, sqladmin sub-collections for Cloud SQL), and the mocks
cascade-delete children when their parent server/instance is deleted.
| Capability | Operations | Implemented by |
|---|---|---|
Databases |
Create / Get / List / Delete | mysqlflex, postgresflex, cloudsql, alloydb |
FirewallRules |
Create / Get / List / Delete | mysqlflex, postgresflex, sql |
Configurations |
Set / Get / List (server parameters) | mysqlflex, postgresflex |
Failover |
FailoverInstance |
mysqlflex, cloudsql |
VNetRules |
Create / Get / List / Delete | sql |
ElasticPools |
Create / Get / List / Delete | sql |
FailoverGroups |
Create / Get / List / Delete / Failover | sql |
AADAdmins |
Set / Get / List / Delete | sql |
Users |
Create / Get / List / Update / Delete | cloudsql, alloydb |
SslCerts |
Create / Get / List / Delete | cloudsql |
Clonable |
CloneInstance |
cloudsql |
ReplicaPromotion |
PromoteReplica |
cloudsql |
ManagedInstances |
managed-instance CRUD + Start/Stop/Failover, managed-database CRUD/List | sql |
AlloyDB |
AlloyDB cluster/instance create, CreateSecondary/Promote, instance Failover/Restart, *Info accessors |
alloydb |
Cloud SQL also serves the startReplica/stopReplica instance actions (mapped
onto Start/Stop) and the static tiers (/v1/projects/{p}/tiers) and flags
(/v1/flags) reference catalogs. Azure SQL adds the SQL Managed Instance family
(Microsoft.Sql/managedInstances + managed databases) alongside the
single-database logical server. Managed relational servers surface in
cross-service discovery (Azure Resource Graph as microsoft.sql/servers,
microsoft.dbformysql/flexibleservers,
microsoft.dbforpostgresql/flexibleservers; GCP Cloud Asset as
sqladmin.googleapis.com/Instance), are billed per instance-hour via the
relationaldb:* cost catalog, and emit their cloud's monitoring metrics
(including the Microsoft.Sql/servers/elasticpools pool namespace).
Total: 21 core operations + 109 optional across 25 type-asserted capability
interfaces — the 12 RDS-oriented ones (SubnetGroups, ParameterGroups,
OptionGroups, ReadReplicas, AdvancedRestore, DBProxies,
EventSubscriptions, ClusterEndpoints, ClusterFailover, GlobalClusters,
Metadata, Tagging) plus the 13 Azure/GCP managed-SQL ones (Databases,
FirewallRules, Configurations, Failover, VNetRules, ElasticPools,
FailoverGroups, AADAdmins, Users, SslCerts, Clonable,
ReplicaPromotion, ManagedInstances). Each cloud implements the subset that
maps to a real resource and answers InvalidAction otherwise.
Control plane: AWS eks, Azure aks, GCP gke — cluster, node-pool, and addon / Fargate-profile / maintenance-config lifecycle, driven by the real cloud SDKs.
Data plane: shared services/kubernetes/ package — an in-memory Kubernetes API server registered by every cluster across all three providers. Kubeconfigs returned by the control plane point at <base>/k8s/<cluster-uid> so client-go and kubectl operate end-to-end.
Each provider exposes its native control-plane API. The data plane has no portable driver — clients connect via the kubeconfig the control plane hands out, then talk standard Kubernetes REST.
| Resource | Operations |
|---|---|
| Clusters | CreateCluster, DescribeCluster, ListClusters, UpdateClusterConfig, UpdateClusterVersion, DeleteCluster |
| Node Groups | CreateNodegroup, DescribeNodegroup, ListNodegroups, UpdateNodegroupConfig, UpdateNodegroupVersion, DeleteNodegroup |
| Fargate Profiles | CreateFargateProfile, DescribeFargateProfile, ListFargateProfiles, DeleteFargateProfile |
| Addons | CreateAddon, DescribeAddon, ListAddons, UpdateAddon, DeleteAddon |
Operations: 21
| Resource | Operations |
|---|---|
| Managed Clusters | CreateOrUpdateCluster, GetCluster, UpdateClusterTags, DeleteCluster, ListClusters, ListClustersByResourceGroup, RotateClusterCertificates |
| Agent Pools | CreateOrUpdateAgentPool, GetAgentPool, DeleteAgentPool, ListAgentPools |
| Maintenance Configs | CreateOrUpdateMaintenanceConfig, GetMaintenanceConfig, DeleteMaintenanceConfig, ListMaintenanceConfigs |
| Credentials | ListClusterAdminCredentials, ListClusterUserCredentials, ListClusterMonitoringUserCredentials — return a kubeconfig pointing at the in-memory data plane (or the *-DATAPLANE-NOT-IMPLEMENTED.cloudemu.local sentinel when no APIServer is wired) |
Operations: 18
| Resource | Operations |
|---|---|
| Clusters | CreateCluster, GetCluster, ListClusters, UpdateCluster, DeleteCluster, SetClusterLogging, SetClusterMonitoring, SetMasterAuth, SetLegacyAbac, SetNetworkPolicy, SetMaintenancePolicy, SetResourceLabels, StartIPRotation, CompleteIPRotation |
| Node Pools | CreateNodePool, GetNodePool, ListNodePools, UpdateNodePool, DeleteNodePool, SetNodePoolSize, SetNodePoolAutoscaling, SetNodePoolManagement, RollbackNodePool |
| Operations | GetOperation, ListOperations, CancelOperation |
Operations: 26
Shared in-memory K8s API server registered by every cluster from any provider. URL: <base>/k8s/<cluster-uid>/.... Served over real TLS: the control plane advertises a shared CA (internal/k8spki) that certifies the serving cert, so client-go and kubectl validate the connection normally — kubeconfigs carry certificate-authority-data, not insecure-skip-tls-verify.
Real kubectl works end-to-end, not just client-go: the server decodes the protobuf request bodies kubectl sends on writes (it accepts protobuf and replies JSON, which kubectl's Accept allows), and serves an OpenAPI v3 discovery document (plus a protobuf v2 for the legacy path) carrying every served GVK so kubectl apply validation passes. Verified against kubectl v1.36 across all three providers: create/apply/scale/set image/patch/rollout/delete, get with short names (pvc, hpa, sts, …), and cascade teardown.
It behaves like a tiny always-converged cluster (minikube-like) rather than a bare object store: a synchronous reconcile engine runs on every write — there are no controller goroutines, so results are immediate and deterministic. Controllers materialize Running Pods, Services get Endpoints, PVCs bind, Jobs complete.
Discovery is derived from the resource registry (registeredResources()), so /api, /apis, and every /apis/<group>/<version> list exactly the resources the server serves — discovery can't promise a kind that 404s.
Core (core/v1): Namespace, ConfigMap, Secret (StringData merged into Data), ServiceAccount (default auto-created per namespace), Pod (driven Running with a synthetic Pod IP — a directly-created Pod with a terminal phase is preserved), Service (ClusterIP from 10.96.0.0/12, immutable on update), Endpoints (get/list/watch only — auto-managed per Service), PersistentVolumeClaim (→ Bound), PersistentVolume (→ Available), Node, Event, ResourceQuota, LimitRange.
Workload controllers (apps/v1): Deployment, ReplicaSet, StatefulSet (stable -0..-N names + one Bound PVC per volumeClaimTemplate), DaemonSet (one Pod per node whose labels satisfy the template nodeSelector and whose taints the pod tolerates — zero Pods when nothing matches; under multi-node it fans out one Pod per matching+tolerated node, e.g. kube-proxy on all N). A Deployment interposes a ReplicaSet per pod-template revision (Deployment→RS→Pod, matching real topology), and a template change creates a new ReplicaSet and deletes the old one outright — an instantaneous swap (no revisionHistoryLimit, no kubectl rollout undo, no surge/unavailable pacing). All materialize Running Pods owned via ownerReferences; deleting a controller cascade-deletes the chain and drains Endpoints. Deployments/StatefulSets expose /scale and /status subresources. CronJob scheduling is driven explicitly via TickCronJobs() (no background timer), which performs real due-evaluation against the cluster clock: it parses the standard 5-field spec.schedule (*, */n, lists, a-b ranges) and materializes a Job only when a scheduled time falls in (status.lastScheduleTime, now] — advancing lastScheduleTime to the fired slot so re-ticking the same instant never double-creates — and honors concurrencyPolicy (Forbid/Replace/Allow) and startingDeadlineSeconds.
Other groups (registry-backed CRUD + list/watch/patch/delete): batch/v1 Job (→ Succeeded Pods) / CronJob; networking.k8s.io/v1 Ingress (→ load-balancer IP) / IngressClass / NetworkPolicy; rbac.authorization.k8s.io/v1 Role / RoleBinding / ClusterRole / ClusterRoleBinding; storage.k8s.io/v1 StorageClass; autoscaling/v2 HorizontalPodAutoscaler; discovery.k8s.io/v1 EndpointSlice; policy/v1 PodDisruptionBudget; apiextensions.k8s.io/v1 CustomResourceDefinition; admissionregistration.k8s.io/v1 Mutating/ValidatingWebhookConfiguration.
Custom resources (CRDs): creating a CustomResourceDefinition dynamically materializes a servable store for every served version — the custom-resource kind is then served by the generic handler (CRUD/list/watch//status) and advertised in discovery immediately; the CRD is marked Established. Deleting the CRD deregisters the kind and cascade-deletes its custom resources — including when the CRD carries a finalizer, in which case teardown runs once the last finalizer drains. Structural schema validation of CRs is a documented simplification (accept-and-store).
Selectors & pagination: label selectors on list; field selectors for metadata.name / metadata.namespace, Pod status.phase / spec.nodeName, and Event fields (involvedObject.name/namespace/kind/uid, reason, type). List responses honor ?limit=&continue= chunked pagination across the registry and typed list paths: the metadata.continue token is key-anchored (it encodes the last object's namespace/name), so an insert or delete before that key cannot skip or duplicate later items under concurrent mutation, and a malformed token returns 410 Gone (reason Expired) per client-go's pager contract. A well-formed token whose key was since deleted resumes gracefully at the next greater key rather than 410-ing on a compacted resourceVersion — strictly more forgiving than upstream.
Patch & server-side apply: JSON-merge-patch, JSONPatch (RFC 6902), and strategic-merge-patch (real strategic merge against the typed struct for core/apps kinds, so kubectl set image merges the container list by name). Server-side apply (application/apply-patch+yaml) tracks per-fieldManager field ownership in metadata.managedFields; an apply that changes a field owned by another manager returns 409 Conflict unless ?force=true (which transfers ownership), and an owner re-applying the same value is a no-op. A re-apply by the same manager that omits a field it previously owned removes that field, unless another manager also owns it. Plain PUT/PATCH updates record an Update-operation managedFields entry for their fieldManager (defaulted from the User-Agent when absent), taking or sharing ownership rather than conflicting (only Apply-vs-Apply is a 409). Ownership is tracked at leaf granularity (map keys / whole arrays) — per-element list merging is not modeled, a documented subset of upstream SSA.
Dry-run: writes with ?dryRun=All (kubectl apply|create|delete --dry-run=server) run validation, defaulting, and quota admission (a create against an at-limit namespace returns the same 403 a real create would), echo the object the server would store, and persist nothing — no resourceVersion bump, reconcile, quota reservation, or watch event.
Finalizers: an object carrying metadata.finalizers goes Terminating on delete (deletionTimestamp stamped, object retained) and is removed only when the last finalizer is cleared via update/patch — on the registry path and typed Namespace/Pod. Finalizers are also honored during cascade: a finalizer-bearing child reached by owner garbage-collection or namespace teardown goes Terminating rather than being reaped, until its finalizers drain. The server-owned deletionTimestamp survives a merge-patch — an RFC-7396 null cannot resurrect a Terminating object.
Pod subresources: pods/{name}/log returns synthetic container output; exec and attach complete the WebSocket streaming upgrade (v5.channel.k8s.io, plus v4 and the base protocols) and run a deterministic synthetic session — a self-describing banner on stdout (exec also echoes the requested command) followed by a Success Status on the error channel (exit 0) — there is no real container runtime, so no command actually runs and nothing is written to disk; a non-WebSocket (SPDY-only) client still gets a clean typed Status. portforward still returns a typed 501 (deferred). pods/{name}/eviction honors PodDisruptionBudgets.
Metrics & autoscaling: metrics.k8s.io/v1beta1 (kubectl top) serves synthetic Pod/Node metrics from the live pods + synthetic node; a HorizontalPodAutoscaler reconcile drives its target Deployment on a Resource CPU averageUtilization metric — sampling the target Pods' CPU from that metrics source and applying the real HPA ratio desiredReplicas = ceil(currentReplicas × currentUtilization ÷ targetUtilization), clamped into [minReplicas, maxReplicas] — and falls back to a plain min/max clamp when no CPU metric is configured or the target Pods declare no CPU request, reporting currentReplicas/desiredReplicas/currentMetrics on status.
Policy enforcement: object-count ResourceQuota is enforced on create (403 over limit) and on server-side dry-run; status.used is updated on create and recomputed from the live count on delete (it tracks the live object count rather than climbing monotonically); LimitRange applies container defaults and min/max validation on pod create; PodDisruptionBudget gates pods/eviction (429 when eviction would violate the budget); RBAC is queryable via authorization.k8s.io/v1 SubjectAccessReview (evaluated against stored Roles/ClusterRoles + bindings); NetworkPolicy is queryable via an in-process evaluation (no live traffic).
Admission webhooks (opt-in): Mutating/ValidatingWebhookConfiguration objects store and round-trip through kubectl apply. With admission explicitly enabled (APIServer.SetAdmissionEnabled), create/update/patch calls matching webhooks apply mutations and honor denials (4xx); it is off by default so the data plane stays zero-network and deterministic.
Watch resume: a watch with resourceVersion>0 skips the initial snapshot replay and streams only subsequent events; allowWatchBookmarks=true emits a post-sync BOOKMARK carrying the current resourceVersion. A slow watcher that overflows its buffer gets a 410 Gone so client-go relists.
Deterministic time: every data-plane timestamp (creationTimestamp, pod start/conditions, managedFields) is sourced from an injectable clock (APIServer.SetClock); a config.FakeClock makes them fully deterministic for tests.
Persistence: the data plane is part of the standalone server's snapshot surface — every cluster's state (namespaces, pods, deployments, services/endpoints, all registry kinds, and CRDs + custom resources) is captured keyed by cluster UID, so a --persist stop/start or a crash restores each cluster under the same /k8s/<uid> endpoint with a pre-restart kubeconfig still valid. A watch open across the restart relists rather than resuming (no cross-restart event history).
Watch streaming: each list endpoint accepts ?watch=true and upgrades to a Transfer-Encoding: chunked JSON event stream ({"type":"ADDED|MODIFIED|DELETED","object":{...}}). Initial state replays as ADDED events on subscribe, and the request's labelSelector/fieldSelector filters both the initial snapshot and live events, so client-go Informer / SharedIndexInformer machinery (operator-sdk, Helm, ArgoCD, …) — including selective informers — just works. A fresh cluster bootstraps a synthetic Ready node (cloudemu-node-0), and each selector Service's endpoints are mirrored into a discovery.k8s.io EndpointSlice so EndpointSlice-mode consumers see the same backends as the Endpoints object.
Cascade: deleting a Namespace or an owning controller publishes DELETED events for every child resource (garbage collection follows ownerReferences) — finalizer-bearing children instead go Terminating (MODIFIED) until drained.
kubectl display fidelity: list/get endpoints honor server-side Table printing (Accept: application/json;as=Table;g=meta.k8s.io;v=v1), returning a meta.k8s.io/v1 Table with the real per-kind columns — so kubectl get pods/deployments/services/nodes/... shows READY/STATUS/UP-TO-DATE/AVAILABLE/etc. (plus -o wide extras) instead of raw JSON, and unknown kinds fall back to NAME/AGE. Every list also carries a collection-level resourceVersion (a single monotonic cluster counter), so client-go reflectors and kubectl rollout status complete their List→Watch handshake rather than hanging.
Events: controllers emit standard core/v1 Events during reconcile — ScalingReplicaSet (Deployment, on an actual replica-count change), SuccessfulCreate (ReplicaSet/StatefulSet/DaemonSet/Job/CronJob pods), Scheduled (Pod placement), Started/Completed — deduplicated by (involvedObject, reason, message, type) with a rolling count, so kubectl describe and kubectl get events show real activity. The synthetic node reports a Ready condition, capacity/allocatable, and a coordination.k8s.io Lease in kube-node-lease.
Opt-in Pod lifecycle progression: by default Pods are driven straight to Running (deterministic, no kubelet). Enabling APIServer.SetLifecycleProgression(true) — or cloudemu serve --k8s-progression (env CLOUDEMU_K8S_PROGRESSION) — instead starts each Pod Pending and advances it Pending → ContainerCreating → Running (and → Terminating on delete) on a logical clock, emitting the kubelet Event sequence at each step. In tests the transitions are driven explicitly via Tick() (fully deterministic under FakeClock); a live cloudemu serve runs a real-time ticker (--k8s-progression-interval, default 1s) so Pods visibly progress.
Emulation boundaries (deliberate simplifications, not gaps): there is no real kubelet — Pods are driven Running synthetically (or through the opt-in staged progression above), pods/log is synthetic, and exec/attach serve a deterministic synthetic WebSocket session (banner + echoed command, exit 0) rather than executing anything in a real container while pods/portforward returns a typed 501; scheduling defaults to a single synthetic node (cloudemu-node-0, instant-Running), and cloudemu serve --k8s-nodes N (opt-in, fixed at cluster creation and immutable thereafter) seeds N nodes — 1 control-plane carrying a node-role.kubernetes.io/control-plane:NoSchedule taint plus workers — behind a deterministic first-fit scheduler that honors spec.nodeName, nodeSelector, taints/tolerations (NoSchedule/NoExecute), and resource requests-vs-allocatable, leaving an unplaceable Pod Pending with PodScheduled=False/Unschedulable and a FailedScheduling event; node & inter-pod affinity, topology spread, scoring/bin-packing, and tolerationSeconds/live eviction are still not modeled; admission webhooks make outbound calls only when explicitly enabled (off by default to stay zero-network); server-side apply tracks ownership at leaf granularity (no per-element list merge); NetworkPolicy and RBAC are queryable (SubjectAccessReview / EvaluateNetworkPolicy) rather than request-time-enforced, since the emulator has no packet path or authenticated identity; CronJob has no wall-clock timer (schedules are evaluated only when TickCronJobs is called) and supports only the standard 5-field cron syntax (nonstandard @-macros, L/W/#/? characters, and seconds/year fields are rejected); rollouts converge instantly (no surge/unavailable pacing, minimal revision history); and OpenAPI is served cluster-independently, so CRD schemas aren't published there (custom resources still work via discovery).
Engine: services/resourcediscovery/ — a cross-service inventory engine that walks the Compute, Networking, Storage, Database, Serverless, Databricks, Kubernetes, and Relational Database drivers of any provider and returns a normalized Resource view (provider, service, type, ID, ARN/URN, region, tags, created-at). Auto-wired by every provider factory and exposed as Provider.ResourceDiscovery.
SDK-compat handlers: AWS Resource Explorer Two + Resource Groups Tagging API, Azure Resource Graph, and GCP Cloud Asset Inventory. All three sit on top of the same engine, so a tag written through any one path is visible through the others.
Surfaced resource types (portable service/Type → per-provider inventory string):
| Portable | AWS RE2 | Azure Resource Graph | GCP Cloud Asset |
|---|---|---|---|
compute/Instance |
compute:instance |
microsoft.compute/virtualmachines |
compute.googleapis.com/Instance |
networking/VPC · Subnet · SecurityGroup · NetworkInterface · ElasticIP |
networking:* |
microsoft.network/* |
compute.googleapis.com/* |
storage/Bucket |
storage:bucket |
microsoft.storage/storageaccounts |
storage.googleapis.com/Bucket |
database/Table |
database:table |
microsoft.documentdb/databaseaccounts |
firestore.googleapis.com/Database |
serverless/Function |
serverless:function |
microsoft.web/sites |
cloudfunctions.googleapis.com/Function |
databricks/Workspace |
— | microsoft.databricks/workspaces |
— |
kubernetes/Cluster |
kubernetes:cluster |
microsoft.containerservice/managedclusters |
container.googleapis.com/Cluster |
kubernetes/NodeGroup |
kubernetes:nodegroup |
microsoft.containerservice/managedclusters/agentpools |
container.googleapis.com/NodePool |
Kubernetes clusters (EKS/GKE/AKS) and their node groups (nodegroups / node pools / agent pools) are surfaced via a KubernetesClusters discovery adapter each provider wires in over its cluster mock.
Relational databases follow the same pattern via a RelationalDatabases adapter: AWS RDS/Aurora instances, clusters, and snapshots surface through Resource Explorer 2 (filter service:rds) via the rdsDiscovery adapter. GCP Cloud SQL and Azure SQL discovery are not yet wired.
| Operation | Signature |
|---|---|
New |
(provider, accountID, region string, drivers *Drivers) *Engine |
ListAll |
(ctx) ([]Resource, error) |
List |
(ctx, Query) ([]Resource, error) — filter by Services, Type, Region, Tags |
SearchByTag |
(ctx, key, value string) ([]Resource, error) |
GetTagKeys |
(ctx) ([]string, error) |
GetTagValues |
(ctx, key string) ([]string, error) |
TagResourceByARN |
(ctx, arn string, tags map[string]string) error |
UntagResourceByARN |
(ctx, arn string, keys []string) error |
| Operation | Notes |
|---|---|
Search |
Free-text + filter expression over the unified inventory; returns ARN, resource type, region, owning account, tags |
| Operation | Notes |
|---|---|
GetResources |
Filter by ResourceTypeFilters and TagFilters; pagination via PaginationToken |
TagResources |
Apply a tag set to one or more ARNs in a single call |
UntagResources |
Remove tag keys from one or more ARNs in a single call |
GetTagKeys |
All tag keys across the inventory |
GetTagValues |
All values for a given tag key |
| Operation | Notes |
|---|---|
Resources |
POST /providers/Microsoft.ResourceGraph/resources?api-version=2022-10-01 — KQL-shaped query over the unified inventory; supports subscriptions[] scoping and $top/$skipToken pagination |
Cost-discovery field projection. Each row projects the sku (name/tier/capacity)
and properties a real discoverer prices on, per Azure type:
| Azure type | Projected fields |
|---|---|
microsoft.compute/virtualmachines |
properties.priority (Spot), properties.licenseType, properties.storageProfile.osDisk.osType, sku.name, zones |
microsoft.compute/disks |
properties.diskIOPSReadWrite, properties.diskMBpsReadWrite, properties.diskSizeGB, properties.tier, sku.name/sku.tier |
microsoft.compute/virtualmachinescalesets |
sku.name/sku.capacity, nested properties.virtualMachineProfile.{priority,licenseType,storageProfile.osDisk.osType} |
microsoft.network/publicipaddresses |
sku.name (Basic/Standard), properties.publicIPAllocationMethod |
microsoft.network/virtualnetworks / subnets |
properties.addressSpace.addressPrefixes / properties.addressPrefix |
microsoft.sql/managedinstances |
sku.name, properties.vCores, properties.tier, properties.licenseType, properties.storageSizeInGB, properties.storageAccountType (backup redundancy) |
microsoft.sql/servers |
properties.version (engine version of the logical server) |
microsoft.sql/servers/databases |
sku.name, properties.currentSku, properties.zoneRedundant |
microsoft.dbformysql/dbforpostgresql flexibleservers |
sku.name/sku.tier (derived), properties.version, nested properties.storage.storageSizeGB + properties.highAvailability.mode |
microsoft.containerservice/managedclusters |
sku.tier, properties.powerState.code, properties.kubernetesVersion |
.../managedclusters/agentpools |
sku.name (vmSize), properties.scaleSetPriority (Spot), properties.count, properties.mode/osType |
microsoft.databricks/workspaces |
sku.name/sku.tier, properties.workspaceId/provisioningState |
microsoft.storage/storageaccounts |
sku.name (redundancy), kind, properties.accessTier |
microsoft.documentdb/databaseaccounts |
kind, properties.databaseAccountOfferType, properties.capabilities (serverless), properties.enableFreeTier |
microsoft.web/serverfarms (App Service plan) |
sku.name/sku.tier/sku.capacity (pricing tier), kind |
Fields are seeded through the portable driver configs (VolumeConfig.IOPS/Throughput/Tier,
InstanceConfig.OSType/Priority/LicenseType/Zones, ManagedInstanceConfig.StorageAccountType,
ElasticIPConfig.SKU/AllocationMethod, the AKS Tier/ScaleSetPriority inputs, the
Databases capability on Azure SQL, the VMSS ScaleSets + serverfarms AppServicePlans
discovery capabilities, and the optional BucketAttributes / TableAttributes capabilities
that enrich storage accounts and Cosmos DB) so a value set at create time round-trips over
the real armresourcegraph SDK. Storage/Cosmos/serverfarms follow the established discovery
patterns — optional type-asserted capabilities (like networking's NetworkInterfaces) for
per-resource enrichment, and provider-projected discovery adapters (like the relational-DB
and Kubernetes walkers) for the net-new plan/scale-set resources.
| Resource | Operations |
|---|---|
| Assets | assets.list (filter by assetTypes[]), searchAllResources (query string + asset-type filter), searchAllIamPolicies (returns empty — out of scope) |
| Export | exportAssets — synchronous, returns an Operation with inline results |
| Feeds | feeds.create, feeds.list, feeds.get, feeds.patch, feeds.delete |
| Operations | operations.get — fetches cached exportAssets results |
| Batch | batchGetAssetsHistory |
Operations: Engine 8 + AWS Resource Explorer 1 + AWS Resource Groups Tagging 5 + Azure Resource Graph 1 + GCP Cloud Asset 11 = 26
Driver interface: services/bedrock/driver/driver.go
AWS: bedrock (+ bedrock-runtime) | Azure: — | GCP: —
AWS-only. Backs the real aws-sdk-go-v2/service/bedrock and .../bedrockruntime clients against the in-memory backend.
| Operation | Signature |
|---|---|
ListFoundationModels |
(ctx) ([]FoundationModel, error) |
GetFoundationModel |
(ctx, modelID) (*FoundationModel, error) |
| Operation | Signature |
|---|---|
CreateModelCustomizationJob |
(ctx, CustomizationJobConfig) (*CustomizationJob, error) |
GetModelCustomizationJob |
(ctx, jobIdentifier) (*CustomizationJob, error) |
ListModelCustomizationJobs |
(ctx) ([]CustomizationJob, error) |
| Operation | Signature |
|---|---|
ListCustomModels |
(ctx) ([]CustomModel, error) |
GetCustomModel |
(ctx, modelIdentifier) (*CustomModel, error) |
DeleteCustomModel |
(ctx, modelIdentifier) error |
| Operation | Signature |
|---|---|
InvokeModel |
(ctx, InvokeModelInput) (*InvokeModelResult, error) |
Converse |
(ctx, ConverseInput) (*ConverseOutput, error) |
| Operation | Signature |
|---|---|
CreateGuardrail |
(ctx, GuardrailConfig) (*Guardrail, error) |
GetGuardrail |
(ctx, identifier, version) (*Guardrail, error) |
ListGuardrails |
(ctx) ([]Guardrail, error) |
UpdateGuardrail |
(ctx, identifier, GuardrailConfig) (*Guardrail, error) |
DeleteGuardrail |
(ctx, identifier) error |
| Operation | Signature |
|---|---|
CreateProvisionedModelThroughput |
(ctx, ProvisionedThroughputConfig) (*ProvisionedThroughput, error) |
GetProvisionedModelThroughput |
(ctx, identifier) (*ProvisionedThroughput, error) |
ListProvisionedModelThroughputs |
(ctx) ([]ProvisionedThroughput, error) |
DeleteProvisionedModelThroughput |
(ctx, identifier) error |
| Operation | Signature |
|---|---|
PutModelInvocationLoggingConfiguration |
(ctx, LoggingConfig) error |
GetModelInvocationLoggingConfiguration |
(ctx) (*LoggingConfig, error) |
DeleteModelInvocationLoggingConfiguration |
(ctx) error |
Total: 22 operations
Driver interfaces: services/databricks/driver/driver.go (control plane), services/databricks/driver/dataplane.go (data plane)
AWS: — | Azure: databricks | GCP: —
Azure-only. The control plane backs the real armdatabricks SDK; the data plane backs the real databricks-sdk-go WorkspaceClient. The SDK-compat-only workspace families (secrets, tokens, git credentials, repos, DBFS, workspace files, SQL warehouses, pipelines, serving endpoints, SCIM identity, Unity Catalog) have no portable Go API — see sdk-server.md.
| Operation | Signature |
|---|---|
CreateWorkspace |
(ctx, WorkspaceConfig) (*Workspace, error) |
GetWorkspace |
(ctx, resourceGroup, name) (*Workspace, error) |
DeleteWorkspace |
(ctx, resourceGroup, name) error |
UpdateWorkspaceTags |
(ctx, resourceGroup, name, tags) (*Workspace, error) |
ListWorkspacesByResourceGroup |
(ctx, resourceGroup) ([]Workspace, error) |
ListWorkspaces |
(ctx) ([]Workspace, error) |
The rest of the Microsoft.Databricks ARM surface beyond workspaces
(services/databricks/driver/arm_resources.go), reachable over the real
armdatabricks SDK:
| Resource | Operations |
|---|---|
Access Connectors (accessConnectors) |
CreateOrUpdateAccessConnector, GetAccessConnector, UpdateAccessConnector, DeleteAccessConnector, ListAccessConnectorsByResourceGroup, ListAccessConnectors |
Private Endpoint Connections (workspaces/{w}/privateEndpointConnections) |
PutPrivateEndpointConnection, GetPrivateEndpointConnection, DeletePrivateEndpointConnection, ListPrivateEndpointConnections |
Private Link Resources (workspaces/{w}/privateLinkResources) |
GetPrivateLinkResource, ListPrivateLinkResources |
VNet Peering (workspaces/{w}/virtualNetworkPeerings) |
CreateOrUpdateVNetPeering, GetVNetPeering, DeleteVNetPeering, ListVNetPeerings |
Outbound Network Dependencies (workspaces/{w}/outboundNetworkDependenciesEndpoints) |
ListOutboundNetworkDependencies |
Operations (/providers/Microsoft.Databricks/operations) |
ListOperations |
Modeled store-and-echo: the ARM resources round-trip faithfully over the SDK
(access connectors and peerings persist and are listed/described; a
system-assigned access-connector identity gets synthesized principal/tenant
IDs; a created peering springs to Connected/Succeeded), but the underlying
Azure networking side effects are not simulated — a private-endpoint
connection stores its approval state without a real private endpoint on the
platform side, private-link resources and outbound-dependency endpoints are a
synthesized (workspace-scoped) catalog rather than a live probe, and a VNet
peering does not actually peer networks. The provider operations list is a
static catalog of the RBAC operations the namespace exposes.
| Operation | Signature |
|---|---|
CreateInstancePool |
(ctx, InstancePoolConfig) (*InstancePool, error) |
GetInstancePool |
(ctx, id) (*InstancePool, error) |
ListInstancePools |
(ctx) ([]InstancePool, error) |
EditInstancePool |
(ctx, id, InstancePoolConfig) error |
DeleteInstancePool |
(ctx, id) error |
| Operation | Signature |
|---|---|
CreateCluster |
(ctx, ClusterConfig) (*Cluster, error) |
GetCluster |
(ctx, id) (*Cluster, error) |
ListClusters |
(ctx) ([]Cluster, error) |
EditCluster |
(ctx, id, ClusterConfig) error |
DeleteCluster |
(ctx, id) error |
PermanentDeleteCluster |
(ctx, id) error |
StartCluster |
(ctx, id) error |
RestartCluster |
(ctx, id) error |
ResizeCluster |
(ctx, id, numWorkers, autoscaleMin, autoscaleMax) error |
PinCluster |
(ctx, id) error |
UnpinCluster |
(ctx, id) error |
ListNodeTypes |
(ctx) ([]NodeType, error) |
ListSparkVersions |
(ctx) ([]SparkVersion, error) |
ListZones |
(ctx) (zones, defaultZone, error) |
| Operation | Signature |
|---|---|
CreateJob |
(ctx, JobConfig) (int64, error) |
GetJob |
(ctx, id) (*Job, error) |
ListJobs |
(ctx) ([]Job, error) |
UpdateJob |
(ctx, id, JobConfig) error |
ResetJob |
(ctx, id, JobConfig) error |
DeleteJob |
(ctx, id) error |
RunJobNow |
(ctx, id) (int64, error) |
| Operation | Signature |
|---|---|
SubmitRun |
(ctx, runName) (int64, error) |
GetRun |
(ctx, runID) (*Run, error) |
ListRuns |
(ctx, jobID) ([]Run, error) |
CancelRun |
(ctx, runID) error |
CancelAllRuns |
(ctx, jobID) error |
DeleteRun |
(ctx, runID) error |
RepairRun |
(ctx, runID) (int64, error) |
GetRunOutput |
(ctx, runID) (*RunOutput, error) |
| Operation | Signature |
|---|---|
CreateClusterPolicy |
(ctx, ClusterPolicyConfig) (*ClusterPolicy, error) |
GetClusterPolicy |
(ctx, policyID) (*ClusterPolicy, error) |
EditClusterPolicy |
(ctx, policyID, ClusterPolicyConfig) error |
DeleteClusterPolicy |
(ctx, policyID) error |
ListClusterPolicies |
(ctx) ([]ClusterPolicy, error) |
| Operation | Signature |
|---|---|
InstallLibraries |
(ctx, clusterID, []LibrarySpec) error |
UninstallLibraries |
(ctx, clusterID, []LibrarySpec) error |
ClusterLibraryStatuses |
(ctx, clusterID) ([]LibraryStatus, error) |
AllClusterLibraryStatuses |
(ctx) ([]ClusterLibraryStatuses, error) |
| Operation | Signature |
|---|---|
GetPermissions |
(ctx, objectType, objectID) (*ObjectPermissions, error) |
SetPermissions |
(ctx, objectType, objectID, acl) (*ObjectPermissions, error) |
UpdatePermissions |
(ctx, objectType, objectID, acl) (*ObjectPermissions, error) |
Total: 70 operations
Driver interface: services/sagemaker/driver/driver.go (control plane + Runtime)
The control plane speaks awsJson1_1 (X-Amz-Target: SageMaker.*); the runtime speaks
restJson1 (POST /endpoints/{name}/invocations). Asynchronous jobs complete synchronously
to a terminal state so Describe/List are deterministic. Auto-metrics → CloudWatch via
SetMonitoring.
| Family | Resources / Operations |
|---|---|
| Jobs | Training, Processing, Transform, HyperParameterTuning, AutoML (V2), Labeling, Compilation — each Create/Describe/List/Stop |
| Inference | Model, EndpointConfig, Endpoint (+ UpdateEndpoint, UpdateEndpointWeightsAndCapacities), InferenceComponent |
| Runtime | InvokeEndpoint, InvokeEndpointAsync (sagemaker-runtime) |
| Model Registry | ModelPackageGroup, ModelPackage (versioned, approval status) |
| Studio | Domain, UserProfile, Space, App |
| Notebooks | NotebookInstance (+ Start/Stop), NotebookInstanceLifecycleConfig, CodeRepository |
| Clusters | HyperPod Cluster (+ ListClusterNodes / DescribeClusterNode) |
| Feature Store | FeatureGroup + online-store runtime (PutRecord / GetRecord / DeleteRecord) |
| Pipelines | Pipeline (+ executions), Experiment, Trial |
| Tagging | AddTags / ListTags / DeleteTags |
SDK-compat HTTP coverage spans every family above, round-tripped against the real
aws-sdk-go-v2/service/sagemaker, sagemakerruntime and sagemakerfeaturestoreruntime
clients. Total: 121 operations.
Driver interface: services/vertexai/driver/ — aiplatform.googleapis.com
REST rooted at /v1/projects/{p}/locations/{l}/... with the Model Garden generateContent
surface at /v1/publishers/.... Control-plane mutations return done
google.longrunning.Operations; job-family creates are synchronous (poll the state
field). Auto-metrics → Cloud Monitoring via SetMonitoring.
| Family | Resources / Operations |
|---|---|
| Datasets | Create/Get/List/Patch/Delete (+ImportData/ExportData) |
| Model registry | UploadModel, Get/List/Patch/Delete, versions, evaluations |
| Endpoints | Create/Get/List/Delete, DeployModel/UndeployModel, Predict/RawPredict |
| Generative AI | generateContent, countTokens (publishers.models + endpoints), tuning jobs, cached contents |
| Jobs | CustomJob, BatchPredictionJob, HyperparameterTuningJob (synchronous create + cancel) |
| Pipelines | TrainingPipeline, PipelineJob |
| Feature Store | Featurestore (+ EntityType + online read/write), FeatureGroup, Feature, FeatureOnlineStore, FeatureView |
| Vector Search | Index (+upsert/remove datapoints), IndexEndpoint (+deploy/undeploy/findNeighbors) |
| ML Metadata | MetadataStore, Tensorboard, Schedule, NotebookRuntimeTemplate, NotebookRuntime |
The full Go API/driver, in-memory provider, and SDK-compat HTTP server (REST round-tripped)
cover every family above — models (+versions/evaluations), endpoints (+predict), datasets,
custom/batch-prediction/hyperparameter-tuning jobs, training & pipeline jobs, tuning jobs,
cached contents, Feature Store (featurestores/entityTypes/features + online read/write),
Feature Registry & online stores, Vector Search (indexes + index endpoints), ML metadata,
tensorboards, schedules, notebook runtimes, and generateContent/countTokens. A portable
Layer-1 wrapper (vertexai/vertexai.go), chaos injection (chaos.WrapVertexAI), and cost
rates integrate Vertex with the cross-cutting layers like every other service.
Total: 128 operations (Go API/driver).
Driver interface: services/ai/driver/ — spans both ARM providers plus the data planes.
Azure: Azure AI Foundry / AI Studio / Azure OpenAI (Microsoft.CognitiveServices) and
Azure Machine Learning (Microsoft.MachineLearningServices).
ARM control-plane PUT returns the resource inline with a terminal provisioningState so the
SDK LRO poller terminates on the first response. The data plane is host/path-routed
(*.openai.azure.com/openai/..., *.inference.ml.azure.com/score). Auto-metrics push to
Azure Monitor via SetMonitoring.
| Family | Resources / Operations |
|---|---|
| AI Services accounts | accounts CRUD, list by RG/sub, listKeys, regenerateKey, listModels, listSkus, listUsages |
| Model deployments | accounts/deployments CRUD + list (gpt-4o, embeddings, …) |
| AI Foundry projects | accounts/projects CRUD + list |
| Responsible AI | accounts/raiPolicies CRUD + list |
| Commitment plans | accounts/commitmentPlans CRUD + list |
| Private endpoints | accounts/privateEndpointConnections CRUD + list |
| Azure OpenAI inference | chat/completions, completions, embeddings |
| Agents / Assistants | assistants, threads, messages, runs (CRUD/list) |
| AML workspaces | workspaces (Default/Hub/Project/FeatureStore) CRUD, list by RG/sub |
| AML compute | computes CRUD + list, start/stop/restart (state machine) |
| AML endpoints | online/batchEndpoints CRUD + list, deployments CRUD + list |
| AML jobs | jobs create/get/list/cancel |
| AML assets | models, data, environments, components, featuresets — versioned CRUD + list (container/versions) |
| AML datastores / connections / schedules | CRUD + list |
| AML registries | cross-workspace registries CRUD + list |
| AML scoring | online-endpoint /score data plane |
Full Go API/driver, in-memory provider, SDK-compat ARM + data-plane HTTP server, a portable
Layer-1 wrapper (ai/ai.go), chaos injection (chaos.WrapAzureAI), and cost rates
integrate Azure AI with the cross-cutting layers like every other service.
Total: 92 operations (Go API/driver) — 31 CognitiveServices + 46 MachineLearningServices
- 15 data plane — all exposed over the SDK-compat HTTP server.
Driver interface: services/search/driver/ — Microsoft.Search/searchServices (ARM control
plane) plus the {service}.search.windows.net data plane.
Azure: Azure AI Search (the RAG / retrieval backbone). AWS / GCP: not applicable.
ARM PUT returns the resource inline with a terminal provisioningState; the data plane is
host/path-routed (service name from the {service}.search.windows.net subdomain). Auto-metrics
push to Azure Monitor via SetMonitoring.
| Family | Resources / Operations |
|---|---|
| Services (control) | searchServices CRUD, list by RG/sub, update; listAdminKeys, regenerateAdminKey, listQueryKeys, createQueryKey, deleteQueryKey |
| Private networking | sharedPrivateLinkResources CRUD+list, privateEndpointConnections CRUD+list |
| Indexes | create-or-update, get, list, delete |
| Documents | index (upload/merge/mergeOrUpload/delete), search (+count), suggest, autocomplete, count, get-by-key |
| Indexers | create-or-update, get, list, delete, run, reset, status |
| Data sources | create-or-update, get, list, delete |
| Skillsets | create-or-update, get, list, delete |
| Synonym maps | create-or-update, get, list, delete |
| Aliases | create-or-update, get, list, delete |
| Service statistics | counts + storage usage |
Full Go API/driver, in-memory provider, SDK-compat ARM + data-plane HTTP server, a portable
Layer-1 wrapper (search/search.go), chaos injection (chaos.WrapAzureSearch), and
cost rates integrate Azure AI Search with the cross-cutting layers like every other service.
Total: 53 operations (Go API/driver) — 19 control plane + 34 data plane.
Driver interface: services/ecs/driver/driver.go
AWS: ECS (AmazonEC2ContainerServiceV20141113.*, AWS JSON 1.1) | Azure: — | GCP: —
AWS-only. Real aws-sdk-go-v2/service/ecs clients work against the SDK-compat
server (awsserver.Drivers{ECS: cloud.ECS}).
Scheduling & placement. Container instances carry CPU/memory capacity;
RunTask/services with launch type EC2 are first-fit placed onto an
instance with sufficient remaining capacity (reserving it, releasing on stop) —
no capacity leaves the task in failures[] (AGENT/RESOURCE:*) or, for a
service, PENDING. FARGATE requires networkConfiguration.awsvpcConfiguration
- an
awsvpctask-def with cpu+memory, and synthesizes an ENIattachment+platformVersion(no capacity pool).launchTypeis validated against the task-def'srequiresCompatibilities.
Services converge synchronously: CreateService actually launches
desiredCount tasks (linked via the service:<name> group), records a PRIMARY
deployment (rolloutState COMPLETED/IN_PROGRESS) and an event; UpdateService
reconciles tasks and promotes a new deployment (superseded deployments drain and
are dropped, so the list does not grow); DAEMON runs one task per container
instance (and rejects a caller-supplied desiredCount). Batch Describe* and
RunTask return partial success (failures[]) rather than erroring; typed
exceptions (ClusterNotFoundException, ServiceNotFoundException,
ClusterContains*Exception, InvalidParameterException, ClientException) match
the SDK.
Accepted but not simulated (stored and round-tripped so SDK calls succeed, but
with no behavioral effect): capacityProviderStrategy (placement still falls
through to EC2/Fargate by launch type — no FARGATE_SPOT/ASG providers),
loadBalancers / serviceRegistries (no target-group registration, health
checks, or Service Connect), and the deployment circuit-breaker / rollback.
Fargate task-level cpu/memory is validated against the supported
configuration table.
Composes with EC2 (#300). RegisterContainerInstance provisions a backing
managed EC2 instance (Operator.Managed=true, principal ecs.amazonaws.com,
aws:ec2:managed-launch tag), so an ECS container instance is discoverable as a
real EC2 instance subject to managed-resource visibility.
| Family | Operations |
|---|---|
| Clusters | CreateCluster, ListClusters, DescribeClusters, DeleteCluster (cascade-guarded), UpdateCluster, UpdateClusterSettings, PutClusterCapacityProviders |
| Task definitions | RegisterTaskDefinition (auto-incrementing revision; the full container/task runtime surface — portMappings, environment, secrets, healthCheck, logConfiguration, mountPoints, ulimits, resourceRequirements, volumes, ephemeralStorage, runtimePlatform, proxyConfiguration, … — is accepted and round-tripped on the task definition, not reflected onto launched containers, which carry only name/image/status), ListTaskDefinitions, DescribeTaskDefinition, DeregisterTaskDefinition, ListTaskDefinitionFamilies |
| Tasks | RunTask (EC2 placement / Fargate ENI), StopTask, ListTasks, DescribeTasks, ExecuteCommand |
| Services | CreateService, UpdateService, ListServices, DescribeServices, DeleteService (force) |
| Container instances | RegisterContainerInstance, DeregisterContainerInstance, UpdateContainerInstancesState (DRAINING), ListContainerInstances, DescribeContainerInstances |
| Tagging | TagResource, UntagResource, ListTagsForResource |
| Account & attributes | PutAccountSetting(+Default), ListAccountSettings, DeleteAccountSetting, PutAttributes, DeleteAttributes, ListAttributes |
Total: 37 operations.
Driver interface: services/route53resolver/driver/driver.go
AWS: Route 53 Resolver (Route53Resolver.*, AWS JSON 1.1) | Azure: — | GCP: —
AWS-only. Real aws-sdk-go-v2/service/route53resolver clients work against the
SDK-compat server (awsserver.Drivers{Route53Resolver: cloud.Route53Resolver}).
Full parity: all 72 SDK operations, no stubs. Each resource group is stored
in an in-memory memstore.Store guarded by a single mutex; reads are
copy-on-write clones. Every group is covered by a real-SDK round-trip test.
Per-VPC configs (Resolver autodefined-reverse, DNSSEC validation, firewall
fail-open) are lazily materialized on first Get with their AWS defaults
(reverse ENABLED, DNSSEC DISABLED, fail-open DISABLED) and only appear in the
corresponding List once touched. Firewall rules are identified within a group by
(FirewallDomainListId, Qtype); deleting a rule group cascades to its rules.
| Family | Operations |
|---|---|
| Resolver endpoints | Create/Get/Update/Delete/ListResolverEndpoint(s), Associate/DisassociateResolverEndpointIpAddress, ListResolverEndpointIpAddresses |
| Resolver rules | Create/Get/Update/Delete/ListResolverRule(s), Associate/DisassociateResolverRule, Get/ListResolverRuleAssociation(s), Put/GetResolverRulePolicy |
| Query-log configs | Create/Get/Delete/ListResolverQueryLogConfig(s), Associate/DisassociateResolverQueryLogConfig, Get/ListResolverQueryLogConfigAssociation(s), Put/GetResolverQueryLogConfigPolicy |
| Resolver & DNSSEC configs | Get/Update/ListResolverConfig(s), Get/Update/ListResolverDnssecConfig(s) |
| DNS Firewall — domain lists | Create/Get/Delete/ListFirewallDomainList(s), Update/Import/ListFirewallDomains |
| DNS Firewall — rules | Create/Update/Delete/ListFirewallRule(s), BatchCreate/BatchUpdate/BatchDeleteFirewallRule |
| DNS Firewall — rule groups | Create/Get/Delete/ListFirewallRuleGroup(s), Put/GetFirewallRuleGroupPolicy |
| DNS Firewall — associations | Associate/Disassociate/Get/Update/ListFirewallRuleGroupAssociation(s) |
| DNS Firewall — configs | Get/Update/ListFirewallConfig(s), ListFirewallRuleTypes |
| Outpost resolvers | Create/Get/Update/Delete/ListOutpostResolver(s) |
| Tagging | TagResource, UntagResource, ListTagsForResource |
Accepted but not simulated (stored/echoed so SDK calls succeed, no behavioral
effect): endpoint/rule/config status stays terminal (no async CREATING→OPERATIONAL
transitions); ImportFirewallDomains records the request without fetching the S3
file; ListFirewallRuleTypes returns an empty descriptor list; resource-share
policies are stored verbatim without RAM enforcement.
Total: 72 operations.
Driver interface: services/vpclattice/driver/driver.go
AWS: VPC Lattice (REST-JSON, awsRestjson1) | Azure: — | GCP: —
AWS-only. Real aws-sdk-go-v2/service/vpclattice clients work against the
SDK-compat server (awsserver.Drivers{VPCLattice: cloud.VPCLattice}). Full
parity: all 73 SDK operations, no stubs.
Unlike the AWS JSON 1.1 services, VPC Lattice uses REST-JSON: the operation
is selected by HTTP method + URL path (e.g. POST /services, GET /services/{id}/listeners/{id}, PATCH /servicenetworks/{id}) rather than an
X-Amz-Target header. The handler gates on path root + method + identifier
shape, so a path-style S3 object op on a bucket named like a Lattice root
(e.g. GET /services/mykey) falls through to the S3 catch-all — only a
Lattice-shaped id (a known prefix or a vpc-lattice ARN) is claimed. The single
unavoidable residual is a bare GET /<root> (list) vs. an S3 list-bucket on an
identically-named bucket. Identifiers accept either a bare ID or a full ARN. Union-typed fields
(a listener's defaultAction, a rule's match/action, a target group's
config, a resource configuration's resourceConfigurationDefinition) are
stored as raw JSON and echoed back verbatim. Create-time tags are persisted;
deletes block on live service-network associations and cascade contained
children (service→listeners→rules); association counts are recomputed on read
and skip targets that no longer exist.
| Family | Operations |
|---|---|
| Service networks | Create/Get/Update/Delete/ListServiceNetwork(s) |
| Services | Create/Get/Update/Delete/ListService(s) |
| Listeners | Create/Get/Update/Delete/ListListener(s) |
| Rules | Create/Get/Update/Delete/ListRule(s), BatchUpdateRule |
| Target groups & targets | Create/Get/Update/Delete/ListTargetGroup(s), Register/Deregister/ListTargets |
| Service-network associations | Create/Get/Update/Delete/List ServiceNetworkVpcAssociation(s) + ListServiceNetworkVpcEndpointAssociations; Create/Get/Delete/List ServiceNetworkService & ServiceNetworkResource Association(s) |
| Resource configurations | Create/Get/Update/Delete/ListResourceConfiguration(s) |
| Resource gateways | Create/Get/Update/Delete/ListResourceGateway(s) |
| Resource endpoint associations | List/DeleteResourceEndpointAssociation(s) |
| Access-log subscriptions | Create/Get/Update/Delete/ListAccessLogSubscription(s) |
| Auth & resource policies | Put/Get/DeleteAuthPolicy, Put/Get/DeleteResourcePolicy |
| Domain verifications | Start/Get/Delete/ListDomainVerification(s) |
| Tagging | TagResource, UntagResource, ListTagsForResource |
Accepted but not simulated (stored/echoed so SDK calls succeed, no behavioral
effect): resources are created directly in a terminal ACTIVE/PENDING status
(no async state machine); VPC-endpoint and resource-endpoint associations are a
managed surface returned as empty lists; Forward/health-check targeting is
stored but not used to route real traffic.
Total: 73 operations.
Driver interface: services/kms/driver/
AWS: KMS (AWS JSON 1.1, X-Amz-Target: TrentService.<Op>) | Azure: — | GCP: —
AWS-only. Real aws-sdk-go-v2/service/kms clients (and the aws kms CLI) work
against the SDK-compat server (awsserver.Drivers{KMS: cloud.KMS}). Full parity
across the key lifecycle, aliases, tags, key policies, grants, rotation,
cryptography, imported key material, and multi-region keys.
Cryptography is real, not stubbed. Symmetric keys use AES-256-GCM with a
self-describing ciphertext blob (so Decrypt needs no key id) and bind the
encryption context as AEAD additional data; RSA keys use RSA-OAEP-SHA-256.
Sign/Verify use RSA (PSS/PKCS1) and ECDSA over the real key material; MAC uses
HMAC. GenerateDataKey/DataKeyPair return usable key material encrypted under the
KMS key, and ImportKeyMaterial unwraps RSAES-OAEP/PKCS1-wrapped material and
installs it as the AES key.
| Family | Operations |
|---|---|
| Key lifecycle | CreateKey, DescribeKey, ListKeys, EnableKey, DisableKey, UpdateKeyDescription, ScheduleKeyDeletion, CancelKeyDeletion |
| Aliases | CreateAlias, UpdateAlias, DeleteAlias, ListAliases |
| Tags | TagResource, UntagResource, ListResourceTags |
| Key policies | GetKeyPolicy, PutKeyPolicy, ListKeyPolicies |
| Grants | CreateGrant, ListGrants, RevokeGrant, RetireGrant, ListRetirableGrants |
| Rotation | EnableKeyRotation, DisableKeyRotation, GetKeyRotationStatus, ListKeyRotations, RotateKeyOnDemand |
| Cryptography | Encrypt, Decrypt, ReEncrypt, GenerateDataKey(+WithoutPlaintext), GenerateDataKeyPair(+WithoutPlaintext), GenerateRandom, Sign, Verify, GenerateMac, VerifyMac |
| Imported material | GetParametersForImport, ImportKeyMaterial, DeleteImportedKeyMaterial |
| Multi-region | ReplicateKey, UpdatePrimaryRegion |
Key references (ID, key ARN, alias/<name>, or alias ARN) resolve uniformly on
every operation.
Grants are record-only: CreateGrant/ListGrants/Revoke/Retire manage grant records, but the emulator carries no caller principal on the wire, so a grant's operation list and encryption-context constraints are not enforced against crypto calls (there is no principal to evaluate them for). Grant management round-trips faithfully; request-time authorization is out of scope.
Out of scope: Custom Key Stores / CloudHSM / external (XKS) key stores — these
are backed by real HSM hardware or third-party stores that can't be emulated
meaningfully. Multi-region replicas are modeled within a single process, so
cross-region replica lookup isn't observable; ReplicateKey/UpdatePrimaryRegion
return wire-complete metadata but there is no second regional endpoint to query.
Total: 45 operations.
Driver interface: services/efs/driver/
AWS: EFS (REST-JSON, awsRestjson1) | Azure: — | GCP: —
AWS-only. Real aws-sdk-go-v2/service/efs clients (and the aws efs CLI) work
against the SDK-compat server (awsserver.Drivers{EFS: cloud.EFS}). Full parity
across file systems, mount targets, access points, lifecycle/backup/replication
configuration, and account preferences.
Unlike the AWS JSON 1.1 services, EFS uses REST-JSON with path + method
routing under a fixed API-version prefix (/2015-02-01/...). The handler gates
on that prefix, so it never shadows the S3 catch-all (no real bucket path begins
with /2015-02-01/). Timestamps are emitted as epoch-seconds numbers, matching
the wire.
| Family | Operations |
|---|---|
| File systems | CreateFileSystem, DeleteFileSystem, DescribeFileSystems, UpdateFileSystem |
| File system policy | PutFileSystemPolicy, DescribeFileSystemPolicy, DeleteFileSystemPolicy |
| Mount targets | CreateMountTarget, DeleteMountTarget, DescribeMountTargets, Describe/ModifyMountTargetSecurityGroups |
| Access points | CreateAccessPoint, DeleteAccessPoint, DescribeAccessPoints |
| Lifecycle | PutLifecycleConfiguration, DescribeLifecycleConfiguration |
| Backup | PutBackupPolicy, DescribeBackupPolicy |
| Replication | CreateReplicationConfiguration, DeleteReplicationConfiguration, DescribeReplicationConfigurations |
| Account preferences | PutAccountPreferences, DescribeAccountPreferences |
| Tags | TagResource, UntagResource, ListTagsForResource + legacy CreateTags/DeleteTags/DescribeTags |
Creating a file system is idempotent on the creation token; a file system with
mount targets can't be deleted until they're removed (NumberOfMountTargets
tracks this). Access points and file systems share one tag store, with the
Name tag mirrored onto the resource name. Replication assigns a destination
file-system id per destination; cross-region replicas aren't separately
queryable in a single-process emulator.
Total: 30 operations.
Driver interface: services/acm/driver/
AWS: ACM (AWS JSON 1.1, X-Amz-Target: CertificateManager.<Op>) | Azure: — | GCP: —
AWS-only. Real aws-sdk-go-v2/service/acm clients (and the aws acm CLI) work
against the SDK-compat server (awsserver.Drivers{ACM: cloud.ACM}). Full parity
across the certificate lifecycle, import/export, renewal, revocation, tags, and
account configuration.
Certificates are real, not stubbed. RequestCertificate generates a genuine
self-signed X.509 certificate (RSA-2048, SHA-256) for the requested domain +
SANs and — since the emulator can't perform real domain validation — auto-issues
it (status ISSUED) so it's immediately usable; GetCertificate returns
parseable PEM. ImportCertificate validates and stores externally-supplied PEM;
ExportCertificate returns the cert, chain, and private key; RenewCertificate
re-issues fresh material.
| Family | Operations |
|---|---|
| Lifecycle | RequestCertificate, DescribeCertificate, ListCertificates, DeleteCertificate, GetCertificate |
| Import / export | ImportCertificate, ExportCertificate |
| Renewal / revocation | RenewCertificate, RevokeCertificate, ResendValidationEmail |
| Options | UpdateCertificateOptions (certificate-transparency logging) |
| Search | SearchCertificates |
| Tags | AddTagsToCertificate, RemoveTagsFromCertificate, ListTagsForCertificate |
| Account | GetAccountConfiguration, PutAccountConfiguration |
Certificate identifiers are ARNs. DNS-validation requests expose the CNAME validation record real clients read. Domain validation is auto-completed in the emulator (no real DNS/email round-trip), which is the local-dev analog of a validated public certificate.
Total: 17 operations.
Driver interface: services/kinesis/driver/
AWS: Kinesis Data Streams (AWS JSON 1.1, X-Amz-Target: Kinesis_20131202.<Op>) | Azure: — | GCP: —
AWS-only. Real aws-sdk-go-v2/service/kinesis clients (and the aws kinesis
CLI) work against the SDK-compat server (awsserver.Drivers{Kinesis: cloud.Kinesis}).
Full parity across the stream lifecycle, records, resharding, enhanced fan-out
consumers, encryption, tags, and resource policies.
Records behave like real Kinesis. Each stream is partitioned into shards
that own a 128-bit MD5 hash-key range; PutRecord/PutRecords route a record to
the open shard covering MD5(partitionKey) (or an explicit hash key) and assign
a per-stream monotonic sequence number. GetShardIterator returns an opaque
iterator honoring TRIM_HORIZON, LATEST, AT/AFTER_SEQUENCE_NUMBER, and
AT_TIMESTAMP; GetRecords advances it and, at the end of a closed shard,
returns the child shards. SplitShard/MergeShards/UpdateShardCount close
parents and create children with correct hash-key ranges and parent links, so
records already written stay readable.
| Family | Operations |
|---|---|
| Stream lifecycle | CreateStream, DeleteStream, DescribeStream, DescribeStreamSummary, ListStreams |
| Configuration | IncreaseStreamRetentionPeriod, DecreaseStreamRetentionPeriod, UpdateStreamMode, StartStreamEncryption, StopStreamEncryption, UpdateMaxRecordSize, UpdateStreamWarmThroughput |
| Resharding | UpdateShardCount, MergeShards, SplitShard, ListShards |
| Records | PutRecord, PutRecords, GetShardIterator, GetRecords |
| Consumers (enhanced fan-out) | RegisterStreamConsumer, DeregisterStreamConsumer, DescribeStreamConsumer, ListStreamConsumers, SubscribeToShard |
| Monitoring | EnableEnhancedMonitoring, DisableEnhancedMonitoring |
| Tags | AddTagsToStream, RemoveTagsFromStream, ListTagsForStream, TagResource, UntagResource, ListTagsForResource |
| Resource policy | PutResourcePolicy, GetResourcePolicy, DeleteResourcePolicy |
| Account & limits | DescribeLimits, DescribeAccountSettings, UpdateAccountSettings |
Streams are addressed by name or ARN. SubscribeToShard (enhanced fan-out)
streams records to a registered consumer as an
application/vnd.amazon.eventstream response: it resolves the consumer's shard
from the requested StartingPosition, emits the initial-response frame the SDK
awaits, then a SubscribeToShardEvent frame carrying the records, continuation
sequence number, and MillisBehindLatest. Polling via
GetShardIterator/GetRecords covers the same read path.
Total: 39 operations.
Driver interface: services/sfn/driver/
AWS: Step Functions (AWS JSON 1.0, X-Amz-Target: AWSStepFunctions.<Op>) | Azure: — | GCP: —
AWS-only. Real aws-sdk-go-v2/service/sfn clients (and the aws stepfunctions
CLI) work against the SDK-compat server (awsserver.Drivers{SFN: cloud.SFN}).
Full parity across state machines, executions, execution history, activities,
versions/aliases, and tags. State machine ARNs are keyed by name (a duplicate
name is StateMachineAlreadyExists); the ASL definition is stored verbatim and
returned unchanged by DescribeStateMachine.
| Family | Operations |
|---|---|
| State machines | CreateStateMachine, DescribeStateMachine, UpdateStateMachine, DeleteStateMachine, ListStateMachines |
| Executions | StartExecution, StartSyncExecution, DescribeExecution, StopExecution, ListExecutions, GetExecutionHistory, DescribeStateMachineForExecution, RedriveExecution |
| Map Runs | DescribeMapRun, ListMapRuns, UpdateMapRun |
| Versions / aliases | PublishStateMachineVersion, ListStateMachineVersions, DeleteStateMachineVersion, CreateStateMachineAlias, DescribeStateMachineAlias, UpdateStateMachineAlias, DeleteStateMachineAlias, ListStateMachineAliases |
| Activities | CreateActivity, DescribeActivity, DeleteActivity, ListActivities, GetActivityTask, SendTaskSuccess, SendTaskFailure, SendTaskHeartbeat |
| Definition tooling | TestState, ValidateStateMachineDefinition |
| Tags | TagResource, UntagResource, ListTagsForResource |
A real ASL interpreter runs executions. StartExecution and
StartSyncExecution actually interpret the Amazon States Language definition
against the input rather than echoing it. The interpreter executes Pass,
Choice, Wait, Task, Parallel, Map, Succeed, and Fail states, following
Next/End transitions to a terminal state and producing the real
GetExecutionHistory event sequence for the path taken (state Entered/Exited,
Task Scheduled/Started/Succeeded/Failed, Parallel/Map iteration events, and the
terminal ExecutionSucceeded/ExecutionFailed). Supported semantics:
- I/O processing —
InputPath,Parameters,ResultSelector,ResultPath, andOutputPathwith JSONPath evaluation, including the.$reference form and merge-onto-inputResultPathsemantics. - Choice rules — string/numeric/boolean/timestamp comparators and the
And/Or/Notcombinators (including the...Pathvariants), withDefault. - Error handling —
Retry(withIntervalSeconds/MaxAttempts/BackoffRateandErrorEqualsmatching) andCatch(routing to a fallback state with the error carried onResultPath). - Intrinsic functions —
States.Format,States.Array,States.ArrayGetItem,States.StringToJson,States.JsonToString, andStates.UUID. - The context object —
$$resolves the execution/state context (Execution.Name,StateMachine,State.EnteredTime, …). - Task → Lambda — a
TaskwhoseResourceisarn:aws:states:::lambda:invoke(payload fromParameters.Payload) or a direct Lambda function ARN really invokes the wired Lambda backend; aFunctionErrorfeedsRetry/Catch.
Definitions are validated at create time: CreateStateMachine (and
ValidateStateMachineDefinition) parse the ASL and reject structural errors —
unknown Type, missing Next/End, a Next/Default that names no state,
result-shaping fields on states that don't support them, malformed Choice rules,
and out-of-range Retry fields. TestState runs a single state through the
interpreter and returns its real output (or error). Bounded guards protect the
host: executions cap total state transitions (CloudEmu.StateTransitionLimitExceeded)
and Parallel/Map nesting depth (CloudEmu.ExecutionNestingLimitExceeded).
Deferred (not yet interpreted): the JSONata query language is rejected at
create time (JSONPath only); the .sync and .waitForTaskToken
service-integration patterns; and service integrations other than Lambda —
including Activity tasks, so GetActivityTask still returns an empty token
and SendTaskSuccess/Failure/Heartbeat reject any token as InvalidToken.
RedriveExecution records a fresh redrive date rather than re-running.
Distributed-map Map Runs are not produced by ordinary executions, so
ListMapRuns returns empty and DescribeMapRun/UpdateMapRun operate on Map Run
records seeded through the provider's SeedMapRun helper.
Total: 36 operations.
Driver interface: services/wafv2/driver/
AWS: WAFv2 (AWS JSON 1.1, X-Amz-Target: AWSWAF_20190729.<Op>) | Azure: — | GCP: —
AWS-only. Real aws-sdk-go-v2/service/wafv2 clients (and the aws wafv2 CLI)
work against the SDK-compat server (awsserver.Drivers{WAFv2: cloud.WAFv2}).
Full parity across WebACLs, IPSets, RuleGroups and RegexPatternSets, web-ACL /
resource associations, and tags.
Scope-partitioned namespace with optimistic locking. Every resource is keyed
by the tuple (Scope, Id), so REGIONAL and CLOUDFRONT resources never
collide. Each resource carries a LockToken that rotates on every mutation;
Update* and Delete* must present the current token or the backend returns a
WAFOptimisticLockException, exactly as real WAF. Rule, statement,
default-action and visibility-config blocks are stored verbatim (as raw JSON), so
Get* returns exactly what Create*/Update* wrote.
| Family | Operations |
|---|---|
| Web ACLs | CreateWebACL, GetWebACL, UpdateWebACL, DeleteWebACL, ListWebACLs |
| IP sets | CreateIPSet, GetIPSet, UpdateIPSet, DeleteIPSet, ListIPSets |
| Rule groups | CreateRuleGroup, GetRuleGroup, UpdateRuleGroup, DeleteRuleGroup, ListRuleGroups |
| Regex pattern sets | CreateRegexPatternSet, GetRegexPatternSet, UpdateRegexPatternSet, DeleteRegexPatternSet, ListRegexPatternSets |
| Associations | AssociateWebACL, DisassociateWebACL, GetWebACLForResource, ListResourcesForWebACL |
| Tags | TagResource, UntagResource, ListTagsForResource |
| Capacity | CheckCapacity |
| Logging config | PutLoggingConfiguration, GetLoggingConfiguration, DeleteLoggingConfiguration, ListLoggingConfigurations |
| Permission policy | PutPermissionPolicy, GetPermissionPolicy, DeletePermissionPolicy |
| API keys | CreateAPIKey, DeleteAPIKey, ListAPIKeys, GetDecryptedAPIKey |
| Managed products / rule groups / sets | DescribeAllManagedProducts, DescribeManagedProductsByVendor, DescribeManagedRuleGroup, ListAvailableManagedRuleGroups, ListAvailableManagedRuleGroupVersions, ListManagedRuleSets, GetManagedRuleSet, PutManagedRuleSetVersions, UpdateManagedRuleSetVersionExpiryDate |
| Mobile SDK | GenerateMobileSdkReleaseUrl, GetMobileSdkRelease, ListMobileSdkReleases |
| Traffic / statistics | GetRateBasedStatementManagedKeys, GetSampledRequests, GetTopPathStatisticsByTraffic, GetRevenueStatistics, GetRevenueStatisticsSummary, GetRevenueStatisticsTimeSeries, ListSettlementRecords |
| Firewall Manager | DeleteFirewallManagerRuleGroups |
Distinct exceptions (WAFNonexistentItemException, WAFDuplicateItemException,
WAFOptimisticLockException, WAFInvalidParameterException) surface as their
real typed errors so SDK errors.As checks work.
Stateful additions. CheckCapacity computes a deterministic, self-consistent
WCU estimate from the submitted rules (documented, non-authoritative — the full
WCU cost table is not modeled). Logging configurations are stored and echoed
verbatim keyed by ResourceArn; permission policies are stored per rule-group
ARN; API keys are issued as opaque base64 tokens stored per scope with their
token domains.
Synthesized read-only ops. Managed-product/rule-group/rule-set catalogs,
mobile-SDK releases, sampled requests, top-path traffic and revenue/settlement
statistics depend on AWS-managed vendor catalogs and live traffic the emulator
does not model. These return plausible empty (or, for GenerateMobileSdkReleaseUrl,
synthesized) results so SDK/CLI calls succeed and round-trip; managed rule set
Get/Put/Update report WAFNonexistentItemException since no managed rule sets are
hosted, and DeleteFirewallManagerRuleGroups echoes back the presented lock token.
Total: 59 operations.
Driver interface: services/sesv2/driver/
AWS: SES v2 (REST-JSON awsRestjson1, path prefix /v2/email/…) | Azure: — | GCP: —
AWS-only. Real aws-sdk-go-v2/service/sesv2 clients (and the aws sesv2 CLI)
work against the SDK-compat server (awsserver.Drivers{SESV2: cloud.SESV2}).
SES v2 uses REST-JSON path + method routing under the /v2/email/ version
prefix, so its handler gates on that prefix ahead of the S3 catch-all.
Identities auto-verify. CreateEmailIdentity marks an address or domain
verified for sending immediately (status SUCCESS) — the emulator can't perform
a real DNS/email round-trip — and domains receive three Easy-DKIM CNAME tokens.
SendEmail validates the from-identity (the address itself or its domain must be
a verified identity) and any referenced configuration set / template, then
returns a generated MessageId; accepted messages are retained so tests can
assert on what was sent. TestRenderEmailTemplate substitutes {{key}}
placeholders from the JSON template data.
Full aws-sdk-go-v2/service/sesv2 parity: every client method (except
Options) is implemented. Beyond the verified/sending core, the emulator also
covers contact lists and contacts, custom verification email templates,
configuration-set event destinations and put-options, dedicated IP pools/IPs,
the deliverability dashboard, email-identity policies and DKIM/feedback/config
-set attributes, import/export jobs, insights/metrics/recommendations, tenants
and tenant-resource associations, reputation entities, multi-region endpoints,
and templated bulk send.
Synthesized read-only data. Deliverability, reputation, insights, and metric figures cannot be observed by an emulator with no real mail flow, so those operations manage opt-in/association state and return plausible, self-consistent but non-real reports (e.g. empty blacklist entries, zeroed metric series, HEALTHY reputation until changed). Import/export jobs complete instantly.
| Family | Operations |
|---|---|
| Email identities | CreateEmailIdentity, GetEmailIdentity, DeleteEmailIdentity, ListEmailIdentities, PutEmailIdentityDkimAttributes, PutEmailIdentityMailFromAttributes |
| Email identity policies / attributes | CreateEmailIdentityPolicy, GetEmailIdentityPolicies, UpdateEmailIdentityPolicy, DeleteEmailIdentityPolicy, PutEmailIdentityConfigurationSetAttributes, PutEmailIdentityDkimSigningAttributes, PutEmailIdentityFeedbackAttributes |
| Configuration sets | CreateConfigurationSet, GetConfigurationSet, DeleteConfigurationSet, ListConfigurationSets |
| Config-set event destinations | Create/Update/Delete ConfigurationSetEventDestination, GetConfigurationSetEventDestinations |
| Config-set put-options | PutConfigurationSet{ArchivingOptions, DeliveryOptions, ReputationOptions, SendingOptions, SuppressionOptions, TrackingOptions, VdmOptions} |
| Email templates | CreateEmailTemplate, GetEmailTemplate, UpdateEmailTemplate, DeleteEmailTemplate, ListEmailTemplates, TestRenderEmailTemplate |
| Custom verification templates | Create/Get/Update/Delete/List CustomVerificationEmailTemplate, SendCustomVerificationEmail |
| Contact lists / contacts | Create/Get/Update/Delete/List ContactList; Create/Get/Update/Delete/List Contact |
| Sending | SendEmail, SendBulkEmail |
| Suppression list | PutSuppressedDestination, GetSuppressedDestination, DeleteSuppressedDestination, ListSuppressedDestinations |
| Dedicated IPs / pools | Create/Delete/Get/List DedicatedIpPool; GetDedicatedIp, GetDedicatedIps, PutDedicatedIpInPool, PutDedicatedIpPoolScalingAttributes, PutDedicatedIpWarmupAttributes, PutAccountDedicatedIpWarmupAttributes |
| Deliverability dashboard | Put/GetDeliverabilityDashboardOption(s), Create/Get/List DeliverabilityTestReport, Get/ListDomainDeliverabilityCampaign(s), GetDomainStatisticsReport, GetBlacklistReports |
| Import / export jobs | Create/Get/List ImportJob; Create/Get/List/Cancel ExportJob |
| Insights / metrics | BatchGetMetricData, GetMessageInsights, GetEmailAddressInsights, ListRecommendations |
| Account | GetAccount, PutAccountSendingAttributes, PutAccountSuppressionAttributes, PutAccountDetails, PutAccountVdmAttributes, PutAccountPricingAttributes |
| Tenants | Create/Get/Delete/List Tenant; Create/Delete TenantResourceAssociation, ListTenantResources, ListResourceTenants, PutTenantSuppressionAttributes |
| Reputation entities | GetReputationEntity, ListReputationEntities, UpdateReputationEntityCustomerManagedStatus, UpdateReputationEntityPolicy |
| Multi-region endpoints | Create/Get/Delete/List MultiRegionEndpoint |
| Tags | TagResource, UntagResource, ListTagsForResource |
Resource identifiers are ARNs (arn:aws:ses:<region>:<account>:identity/…,
…:configuration-set/…, …:template/…); the tag operations resolve the ARN to
the referenced identity, configuration set, or template.
Total: 113 operations.
Driver interface: services/opensearch/driver/
AWS: OpenSearch Service (REST-JSON awsRestjson1, version-path prefix /2021-01-01/opensearch/…) | Azure: — | GCP: —
AWS-only. Real aws-sdk-go-v2/service/opensearch clients (and the aws opensearch
CLI) work against the SDK-compat server (awsserver.Drivers{OpenSearch: cloud.OpenSearch}).
The handler gates on the /2021-01-01/opensearch/ version prefix, so it never
shadows the S3 catch-all. Full aws-sdk-go-v2/service/opensearch parity: every
client method (except Options) is implemented. A few write-path capability
helpers (AuthorizeVpcEndpointAccess, RegisterCapability, AttachDataSource)
validate their inputs and echo a synthesized result without persisting state.
Domains behave realistically. CreateDomain claims the domain name
atomically (ResourceAlreadyExistsException on a duplicate) and returns a domain
that is immediately Active with a synthesized endpoint (the emulator
provisions deterministically, so there is no wall-clock Processing phase);
DescribeDomain/DescribeDomainConfig reflect stored config; UpdateDomainConfig
mutates it; reads deep-copy so concurrent tag/config mutations don't race.
| Family | Operations |
|---|---|
| Domains | CreateDomain, DescribeDomain, DescribeDomains, DescribeDomainConfig, DescribeDomainHealth/Nodes, UpdateDomainConfig, DeleteDomain, ListDomainNames, GetCompatibleVersions, ListVersions |
| Config history / changes | GetUpgradeStatus/History, StartServiceSoftwareUpdate, CancelServiceSoftwareUpdate, RollbackServiceSoftwareUpdate, UpgradeDomain, DescribeDomainChangeProgress |
| Packages | CreatePackage, DeletePackage, DescribePackages, AssociatePackage(s), DissociatePackage(s), GetPackageVersionHistory, ListPackagesForDomain, ListDomainsForPackage, UpdatePackage, UpdatePackageScope |
| VPC endpoints | CreateVpcEndpoint, DeleteVpcEndpoint, UpdateVpcEndpoint, DescribeVpcEndpoints, ListVpcEndpoints, ListVpcEndpointsForDomain, AuthorizeVpcEndpointAccess, RevokeVpcEndpointAccess, ListVpcEndpointAccess |
| Data sources | AddDataSource, GetDataSource, UpdateDataSource, DeleteDataSource, ListDataSources, AddDirectQueryDataSource, …, ListDirectQueryDataSources |
| Applications | CreateApplication, GetApplication, UpdateApplication, DeleteApplication, ListApplications |
| Reserved instances | PurchaseReservedInstanceOffering, DescribeReservedInstances, DescribeReservedInstanceOfferings |
| Cross-cluster | Create/Delete/Accept/Reject/DescribeInbound & Outbound Connections |
| Instance/limits | DescribeInstanceTypeLimits, ListInstanceTypeDetails, DescribeDomainAutoTunes, GetDomainMaintenanceStatus, ListDomainMaintenances, StartDomainMaintenance |
| Scheduled actions / config | ListScheduledActions, UpdateScheduledAction, ListInstanceTypeDetails |
| Tags | AddTags, RemoveTags, ListTags |
Read-only catalog/limit/insight ops return plausible synthesized results (the emulator models no real cluster hardware or search traffic), documented in code.
Resources below are served for one provider only, because the concept exists in one cloud and has no counterpart to abstract. They are reached through the same endpoints as everything else; the difference is that no portable driver interface covers them.
| Resource | Operations |
|---|---|
| Cloud Routers | insert · get · list · patch · delete |
| Addresses (global and regional) | insert · get · list · delete |
| Service Networking connections | list · create · patch · delete |
Cloud NAT is configured by patching a router, and private services access reserves a global address and opens a connection. A caller building a private network uses all three, and releases them when the network goes away.
Addresses are keyed by the scope they were reserved in, so a global address and a regional one sharing a name stay distinct.
| Resource | Operations |
|---|---|
| Resource groups | create · get · list · delete |
| Subscriptions | list |
Every Azure resource lives in a resource group, so one is created before anything else and deleted last. A group is usable as soon as it exists; deleting one that is already gone succeeds, since that is the caller's desired end state and a teardown retry must not fail on its second pass.
The subscriptions list is empty. This emulator has no tenant model, so it cannot say which subscriptions a credential reaches, and inventing some would fabricate an authorization boundary that does not exist here.
Two families exist in every real AWS account without anyone creating them, so callers reference them directly. Both are materialized on first reference, matched against the sets AWS actually publishes — an unrecognized name is rejected, because accepting anything would let a typo through here and fail only in production.
| Family | Recognized |
|---|---|
IAM managed policies (arn:aws:iam::aws:policy/…) |
A catalog of real policy names, pathed ones included |
SSM parameters (/aws/service/…/ami-id) |
The published image trees; the id is derived from the parameter name, so it is stable per parameter and distinct across distros |
| Operation | Signature |
|---|---|
SendCommand |
(ctx, CommandConfig) (commandID string, error) |
GetCommandInvocation |
(ctx, commandID, instanceID) (*CommandInvocation, error) |
Discovered by type assertion on the parameter-store driver, like the subnet and replication group capabilities.
Targets are validated: sending to an instance that does not exist is
InvalidInstanceId, which is the most common Run Command failure during
bring-up.
Nothing executes. An emulated instance has no guest operating system, so invocations report success with empty output. This exercises a caller's send-and-poll orchestration — that it waits for a terminal status and reads the response code — but not the script. A caller whose bootstrap script is wrong still sees success.
Driver interface: services/cloudtrail/driver/
AWS: CloudTrail (AWS JSON 1.1, X-Amz-Target: CloudTrail_20131101.<Op>) | Azure: — | GCP: —
AWS-only. Real aws-sdk-go-v2/service/cloudtrail clients (and the
aws cloudtrail CLI) work against the SDK-compat server
(awsserver.Drivers{CloudTrail: cloud.CloudTrail}). Broad operation coverage
across trails, event data stores, channels, dashboards, imports, event/insight
selectors, ad-hoc CloudTrail Lake queries, resource policies, and tags. The
control-plane CRUD/state paths are faithfully emulated, and management events
are recorded from served API activity so LookupEvents reflects real calls
(see below); only the Lake analytics / Insights surfaces remain
synthesized/limited.
| Family | Operations |
|---|---|
| Trails | CreateTrail, GetTrail, UpdateTrail, DeleteTrail, DescribeTrails, ListTrails, GetTrailStatus, StartLogging, StopLogging |
| Selectors | PutEventSelectors, GetEventSelectors, PutInsightSelectors, GetInsightSelectors |
| Event data stores | CreateEventDataStore, GetEventDataStore, UpdateEventDataStore, DeleteEventDataStore, RestoreEventDataStore, ListEventDataStores, StartEventDataStoreIngestion, StopEventDataStoreIngestion, EnableFederation, DisableFederation |
| Channels | CreateChannel, GetChannel, UpdateChannel, DeleteChannel, ListChannels |
| Dashboards | CreateDashboard, GetDashboard, UpdateDashboard, DeleteDashboard, ListDashboards, StartDashboardRefresh |
| Imports | StartImport, GetImport, StopImport, ListImports, ListImportFailures |
| Queries | StartQuery, DescribeQuery, GetQueryResults, CancelQuery, ListQueries, GenerateQuery |
| Resource policy / config | PutResourcePolicy, GetResourcePolicy, DeleteResourcePolicy, PutEventConfiguration, GetEventConfiguration |
| Organization | RegisterOrganizationDelegatedAdmin, DeregisterOrganizationDelegatedAdmin |
| Tags | AddTags, RemoveTags, ListTags |
| Read-only (recorded) | LookupEvents |
| Read-only (synthesized) | ListPublicKeys, ListInsightsData, ListInsightsMetricData, SearchSampleQueries |
CreateTrail validates the trail name (3–128 chars, allowed charset, no
adjacent separators, not an IP) → InvalidTrailNameException, claims the name
atomically (a duplicate is TrailAlreadyExistsException), stores the config and
returns the trail ARN. StartLogging/StopLogging flip IsLogging (with real
recorded start/stop times) reported by GetTrailStatus. Event data stores are
created ENABLED with an ARN; a malformed EDS ARN is
EventDataStoreARNInvalidException, a well-formed-but-absent one is
EventDataStoreNotFoundException; DeleteEventDataStore is a soft delete
(→ PENDING_DELETION) unless termination protection is on.
Management events are recorded; Lake analytics are synthesized. A
post-dispatch observer derives a CloudTrail management event from each served
request (the operation name from X-Amz-Target/Action, the source service and
access-key id from the SigV4 credential scope, and a read-only classification by
verb prefix), so LookupEvents returns the real API activity — newest first,
paginated, and filtered by the request's attribute/time selectors — rather than
an empty page. CloudTrail's own read-only polling is not recorded, so a client
tailing LookupEvents never crowds out the activity it is observing, and the log
is bounded. The remaining analytics surfaces stay synthesized: ListInsightsData,
ListInsightsMetricData and ListPublicKeys return empty pages; ad-hoc
StartQuery is accepted, stored and immediately marked FINISHED with an empty
result set; SearchSampleQueries returns a small fixed catalog of CloudTrail
Lake sample queries; and emulated imports complete instantly with no failures.
Total: 60 operations.
Driver interface: services/configservice/driver/
AWS: AWS Config (AWS JSON 1.1, X-Amz-Target: StarlingDoveService.<Op>) | Azure: — | GCP: —
AWS-only. Real aws-sdk-go-v2/service/configservice clients (and the
aws configservice CLI) work against the SDK-compat server
(awsserver.Drivers{Config: cloud.Config}). All 102 SDK operations are wired.
The control-plane CRUD/state paths — configuration recorders, delivery channels,
config rules, conformance packs, organization rules/packs, aggregators and
authorizations, remediation, stored queries, and retention — are faithfully
emulated. The compliance, evaluation, discovered-resource, and aggregate-query
read/analytics surfaces are synthesized approximations (see below), not full
parity: the emulator runs no real Config recording pipeline, so they answer from
the emulator's own recorded state rather than from continuously discovered
configuration data.
| Family | Operations |
|---|---|
| Configuration recorders | PutConfigurationRecorder, DescribeConfigurationRecorders, DescribeConfigurationRecorderStatus, DeleteConfigurationRecorder, StartConfigurationRecorder, StopConfigurationRecorder, ListConfigurationRecorders, PutServiceLinkedConfigurationRecorder, PutThirdPartyServiceLinkedConfigurationRecorder, DeleteServiceLinkedConfigurationRecorder, AssociateResourceTypes, DisassociateResourceTypes |
| Delivery channels | PutDeliveryChannel, DescribeDeliveryChannels, DescribeDeliveryChannelStatus, DeleteDeliveryChannel, DeliverConfigSnapshot |
| Config rules | PutConfigRule, DescribeConfigRules, DeleteConfigRule, DescribeConfigRuleEvaluationStatus, StartConfigRulesEvaluation, PutEvaluations, PutExternalEvaluation, DeleteEvaluationResults, GetCustomRulePolicy |
| Compliance (synthesized) | DescribeComplianceByConfigRule, DescribeComplianceByResource, GetComplianceDetailsByConfigRule, GetComplianceDetailsByResource, GetComplianceSummaryByConfigRule, GetComplianceSummaryByResourceType |
| Conformance packs | PutConformancePack, DescribeConformancePacks, DescribeConformancePackStatus, DeleteConformancePack, GetConformancePackComplianceDetails, GetConformancePackComplianceSummary, DescribeConformancePackCompliance, ListConformancePackComplianceScores |
| Organization rules/packs | PutOrganizationConfigRule, DescribeOrganizationConfigRules, DescribeOrganizationConfigRuleStatuses, DeleteOrganizationConfigRule, GetOrganizationConfigRuleDetailedStatus, GetOrganizationCustomRulePolicy, PutOrganizationConformancePack, DescribeOrganizationConformancePacks, DescribeOrganizationConformancePackStatuses, DeleteOrganizationConformancePack, GetOrganizationConformancePackDetailedStatus |
| Aggregators / authorizations | PutConfigurationAggregator, DescribeConfigurationAggregators, DeleteConfigurationAggregator, DescribeConfigurationAggregatorSourcesStatus, PutAggregationAuthorization, DescribeAggregationAuthorizations, DeleteAggregationAuthorization, DescribePendingAggregationRequests, DeletePendingAggregationRequest |
| Aggregate queries (synthesized) | DescribeAggregateComplianceByConfigRules, DescribeAggregateComplianceByConformancePacks, GetAggregateComplianceDetailsByConfigRule, GetAggregateConfigRuleComplianceSummary, GetAggregateConformancePackComplianceSummary, GetAggregateDiscoveredResourceCounts, GetAggregateResourceConfig, BatchGetAggregateResourceConfig, ListAggregateDiscoveredResources, SelectAggregateResourceConfig |
| Remediation | PutRemediationConfigurations, DescribeRemediationConfigurations, DeleteRemediationConfiguration, PutRemediationExceptions, DescribeRemediationExceptions, DeleteRemediationExceptions, DescribeRemediationExecutionStatus, StartRemediationExecution |
| Resource config (synthesized) | PutResourceConfig, GetResourceConfigHistory, DeleteResourceConfig, BatchGetResourceConfig, ListDiscoveredResources, GetDiscoveredResourceCounts, SelectResourceConfig, StartResourceEvaluation, GetResourceEvaluationSummary, ListResourceEvaluations |
| Stored queries / retention / connectors | PutStoredQuery, GetStoredQuery, ListStoredQueries, DeleteStoredQuery, PutRetentionConfiguration, DescribeRetentionConfigurations, DeleteRetentionConfiguration, PutConnector, GetConnector, ListConnectors, DeleteConnector |
| Tags | TagResource, UntagResource, ListTagsForResource |
PutConfigurationRecorder and PutDeliveryChannel enforce AWS's one-per-account
invariant: a Put naming the existing resource is an idempotent upsert, but a Put
naming a different one while one exists is
MaxNumberOfConfigurationRecordersExceededException /
MaxNumberOfDeliveryChannelsExceededException. StartConfigurationRecorder
requires a delivery channel (NoAvailableDeliveryChannelException otherwise) and
flips recording state with real start/stop/status-change times reported by
DescribeConfigurationRecorderStatus. Missing rules/recorders/channels return
their specific NoSuch* exceptions; bad input is InvalidParameterValueException
/ ValidationException; a malformed pagination token is
InvalidNextTokenException. PutEvaluations/PutExternalEvaluation record
evaluations and roll a rule's aggregate compliance up from them (any
NON_COMPLIANT wins). Batch mutations (PutRemediationConfigurations) validate
every entry before applying any, so a bad entry never partially mutates.
Synthesized surfaces — a deliberate simplification. The emulator runs no real
recording pipeline, so the discovered-resource and query surfaces are backed by
what callers supply via PutResourceConfig: GetResourceConfigHistory,
BatchGetResourceConfig, ListDiscoveredResources, GetDiscoveredResourceCounts
and SelectResourceConfig answer from that in-memory store (a resource never
recorded is ResourceNotDiscoveredException). SelectResourceConfig /
SelectAggregateResourceConfig parse a supported subset of the Config SQL SELECT
grammar (a projection plus an optional WHERE resourceType = '...' equality);
unsupported syntax is a typed InvalidExpressionException. Aggregate-query
operations validate the aggregator exists and gate results on authorization: the
local account/region contributes data only when the aggregator selects it AND a
matching AggregationAuthorization exists — an unauthorized source contributes
nothing. Compliance summaries are derived from reported evaluations.
PutEvaluations validates an opaque result token (issued per rule at create time
and refreshed by StartConfigRulesEvaluation); an unknown/malformed token is
InvalidResultTokenException. StartResourceEvaluation/GetResourceEvaluationSummary,
pending aggregation requests, and organization per-account detailed statuses
return plausible synthesized results. Conformance-pack and organization-pack
creation completes instantly (always CREATE_COMPLETE; the transient in-progress
states are never observable). This preserves the SDK wire shapes for
build-and-orchestrate testing without a dependency on real Config data.
Total: 102 operations.
Driver interface: services/glue/driver/
AWS: Glue (AWS JSON 1.1, X-Amz-Target: AWSGlue.<Op>) | Azure: — | GCP: —
AWS-only. Real aws-sdk-go-v2/service/glue clients (and the aws glue CLI) work
against the SDK-compat server (awsserver.Drivers{Glue: cloud.Glue}). Full
operation coverage of the entire Glue Client (299 operations). The Data Catalog,
crawler, ETL job/run, trigger, workflow, blueprint, schema-registry,
dev-endpoint, and tag control-plane paths model real CRUD and lifecycle state in
memory, including enum/required-field validation (connection type, classifier
kind, trigger type/schedule), schema-registry compatibility + dedup, and the
PutResourcePolicy conditional-put — where noted below. The read/analytics
surfaces (analytics, ML-transform, data-quality, integration,
glossary/asset/form, column-statistics, session/statement, usage-profile,
materialized-view, identity-center, and unfiltered-metadata) remain synthesized:
there is no real Spark/compute or data plane behind the emulator, so they return
empty, well-formed responses rather than fabricated results. This is control-
plane emulation, not a full data-plane implementation.
| Family | Operations |
|---|---|
| Databases | CreateDatabase, GetDatabase, UpdateDatabase, DeleteDatabase, GetDatabases |
| Tables | CreateTable, GetTable, UpdateTable, DeleteTable, GetTables, SearchTables, BatchDeleteTable |
| Table versions | GetTableVersion, GetTableVersions, DeleteTableVersion, BatchDeleteTableVersion |
| Partitions | CreatePartition, GetPartition, UpdatePartition, DeletePartition, GetPartitions, BatchCreatePartition, BatchDeletePartition, BatchUpdatePartition, BatchGetPartition |
| User-defined functions | CreateUserDefinedFunction, GetUserDefinedFunction, UpdateUserDefinedFunction, DeleteUserDefinedFunction, GetUserDefinedFunctions |
| Connections | CreateConnection, GetConnection, UpdateConnection, DeleteConnection, GetConnections, BatchDeleteConnection, TestConnection |
| Catalogs | CreateCatalog, GetCatalog, UpdateCatalog, DeleteCatalog, GetCatalogs |
| Crawlers | CreateCrawler, GetCrawler, UpdateCrawler, DeleteCrawler, GetCrawlers, ListCrawlers, StartCrawler, StopCrawler, BatchGetCrawlers |
| Classifiers | CreateClassifier, GetClassifier, UpdateClassifier, DeleteClassifier, GetClassifiers |
| Jobs & runs | CreateJob, GetJob, UpdateJob, DeleteJob, GetJobs, ListJobs, BatchGetJobs, StartJobRun, GetJobRun, GetJobRuns, BatchStopJobRun |
| Triggers | CreateTrigger, GetTrigger, UpdateTrigger, DeleteTrigger, GetTriggers, ListTriggers, StartTrigger, StopTrigger, BatchGetTriggers |
| Workflows & runs | CreateWorkflow, GetWorkflow, UpdateWorkflow, DeleteWorkflow, ListWorkflows, BatchGetWorkflows, StartWorkflowRun, GetWorkflowRun, GetWorkflowRuns, StopWorkflowRun, ResumeWorkflowRun, GetWorkflowRunProperties, PutWorkflowRunProperties |
| Blueprints & runs | CreateBlueprint, GetBlueprint, UpdateBlueprint, DeleteBlueprint, ListBlueprints, BatchGetBlueprints, StartBlueprintRun, GetBlueprintRun, GetBlueprintRuns |
| Schema registry | CreateRegistry, GetRegistry, UpdateRegistry, DeleteRegistry, ListRegistries, CreateSchema, GetSchema, UpdateSchema, DeleteSchema, ListSchemas, RegisterSchemaVersion, GetSchemaVersion, GetSchemaByDefinition, ListSchemaVersions, DeleteSchemaVersions, CheckSchemaVersionValidity, GetSchemaVersionsDiff |
| Security configurations | CreateSecurityConfiguration, GetSecurityConfiguration, DeleteSecurityConfiguration, GetSecurityConfigurations |
| Dev endpoints | CreateDevEndpoint, GetDevEndpoint, UpdateDevEndpoint, DeleteDevEndpoint, GetDevEndpoints, ListDevEndpoints, BatchGetDevEndpoints |
| Tags / policy / encryption | TagResource, UntagResource, GetTags, PutResourcePolicy, GetResourcePolicy, DeleteResourcePolicy, PutDataCatalogEncryptionSettings, GetDataCatalogEncryptionSettings |
| Read-only / analytics / ML / data-quality / integrations (synthesized) | 165 remaining operations (ML transforms, data quality, integrations, glossary/assets/forms, column statistics, sessions/statements, usage profiles, materialized views, identity center, dashboards, unfiltered metadata, catalog import, job bookmarks, partition indexes, table optimizers, schema-version metadata) |
CreateDatabase/CreateTable/CreatePartition/CreateCrawler (etc.) claim
their name atomically (memstore.SetIfAbsent) so a duplicate is
AlreadyExistsException; a bad name is validated before any lookup
(InvalidInputException); an absent resource is EntityNotFoundException. Reads
(Get*/Batch*/list) return deep copies so callers never alias stored maps,
column lists, partition value lists, or parameters. UpdateTable appends a table
version. DeleteDatabase cascades to its tables, table partitions, and UDFs;
DeleteTable releases its partitions — no dependents are orphaned, and the write
lock is held across the check+delete. CatalogId defaults to the account ID.
Tag caps and BatchGet* size caps are enforced before any mutation, so a
breach leaves committed state unchanged. Pagination honors NextToken/
MaxResults; a malformed token is an InvalidInputException, never a silent
page-one restart. Real ARNs are minted for registries/schemas.
No real compute or data plane — a deliberate simplification. A StartJobRun
completes SUCCEEDED synchronously and returns its run ID; crawler, workflow,
and blueprint runs settle immediately as well. This preserves the SDK wire
shapes for build-and-orchestrate testing without a real Spark cluster. The
synthesized read-only surfaces (ML transforms, data quality, glossary, column
statistics, integrations, etc.) accept the request and return an empty,
well-formed response body rather than fabricating fake job results or scores.
Total: 299 operations.
Driver interface: services/guardduty/driver/
AWS: GuardDuty (REST-JSON awsRestjson1, path + HTTP-method routing, no version prefix) | Azure: — | GCP: —
AWS-only. Real aws-sdk-go-v2/service/guardduty clients (and the aws guardduty
CLI) work against the SDK-compat server (awsserver.Drivers{GuardDuty: cloud.GuardDuty}).
GuardDuty has no version-path prefix, so the handler gates on its known root
segments (detector, admin, invitation, tags, malware-scan,
malware-protection-plan, object-malware-scan, organization) and registers
before the S3 catch-all; an S3 bucket named exactly one of those roots would be
shadowed (a documented limitation). Full aws-sdk-go-v2/service/guardduty
parity — every one of the 87 client operations is implemented.
Detectors and their children behave realistically. CreateDetector mints a
detector id atomically; child resources (IP sets, threat-intel/entity sets,
trusted-entity sets, filters) are created under the detector scope lock so a
concurrent DeleteDetector can't orphan them, and DeleteDetector cascades to
remove them. Findings support sample generation, FindingCriteria filtering,
sort + pagination, archive/unarchive, statistics, and feedback. Reads deep-copy
so concurrent tag/config mutations don't race.
| Family | Operations |
|---|---|
| Detectors | CreateDetector, GetDetector, UpdateDetector, DeleteDetector, ListDetectors |
| IP sets / threat sets | Create/Get/Update/Delete/List for IPSet, ThreatIntelSet, ThreatEntitySet, TrustedEntitySet |
| Filters | CreateFilter, GetFilter, UpdateFilter, DeleteFilter, ListFilters |
| Members | CreateMembers, GetMembers, ListMembers, DeleteMembers, InviteMembers, DisassociateMembers, Start/StopMonitoringMembers, Get/UpdateMemberDetectors |
| Invitations / admin | Accept(Administrator)Invitation, Decline/DeleteInvitations, ListInvitations, GetInvitationsCount, Get(Administrator/Master)Account, DisassociateFrom(Administrator/Master)Account |
| Organization | Enable/Disable/ListOrganizationAdminAccounts, Describe/UpdateOrganizationConfiguration, GetOrganizationStatistics |
| Publishing destinations | Create/Describe/Update/Delete/ListPublishingDestinations |
| Findings | CreateSampleFindings, ListFindings, GetFindings, GetFindingsStatistics, Archive/UnarchiveFindings, UpdateFindingsFeedback |
| Coverage / usage | ListCoverage, GetCoverageStatistics, GetUsageStatistics, GetRemainingFreeTrialDays |
| Malware protection | Create/Get/Update/Delete/ListMalwareProtectionPlans, StartMalwareScan, GetMalwareScan, List/DescribeMalwareScans, SendObjectMalwareScan, Get/UpdateMalwareScanSettings |
| Tags | ListTagsForResource, TagResource, UntagResource |
Total: 87 operations.
Driver interface: services/kafka/driver/
AWS: MSK (REST-JSON awsRestjson1, path + HTTP-method routing under the /v1/, /api/v2/, and /replication/v1/ version prefixes) | Azure: — | GCP: —
AWS-only. Real aws-sdk-go-v2/service/kafka clients (and the aws kafka CLI)
work against the SDK-compat server (awsserver.Drivers{Kafka: cloud.Kafka}). The
handler gates on the three version prefixes plus a known root segment, so it
registers before the S3 catch-all without shadowing it (a bucket literally named
v1/api/replication would be shadowed — a documented limitation). Full
aws-sdk-go-v2/service/kafka parity — every one of the 59 client operations is
implemented.
Clusters behave realistically. CreateCluster/CreateClusterV2 claim the
cluster name atomically (ConflictException on a duplicate) and return a cluster
that is immediately ACTIVE (deterministic — no wall-clock provisioning). The v1
and v2 shapes render the same underlying cluster, so a v1-created cluster is
describable via DescribeClusterV2. Each mutating op (broker count/storage/type,
storage, configuration, version, connectivity, monitoring, security, rebalancing,
reboot) validates the optimistic-concurrency CurrentVersion, applies the change,
records a ClusterOperation, and bumps the version; reads deep-copy. Broker
counts validate real MSK's constraints (increase-only, a multiple of the AZ
count); CreateCluster validates the kafka.* instance type and the EBS volume
size (1–16384 GiB); a VPC connection's target cluster must exist and be
provisioned. Tags apply to all four taggable resources (clusters, configurations,
VPC connections, replicators), routed by ARN.
Limitation (synchronous lifecycle). Clusters provision immediately ACTIVE
and every mutation applies synchronously, so a cluster never passes through the
transient CREATING/UPDATING states and DeleteCluster removes it rather than
leaving it DELETING. Consequently real MSK's rule "reject a mutation while the
cluster is CREATING/UPDATING/DELETING" is not reproduced — back-to-back
updates all succeed. Optimistic-concurrency CurrentVersion (including on
delete) is still enforced.
| Family | Operations |
|---|---|
| Clusters (v1) | CreateCluster, DescribeCluster, ListClusters, DeleteCluster, GetBootstrapBrokers |
| Clusters (v2) | CreateClusterV2, DescribeClusterV2, ListClustersV2 |
| Cluster mutations | UpdateBrokerCount/Storage/Type, UpdateStorage, UpdateClusterConfiguration, UpdateClusterKafkaVersion, UpdateConnectivity, UpdateMonitoring, UpdateSecurity, UpdateRebalancing, RebootBroker |
| Cluster operations | ListClusterOperations(V2), DescribeClusterOperation(V2) |
| Configurations | Create/Describe/Update/Delete/ListConfigurations, ListConfigurationRevisions, DescribeConfigurationRevision |
| Nodes / versions | ListNodes, ListKafkaVersions, GetCompatibleKafkaVersions |
| VPC connections | Create/Describe/Delete/ListVpcConnections, ListClientVpcConnections, RejectClientVpcConnection |
| Topics | CreateTopic, DescribeTopic, ListTopics, UpdateTopic, DeleteTopic, DescribeTopicPartitions |
| SCRAM secrets | BatchAssociateScramSecret, BatchDisassociateScramSecret, ListScramSecrets |
| Cluster policy | PutClusterPolicy, GetClusterPolicy, DeleteClusterPolicy |
| Replicators | CreateReplicator, DescribeReplicator, ListReplicators, DeleteReplicator, UpdateReplicationInfo |
| Tags (clusters, configurations, VPC connections, replicators) | ListTagsForResource, TagResource, UntagResource |
Total: 59 operations.
| Service | Operations |
|---|---|
| Storage | 33 |
| Compute | 35 |
| Database | 21 |
| Serverless | 26 |
| Networking | 51 |
| Networking — AWS-specific (Transit Gateway / VPN / DHCP / prefix lists / egress-only IGW / endpoint services / Client VPN / Traffic Mirroring / Network Insights / VPC Block Public Access / IPAM full incl. discovery/BYOASN/BYOIP/resolver/policy + AWS/IPAM metrics) | 162 |
| Network Firewall — AWS | 20 |
| Monitoring | 12 |
| IAM | 35 |
| DNS | 15 |
| Load Balancer | 21 |
| Message Queue | 14 |
| Cache | 16 (+7 optional) |
| MemoryDB — AWS (Redis/Valkey control plane) | 33 (+13 optional) |
| Keyspaces — AWS (Cassandra control plane) | 18 (+1 optional) |
| Managed Cassandra — Azure (Cosmos DB) | 15 |
| Bigtable — GCP (wide-column NoSQL) | 38 |
| Cosmos DB for PostgreSQL — Azure (Citus) | 34 |
| Secrets | 7 |
| Logging | 13 |
| Notification | 8 |
| Container Registry | 14 |
| Event Bus | 15 |
| Relational Database | 21 (+117 optional) |
| Kubernetes — AWS EKS (control plane) | 21 |
| Kubernetes — Azure AKS (control plane) | 18 |
| Kubernetes — GCP GKE (control plane) | 26 |
| Kubernetes — data plane (30 resources, most × 7 verbs incl. Watch, + /scale and /status subresources) | 249 |
| Resource Discovery (engine + AWS + Azure + GCP handlers) | 26 |
| Generative AI — AWS Bedrock (control plane + runtime) | 65 |
| Generative AI — AWS Bedrock Agent (control plane + runtime) | 32 |
| Databricks — Azure (control + data plane) | 70 |
| Machine Learning — AWS SageMaker (control plane + runtime) | 121 |
| Machine Learning — Azure AI (CognitiveServices + MachineLearningServices + data plane) | 92 |
| Machine Learning — GCP Vertex AI (Go API/driver) | 128 |
| AI Search — Azure AI Search (control + data plane) | 53 |
| Container Orchestration — AWS ECS | 37 |
| DNS Resolver — AWS Route 53 Resolver | 72 |
| Application Networking — AWS VPC Lattice | 73 |
| Key Management — AWS KMS | 45 |
| File System — AWS EFS | 30 |
| Certificate Manager — AWS ACM | 17 |
| Email Service — AWS SES v2 | 113 |
| Web Application Firewall — AWS WAFv2 | 59 |
| Data Streams — AWS Kinesis | 39 |
| Step Functions — AWS SFN | 36 |
| Search & Analytics — AWS OpenSearch | 96 |
| Audit Logging — AWS CloudTrail | 60 |
| Configuration Management — AWS Config | 102 |
| Data Integration — AWS Glue | 299 |
| Threat Detection — Amazon GuardDuty | 87 |
| Streaming — Amazon MSK | 59 |
| Grand Total | 2749 (+138 optional) |
Optional operations are capabilities a driver may implement but is not required to; see the sections marked "optional capability". They are counted separately because a driver without them is still complete.
Provider-specific resources are not counted: no driver interface covers them, so there are no driver operations to count.