HTTP proxy
Enable traffic through a proxy server using the HTTP_PROXY environment variable.
Fluent Bit supports configuring an HTTP proxy for all egress HTTP/HTTPS traffic using the HTTP_PROXY or http_proxy environment variable.
The format for the HTTP proxy environment variable is SCHEME://USER:PASS@HOST:PORT, where:
SCHEMEis eitherhttporhttps. Usehttpswhen the connection to the proxy itself must be TLS-encrypted, for example when the proxy sits behind a corporate TLS-terminating gateway. There's no separateHTTPS_PROXYenvironment variable: the scheme lives inside the sameHTTP_PROXY/http_proxyvalue. See TLS to the proxy to configure certificate verification for this connection.USERis the username when using basic authentication.PASSis the password when using basic authentication.HOSTis the HTTP proxy hostname or IP address.PORTis the port the HTTP proxy is listening on.
To use an HTTP proxy with basic authentication, provide the username and password:
HTTP_PROXY='http://example_user:example_pass@proxy.example.com:8080'When no authentication is required, omit the username and password:
HTTP_PROXY='http://proxy.example.com:8080'The HTTP_PROXY environment variable is a standard way of setting a HTTP proxy in a containerized environment, and it's also natively supported by any application written in Go. Fluent Bit implements the same convention. The http_proxy environment variable is also supported. When both the HTTP_PROXY and http_proxy environment variables are provided, HTTP_PROXY will be preferred.
The HTTP output plugin also supports configuring an HTTP proxy. This configuration works, but shouldn't be used with the HTTP_PROXY or http_proxy environment variable. The environment variable-based proxy configuration is implemented by creating a TCP connection tunnel using HTTP CONNECT. Unlike the plugin's implementation, this supports both HTTP and HTTPS egress traffic.
TLS to the proxy
When HTTP_PROXY/http_proxy uses the https scheme, Fluent Bit establishes a TLS connection to the proxy itself before issuing the HTTP CONNECT request described previously. This proxy-side TLS connection is configured independently from the destination's own tls.* settings (see TLS/SSL), using a dedicated set of properties:
tls.proxy.ca_file
Absolute path to the CA certificate file used to verify the HTTPS proxy's certificate. Independent from tls.ca_file, which verifies the destination's certificate. Only applies to output plugins. Supported in v5.1 or later.
none
tls.proxy.ca_path
Absolute path to scan for CA certificate files used to verify the HTTPS proxy's certificate. Only applies to output plugins. Supported in v5.1 or later.
none
tls.proxy.verify
Force certificate validation for the HTTPS proxy connection. Only applies to output plugins. Supported in v5.1 or later.
on
tls.proxy.verify_hostname
Force hostname verification for the HTTPS proxy connection. Only applies to output plugins. Supported in v5.1 or later.
on
tls.proxy.* properties are set on the output plugin, the same way as tls.* properties. When tls.proxy.ca_file and tls.proxy.ca_path are both left unset, Fluent Bit falls back to the system's default trust store to verify the HTTPS proxy's certificate.
For example, to reach an HTTPS proxy signed by a private or corporate CA:
Then set the proxy environment variable to the HTTPS proxy:
NO_PROXY
Use the NO_PROXY environment variable when traffic shouldn't flow through the HTTP proxy. The no_proxy environment variable is also supported. When both NO_PROXY and no_proxy environment variables are provided, NO_PROXY takes precedence.
The format for the no_proxy environment variable is a comma-separated list of host names or IP addresses.
A domain name matches itself and all of its subdomains (for example, example.com matches both example.com and test.example.com):
A domain with a leading dot (.) matches only its subdomains (for example, .example.com matches test.example.com but not example.com):
As an example, you might use NO_PROXY when running Fluent Bit in a Kubernetes environment, where and you want:
All real egress traffic to flow through an HTTP proxy.
All local Kubernetes traffic to not flow through the HTTP proxy.
In this case, set:
Last updated
Was this helpful?