代理设置 · 1 分钟阅读

使用 HTTP_PROXY / HTTPS_PROXY 环境变量

HTTP_PROXY、HTTPS_PROXY 和 NO_PROXY 环境变量是将程序的出站流量通过代理发送的最快方法。以下是它们在 curl、wget、Python、Node.js 和 Docker 中的行为 — 以及它们安静地不支持的地方。

代理环境变量的工作原理

HTTP_PROXY、HTTPS_PROXY和NO_PROXY是一种旧的跨平台约定:许多命令行工具和HTTP库在启动时读取它们,并通过您指定的代理路由出站请求。效果很简单——您的真实/源IP保持隐藏,目标看到的是代理的出口地址。

The naming trips people up. HTTP_PROXY is the proxy used for http:// destination URLs and HTTPS_PROXY for https:// destination URLs — it does not mean "a proxy reached over HTTPS". The scheme inside the value (http:// or socks5h://) is what decides how your client reaches our proxy.

并不是每个工具都遵循这些变量,而遵循的工具在细节上存在分歧:

传递
工具读取环境变量?备注
curl是的小写的http_proxy仅适用于HTTP;HTTPS使用两种情况
wget是的遵循http_proxy、https_proxy、no_proxy
Python requests / urllib是的自动;每个请求的proxies=参数会覆盖
Node.js核心fetch / http不需要undiciProxyAgent或global-agent
Docker CLI / build部分通过--build-arg、-e或config.json

我们的代理是数据中心代理(不是住宅代理),因此消费者网站可能更容易标记它们——非常适合API、CI和您控制的抓取目标,但对于受限的消费者平台则不太适合。我们的认证SOCKS5和HTTP代理需要用户名和密码,因此没有凭证就无法外发。要实现始终在线的全设备路由,请使用WireGuard VPN;要尝试一次性公共代理列表或价格计量访问,请参见定价。更多配方请查看指南,关于VPN与代理的完整比较也在这里。

在您的 shell 中设置变量(curl + wget)

导出一次,然后普通命令通过代理出口。身份验证在 URL 中以 USER:PASS 的形式内联。也设置小写形式 — curl 仅读取 HTTP 方案的小写 http_proxy。

bash
# HTTP proxy endpoint (port 3128) with inline auth
export HTTP_PROXY="http://USER:PASS@proxy.s4m.online:3128"
export HTTPS_PROXY="http://USER:PASS@proxy.s4m.online:3128"
# curl and some tools only read the lowercase form — set both
export http_proxy="$HTTP_PROXY"
export https_proxy="$HTTPS_PROXY"

# Never send local / internal traffic through the proxy
export NO_PROXY="localhost,127.0.0.1,::1,.internal,169.254.169.254"
export no_proxy="$NO_PROXY"

# Now normal commands go through the proxy
curl https://api.ipify.org      # prints the proxy exit IP, not yours
wget -qO- https://api.ipify.org

# One-off, without exporting anything:
curl -x http://USER:PASS@proxy.s4m.online:3128 https://example.com

# SOCKS5 (port 1080). socks5h makes DNS resolve AT the proxy,
# so your origin never leaks the hostname lookup.
export ALL_PROXY="socks5h://USER:PASS@proxy.s4m.online:1080"
curl https://api.ipify.org

Python 和 Node.js

Python的requests/urllib会自动获取变量。Node的核心http和全局fetch()不会 — 您必须自己附加代理代理。

python
# --- Python: requests, urllib, pip and httpx honor the env vars ---
import requests
print(requests.get("https://api.ipify.org").text)   # proxy exit IP

# Override per-request (this ignores the env vars):
proxies = {
    "http":  "http://USER:PASS@proxy.s4m.online:3128",
    "https": "http://USER:PASS@proxy.s4m.online:3128",
}
requests.get("https://api.ipify.org", proxies=proxies)

# SOCKS5 needs the extra:  pip install "requests[socks]"
proxies = {"https": "socks5h://USER:PASS@proxy.s4m.online:1080"}


# --- Node.js (>=18): core fetch does NOT read HTTP_PROXY on its own ---
// import { ProxyAgent, setGlobalDispatcher } from "undici";
// setGlobalDispatcher(
//   new ProxyAgent("http://USER:PASS@proxy.s4m.online:3128"));
// const r = await fetch("https://api.ipify.org");
// console.log(await r.text());        // proxy exit IP
//
// To make libraries respect the env vars instead:
//   npm i global-agent
//   GLOBAL_AGENT_HTTP_PROXY=$HTTP_PROXY node -r global-agent/bootstrap app.js

Docker(构建和运行时)

容器不会继承您的shell环境。为构建和运行显式传递变量;拉取镜像的守护进程从其自己的配置文件中读取它们。

bash
# Build-time: forward the proxy into the build
docker build \
  --build-arg HTTP_PROXY="http://USER:PASS@proxy.s4m.online:3128" \
  --build-arg HTTPS_PROXY="http://USER:PASS@proxy.s4m.online:3128" \
  --build-arg NO_PROXY="localhost,127.0.0.1" .

