Documentation
¶
Overview ¶
Package passthrough holds the allowlist of third-party origins apt-proxy will fetch and cache on a client's behalf.
apt-proxy mirrors distributions: it rewrites a request onto a mirror it was configured for, and anything else is a 404. That is deliberate -- it is not an open forward proxy. But the archives people actually install from are not only distributions: a Launchpad PPA, a vendor repository like download.docker.com, an internal archive. Without a way to name those, each one has to be modelled as a distribution in distributions.yaml, or skipped with a per-host DIRECT rule on every client.
An allowlist is the middle ground, and it is the same shape apt-cacher-ng settles on with PassThroughPattern: the operator names the origins, and only those are fetched unrewritten. The list is the security boundary, so parsing is strict -- an entry that is not plainly a public origin is rejected at startup rather than tolerated at request time.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type List ¶
type List struct {
// contains filtered or unexported fields
}
List is a parsed allowlist. The zero value allows nothing, which is what an unconfigured apt-proxy must do.
func Parse ¶
Parse builds a List from configuration entries. Accepted forms are a bare host ("ppa.launchpad.net", "repo.example.com:8080") and a host with a scheme, where https:// additionally forces the upstream request to TLS.
Everything else is an error. A silently-dropped entry in an allowlist reads as "allowed" to whoever wrote it, so a typo has to be loud.
type Rule ¶
type Rule struct {
// Host is the lower-cased hostname, without a port.
Host string
// Port, when set, is the only port this rule matches. Empty means the
// scheme default (80 or 443) -- an allowlisted archive host should not
// also expose whatever else happens to listen on that machine.
Port string
// ForceHTTPS upgrades the upstream request, for an origin written as
// https://host. apt speaks http to its proxy, so without this an
// https-only archive answers with a redirect the client cannot follow
// back through apt-proxy.
ForceHTTPS bool
}
Rule is one allowlisted origin.