Repository navigation
fix(ci): use localhost endpoints in LocalStack demo to avoid DNS hangs - #2598
Conversation
The demo-localstack CI job began timing out at the 20-minute limit across all branches on 2026-06-10. Root cause: the provider endpoints used https://localhost.localstack.cloud:4566, a public DNS record hosted by LocalStack. After LocalStack EOL'd Community Edition, their DNS zone was restructured on 2026-06-08 (localhost.localstack.cloud re-delegated to a new Route53 subzone), and GitHub's Azure runners now intermittently fail to resolve it. The AWS provider treats DNS failure as retryable and backs off past the job timeout, hanging silently before its first API call. Switch all endpoints to http://localhost:4566 (the port the GitHub Actions service container actually exposes), enable path-style S3 so bucket operations don't depend on wildcard *.localhost.localstack.cloud DNS/TLS, and skip the account-id lookup during provider configure. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Tip Atmos Pro
No affected stacks workflow was detected for this pull request. |
Dependency Review✅ No vulnerabilities or license issues found.Scanned FilesNone |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (2)
📝 WalkthroughWalkthroughThe LocalStack demo example is updated to use HTTP endpoints with path-style S3 instead of HTTPS. The Terraform provider configuration switches the shared LocalStack URL from TLS to plain HTTP and consolidates S3 endpoint wiring. The README is updated to document this choice and clarify that the resulting Terraform warning is expected. ChangesLocalStack Example Configuration Update
Estimated code review effort🎯 2 (Simple) | ⏱️ ~8 minutes Suggested labels
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #2598 +/- ##
==========================================
+ Coverage 79.01% 79.03% +0.02%
==========================================
Files 1210 1210
Lines 117219 117219
==========================================
+ Hits 92620 92647 +27
+ Misses 19521 19492 -29
- Partials 5078 5080 +2
Flags with carried forward coverage won't be shown. Click here to find out more. 🚀 New features to boost your workflow:
|
|
Tip Atmos Pro
No affected stacks workflow was detected for this pull request. |
Resolve modify/delete conflicts on the renamed example: main #2598 ("use localhost endpoints in LocalStack demo to avoid DNS hangs") modified examples/demo-localstack/README.md and stacks/mixins/localstack.yaml, which this branch deleted as part of renaming demo-localstack -> demo-floci. Resolved by keeping the deletions: the same fixes (s3_use_path_style: true, skip_requesting_account_id: true, http://localhost:4566 path-style endpoints, and the expected-warning note) already exist in the renamed files examples/demo-floci/stacks/mixins/floci.yaml and examples/demo-floci/README.md, so nothing from #2598 is lost. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…atmos into 1198-pact-consumer-contracts * '1198-pact-consumer-contracts' of github.com:cloudposse/atmos: fix(ansible): forward `-- <args>` passthrough to ansible-playbook (#2594) fix(ci): use localhost endpoints in LocalStack demo to avoid DNS hangs (#2598) DAG follow-up: aggregate CI output for concurrent Terraform runs (#2577) fix(list): prevent nil pointer panic when spinner exits early (#2591) feat: describe affected evaluates all provisioned component sections (#2573)
|
These changes were released in v1.221.1. |
what
demo-localstackexample's AWS provider endpoints fromhttps://localhost.localstack.cloud:4566tohttp://localhost:4566s3_use_path_style: trueso S3 operations don't depend on wildcard*.localhost.localstack.cloudDNS/TLSskip_requesting_account_id: trueso provider configure doesn't block on identity lookupswhy
The
[localstack] demo-localstackCI job started hanging until the 20-minute timeout across all branches beginning 2026-06-10 ~02:18 UTC, with no corresponding code change (identical commits both passed and failed; the LocalStack image is pinned at1.4.0with the same build hash in green and red runs).Root cause:
localhost.localstack.cloudis a public DNS record hosted by LocalStack that resolves to127.0.0.1. After LocalStack EOL'd Community Edition (repo archived March 2026), their DNS zone was restructured on 2026-06-08 18:53 UTC (SOA serial; the record is now a freshly delegated Route53 subzone). GitHub's Azure runners began intermittently failing to resolve the name ~31h later as resolver caches expired. The Terraform AWS provider treats DNS failure as retryable and backs off past the job timeout — hanging silently before its first API call.Evidence:
terraform workspace new dev-demo, before the provider's first API call. The LocalStack container log shows exactly one completed request (sts.GetSessionToken => 200— issued by atmos auth, which useshttp://localhost:4566and always succeeds). The provider's first call vialocalhost.localstack.cloudnever arrives.osterman/fix-post-merge-sha, a run with the old endpoints timed out at 13:43 UTC; the identical change in this PR passed at 13:53 UTC (run 27281214186).Extending the timeout would not help — the provider's retry backoff exceeds any reasonable limit when DNS is failing.
references
[localstack]job timeout🤖 Generated with Claude Code
Summary by CodeRabbit