jenkinsci / jenkinsci/git-client-plugin

[JENKINS-61193] When using proxy also export the no_proxy hosts.

Open
#1,613 4 comments 0 reactions 0 assignees View on GitHub
component:git-client-plugin good first issue imported-jira-issue priority:minor resolution:unresolved
Dominant language
Java
Stars
152
Forks
402
Avg merge
6h 47m
Merged PRs (30d)
4

Description

The code in CliGitApiImpl will put the http_proxy and https_proxy variables in the env when a proxy should be used.

The relevant code can be found here:

https://github.com/jenkinsci/git-client-plugin/blob/master/src/main/java/org/jenkinsci/plugins/gitclient/CliGitAPIImpl.java#L2014

In our concrete case we are using CodeCommit as git repository. Jenkins is running on an AWS EC2 instance which is configured with a Role that has the required allowed actions.

For this to work we use the codecommit credential-helper. This credential helper will handle the required authentication/authorization steps. One of these steps involves calling the local IP 169.254.169.254

Setup of this credential-helper can be found: https://docs.aws.amazon.com/codecommit/latest/userguide/setting-up-https-unixes.html

This EC2 also runs inside a subnet with no default route and needs to use a forward proxy.

Now when we configure the proxy inside Jenkins the git plugin will set the http_proxy and https_proxy. By doing this the credential helper's call to the IP 169.254.169.254 will also be sent over the proxy. Which shouldn't happen.

Now if NO_PROXY would be set with the list of the "No Proxy Host" field, it would work. As the credential-helper would not use the proxy to call the IP 169.254.169.254.

This can also be found in the AWS documentation: https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-proxy.html#cli-configure-proxy-ec2

Would it be possible to alter the code so that after

env.put("http_proxy", http_proxy.toString());

env.put("https_proxy", http_proxy.toString());

The no_proxy would also be set?

 env.put("no_proxy", listOfConfiguredNoProxyHosts);

---
Originally reported by codingtim, imported from: When using proxy also export the no_proxy hosts.


  • status: In Review
  • priority: Minor
  • component(s): git-client-plugin
  • label(s): newbie-friendly
  • resolution: Unresolved
  • votes: 0
  • watchers: 2
  • imported: 20251211-071809

Raw content of original issue

The code in CliGitApiImpl will put the http_proxy and https_proxy variables in the env when a proxy should be used.
The relevant code can be found here:
https://github.com/jenkinsci/git-client-plugin/blob/master/src/main/java/org/jenkinsci/plugins/gitclient/CliGitAPIImpl.java#L2014

In our concrete case we are using CodeCommit as git repository. Jenkins is running on an AWS EC2 instance which is configured with a Role that has the required allowed actions.
For this to work we use the codecommit credential-helper. This credential helper will handle the required authentication/authorization steps. One of these steps involves calling the local IP 169.254.169.254
Setup of this credential-helper can be found: https://docs.aws.amazon.com/codecommit/latest/userguide/setting-up-https-unixes.html

This EC2 also runs inside a subnet with no default route and needs to use a forward proxy.

Now when we configure the proxy inside Jenkins the git plugin will set the http_proxy and https_proxy. By doing this the credential helper's call to the IP 169.254.169.254 will also be sent over the proxy. Which shouldn't happen.

Now if NO_PROXY would be set with the list of the "No Proxy Host" field, it would work. As the credential-helper would not use the proxy to call the IP 169.254.169.254.
This can also be found in the AWS documentation: https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-proxy.html#cli-configure-proxy-ec2

Would it be possible to alter the code so that after



env.put("http_proxy", http_proxy.toString());

env.put("https_proxy", http_proxy.toString());


The no_proxy would also be set?



 env.put("no_proxy", listOfConfiguredNoProxyHosts);

environment

```
Jenkins ver. 2.190.1

Git client 3.0.0
```

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.