git指南 · 1 分钟阅读

通过代理使用git:HTTP和SOCKS5

git 在 HTTPS 和 SSH 上以不同方式处理代理。此指南涵盖两者:用于 HTTPS 远程的 http.proxy(包括 SOCKS5),以及用于 SSH 远程的 ProxyCommand — 具有每个主机的作用域,以便仅路由正确的流量。

HTTPS远程与SSH远程

How you proxy git depends entirely on your remote's protocol. For HTTPS remotes (URLs like https://github.com/...), git uses libcurl, so it honours the http.proxy config and the standard http_proxy environment variables — and because it is libcurl, it accepts a SOCKS5 proxy via the socks5h:// scheme just like curl does. For SSH remotes (git@github.com:...), git is not involved in the networking at all; SSH is, so you configure a ProxyCommand in your SSH config to tunnel the connection.

使用 s4m,您有两个端点:端口 1080 上的 SOCKS5 和端口 3128 上的 HTTP,使用 USER:PASS 进行身份验证,针对 proxy.s4m.online。对于 HTTPS 远程,socks5h:// 保持 DNS 远程;对于 SSH,使用 ProxyCommand 通过 nc 或 ncat 将 SSH 流量路由通过 SOCKS5。请参阅 代理页面 和 什么是 SOCKS5;相同的 ProxyCommand 思路出现在 SOCKS5 与 HTTP 比较中。

通过 HTTPS 和 SSH 的 git,代理

用于HTTPS远程的http.proxy(SOCKS5或HTTP),以及SSH的ProxyCommand。每个URL的作用域避免了代理所有内容。替换USER:PASS。

bash
# --- HTTPS remotes: SOCKS5 with remote DNS ---
git config --global http.proxy socks5h://USER:PASS@proxy.s4m.online:1080
# or the HTTP proxy:
git config --global http.proxy http://USER:PASS@proxy.s4m.online:3128

# --- Scope the proxy to ONE host only (leave the rest direct) ---
git config --global http.https://github.com/.proxy \
    socks5h://USER:PASS@proxy.s4m.online:1080

# --- Remove the proxy later ---
git config --global --unset http.proxy

# --- SSH remotes: tunnel git@... through SOCKS5 via ~/.ssh/config ---
cat >> ~/.ssh/config <<'CFG'
Host github.com
  HostName github.com
  User git
  ProxyCommand nc -X 5 -x proxy.s4m.online:1080 %h %p
CFG
# -X 5 = SOCKS5; nc/ncat must be installed.

# --- One-off, no persistent config ---
git -c http.proxy=socks5h://USER:PASS@proxy.s4m.online:1080 clone https://example.com/repo.git

正确地使用代理git

首先选择您的远程类型,然后应用匹配的配置。

识别你的远程协议

运行 git remote -v。一个 https:// URL 使用 http.proxy;一个 git@host: URL 使用 SSH,这需要一个 ProxyCommand。

对于 HTTPS,设置 http.proxy

使用git config --global http.proxy和socks5h://proxy.s4m.online:1080进行远程DNS,或者在3128上使用HTTP端点。如果您只想代理一个主机,请按URL范围设置。

对于 SSH,添加一个 ProxyCommand

在~/.ssh/config中,在相关的Host块下添加ProxyCommand nc -X 5 -x proxy.s4m.online:1080 %h %p。如果缺少nc/ncat,请安装。

通过克隆进行验证

克隆一个小的代码库并确认成功。如果挂起,请重新检查端点和凭据,并确保您选择了正确的协议。

每个主机的范围、认证和诚实

You rarely want to route all git traffic through a proxy. git supports per-URL proxy config — http.https://github.com/.proxy applies a proxy only to that host, leaving other remotes direct. That keeps internal mirrors fast while an external host goes through the proxy. Credentials live inline in the proxy URL; if your password has special characters, URL-encode them.

s4m 代理是经过身份验证的 数据中心 SOCKS5 和 HTTP 端点,按需计费 — 非常适合从受控出口克隆依赖项的 CI 运行器,或从受限网络访问 git 主机。它们是数据中心,而不是住宅,代理仅更改您的网络路径,而不更改您的 git 凭据或 SSH 密钥。当 CI 需要一个白名单中的出口 IP 时,添加一个 专用个人 IP。通过 HTTPS 的 407 表示代理凭据错误 — 请参阅 407 指南。使用 工具 验证端点,并阅读 API 文档。

FAQ

问题,已解答

我如何让 git 使用 SOCKS5 代理?

对于HTTPS远程,设置git config --global http.proxy socks5h://USER:PASS@proxy.s4m.online:1080 — git使用libcurl,因此它像curl一样接受SOCKS5。对于SSH远程,请在~/.ssh/config中使用ProxyCommand。

http.proxy适用于SSH(git@...)远程吗?

不。http.proxy仅影响HTTPS远程。SSH远程在SSH层通过ProxyCommand进行代理——例如nc -X 5 -x proxy.s4m.online:1080 %h %p用于SOCKS5。

我如何只代理一个 git 主机?

使用每个URL配置:git config --global http.https://github.com/.proxy 。只有该主机通过代理路由;其他所有远程连接保持直接。

我如何移除 git 代理?

运行 git config --global --unset http.proxy(以及任何每个 URL 的变体),或从 ~/.ssh/config 中删除 ProxyCommand 行以用于 SSH 远程连接。

从代理后克隆

在 proxy.s4m.online 上提供经过身份验证的 SOCKS5 (1080) 和 HTTP (3128) 代理,准备好用于 http.proxy 和 SSH ProxyCommand。按需计费,专用 IP 用于 CI 白名单。

人们通过搜索找到此页面

此页面回答的真实搜索短语 — 链接的短语打开详细覆盖它们的页面。