acme_proxy/config/types/proxy.rs
1//! `[proxy]` — the forward proxy every outbound client dials through.
2
3use serde::Deserialize;
4
5/// Where this server's own outbound HTTP goes.
6///
7/// Process-wide, so deliberately absent from `PROFILE_SECTIONS`: egress is a
8/// property of the network position the process runs in, not of one of the ACME
9/// endpoints it serves. Two profiles cannot reach the internet differently.
10///
11/// There is no `enabled` key either — the presence of a URL is the switch, the
12/// same shape as `ipam.backend = ""` and an unset `dns.resolver`. Every key
13/// empty (the default) means every connection dials the origin directly.
14///
15/// Each key falls back to its conventional environment variable when left
16/// empty; the precedence and the one variable deliberately *not* read are
17/// documented on [`crate::proxy::OutboundProxies::from_config`].
18#[derive(Debug, Clone, Default, Deserialize)]
19#[serde(default)]
20pub struct ProxyConfig {
21 /// Proxy for `http://` targets, e.g. `http://proxy.corp:3128`.
22 ///
23 /// Falls back to `$http_proxy`. Cleartext to the proxy itself: an
24 /// `https://` value is a startup error rather than a second TLS layer
25 /// nobody configured a trust anchor for.
26 pub http_url: String,
27 /// Proxy for `https://` targets, reached by `CONNECT`.
28 ///
29 /// Falls back to `$https_proxy`, then `$HTTPS_PROXY`. Normally the same
30 /// `http://proxy.corp:3128` as `http_url`: this names the proxy used *for*
31 /// https targets, not a proxy spoken to over https.
32 ///
33 /// Set independently of `http_url` on purpose — an estate that proxies only
34 /// its TLS egress is ordinary, and the silent version of that ("it worked
35 /// for http and did nothing for https") is what separate keys prevent.
36 pub https_url: String,
37 /// Targets that bypass the proxy: `*`, a domain, `.domain`, an address or a
38 /// CIDR block.
39 ///
40 /// Falls back to `$no_proxy`, then `$NO_PROXY`. Loopback and `localhost`
41 /// are bypassed unconditionally and need no entry here.
42 #[serde(deserialize_with = "super::empty_string_is_no_values")]
43 pub no_proxy: Vec<String>,
44}