-
Notifications
You must be signed in to change notification settings - Fork 27
Document tls_no_verify #394
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
This builds upon this commit #388 to further document this configuration variable. Completes [doc-9](https://linear.app/localstack/issue/DOC-9/document-ssl-no-verify-flag)
Deploying localstack-docs with
|
| Latest commit: |
d76e74b
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://fc95965a.localstack-docs.pages.dev |
| Branch Preview URL: | https://tls-ssl-no-verify.localstack-docs.pages.dev |
|
If you approve @simonrw, we'll merge it! |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Minor nits but looks good, thanks!
|
|
||
| ## Disabling TLS verification for LocalStack Cloud | ||
|
|
||
| If your proxy intercepts traffic to LocalStack cloud services (e.g., license server, localhost.localstack.cloud), you can disable TLS verification for these specific requests using the `SSL_NO_VERIFY` [configuration variable](/aws/capabilities/config/configuration#security). |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
nit: localhost.localstack.cloud is not one of our cloud services. The two requests we make are to the license server, and to fetch our TLS certificate so that we can serve a trusted certificate for localhost.localstack.cloud.
| If your proxy intercepts traffic to LocalStack cloud services (e.g., license server, localhost.localstack.cloud), you can disable TLS verification for these specific requests using the `SSL_NO_VERIFY` [configuration variable](/aws/capabilities/config/configuration#security). | ||
|
|
||
| ```bash | ||
| SSL_NO_VERIFY=1 localstack start |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
question: don't we have a thing where our envars need to be prefixed with LOCALSTACK_?
| ``` | ||
|
|
||
| :::caution | ||
| This approach disables certificate verification rather than trusting your proxy's certificate. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
praise: good worth putting in here that disabling TLS verification should be a last resort 👍
This builds upon this commit #388 to further document this configuration variable.
Completes doc-9