Go HTTP proxy setup
Go's net/http supports the Fixedmark https:// proxy URL and SOCKS5 natively. Set Proxy on an http.Transport, or build a SOCKS5 dialer for database drivers.
Docs preview: Fixedmark is not live yet. Endpoints are issued at launch, and these pages describe planned launch behavior. Anything marked planned may change. Join early access to get yours first.
http.Transport with a proxy URL
http.ProxyURL returns a proxy function for a fixed URL. With an https scheme, the transport opens TLS to the proxy, sends CONNECT with Basic credentials from the URL, and then starts TLS to the destination inside the tunnel.
package main
import (
"fmt"
"log"
"net/http"
"net/url"
"os"
"time"
)
func main() {
proxyURL, err := url.Parse(os.Getenv("FIXEDMARK_PROXY_URL"))
if err != nil {
log.Fatal(err)
}
// Build one client and reuse it so connections are pooled.
client := &http.Client{
Transport: &http.Transport{
Proxy: http.ProxyURL(proxyURL),
MaxIdleConnsPerHost: 10,
IdleConnTimeout: 90 * time.Second,
},
Timeout: 15 * time.Second,
}
res, err := client.Get("https://api.partner.example/v1/orders")
if err != nil {
log.Fatal(err)
}
defer res.Body.Close()
fmt.Println(res.Status)
}From the environment
// http.DefaultTransport already uses http.ProxyFromEnvironment.
// Set HTTPS_PROXY=$FIXEDMARK_PROXY_URL and NO_PROXY as needed.
// ProxyFromEnvironment never proxies localhost or 127.0.0.1.
res, err := http.Get("https://api.partner.example/v1/orders")Use a separate client with http.ProxyURL when only some calls need the static IP. Clients built from http.DefaultTransport follow the environment, so a global HTTPS_PROXY affects every library in the process.
SOCKS5 in net/http
http.Transport also accepts a socks5h:// URL. Set FIXEDMARK_SOCKS_URL as the proxy and nothing else changes. Go treats socks5 the same as socks5h, so DNS always resolves on the proxy. SOCKS5 authentication is not encrypted, so prefer the HTTPS proxy URL for HTTP traffic.
SOCKS5 dialer for database drivers
Drivers such as pgx, go-sql-driver/mysql, and go-redis take a custom dial function. golang.org/x/net/proxy builds one from the SOCKS5 URL. The databases guide shows how to plug it into each driver.
import (
"net/url"
"os"
"golang.org/x/net/proxy"
)
// socksDialer returns a dialer that connects through Fixedmark SOCKS5.
// It sends host names to the proxy, so DNS resolves on the proxy side.
func socksDialer() (proxy.ContextDialer, error) {
u, err := url.Parse(os.Getenv("FIXEDMARK_SOCKS_URL"))
if err != nil {
return nil, err
}
pw, _ := u.User.Password()
d, err := proxy.SOCKS5("tcp", u.Host,
&proxy.Auth{User: u.User.Username(), Password: pw}, proxy.Direct)
if err != nil {
return nil, err
}
return d.(proxy.ContextDialer), nil
}Production tips
- Reuse one
http.Client. Idle connections are kept per proxy and destination, so later requests skip the TLS handshakes. - Always set
Client.Timeoutor a context deadline. The default client has no timeout. - Always close
res.Body. Unread bodies keep the tunnel from being reused.
http.Transport.Proxy documentation.Platform guides
Frequently asked questions
Does Go net/http support an HTTPS proxy?
Yes. Since Go 1.10, http.Transport accepts an https:// proxy URL and opens TLS to the proxy before sending CONNECT. Credentials in the URL become a Proxy-Authorization header.
Can Go use a SOCKS5 proxy with net/http?
Yes. http.Transport supports socks5 and socks5h proxy URLs. Go treats both the same and sends the host name to the proxy.
Why does HTTPS_PROXY not apply to localhost in Go?
http.ProxyFromEnvironment never proxies requests to localhost or loopback addresses. Use http.ProxyURL to force a proxy for testing.
Make it fixed.
Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.