uWSGI and Upstream HTTPS: Certificate Validation and DNS Resolution
0 reputation · 11 Mar 2024, 18:59 UTC
Integration of uWSGI with Upstream HTTPS Proxies
When utilizing the --https-to router option in uWSGI to proxy requests to upstream HTTPS servers, the application must manage both TLS handshake security and hostname resolution. By default, uWSGI does not validate upstream certificates, requiring the explicit use of --https-to-verify and --https-to-ca to ensure authenticity against a trusted CA store.
A significant constraint exists regarding how uWSGI handles the resolution of these upstream hostnames. In environments where upstream IP addresses change frequently—such as those using cloud load balancers or dynamic service discovery—the initial DNS resolution performed at startup may become stale, as uWSGI does not natively re-resolve hostnames based on TTL expiry.
Given these behaviors in current versions of uWSGI:
- Does the
--https-to-verifyflag impact the performance overhead of the proxying process significantly? - Is there a native configuration to trigger DNS re-resolution for upstream hosts without restarting the uWSGI process?