Skip to content

fix: bypass proxy for Runtime API calls - #68

Open
benrkia wants to merge 5 commits into
mainfrom
ilbe/proxy-bypass
Open

benrkia wants to merge 5 commits into
mainfrom
ilbe/proxy-bypass

Conversation

@benrkia

@benrkia benrkia commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Description of changes:

The Runtime API client used Net::HTTP.post and Net::HTTP.new(host, port), both of which default to :ENV proxy resolution and honor HTTP(S)_PROXY. A customer-configured proxy then routed calls to the API endpoint through the proxy, so a proxy in the environment could break function init and result delivery even though it should never affect communication with the API.

Route the invocation poll and the three write-backs through a single client built with a nil proxy argument, which disables Net::HTTP's default proxy resolution so the link-local API endpoint is never proxied.

Target (OCI, Managed Runtime, both):

Both

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

The Runtime API client used Net::HTTP.post and Net::HTTP.new(host, port),
both of which default to :ENV proxy resolution and honor HTTP(S)_PROXY. A
customer-configured proxy then routed calls to the API endpoint through the
proxy, so a proxy in the environment could break function init and result
delivery even though it should never affect communication with the API.

Route the invocation poll and the three write-backs through a single client
built with a nil proxy argument, which disables Net::HTTP's default proxy
resolution so the link-local API endpoint is never proxied.
Adds a handler that asks the fixed RapidClient#build_client for an HTTP
client bound to a non-loopback URI while HTTP_PROXY is set, and returns
the resulting proxy? values. Suite asserts that a bare Net::HTTP.new
picks up the proxy and RapidClient does not. On unfixed code
build_client does not exist, the handler raises NoMethodError and the
suite fails.
@maxday
maxday self-requested a review September 22, 2026 09:00
maxday and others added 3 commits September 22, 2026 12:51
The earlier commit introspected RapidClient#build_client directly, which
overlapped with the unit tests already added in PR #68. Per review
feedback, replace it with a customer-shaped test: bind RIE Runtime API
to the container's own non-loopback hostname (so Ruby's URI.find_proxy
does not silently bypass the proxy for loopback), set HTTP_PROXY on the
image to an unreachable address, and have the handler simply return
"success".

With the fix the RIC bypasses HTTP_PROXY and the handler runs; without
it the RIC tries the unreachable proxy for next_invocation and every
suite in the image fails.
Reviewer flagged that setting HTTP_PROXY globally in Dockerfile.test
made every suite exercise the fix, so proxy.json no longer proved
anything the other suites did not, and a regression would break the
whole matrix instead of the one intended test.

Move the proxy setup into a second image (Dockerfile.test.proxy) that
extends local/test with HTTP_PROXY and the custom entrypoint, and move
the proxy suite under test/dockerized/suites/proxy/ so the default
suites/*.json glob no longer picks it up. Workflow now builds both
images and runs each glob against its own image.
test: add dockerized regression test for the proxy-bypass fix
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants