Sign inSign up

maideduo/githubproxy

By maideduo

•Updated 5 months ago

一个Go 代理服务,用于让纯 IPv6 网络访问 GitHub 及其常见资源域名。

Image
Networking
0

205

maideduo/githubproxy repository overview

⁠githubproxy

一个部署在双栈服务器上的 Go 代理服务,用于让纯 IPv6 网络通过服务器 A 的 IPv6 地址访问 GitHub 及其常见资源域名。

⁠工作原理

本项目采用 SNI/TCP 透传:

  • 客户端把 github.com 等域名解析到服务器 A 的 IPv6
  • 客户端发起 TLS 连接到服务器 A
  • 代理读取 TLS ClientHello 中的 SNI
  • 根据 SNI 把 TCP 连接转发到真实 GitHub 上游
  • 代理本身 不解密 TLS,只负责按域名路由和双向字节转发

这意味着:

  • 不需要在代理中处理 GitHub 的 HTTP 细节
  • 不需要改写 Host header
  • 不需要在代理中持有 GitHub 站点证书
  • 兼容绝大多数基于 HTTPS 的 GitHub 访问场景

⁠适用场景

适合以下场景:

  • 客户端网络是纯 IPv6
  • GitHub 或其部分资源域名在纯 IPv6 环境中不可达
  • 你有一台既能被 IPv6 客户端访问、又能访问公网 IPv4/IPv6 的双栈服务器 A
  • 你希望通过修改 hosts,把 GitHub 流量中转到服务器 A

⁠不适用的场景

以下情况不适合本项目:

  • 需要代理明文 HTTP 而不是 HTTPS
  • 客户端 TLS 握手里没有 SNI
  • 需要对 GitHub 页面做内容修改、缓存或鉴权
  • 需要 SOCKS5 / HTTP CONNECT 通用代理能力

⁠前置条件

部署前请确认:

  1. 服务器 A 具备公网 IPv6 入站能力
  2. 服务器 A 具备访问 GitHub 真实上游的双栈出站能力
  3. 服务器 A 已放通 TCP 443
  4. 如启用健康检查,已放通健康检查端口(默认 8080)
  5. 客户端可以修改 /etc/hosts 或等效 hosts 文件

⁠配置说明

示例配置见 config.example.yaml。

listen_addr: ":443"
health_listen_addr: ":8080"
default_port: 443
dial_timeout: 10s
idle_timeout: 2m
log_level: info
routes:
  - github.com
  - raw.githubusercontent.com
  - '*.githubusercontent.com'
  - pattern: '*.githubusercontent.com'
    upstream: raw.githubusercontent.com
  - pattern: objects.githubusercontent.com
    upstream: objects.githubusercontent.com:8443

字段说明:

  • listen_addr:TCP 监听地址,通常为 :443
  • health_listen_addr:HTTP 健康检查监听地址,留空可关闭
  • default_port:未显式指定端口时的默认上游端口
  • dial_timeout:连接上游超时
  • idle_timeout:连接空闲超时
  • log_level:日志级别,可选 debug / info / warn / error
  • routes:SNI 路由规则,支持两种写法
    • 简写:直接写精确域名或 *.example.com 通配模式
      • github.com 会自动解析为 upstream: github.com
      • *.githubusercontent.com 会自动解析为 upstream: githubusercontent.com
    • 完整写法:pattern + 可选 upstream
      • 省略 upstream 时也会自动按上面规则推导
      • 仅在需要转发到不同目标,或指定 host:port 时显式填写 upstream

⁠常见 hosts 覆盖方式

在纯 IPv6 客户端中,把常用 GitHub 域名指向服务器 A 的 IPv6,例如:

sudo tee -a /etc/hosts <<EOF

# GitHub IPv6 Hosts
2001:db8::100 github.com
2001:db8::100 api.github.com
2001:db8::100 codeload.github.com
2001:db8::100 ghcr.io
2001:db8::100 pkg.github.com npm.pkg.github.com maven.pkg.github.com nuget.pkg.github.com rubygems.pkg.github.com
2001:db8::100 uploads.github.com
2001:db8::100 objects.githubusercontent.com www.objects.githubusercontent.com release-assets.githubusercontent.com gist.githubusercontent.com repository-images.githubusercontent.com camo.githubusercontent.com private-user-images.githubusercontent.com avatars0.githubusercontent.com avatars1.githubusercontent.com avatars2.githubusercontent.com avatars3.githubusercontent.com cloud.githubusercontent.com desktop.githubusercontent.com support.github.com
2001:db8::100 support-assets.githubassets.com github.githubassets.com opengraph.githubassets.com github-registry-files.githubusercontent.com github-cloud.githubusercontent.com
EOF
2001:db8::100 github.com
2001:db8::100 www.github.com
2001:db8::100 api.github.com
2001:db8::100 gist.github.com
2001:db8::100 raw.githubusercontent.com
2001:db8::100 objects.githubusercontent.com
2001:db8::100 codeload.github.com
2001:db8::100 github-releases.githubusercontent.com
2001:db8::100 central.github.com
2001:db8::100 collector.github.com
2001:db8::100 alive.github.com
2001:db8::100 live.github.com
2001:db8::100 uploads.github.com
2001:db8::100 assets-cdn.github.com
2001:db8::100 media.githubusercontent.com
2001:db8::100 camo.githubusercontent.com
2001:db8::100 user-images.githubusercontent.com
2001:db8::100 private-user-images.githubusercontent.com
2001:db8::100 secured-user-images.githubusercontent.com
2001:db8::100 repositories.githubusercontent.com

说明:

  • *.githubusercontent.com 和 *.githubassets.com 这类通配规则无法直接写进标准 hosts 文件,需要把你实际访问到的具体子域名逐条加入 hosts
  • 如果某些页面、图片、Release、clone 或 Actions 资源仍然失败,通常就是少了对应子域名的 hosts 记录

⁠健康检查

默认暴露:

GET /healthz

示例:

curl http://127.0.0.1:8080/healthz

预期返回:

ok

⁠Docker 部署

构建镜像:

docker build -t githubproxy .

运行容器:

docker run -d \
  --name githubproxy \
  -p 443:443 \
  -p 8080:8080 \
  -v $(pwd)/config.example.yaml:/etc/githubproxy/config.yaml:ro \
  maideduo/githubproxy

说明:

  • 第一版容器默认以 root 运行,以便直接绑定 443
  • 生产环境可结合宿主机能力进一步收敛权限

⁠验证方式

⁠健康检查
curl http://[服务器A的IPv6]:8080/healthz
⁠GitHub 首页

在客户端 hosts 指向服务器 A 后:

curl -I https://github.com
⁠Git 仓库探测
git ls-remote https://github.com/OWNER/REPO.git
⁠SNI 验证
openssl s_client -servername github.com -connect [服务器A的IPv6]:443

⁠注意事项

  1. 本项目是 SNI/TCP 透传,不是 HTTP 反向代理
  2. 本项目不会缓存或修改 GitHub 内容
  3. 如果某些 GitHub 资源仍然失败,通常是因为缺少对应域名的 hosts 记录或路由规则
  4. 通配规则可以覆盖一类子域名,但具体资源域名仍建议按实际访问情况补充
  5. 如果服务器 A 自身无法稳定访问 GitHub 上游,代理也无法工作

Tag summary

Content type

Image

Digest

sha256:23b9d8467…

Size

32.5 MB

Last updated

5 months ago

docker pull maideduo/githubproxy