Make the egress proxy start, and prove what it lets through

Two mistakes in the configuration, both of which stopped squid dead. It refuses
an allowlist that names a host and something above it - registry.npmjs.org beside
.npmjs.org - and the continuation lines that followed were then read as
directives of their own. The domains are now one directive per line, each with a
leading dot so it covers the host and everything under it.

Pointing the logs at /dev/stdout so they would reach `docker logs` was the second
one, and it is not fixable here: squid drops to the proxy user, the container's
stdout is a root-owned pipe, and squid calls being unable to open its log fatal.
They stay at squid's own paths, and the config says where to read them.

Checked against a running proxy rather than by reading: npm, PyPI, pythonhosted
and both Maven hosts tunnel through, example.com is refused, a plain HTTP request
to an allowed host is refused as well, and the access log names the refusal.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Lucio Lelii 2026-09-22 12:44:25 +02:00
parent a5769114eb
commit 7f1d06ba7e
1 changed files with 15 additions and 11 deletions

View File

@ -10,13 +10,14 @@
http_port 3128
acl registries dstdomain \
registry.npmjs.org \
.npmjs.org \
pypi.org \
files.pythonhosted.org \
repo.maven.apache.org \
repo1.maven.org
# One directive per line, and each domain written with a leading dot so it covers the host and
# its subdomains. Squid refuses a list that names both a domain and something beneath it, so
# registry.npmjs.org is not spelled out: .npmjs.org already includes it.
acl registries dstdomain .npmjs.org
acl registries dstdomain .pypi.org
acl registries dstdomain .pythonhosted.org
acl registries dstdomain .maven.apache.org
acl registries dstdomain .maven.org
acl ssl_ports port 443
acl connect_method method CONNECT
@ -31,14 +32,17 @@ http_access deny all
cache deny all
cache_mem 8 MB
# One line per request, so a refused host can be found without guessing.
access_log stdio:/dev/stdout
cache_log stdio:/dev/stderr
# Left at squid's own defaults, under /var/log/squid inside the container. Pointing them at
# /dev/stdout so they would reach `docker logs` does not work here: squid drops to the proxy user
# and the container's stdout is a root-owned pipe, which it then cannot open - and squid treats
# that as fatal, so the proxy would not start at all.
#
# docker compose logs egress-proxy startup and configuration errors
# docker compose exec egress-proxy tail -f /var/log/squid/access.log who asked for what
# A client that cannot reach the internet should learn so quickly rather than hang.
connect_timeout 15 seconds
request_timeout 60 seconds
forwarded_for delete
via off
httpd_suppress_version_string on