Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Patch to support VAULT_HTTP_PROXY variable #12582

Merged
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
16 changes: 16 additions & 0 deletions api/client.go
Expand Up @@ -42,6 +42,7 @@ const (
EnvVaultToken = "VAULT_TOKEN"
EnvVaultMFA = "VAULT_MFA"
EnvRateLimit = "VAULT_RATE_LIMIT"
EnvHTTPProxy = "VAULT_HTTP_PROXY"
)

// Deprecated values
Expand Down Expand Up @@ -271,6 +272,7 @@ func (c *Config) ReadEnvironment() error {
var envMaxRetries *uint64
var envSRVLookup bool
var limit *rate.Limiter
var envHTTPProxy string

// Parse the environment variables
if v := os.Getenv(EnvVaultAddress); v != "" {
Expand Down Expand Up @@ -339,6 +341,10 @@ func (c *Config) ReadEnvironment() error {
envTLSServerName = v
}

if v := os.Getenv(EnvHTTPProxy); v != "" {
envHTTPProxy = v
}

// Configure the HTTP clients TLS configuration.
t := &TLSConfig{
CACert: envCACert,
Expand Down Expand Up @@ -375,6 +381,16 @@ func (c *Config) ReadEnvironment() error {
c.Timeout = envClientTimeout
}

if envHTTPProxy != "" {
url, err := url.Parse(envHTTPProxy)
if err != nil {
return err
}

transport := c.HttpClient.Transport.(*http.Transport)
transport.Proxy = http.ProxyURL(url)
}

return nil
}

Expand Down
3 changes: 3 additions & 0 deletions changelog/12582.txt
@@ -0,0 +1,3 @@
```release-note:improvement
api: Support VAULT_HTTP_PROXY environment variable to allow overriding the Vault client's HTTP proxy
```
6 changes: 6 additions & 0 deletions website/content/docs/commands/index.mdx
Expand Up @@ -323,6 +323,12 @@ can be supplied. If a MFA method expects multiple credential values, or if there
are multiple MFA methods specified on a path, then the CLI flag `-mfa` should be
used.

### `VAULT_HTTP_PROXY`

HTTP proxy location which should be used to access Vault. When present, this
overrides any other proxies found in the environment. Format should be
`http://server:port`.

## Flags

There are different CLI flags that are available depending on subcommands. Some
Expand Down