Skip to main content

acme_proxy/config/types/
proxy.rs

1//! `[proxy]` — the forward proxy every outbound client dials through.
2
3use serde::Deserialize;
4
5/// Where this server's own outbound HTTP goes.
6///
7/// Process-wide, so deliberately absent from `PROFILE_SECTIONS`: egress is a
8/// property of the network position the process runs in, not of one of the ACME
9/// endpoints it serves. Two profiles cannot reach the internet differently.
10///
11/// There is no `enabled` key either — the presence of a URL is the switch, the
12/// same shape as `ipam.backend = ""` and an unset `dns.resolver`. Every key
13/// empty (the default) means every connection dials the origin directly.
14///
15/// Each key falls back to its conventional environment variable when left
16/// empty; the precedence and the one variable deliberately *not* read are
17/// documented on [`crate::proxy::OutboundProxies::from_config`].
18#[derive(Debug, Clone, Default, Deserialize)]
19#[serde(default)]
20pub struct ProxyConfig {
21    /// Proxy for `http://` targets, e.g. `http://proxy.corp:3128`.
22    ///
23    /// Falls back to `$http_proxy`. Cleartext to the proxy itself: an
24    /// `https://` value is a startup error rather than a second TLS layer
25    /// nobody configured a trust anchor for.
26    pub http_url: String,
27    /// Proxy for `https://` targets, reached by `CONNECT`.
28    ///
29    /// Falls back to `$https_proxy`, then `$HTTPS_PROXY`. Normally the same
30    /// `http://proxy.corp:3128` as `http_url`: this names the proxy used *for*
31    /// https targets, not a proxy spoken to over https.
32    ///
33    /// Set independently of `http_url` on purpose — an estate that proxies only
34    /// its TLS egress is ordinary, and the silent version of that ("it worked
35    /// for http and did nothing for https") is what separate keys prevent.
36    pub https_url: String,
37    /// Targets that bypass the proxy: `*`, a domain, `.domain`, an address or a
38    /// CIDR block.
39    ///
40    /// Falls back to `$no_proxy`, then `$NO_PROXY`. Loopback and `localhost`
41    /// are bypassed unconditionally and need no entry here.
42    #[serde(deserialize_with = "super::empty_string_is_no_values")]
43    pub no_proxy: Vec<String>,
44}