Ruby HTTPS proxy setup
Ruby's standard Net::HTTP cannot yet reach HTTPS destinations through a TLS-wrapped proxy. Use Typhoeus, which runs on libcurl, or one of the fallbacks below.
Docs preview: Fixedmark is not live yet. Endpoints are issued at launch, and these pages describe planned launch behavior. Anything marked planned may change. Join early access to get yours first.
Typhoeus (recommended)
Typhoeus wraps libcurl. libcurl 7.52 and later open TLS to an https:// proxy and tunnel your request with CONNECT. Pass the full proxy URL, including credentials.
# gem install typhoeus (libcurl 7.52+ handles the https:// proxy)
require "typhoeus"
res = Typhoeus.get(
"https://api.partner.example/v1/orders",
proxy: ENV.fetch("FIXEDMARK_PROXY_URL"),
connecttimeout: 10,
timeout: 30
)
puts res.code
warn res.return_message unless res.success?Why Net::HTTP fails today
net-http 0.5.0 (bundled with Ruby 3.4) added a p_use_ssl argument to Net::HTTP.new. With it, Net::HTTP opens TLS to the proxy and sends CONNECT inside that session. That part works: the proxy accepts the credentials.
The next step fails. Net::HTTP starts the destination's TLS handshake on the raw TCP socket instead of inside the proxy's TLS session, so the proxy receives bytes it cannot decode. You see SSL_connect ... unexpected message. We reproduced this with net-http 0.6.0 on Ruby 3.4, and the current upstream source has the same code path. Plain http:// destinations are not affected, but they are rare.
Faraday
Faraday's default adapter, faraday-net_http, sets p_use_ssl for https:// proxy URLs from version 3.4. It inherits the Net::HTTP problem above, so HTTPS destinations fail the same way. Move the allowlisted calls to Typhoeus, or use a fallback.
Fallbacks
- Plain HTTP listener (planned). Net::HTTP works with a plain HTTP CONNECT proxy. A plain listener for clients like this is planned, but its host and port are not final. The token crosses the network unencrypted on that hop, so add a destination allowlist to the token.
- bm tunnel (planned). For databases and other TCP, the CLI forwards a local port through your static IPs. See the bm tunnel reference.
# Planned plain HTTP CONNECT listener; host and port are not final.
# Credentials cross the network unencrypted on this hop.
require "net/http"
require "uri"
uri = URI("https://api.partner.example/v1/orders")
http = Net::HTTP.new(
uri.host, uri.port,
ENV.fetch("FIXEDMARK_PROXY_HOST"),
Integer(ENV.fetch("FIXEDMARK_PROXY_PORT")),
ENV.fetch("FIXEDMARK_APP_ID"),
ENV.fetch("FIXEDMARK_TOKEN")
)
http.use_ssl = true
http.open_timeout = 10
http.read_timeout = 15
res = http.request(Net::HTTP::Get.new(uri))
puts res.codep_use_ssl and Faraday 2.14 with faraday-net_http failed for HTTPS destinations. Net::HTTP succeeded through a plain HTTP CONNECT proxy.Platform guides
Frequently asked questions
Does Ruby Net::HTTP support an HTTPS proxy?
Partly. net-http 0.5 added a p_use_ssl argument that opens TLS to the proxy. In our tests with net-http 0.6 on Ruby 3.4, requests to HTTPS destinations still failed, because the inner TLS handshake is not sent through the proxy's TLS session.
Which Ruby HTTP client works with the Fixedmark proxy URL?
Typhoeus works, because it uses libcurl, which has supported https:// proxies since 7.52. Any client built on libcurl should behave the same.
Does Faraday work?
Not with its default net_http adapter for HTTPS destinations, for the same Net::HTTP reason. Call Typhoeus directly, or use the planned plain listener or bm tunnel.
Make it fixed.
Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.