For the complete documentation index, see llms.txt. This page is also available as Markdown.

HTTP proxy

Enable traffic through a proxy server using the HTTP_PROXY environment variable.

Fluent Bit supports configuring an HTTP proxy for all egress HTTP/HTTPS traffic using the HTTP_PROXY or http_proxy environment variable.

The format for the HTTP proxy environment variable is SCHEME://USER:PASS@HOST:PORT, where:

  • SCHEME is either http or https. Use https when the connection to the proxy itself must be TLS-encrypted, for example when the proxy sits behind a corporate TLS-terminating gateway. There's no separate HTTPS_PROXY environment variable: the scheme lives inside the same HTTP_PROXY/http_proxy value. See TLS to the proxy to configure certificate verification for this connection.

  • USER is the username when using basic authentication.

  • PASS is the password when using basic authentication.

  • HOST is the HTTP proxy hostname or IP address.

  • PORT is the port the HTTP proxy is listening on.

To use an HTTP proxy with basic authentication, provide the username and password:

HTTP_PROXY='http://example_user:example_pass@proxy.example.com:8080'

When no authentication is required, omit the username and password:

HTTP_PROXY='http://proxy.example.com:8080'

The HTTP_PROXY environment variable is a standard way of setting a HTTP proxy in a containerized environment, and it's also natively supported by any application written in Go. Fluent Bit implements the same convention. The http_proxy environment variable is also supported. When both the HTTP_PROXY and http_proxy environment variables are provided, HTTP_PROXY will be preferred.

The HTTP output plugin also supports configuring an HTTP proxy. This configuration works, but shouldn't be used with the HTTP_PROXY or http_proxy environment variable. The environment variable-based proxy configuration is implemented by creating a TCP connection tunnel using HTTP CONNECT. Unlike the plugin's implementation, this supports both HTTP and HTTPS egress traffic.

TLS to the proxy

When HTTP_PROXY/http_proxy uses the https scheme, Fluent Bit establishes a TLS connection to the proxy itself before issuing the HTTP CONNECT request described previously. This proxy-side TLS connection is configured independently from the destination's own tls.* settings (see TLS/SSL), using a dedicated set of properties:

Key
Description
Default

tls.proxy.ca_file

Absolute path to the CA certificate file used to verify the HTTPS proxy's certificate. Independent from tls.ca_file, which verifies the destination's certificate. Only applies to output plugins. Supported in v5.1 or later.

none

tls.proxy.ca_path

Absolute path to scan for CA certificate files used to verify the HTTPS proxy's certificate. Only applies to output plugins. Supported in v5.1 or later.

none

tls.proxy.verify

Force certificate validation for the HTTPS proxy connection. Only applies to output plugins. Supported in v5.1 or later.

on

tls.proxy.verify_hostname

Force hostname verification for the HTTPS proxy connection. Only applies to output plugins. Supported in v5.1 or later.

on

tls.proxy.* properties are set on the output plugin, the same way as tls.* properties. When tls.proxy.ca_file and tls.proxy.ca_path are both left unset, Fluent Bit falls back to the system's default trust store to verify the HTTPS proxy's certificate.

For example, to reach an HTTPS proxy signed by a private or corporate CA:

Then set the proxy environment variable to the HTTPS proxy:

NO_PROXY

Use the NO_PROXY environment variable when traffic shouldn't flow through the HTTP proxy. The no_proxy environment variable is also supported. When both NO_PROXY and no_proxy environment variables are provided, NO_PROXY takes precedence.

The format for the no_proxy environment variable is a comma-separated list of host names or IP addresses.

A domain name matches itself and all of its subdomains (for example, example.com matches both example.com and test.example.com):

A domain with a leading dot (.) matches only its subdomains (for example, .example.com matches test.example.com but not example.com):

As an example, you might use NO_PROXY when running Fluent Bit in a Kubernetes environment, where and you want:

  • All real egress traffic to flow through an HTTP proxy.

  • All local Kubernetes traffic to not flow through the HTTP proxy.

In this case, set:

Last updated

Was this helpful?