# Runtime: inject into the running container
docker run --rm \
  -e HTTP_PROXY="http://USER:PASS@proxy.s4m.online:3128" \
  -e HTTPS_PROXY="http://USER:PASS@proxy.s4m.online:3128" \
  -e NO_PROXY="localhost,127.0.0.1" \
  curlimages/curl https://api.ipify.org

# The Docker daemon itself (image pulls) reads ~/.docker/config.json:
#   { "proxies": { "default": {
#       "httpProxy":  "http://USER:PASS@proxy.s4m.online:3128",
#       "httpsProxy": "http://USER:PASS@proxy.s4m.online:3128",
#       "noProxy":    "localhost,127.0.0.1" } } }

值得了解的注意事项

百分比编码凭据

USER:PASS 中的特殊字符会破坏 URL。请对它们进行编码:@ 变为 %40,: 变为 %3A,/ 变为 %2F,# 变为 %23。否则解析器会在错误的位置切割值。

HTTPS_PROXY 目标为 https:// URLs

它为 HTTPS 目标 URL 选择代理 — 而不是通过 HTTPS 访问的代理。值中的方案 (http:// 或 socks5h://) 决定了您如何连接到我们的代理。

NO_PROXY 很挑剔

以逗号分隔,无空格,后缀匹配(.example.com)。CIDR 范围和 * 通配符由某些工具支持,其他工具则忽略,因此请测试而不是假设。

socks5h与socks5

使用socks5://时,您的机器在本地解析DNS,只有TCP连接被代理。使用socks5h://以便主机名查找也在代理处进行,从而将DNS保持在您的源之外。

凭据在本地可见

环境变量会出现在 ps 输出、shell 历史记录和 CI 日志中。使用可以轮换的每个账户代理凭证,并优先使用秘密存储,而不是将其提交到 Dockerfile 或管道中。

并不是每个客户端都遵守它们

节点的核心http和fetch,以及一些SDK,完全忽略这些变量。始终通过像api.ipify.org这样的IP回显确认流量确实通过代理出口离开,而不是您的真实IP。

Share this page
FAQ

问题,已解答

为什么curl忽略HTTP_PROXY但尊重http_proxy?

对于HTTP方案,curl故意只读取小写的http_proxy。大写的HTTP_PROXY多年前被禁用,因为CGI脚本从客户端头部接收HTTP_*环境变量,这可能会劫持代理设置。对于HTTPS和NO_PROXY,curl读取两种情况。安全的习惯是同时导出大写和小写形式。

HTTPS_PROXY 和 '通过 HTTPS 的代理' 之间有什么区别?

HTTPS_PROXY选择哪个代理处理对https://目标URL的请求。它并没有说明您如何连接到代理本身——这由值中的方案设置。http://proxy.s4m.online:3128以明文CONNECT到达我们的HTTP代理;socks5h://proxy.s4m.online:1080到达SOCKS5端点。您对https网站的实际有效载荷始终保持TLS加密,端到端。

我可以在 HTTP_PROXY 中放入 SOCKS5 URL 吗?

curl 在代理 URL 中接受 socks5:// 和 socks5h://,但许多其他工具不支持。为了便携性,使用 ALL_PROXY 进行 SOCKS5 或库自己的 SOCKS 选项。优先使用 socks5h:// 以便 DNS 在 proxy.s4m.online:1080 解析,而不是从您的源泄露查找。

这些是住宅代理吗?

不。s4m 代理是经过认证的数据中心 SOCKS5 和 HTTP 代理,按需计费。数据中心 IP 对于您控制的 API、CI 和抓取目标速度快且可靠,但某些消费者网站比住宅 IP 更容易检测和阻止数据中心范围。我们不出售或声称住宅 IP。

设置这些变量会在所有地方隐藏我的真实 IP 吗?

仅适用于实际读取它们的程序。Node的核心http、全局fetch、某些SDK和任何打开原始套接字的应用程序将绕过代理并暴露您的真实IP。配置后,请通过api.ipify.org等IP回显进行验证,或者在需要将设备上的每个进程路由时使用我们的WireGuard VPN。

通过 s4m 路由您的请求

经过身份验证的SOCKS5和HTTP数据中心代理,计量按需付费,以及固定费率的WireGuard VPN。设计上无日志,优先使用RAM,匿名账户。每当您需要静态出口时,添加一个专用个人IP。

人们通过搜索找到此页面

此页面回答的真实搜索短语 — 链接的短语打开详细覆盖它们的页面。