Conversation
Real Lambda injects region and execution-role credentials, and function code relies on them: an SDK client built with no region or credentials fails before it reaches an endpoint. fakecloud injected none of the standard variables, only the function's own environment, so handler code that called AWS did nothing useful -- CDK's `BucketDeployment` reported success having copied no files. Inject `AWS_REGION`, `AWS_DEFAULT_REGION` and credentials, plus `AWS_ENDPOINT_URL` pointing at the backend's host alias and this server's port. The endpoint is the one deliberate deviation from AWS: there the variable is absent and the SDK's defaults are correct, whereas here the container has to be pointed back at fakecloud or the handler reaches out to the real internet. `localhost` would resolve to the container itself, so the existing host alias is reused. Defaults are emitted before the function's own environment, so a function that sets any of them wins. The E2E asserts the environment the container actually observes. It stops short of a full SDK round-trip from inside the container: that also needs container-to-host reachability on an arbitrary host port, which does not hold on every developer machine (WSL2 here), and would make the test flaky for reasons unrelated to this change.
Sorttech
force-pushed
the
fix/lambda-container-aws-endpoint
branch
from
September 24, 2026 16:14
3b77281 to
2623556
Compare
Owner
Author
|
Retargeted upstream as faiscadev#2562. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Real Lambda injects region and execution-role credentials, and function
code relies on them: an SDK client built with no region or credentials
fails before it reaches an endpoint. fakecloud injected none of the
standard variables, only the function's own environment, so handler code
that called AWS did nothing useful -- CDK's
BucketDeploymentreportedsuccess having copied no files.
Inject
AWS_REGION,AWS_DEFAULT_REGIONand credentials, plusAWS_ENDPOINT_URLpointing at the backend's host alias and this server'sport. The endpoint is the one deliberate deviation from AWS: there the
variable is absent and the SDK's defaults are correct, whereas here the
container has to be pointed back at fakecloud or the handler reaches out
to the real internet.
localhostwould resolve to the container itself,so the existing host alias is reused. Defaults are emitted before the
function's own environment, so a function that sets any of them wins.
The E2E asserts the environment the container actually observes. It stops
short of a full SDK round-trip from inside the container: that also needs
container-to-host reachability on an arbitrary host port, which does not
hold on every developer machine (WSL2 here), and would make the test flaky
for reasons unrelated to this change.
Test plan
Regression test:
lambda_container_receives_the_aws_environmentincrates/fakecloud-e2e/tests/lambda_aws_env.rsVerification
On this exact head, rebased onto current
main:cargo fmt --all --check- clean.cargo clippy --workspace --all-targets -- -D warnings- clean.cargo test --workspaceexcludingfakecloud-e2e,fakecloud-conformance,fakecloud-tfaccandfakecloud-parity(the same set CI'stestjob runs),plus
cargo test -p fakecloud-conformance --lib- 9931 passed, 0 failed.cargo test -p fakecloud-e2e --test lambda_aws_env- the regression testabove passes in a real Lambda container under Docker against a freshly
built
target/debug/fakecloud.Found by deploying a CDK CloudFront + S3 SPA against fakecloud.