aws-bench on Floci — gap matrix (derived 2026-07-26, corrected count v2)
Source: offline cdk synth of all 8 aws-bench-datasets scenarios (211 distinct resource types) diffed against Floci main's CFN provisioner (75 unique types incl. extracted provisioners). v2 fixes a double-count of the provision/delete switches in v1.
Per-scenario CFN coverage
- api-and-observability: 31 of 80 types missing
- compute-and-data: 15 of 40 types missing
- databases-and-storage: 25 of 69 types missing
- ec2-multiregion: 4 of 18 types missing
- reference-architectures: 70 of 129 types missing
- serverless-apps: 21 of 62 types missing
- streaming-and-iot: 22 of 47 types missing
- troubleshooting-multiservice: 50 of 93 types missing
Missing CFN resource types (140), tagged by scenario
- AWS::AmazonMQ::Broker refe
- AWS::ApiGateway::Account api-,data,refe,serv
- AWS::ApiGateway::ApiKey refe
- AWS::ApiGateway::UsagePlan refe
- AWS::ApiGateway::UsagePlanKey refe
- AWS::AppConfig::Application trou
- AWS::AppConfig::ConfigurationProfile trou
- AWS::AppConfig::Deployment trou
- AWS::AppConfig::DeploymentStrategy trou
- AWS::AppConfig::Environment trou
- AWS::AppConfig::HostedConfigurationVersion trou
- AWS::AppSync::DataSource refe
- AWS::AppSync::FunctionConfiguration refe
- AWS::AppSync::GraphQLApi refe
- AWS::AppSync::GraphQLSchema refe
- AWS::AppSync::Resolver refe
- AWS::Athena::WorkGroup data,serv
- AWS::AutoScaling::LifecycleHook serv,stre,trou
- AWS::AutoScaling::ScalingPolicy refe
- AWS::Backup::BackupPlan refe
- AWS::Backup::BackupSelection refe
- AWS::Backup::BackupVault refe
- AWS::Bedrock::KnowledgeBase api-
- AWS::CloudFront::CloudFrontOriginAccessIdentity comp,refe
- AWS::CloudFront::ConnectionGroup api-
- AWS::CloudFront::Distribution api-,comp,refe,trou
- AWS::CloudFront::Function refe
- AWS::CloudFront::OriginAccessControl api-
- AWS::CloudWatch::Dashboard api-,refe,serv
- AWS::CloudWatch::MetricStream serv
- AWS::CodeBuild::Project data,refe
- AWS::CodeCommit::Repository refe
- AWS::CodeDeploy::Application refe
- AWS::CodeDeploy::DeploymentGroup refe
- AWS::CodePipeline::Pipeline refe
- AWS::Cognito::IdentityPool api-
- AWS::Cognito::IdentityPoolRoleAttachment api-
- AWS::Cognito::UserPoolDomain api-
- AWS::CustomerProfiles::Domain stre
- AWS::DocDB::DBCluster serv
- AWS::DocDB::DBInstance serv
- AWS::DocDB::DBSubnetGroup serv
- AWS::EC2::FlowLog api-,data,trou
- AWS::EC2::InstanceConnectEndpoint refe
- AWS::EC2::IPAM comp
- AWS::EC2::IPAMPool comp
- AWS::EC2::IPAMScope comp
- AWS::EC2::LaunchTemplate comp,data,ec2-,refe,serv,stre,trou
- AWS::EC2::NetworkAcl data,trou
- AWS::EC2::NetworkAclEntry data,trou
- AWS::EC2::NetworkInterface data,trou
- AWS::EC2::NetworkInterfaceAttachment trou
- AWS::EC2::SecurityGroupEgress refe,serv,stre,trou
- AWS::EC2::SecurityGroupIngress api-,refe,serv,stre,trou
- AWS::EC2::SubnetNetworkAclAssociation data,trou
- AWS::EC2::TransitGateway trou
- AWS::EC2::TransitGatewayAttachment trou
- AWS::EC2::TransitGatewayRoute trou
- AWS::EC2::TransitGatewayRouteTable trou
- AWS::EC2::TransitGatewayRouteTableAssociation trou
- AWS::EC2::TransitGatewayRouteTablePropagation trou
- AWS::EC2::Volume comp
- AWS::EC2::VPCEndpoint api-,data,refe,stre,trou
- AWS::EC2::VPCGatewayAttachment api-,comp,data,ec2-,refe,serv,stre,trou
- AWS::ECS::CapacityProvider data,serv,stre,trou
- AWS::ECS::ClusterCapacityProviderAssociations api-,data,refe,serv,stre,trou
- AWS::EFS::FileSystem refe
- AWS::EFS::MountTarget refe
- AWS::EKS::Addon comp
- AWS::ElastiCache::CacheCluster trou
- AWS::ElastiCache::SubnetGroup trou
- AWS::EMR::Cluster trou
- AWS::Events::EventBus stre
- AWS::Glue::Database api-,data,trou
- AWS::Glue::Job trou
- AWS::Glue::Table api-,data,trou
- AWS::IAM::Group refe
- AWS::ImageBuilder::Component refe
- AWS::ImageBuilder::ContainerRecipe refe
- AWS::ImageBuilder::DistributionConfiguration refe
- AWS::ImageBuilder::ImagePipeline refe
- AWS::ImageBuilder::InfrastructureConfiguration refe
- AWS::IoT::Thing stre
- AWS::LakeFormation::DataLakeSettings trou
- AWS::Lambda::Alias serv,trou
- AWS::Lambda::Permission api-,data,refe,serv,stre,trou
- AWS::Lambda::Version serv,trou
- AWS::Lex::Bot refe
- AWS::Lex::BotAlias refe
- AWS::Lex::BotVersion refe
- AWS::Logs::LogStream serv
- AWS::Logs::MetricFilter refe
- AWS::MSK::Cluster stre
- AWS::MSK::Topic stre
- AWS::Neptune::DBCluster stre
- AWS::Neptune::DBInstance stre
- AWS::Neptune::DBSubnetGroup stre
- AWS::NetworkFirewall::Firewall trou
- AWS::NetworkFirewall::FirewallPolicy trou
- AWS::OpenSearchService::Domain api-
- AWS::Redshift::Cluster api-,trou
- AWS::Redshift::ClusterParameterGroup api-,trou
- AWS::Redshift::ClusterSubnetGroup api-,trou
- AWS::RedshiftServerless::Namespace comp
- AWS::RedshiftServerless::Workgroup comp
- AWS::Route53Resolver::FirewallDomainList refe
- AWS::Route53Resolver::FirewallRuleGroup refe
- AWS::Route53Resolver::FirewallRuleGroupAssociation refe
- AWS::Route53Resolver::ResolverEndpoint refe
- AWS::Route53Resolver::ResolverQueryLoggingConfig refe
- AWS::Route53Resolver::ResolverQueryLoggingConfigAssociation refe
- AWS::S3Tables::TableBucket data,stre
- AWS::S3Vectors::Index api-,data
- AWS::S3Vectors::VectorBucket api-,data
- AWS::SageMaker::Domain api-
- AWS::SecretsManager::SecretTargetAttachment data,refe,serv,stre,trou
- AWS::ServiceCatalog::CloudFormationProduct refe
- AWS::ServiceCatalog::LaunchNotificationConstraint refe
- AWS::ServiceCatalog::LaunchRoleConstraint refe
- AWS::ServiceCatalog::LaunchTemplateConstraint refe
- AWS::ServiceCatalog::Portfolio refe
- AWS::ServiceCatalog::PortfolioPrincipalAssociation refe
- AWS::ServiceCatalog::PortfolioProductAssociation refe
- AWS::ServiceCatalog::TagOption refe
- AWS::ServiceCatalog::TagOptionAssociation refe
- AWS::SNS::TopicPolicy refe
- AWS::SSM::Association refe
- AWS::SSM::Document refe,trou
- AWS::Transfer::Server refe
- AWS::Transfer::User refe
- AWS::WAFv2::WebACL data,refe,trou
- AWS::WAFv2::WebACLAssociation trou
- Custom::AWS api-,comp,data,ec2-,refe
- Custom::CDKBucketDeployment api-,comp,data,stre,trou
- Custom::CloudwatchLogResourcePolicy api-
- Custom::LogRetention api-,refe,stre,trou
- Custom::OpenSearchAccessPolicy api-
- Custom::S3AutoDeleteObjects api-,comp,data,refe,serv,stre,trou
- Custom::S3BucketNotifications refe
- Custom::VpcRestrictDefaultSG api-,comp,data,ec2-,refe,serv,trou
Verifier/solution-blocked tasks (8 of 134)
- compute-and-data/amplify-deploy-frontend-from-s3: amplify
- compute-and-data/appstream-stack-with-streaming-vpce: appstream
- compute-and-data/create-medialive-channel: medialive
- compute-and-data/create-s3-tables-with-compaction: s3tables
- compute-and-data/ec2-image-builder-pipeline: imagebuilder
- compute-and-data/kinesis-flink-studio-realtime: kinesisanalyticsv2
- streaming-and-iot/connect-create-customer-profiles: customer-profiles
- streaming-and-iot/iotsitewise-windfarm-rollup-models: iotsitewise
Upstream floci-io/floci overlaps (do not reimplement)
Custom:: resources (verify, may already work via Lambda-backed CR flow)
- Custom::AWS
- Custom::CDKBucketDeployment
- Custom::CloudwatchLogResourcePolicy
- Custom::LogRetention
- Custom::OpenSearchAccessPolicy
- Custom::S3AutoDeleteObjects
- Custom::S3BucketNotifications
- Custom::VpcRestrictDefaultSG
Thin service modules needed (no upstream work open)
- s3tables, medialive, imagebuilder, customer-profiles, iotsitewise, amplify, appstream (verifier-blocking, 1 task each)
- redshift + redshift-serverless, efs, codecommit, lex, lakeformation, network-firewall, servicecatalog, route53resolver (scenario-deploy / introspection surface)
Harness
- aws-bench fork: --emulator floci mode (skip org provisioning, inject AWS_ENDPOINT_URL into deploy/agent/verifier)
aws-bench on Floci — gap matrix (derived 2026-07-26, corrected count v2)
Source: offline cdk synth of all 8 aws-bench-datasets scenarios (211 distinct resource types) diffed against Floci main's CFN provisioner (75 unique types incl. extracted provisioners). v2 fixes a double-count of the provision/delete switches in v1.
Per-scenario CFN coverage
Missing CFN resource types (140), tagged by scenario
Verifier/solution-blocked tasks (8 of 134)
Upstream floci-io/floci overlaps (do not reimplement)
Custom:: resources (verify, may already work via Lambda-backed CR flow)
Thin service modules needed (no upstream work open)
Harness