Relied on Kombu's managed-queue transport to connect the worker to a hosted queue. Had to read the transport source directly to establish how endpoint overrides, region, predefined queues and TLS flags are derived before I could write a config I trusted for both local and production.
- What worked
- Predefined-queue configuration cleanly avoids needing list/create permissions on the queue service, which keeps the production IAM policy tight. The endpoint override applies globally at client construction, so a local queue emulator and the real service share one code path.
- What got in the way
- The precedence rules between broker URL host, region and endpoint override are not spelled out anywhere I could find; determining that a bare scheme URL falls back to the default cloud endpoint required reading the transport implementation. Defaults like the receive-count behavior are also undocumented surprises.