Skip to content

Conversation

@tsmithsz
Copy link
Contributor

@tsmithsz tsmithsz commented Jun 25, 2025

Problem

We enabled experimental proxy support in FLARE in this PR. The ProxyConfigManager within FLARE gathers and injects OS CAs. See here.

The current setSystemCertificates() call also extracts system certificates and sets NODE_EXTRA_CA_CERTS/AWS_CA_BUNDLE. This duplicates and can even override our custom logic, leading to unpredictable CA bundles.

Solution

  • Remove redundant setSystemCertificates() method from proxy util.

All certificate loading now flows through a single code path (ProxyConfigManager.getCertificates()), eliminating conflicts and ensuring consistent OS CA handling.

Testing

  • Tested using MITM Proxy in local capture mode

  • Treat all work as PUBLIC. Private feature/x branches will not be squash-merged at release time.
  • Your code changes must meet the guidelines in CONTRIBUTING.md.
  • License: I confirm that my contribution is made under the terms of the Apache 2.0 license.

@tsmithsz tsmithsz requested a review from a team as a code owner June 25, 2025 23:01
@github-actions
Copy link

  • This pull request modifies code in src/* but no tests were added/updated.
    • Confirm whether tests should be added or ensure the PR description explains why tests are not required.
  • This pull request implements a feat or fix, so it must include a changelog entry (unless the fix is for an unreleased feature). Review the changelog guidelines.
    • Note: beta or "experiment" features that have active users should announce fixes in the changelog.
    • If this is not a feature or fix, use an appropriate type from the title guidelines. For example, telemetry-only changes should use the telemetry type.

@tsmithsz tsmithsz marked this pull request as draft June 25, 2025 23:04
@tsmithsz tsmithsz marked this pull request as ready for review June 25, 2025 23:24
@tsmithsz tsmithsz force-pushed the fix-amazonq-proxy-certificates branch from f152698 to 7a5cbd3 Compare June 26, 2025 21:43
@tsmithsz tsmithsz closed this Jun 27, 2025
@tsmithsz tsmithsz reopened this Jul 7, 2025
@tsmithsz tsmithsz merged commit c76fcc3 into aws:master Jul 7, 2025
55 of 56 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants