passthrough

package
v0.17.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 21, 2026 License: Apache-2.0 Imports: 4 Imported by: 0

Documentation

Overview

Package passthrough holds the allowlist of third-party origins apt-proxy will fetch and cache on a client's behalf.

apt-proxy mirrors distributions: it rewrites a request onto a mirror it was configured for, and anything else is a 404. That is deliberate -- it is not an open forward proxy. But the archives people actually install from are not only distributions: a Launchpad PPA, a vendor repository like download.docker.com, an internal archive. Without a way to name those, each one has to be modelled as a distribution in distributions.yaml, or skipped with a per-host DIRECT rule on every client.

An allowlist is the middle ground, and it is the same shape apt-cacher-ng settles on with PassThroughPattern: the operator names the origins, and only those are fetched unrewritten. The list is the security boundary, so parsing is strict -- an entry that is not plainly a public origin is rejected at startup rather than tolerated at request time.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type List

type List struct {
	// contains filtered or unexported fields
}

List is a parsed allowlist. The zero value allows nothing, which is what an unconfigured apt-proxy must do.

func Parse

func Parse(entries []string) (*List, error)

Parse builds a List from configuration entries. Accepted forms are a bare host ("ppa.launchpad.net", "repo.example.com:8080") and a host with a scheme, where https:// additionally forces the upstream request to TLS.

Everything else is an error. A silently-dropped entry in an allowlist reads as "allowed" to whoever wrote it, so a typo has to be loud.

func (*List) Empty

func (l *List) Empty() bool

Empty reports whether the list allows nothing.

func (*List) Match

func (l *List) Match(authority string) (Rule, bool)

Match reports the rule covering authority, which may carry a port.

func (*List) Rules

func (l *List) Rules() []Rule

Rules returns the parsed entries, for logging and tests.

type Rule

type Rule struct {
	// Host is the lower-cased hostname, without a port.
	Host string
	// Port, when set, is the only port this rule matches. Empty means the
	// scheme default (80 or 443) -- an allowlisted archive host should not
	// also expose whatever else happens to listen on that machine.
	Port string
	// ForceHTTPS upgrades the upstream request, for an origin written as
	// https://host. apt speaks http to its proxy, so without this an
	// https-only archive answers with a redirect the client cannot follow
	// back through apt-proxy.
	ForceHTTPS bool
}

Rule is one allowlisted origin.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL