Using a Proxy with Private Locations¶
Configuring a Proxy¶
Use ESCAPE_FRONTEND_PROXY_URL and ESCAPE_BACKEND_PROXY_URL to configure Private Location proxies. The standard environment variables HTTP_PROXY, HTTPS_PROXY, and NO_PROXY aren't used.
See Environment Variables for proxy defaults and the legacy ESCAPE_REPEATER_PROXY_URL alias.
Choose which connections to route through a proxy:
- Set
ESCAPE_FRONTEND_PROXY_URLto route connections fromescape-clito Escape through a proxy. - Set
ESCAPE_BACKEND_PROXY_URLto route connections fromescape-clito your internal services through a proxy.
Supported Proxy Protocols
Include a scheme and port in each proxy URL, for example http://proxy.example.com:8080.
- Frontend: Use
http://orsocks5://. An HTTP proxy must allowCONNECTtoprivate-location.escape.tech:2222for the SSH tunnel, as well as the agent's HTTPS API calls. Anhttps://frontend proxy supports API calls only and can't be used for the SSH tunnel. - Backend: Use
http://,https://, orsocks5://to reach your internal targets.
WAF and Enterprise Proxy Compatibility¶
Configure the frontend proxy for connectivity to Escape and the backend proxy for connectivity to your internal services. Check that your proxy permits the connections described above.
Example: Using Helm¶
With the following values.yaml file, you'll add a proxy to your Helm deployment:
container:
env:
- name: ESCAPE_FRONTEND_PROXY_URL # Deployment -> Proxy -> Internet -> Escape Platform
value: http://user:pass@my-proxy.server.tld:1234
- name: ESCAPE_BACKEND_PROXY_URL # Deployment -> Proxy -> Your API
value: http://user:pass@my-proxy.server.tld:1234
You can update your Helm deployment with the following command: