-
Notifications
You must be signed in to change notification settings - Fork 18
docs: Adding limitation to TEI docs. #166
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
Deploying localstack-docs with
|
| Latest commit: |
2d68a07
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://a699adea.localstack-docs.pages.dev |
| Branch Preview URL: | https://tei-limitations-update.localstack-docs.pages.dev |
src/content/docs/aws/capabilities/networking/transparent-endpoint-injection.md
Outdated
Show resolved
Hide resolved
Co-authored-by: Quetzalli <hola@quetzalliwrites.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I think this is better now, do you agree @remotesynth?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
As discussed in Slack, this needs adaptions.
Copying my message here:
Transparent endpoint injection is a combination of us redirecting requests using DNS, and of us disabling certificate validation for these requests (because otherwise, something will complain if using https). The DNS part works in both the LocalStack container itself, and the spawned compute containers. The certificate part only works for processes we control ourselves, so usually Lambda (managed runtimes) and processes we ourselves start in the LocalStack container. This is why the customer reported the issue - the request was redirected correctly, but we did not disable certificate validation.
Taking this in mind, I think it is worth adding a warning in the docs, that while the DNS redirects the requests both inside the main LS container, and the spawned containers, they might run into certificate issues they have to resolve themselves. (Or use AWS_ENDPOINT_URL as a better alternative, if their SDK is new enough).
|
@dfangl Sorry for the slow response here. I attempted to address this change request by adding another bullet point, though the details were a bit difficult to explain clearly. Please let me know if the following bullet point would address the changes requested: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for adding the additional paragraph! I added some more suggestions, feel free to rephrase them if necessary, then we can merge 🎉
src/content/docs/aws/capabilities/networking/transparent-endpoint-injection.md
Outdated
Show resolved
Hide resolved
src/content/docs/aws/capabilities/networking/transparent-endpoint-injection.md
Outdated
Show resolved
Hide resolved
src/content/docs/aws/capabilities/networking/transparent-endpoint-injection.md
Outdated
Show resolved
Hide resolved
…int-injection.md Co-authored-by: Daniel Fangl <daniel.fangl@gmail.com>
…int-injection.md Co-authored-by: Daniel Fangl <daniel.fangl@gmail.com>
…int-injection.md Co-authored-by: Daniel Fangl <daniel.fangl@gmail.com>
Adding some limitations to clarify that TEI is not intended to work within the LocalStack container itself or any spawned containers by it, such as Lambda.