Skip to content

Using a Proxy with Private Locations

Configuring a Proxy

Use ESCAPE_FRONTEND_PROXY_URL and ESCAPE_BACKEND_PROXY_URL to configure Private Location proxies. The standard environment variables HTTP_PROXY, HTTPS_PROXY, and NO_PROXY aren't used.

See Environment Variables for proxy defaults and the legacy ESCAPE_REPEATER_PROXY_URL alias.

Choose which connections to route through a proxy:

  • Set ESCAPE_FRONTEND_PROXY_URL to route connections from escape-cli to Escape through a proxy.
  • Set ESCAPE_BACKEND_PROXY_URL to route connections from escape-cli to your internal services through a proxy.

Supported Proxy Protocols

Include a scheme and port in each proxy URL, for example http://proxy.example.com:8080.

  • Frontend: Use http:// or socks5://. An HTTP proxy must allow CONNECT to private-location.escape.tech:2222 for the SSH tunnel, as well as the agent's HTTPS API calls. An https:// frontend proxy supports API calls only and can't be used for the SSH tunnel.
  • Backend: Use http://, https://, or socks5:// to reach your internal targets.

WAF and Enterprise Proxy Compatibility

Configure the frontend proxy for connectivity to Escape and the backend proxy for connectivity to your internal services. Check that your proxy permits the connections described above.

Example: Using Helm

With the following values.yaml file, you'll add a proxy to your Helm deployment:

container:
  env:
    - name: ESCAPE_FRONTEND_PROXY_URL # Deployment -> Proxy -> Internet -> Escape Platform
      value: http://user:pass@my-proxy.server.tld:1234
    - name: ESCAPE_BACKEND_PROXY_URL # Deployment -> Proxy -> Your API
      value: http://user:pass@my-proxy.server.tld:1234

You can update your Helm deployment with the following command:

helm upgrade --install escape-private-location escape-cli/private-location --values values.yaml --set ESCAPE_API_KEY="${ESCAPE_API_KEY}"