What floci-io/floci shipped
Written by FoxPlug from public releases; not affiliated with Floci. An automatic summary of the public release, pull request and commit data of github.com/floci-io/floci. Floci did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- ECS task containers now receive their IAM role credentials, enabling tasks to authenticate as their configured role. Pull request #4486
- Route 53 now resolves private hosted zone records from cluster containers, bridging the management plane and DNS serving. Pull request #4353
- S3 CreateBucket applies AWS's region rules consistently across all partitions. Pull request #4494
- SES list operations now support pagination with a shared mechanism covering ListTemplates and ListExportJobs. Pull request #4465
- KMS imported key material now supports elliptic curve key types: ECC_NIST_P256, ECC_NIST_P384, ECC_NIST_P521, and ECC_SECG_P256K1. Pull request #4428
- EC2 route tables now support InstanceId and NetworkInterfaceId route targets with automatic InstanceOwnerId population. Pull request #4416
- API Gateway import now honors the failonwarnings parameter and preserves parser warnings in responses. Pull request #4531
- Cloud Map DNS A record answers now include the configured TTL and distinguish NXDOMAIN from no-data responses. Pull request #4448
- IoT MQTT WebSocket bridge stabilizes concurrent client sessions and handles broker-initiated closes. Pull request #3816
- ElastiCache now accepts HELLO AUTH handshakes for protected endpoints. Pull request #4476
Why it matters
This week brings critical AWS feature coverage: ECS tasks can now authenticate as their roles, Route 53 serves private DNS to containers, and multi-partition support extends S3 and hostname handling across AWS regions. The additions span authentication, DNS resolution, and regional compatibility.
Changelog entry
- feat(ecs): ECS task containers receive IAM role credentials from task-role sessions Pull request #4486
- feat(route53): Route 53 resolves private hosted zone records from cluster containers Pull request #4353
- fix(s3): S3 CreateBucket applies AWS region rules in every partition Pull request #4494
- feat(ses): SES list operations support pagination for ListTemplates and ListExportJobs Pull request #4465
- feat(kms): KMS imported key material supports ECC_NIST_P256, ECC_NIST_P384, ECC_NIST_P521, ECC_SECG_P256K1 Pull request #4428
- feat(ec2): EC2 route tables support InstanceId and NetworkInterfaceId route targets Pull request #4416
- fix(apigateway): API Gateway import honors failonwarnings and preserves parser warnings Pull request #4531
- feat(cloudmap): Cloud Map DNS A answers include configured TTL Pull request #4448
- fix(iot): IoT MQTT WebSocket bridge stabilizes concurrent sessions Pull request #3816
- fix(elasticache): ElastiCache accepts HELLO AUTH handshakes Pull request #4476
- fix(cognito): Cognito PasswordPolicy validates MinimumLength and removes default of 8 Pull request #4359
- fix(sqs): SQS FIFO deduplication retained for full five-minute window after deletion Pull request #4460
- fix(sns): SNS retries failed SQS subscription deliveries up to three times with DLQ support Pull request #4468
- fix(core): AWS hostnames built and recognized in every partition Pull request #4451
- fix(cloudformation): CloudFormation DeleteStack deletes UPDATE_FAILED resources Pull request #4470
- fix(rds): RDS RestoreDBClusterFromSnapshot honors Port parameter Pull request #4326
- fix(cognito): Cognito auth challenge sessions expire Pull request #4417
- fix(cognito): Cognito USER_AUTH flow hides unknown users with PreventUserExistenceErrors Pull request #4478
- feat(iam): IAM adds last-accessed reporting actions Pull request #4488
- fix(elbv2): ELBv2 health checks use target group's HealthCheckPort Pull request #4432
Floci ships ECS task role credentials, Route 53 private DNS from containers, and multi-partition S3 region rules. EC2 route targets, KMS ECC keys, and ElastiCache HELLO AUTH also land.
This week's Floci update strengthens container authentication and DNS: ECS tasks now receive IAM role credentials, Route 53 resolves private zones from cluster containers, and S3 applies region rules across partitions. Additional improvements include EC2 route target support, KMS elliptic curve imported keys, ElastiCache HELLO AUTH, and SES pagination.
Week of September 14, 2026
What shipped
- SageMaker training jobs now respect GPU instance types like ml.g5.xlarge instead of running on CPU. Pull request #4015
- EKS Pod Identity association management lets you map Kubernetes namespaces and service accounts to IAM roles. Pull request #4012
- Glue catalog resource policy and Data Catalog encryption settings are now supported. Pull request #4027
- Glue Data Catalog connections API is implemented with create, get, update, delete and test operations. Pull request #3939
- EventBridge can now route events to Step Functions state machines as direct targets. Pull request #4006
- Cognito USER_AUTH flow lets users choose between password, password SRP, email OTP or SMS OTP authentication. Pull request #3930
- Redshift supports S3 COPY with JSON format and manifest files, plus DynamoDB zero-ETL backfill. Pull request #3889
- AWS Batch CancelJob and TerminateJob operations stop containers and manage job lifecycle state correctly. Pull request #3922
- IAM and STS now use cryptographic random generation for access key secrets, session secrets, tokens and KMS grant tokens. Pull request #3960
Why it matters
This week brought significant AWS service coverage expansions—Glue catalogs and classifiers, EKS Pod Identity, SageMaker GPU support, EventBridge-to-Step-Functions integration, and Redshift JSON copying—alongside critical security fixes for credential generation and important lifecycle fixes for Cognito, Batch and other services. The work spans multiple AWS services with both new capabilities and correctness improvements.
Changelog entry
- feat(sagemaker): support GPU-backed training jobs Pull request #4015
- feat(eks): implement pod identity association management Pull request #4012
- feat(glue): catalog resource policy and Data Catalog encryption settings Pull request #4027
- fix(cognito): accept USER_SRP_AUTH in AdminInitiateAuth Pull request #3973
- fix(cognito): omit AvailableChallenges from RespondToAuthChallenge responses Pull request #4025
- fix(iam): use SecureRandom for secret credentials and tokens Pull request #3960
- fix(eks): store and return encryptionConfig and logging on clusters Pull request #4007
- feat(glue): Data Catalog connections Pull request #3939
- feat(eventbridge): start Step Functions targets Pull request #4006
- feat(cognito): support the USER_AUTH choice-based auth flow Pull request #3930
- fix(dynamodb): enforce the 400KB item limit on every update surface Pull request #3991
- feat(glue): add crawler classifier APIs Pull request #3985
- feat(redshift): support S3 COPY JSON and manifest, and DynamoDB zero-ETL backfill Pull request #3889
- feat(batch): support canceling and terminating jobs Pull request #3922
- fix(kms): match the AWS error codes, messages and check order Pull request #3968
This week: SageMaker GPU support, EKS Pod Identity, Glue catalog/classifiers, EventBridge→StepFunctions, Redshift JSON COPY, Cognito USER_AUTH, Batch job control, plus cryptographic credential generation and dozens of correctness fixes.
This week's Floci updates span AWS service expansion and critical fixes. New: SageMaker GPU-backed training, EKS Pod Identity associations, Glue catalog policies and classifiers, EventBridge-to-StepFunctions routing, Redshift JSON/manifest COPY, Cognito USER_AUTH flow, Batch job cancellation. Security: switched credential generation to cryptographic randomness. Correctness: fixed Cognito auth flows, DynamoDB item limits, KMS error codes, CloudFormation lifecycle, ECS request handling, and dozens more.