Skip to content

Docs: drop the claim that Phala must allowlist a domain's SNI suffix - #139

Merged
HONGJICAI merged 2 commits into
mainfrom
claude/sni-allowlist-docs
Sep 29, 2026
Merged

HONGJICAI merged 2 commits into
mainfrom
claude/sni-allowlist-docs

Conversation

@HONGJICAI

@HONGJICAI HONGJICAI commented Sep 29, 2026 •

Copy link
Copy Markdown
Collaborator

Several docs said the Phala platform only forwards SNI suffixes that Phala has allowlisted, so a new domain or a new cluster needed Phala's sign-off first. Nothing supports that claim, and it sent operators to wait on a step that does not exist. This PR removes the claim everywhere and does not replace it with a note.

Why the claim is wrong

  • Upstream dstack gateway (gateway/src/proxy.rs, handle_connection) sends any SNI outside its own base domain to proxy_with_sni, which looks up the _dstack-app-address TXT record. There is no allowlist or suffix check.
  • Phala's custom-domain guide (dstack-examples, custom-domain/dstack-ingress) and the dstack-cloud gateway docs have no registration step.
  • This repo's history. The claim was added in Make on-chain signer grounding survivable enough to enforce #77 (on-chain signer grounding) with no source. The Fix three runbook claims a staging rehearsal proved wrong #131 staging rehearsal stood up a new hostname and did not hit it. The operator has never had to do this either.

Changes

  • deploy/phala/README.md: the prerequisite bullet is removed, and so is (SNI-suffix allowlist) in the architecture diagram. The remaining prerequisite, that the three CNAMEs must exist before first boot, is kept as a paragraph.
  • deploy/phala/blue-green.md ("Cross-cluster fallback"):
    • The setup step "ask Phala to allow the SNI suffix on the cold cluster" is removed.
    • The drill wording no longer calls the drill a proof of an allowlist.
    • The text still says what is true: status cannot prove that <DOMAIN> works end to end on the cold cluster, because the -443s probe uses the platform hostname. The first drill is what proves it.
  • docs/design/cloud-gateway.md: the "one platform-side prerequisite" sentence is removed.
  • deploy/phala/docker-compose.yml: the NOTE sentence on ports is removed. This is a comment-only edit to the measured compose. It changes the compose_hash of the next release, but that hash changes with every image digest anyway, and running deployments are unaffected.

Testing

This PR changes only docs and comments.

  • switch_test.sh: 72 passing.
  • The Go tests that read these files pass: cmd/gateway, release, compose, openaiproxy and evidence.

🤖 Generated with Claude Code

https://claude.ai/code/session_01HwZ4eHgoC138puscLp1Wh6

README, the compose comment, cloud-gateway.md and the new cross-cluster
section all said the platform only forwards SNI suffixes Phala has
allowlisted, so a new domain (or a new cluster) needed Phala's sign-off
first. Nothing supports it: upstream dstack gateway routes any SNI outside
its base domain through the TXT lookup with no allowlist
(gateway/src/proxy.rs), Phala's custom-domain guide has no such step, and
new hostnames have gone live without one. The claim arrived in #77 with no
source.

Each place now says there is no per-domain registration, and keeps what
is true: if a filter in front of the gateway ever did drop a name, it
shows as a bare TLS handshake failure, so the first connection to a new
name or cluster (a drill, for the cold standby) is the check.

The compose change is a comment only; it moves the compose_hash of the
next release, which changes with its image digest anyway.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HwZ4eHgoC138puscLp1Wh6
Review: a note that no registration is needed is noise when nothing ever
required one. Drop the claim outright; keep only the blue-green point
that status cannot prove end-to-end reachability of <DOMAIN> on the cold
cluster, so the first drill is what does.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01HwZ4eHgoC138puscLp1Wh6
@HONGJICAI
HONGJICAI merged commit 2e40a8a into main Sep 29, 2026
4 checks passed
@HONGJICAI
HONGJICAI deleted the claude/sni-allowlist-docs branch September 29, 2026 11:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants