Skip to content

feat(lambda): give function containers the AWS environment - #4

Closed
Sorttech wants to merge 1 commit into
mainfrom
fix/lambda-container-aws-endpoint
Closed

Sorttech wants to merge 1 commit into
mainfrom
fix/lambda-container-aws-endpoint

Conversation

@Sorttech

@Sorttech Sorttech commented Sep 11, 2026 •

Copy link
Copy Markdown
Owner

Real Lambda injects region and execution-role credentials, and function
code relies on them: an SDK client built with no region or credentials
fails before it reaches an endpoint. fakecloud injected none of the
standard variables, only the function's own environment, so handler code
that called AWS did nothing useful -- CDK's BucketDeployment reported
success having copied no files.

Inject AWS_REGION, AWS_DEFAULT_REGION and credentials, plus
AWS_ENDPOINT_URL pointing at the backend's host alias and this server's
port. The endpoint is the one deliberate deviation from AWS: there the
variable is absent and the SDK's defaults are correct, whereas here the
container has to be pointed back at fakecloud or the handler reaches out
to the real internet. localhost would resolve to the container itself,
so the existing host alias is reused. Defaults are emitted before the
function's own environment, so a function that sets any of them wins.

The E2E asserts the environment the container actually observes. It stops
short of a full SDK round-trip from inside the container: that also needs
container-to-host reachability on an arbitrary host port, which does not
hold on every developer machine (WSL2 here), and would make the test flaky
for reasons unrelated to this change.

Test plan

Regression test: lambda_container_receives_the_aws_environment in crates/fakecloud-e2e/tests/lambda_aws_env.rs

Verification

On this exact head, rebased onto current main:

  • cargo fmt --all --check - clean.
  • cargo clippy --workspace --all-targets -- -D warnings - clean.
  • cargo test --workspace excluding fakecloud-e2e, fakecloud-conformance,
    fakecloud-tfacc and fakecloud-parity (the same set CI's test job runs),
    plus cargo test -p fakecloud-conformance --lib - 9931 passed, 0 failed.
  • cargo test -p fakecloud-e2e --test lambda_aws_env - the regression test
    above passes in a real Lambda container under Docker against a freshly
    built target/debug/fakecloud.

Found by deploying a CDK CloudFront + S3 SPA against fakecloud.

@Sorttech Sorttech closed this Sep 11, 2026
@Sorttech Sorttech reopened this Sep 11, 2026
Real Lambda injects region and execution-role credentials, and function
code relies on them: an SDK client built with no region or credentials
fails before it reaches an endpoint. fakecloud injected none of the
standard variables, only the function's own environment, so handler code
that called AWS did nothing useful -- CDK's `BucketDeployment` reported
success having copied no files.

Inject `AWS_REGION`, `AWS_DEFAULT_REGION` and credentials, plus
`AWS_ENDPOINT_URL` pointing at the backend's host alias and this server's
port. The endpoint is the one deliberate deviation from AWS: there the
variable is absent and the SDK's defaults are correct, whereas here the
container has to be pointed back at fakecloud or the handler reaches out
to the real internet. `localhost` would resolve to the container itself,
so the existing host alias is reused. Defaults are emitted before the
function's own environment, so a function that sets any of them wins.

The E2E asserts the environment the container actually observes. It stops
short of a full SDK round-trip from inside the container: that also needs
container-to-host reachability on an arbitrary host port, which does not
hold on every developer machine (WSL2 here), and would make the test flaky
for reasons unrelated to this change.
@Sorttech
Sorttech force-pushed the fix/lambda-container-aws-endpoint branch from 3b77281 to 2623556 Compare September 24, 2026 16:14
@Sorttech

Copy link
Copy Markdown
Owner Author

Retargeted upstream as faiscadev#2562.

@Sorttech Sorttech closed this Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant