Missing proxy support in AWSCRTHTTPClient → blocks aws_sdk_bedrock_runtime in private VPCs
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 42/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- aws, python
- Lĩnh vực
- backend, networking
Hướng nghiên cứu
Bắt đầu với AWSCRTHTTPClientConfig và AWSCRTHTTPClient trong smithy-http, sau đó theo dõi _build_new_connection và lệnh gọi đến crt_http.HttpClientConnection.new(...). Xác định cấu hình proxy nên được biểu diễn và truyền qua CRT client như thế nào. Được xem là hoàn tất khi AWSCRTHTTPClient có thể sử dụng HTTP_PROXY/HTTPS_PROXY hoặc các thiết lập proxy tương đương được hỗ trợ trực tiếp cho các Bedrock client trong các VPC riêng tư.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Please let me know if I'm missing something When using aws_sdk_bedrock_runtime to invoke Amazon Nova Sonic in a private VPC (us-west-2), the HTTP stack cannot honor HTTP_PROXY / HTTPS_PROXY because the CRT-based HTTP client does not expose any proxy configuration.
This makes aws_sdk_bedrock_runtime unusable in environments where all outbound internet access must go through a proxy (e.g., ECS Fargate in private subnets without NAT or VPC endpoint).
Application creates a Bedrock client:
crt_http_client = create_crt_http_client(PROXY_URL if not IS_DEV else None)
bedrock_nova_sonic_config = BedrockConfig(
endpoint_uri=f"https://bedrock-runtime.{ONLY_AVAILABLE_REGION_FOR_AWS_NOVA}.amazonaws.com",
region=ONLY_AVAILABLE_REGION_FOR_AWS_NOVA,
aws_credentials_identity_resolver=EnvironmentCredentialsResolver(),
http_auth_scheme_resolver=HTTPAuthSchemeResolver(),
http_auth_schemes={"aws.auth#sigv4": SigV4AuthScheme()},
http_client=crt_http_client,
)
bedrock_client = BedrockRuntimeClient(bedrock_nova_sonic_config)
That crt_http_client is always an instance of:
from smithy_http.aio.crt import AWSCRTHTTPClient
Which in turn requires AWSCRTHTTPClientConfig:
class AWSCRTHTTPClientConfig(http_interfaces.HTTPClientConfiguration):
def __post_init__(self) -> None:
_assert_crt()
And the actual client implementation:
class AWSCRTHTTPClient(http_aio_interfaces.HTTPClient):
_HTTP_PORT = 80
_HTTPS_PORT = 443
def __init__(self, eventloop=None, client_config=None):
_assert_crt()
self._config = client_config or AWSCRTHTTPClientConfig()
self._eventloop = eventloop or _AWSCRTEventLoop()
self._client_bootstrap = self._eventloop.bootstrap
self._tls_ctx = crt_io.ClientTlsContext(crt_io.TlsContextOptions())
self._socket_options = crt_io.SocketOptions()
self._connections = {}
The only config type available is:
@dataclass(kw_only=True)
class HTTPClientConfiguration:
"""Client-level HTTP configuration.
:param force_http_2: Whether to require HTTP/2.
"""
force_http_2: bool = False
There is no field for proxy configuration, nor does AWSCRTHTTPClient internally handle HTTP_PROXY / HTTPS_PROXY.
The underlying call in _build_new_connection goes directly to crt_http.HttpClientConnection.new(...) with just host_name, port, socket_options, and tls_connection_options.
Please add first-class proxy support to smithy-http’s AWSCRTHTTPClient.
- Ngôn ngữ chính
- Python
- Star
- 173
- Fork
- 23
- Merge trung bình
- 2 ngày 7 giờ
- Pull request đã merge (30 ngày)
- 8
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của aws/aws-sdk-python
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
aws/aws-sdk-python#13 ·
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
aws/aws-sdk-python#99 ·
-
Support Python 3.11Đang mở
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 35/100
aws/aws-sdk-python#92 ·
-
announcement
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
aws/aws-sdk-python#90 ·
-
announcement
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 35/100
aws/aws-sdk-python#84 ·
Tất cả issue của aws/aws-sdk-python
Issue tương tự
-
New InternshipĐang mởnew_internship
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 70/100
-
[BUG] Reports tab: "Unban" button tooltip shows raw `{{ip}}` placeholder instead of the IP addressĐang mởbug javascript ui
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
bunkerity/bunkerweb#4001 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
PedestrianDynamics/pyFDS-Evac#476 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
google/differential-privacy#516 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
adobe-fonts/source-serif#153 ·