Very simple, lightweight, zero-dependency HTTP/HTTPS proxy with TLS-passthrough and authentication.
454
Lightweight, high-performance forward proxy written in Go 1.25 with zero dependencies. Supports HTTP forwarding, HTTPS tunneling (CONNECT method), Basic authentication, and streaming connections.
http.Transport connection poolinggo build -o proxy .
./proxy
# Build image
docker build -t https-proxy .
# Run with environment variables
docker run -d \
-p 8080:8080 \
-e PROXY_AUTH_USERNAME=admin \
-e PROXY_AUTH_PASSWORD=secret \
--name https-proxy \
daniknik/https_proxy
# Run with config file
docker run -d \
-p 8080:8080 \
-v $(pwd)/config.toml:/config.toml:ro \
--name https-proxy \
daniknik/https_proxy -config /config.toml
Configuration is loaded in priority order: defaults → TOML file → environment variables.
| Variable | Default | Description |
|---|---|---|
PROXY_LISTEN_ADDR | :8080 | Listen address |
PROXY_AUTH_USERNAME | "" | Basic auth username (empty = disabled) |
PROXY_AUTH_PASSWORD | "" | Basic auth password |
PROXY_TIMEOUT_DIAL | 10s | Dial timeout for upstream connections |
PROXY_TIMEOUT_IDLE | 120s | Idle connection timeout |
PROXY_TIMEOUT_READ | 30s | Read timeout (applies to request headers only) |
PROXY_TIMEOUT_WRITE | 30s | Write timeout |
PROXY_TUNNEL_BUFFER_SIZE | 32768 | Buffer size for CONNECT tunneling (bytes) |
PROXY_LOG_LEVEL | info | Log level: debug, info, error |
Create config.toml:
listen_addr = ":8080"
[auth]
username = "admin"
password = "secret"
[timeout]
dial = "10s"
idle = "120s"
read = "30s"
write = "30s"
[tunnel]
buffer_size = 32768
[log]
level = "info"
# Build image
docker build -t https-proxy .
# Run with authentication
docker run -d \
--name https-proxy \
--restart unless-stopped \
-p 8080:8080 \
-e PROXY_AUTH_USERNAME=myuser \
-e PROXY_AUTH_PASSWORD=mypass \
-e PROXY_LOG_LEVEL=info \
daniknik/https_proxy
config.toml:listen_addr = ":8080"
[auth]
username = "production-user"
password = "strong-password-here"
[timeout]
dial = "15s"
idle = "300s"
read = "60s"
write = "300s"
[tunnel]
buffer_size = 65536
[log]
level = "info"
docker run -d \
--name https-proxy \
--restart unless-stopped \
-p 8080:8080 \
-v $(pwd)/config.toml:/config.toml:ro \
--read-only \
--cap-drop ALL \
--security-opt no-new-privileges:true \
daniknik/https_proxy -config /config.toml
docker run -d \
--name https-proxy \
--restart unless-stopped \
-p 8080:8080 \
-e PROXY_AUTH_USERNAME=admin \
-e PROXY_AUTH_PASSWORD=secret \
--memory=256m \
--cpus=1 \
daniknik/https_proxy
docker logs -f https-proxy
curl -x http://admin:secret@localhost:8080 http://httpbin.org/get
curl -x http://admin:secret@localhost:8080 https://httpbin.org/get
curl https://api.openai.com/v1/chat/completions \
-x http://admin:secret@localhost:8080 \
-H "Authorization: Bearer $OPENAI_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"model": "gpt-4",
"messages": [{"role": "user", "content": "Hello"}],
"stream": true
}'
import openai
import os
openai.api_key = os.getenv("OPENAI_API_KEY")
openai.proxy = "http://admin:secret@localhost:8080"
stream = openai.ChatCompletion.create(
model="gpt-4",
messages=[{"role": "user", "content": "Write a poem"}],
stream=True
)
for chunk in stream:
if chunk.choices[0].delta.get("content"):
print(chunk.choices[0].delta.content, end="")
Python (requests):
import requests
proxies = {
'http': 'http://admin:secret@localhost:8080',
'https': 'http://admin:secret@localhost:8080',
}
response = requests.get('https://api.example.com', proxies=proxies)
Node.js:
const axios = require('axios');
const proxy = {
protocol: 'http',
host: 'localhost',
port: 8080,
auth: {
username: 'admin',
password: 'secret'
}
};
axios.get('https://api.example.com', { proxy });
GET http://example.com/pathhttp.Transport.RoundTrip (no redirect following)CONNECT api.openai.com:443HTTP/1.1 200 Connection EstablishedNo SSL certificate needed — proxy operates at TCP level, never decrypts TLS traffic.
Proxy removes hop-by-hop and proxy-revealing headers:
Connection, Keep-Alive, Proxy-AuthorizationX-Forwarded-For, X-Forwarded-Host, Via, ForwardedConnection header valuewss://crypto/subtle.ConstantTimeCompare to prevent timing attacksIncrease write timeout for long-running streaming responses:
docker run -d \
-p 8080:8080 \
-e PROXY_TIMEOUT_WRITE=600s \
daniknik/https_proxy
Check credentials format:
# Correct
curl -x http://user:pass@localhost:8080 https://example.com
# Incorrect (missing scheme)
curl -x user:pass@localhost:8080 https://example.com
If running proxy and client in separate containers, use Docker network:
docker network create proxy-net
docker run -d \
--name https-proxy \
--network proxy-net \
-e PROXY_AUTH_USERNAME=admin \
-e PROXY_AUTH_PASSWORD=secret \
daniknik/https_proxy
# In client container, use: http://https-proxy:8080
This project is provided as-is for educational and production use.
Content type
Image
Digest
sha256:396ef5b82…
Size
2.5 MB
Last updated
8 months ago
docker pull daniknik/https_proxy