Docs: drop the claim that Phala must allowlist a domain's SNI suffix - #139
Merged
Merged
Conversation
README, the compose comment, cloud-gateway.md and the new cross-cluster section all said the platform only forwards SNI suffixes Phala has allowlisted, so a new domain (or a new cluster) needed Phala's sign-off first. Nothing supports it: upstream dstack gateway routes any SNI outside its base domain through the TXT lookup with no allowlist (gateway/src/proxy.rs), Phala's custom-domain guide has no such step, and new hostnames have gone live without one. The claim arrived in #77 with no source. Each place now says there is no per-domain registration, and keeps what is true: if a filter in front of the gateway ever did drop a name, it shows as a bare TLS handshake failure, so the first connection to a new name or cluster (a drill, for the cold standby) is the check. The compose change is a comment only; it moves the compose_hash of the next release, which changes with its image digest anyway. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HwZ4eHgoC138puscLp1Wh6
Review: a note that no registration is needed is noise when nothing ever required one. Drop the claim outright; keep only the blue-green point that status cannot prove end-to-end reachability of <DOMAIN> on the cold cluster, so the first drill is what does. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01HwZ4eHgoC138puscLp1Wh6
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Several docs said the Phala platform only forwards SNI suffixes that Phala has allowlisted, so a new domain or a new cluster needed Phala's sign-off first. Nothing supports that claim, and it sent operators to wait on a step that does not exist. This PR removes the claim everywhere and does not replace it with a note.
Why the claim is wrong
gateway/src/proxy.rs,handle_connection) sends any SNI outside its own base domain toproxy_with_sni, which looks up the_dstack-app-addressTXT record. There is no allowlist or suffix check.custom-domain/dstack-ingress) and the dstack-cloud gateway docs have no registration step.Changes
deploy/phala/README.md: the prerequisite bullet is removed, and so is(SNI-suffix allowlist)in the architecture diagram. The remaining prerequisite, that the three CNAMEs must exist before first boot, is kept as a paragraph.deploy/phala/blue-green.md("Cross-cluster fallback"):statuscannot prove that<DOMAIN>works end to end on the cold cluster, because the-443sprobe uses the platform hostname. The first drill is what proves it.docs/design/cloud-gateway.md: the "one platform-side prerequisite" sentence is removed.deploy/phala/docker-compose.yml: theNOTEsentence onportsis removed. This is a comment-only edit to the measured compose. It changes the compose_hash of the next release, but that hash changes with every image digest anyway, and running deployments are unaffected.Testing
This PR changes only docs and comments.
switch_test.sh: 72 passing.cmd/gateway,release,compose,openaiproxyandevidence.🤖 Generated with Claude Code
https://claude.ai/code/session_01HwZ4eHgoC138puscLp1Wh6