@bluealba/pillar-egress
v0.1.1-develop-194
Published
Outbound corporate proxy support for Pillar processes: undici dispatcher, node:http agents and proxy failure diagnostics
Readme
@bluealba/pillar-egress
Outbound corporate proxy support for Pillar Node processes. It reads the typed
egressProxy config of @bluealba/pillar-config (PILLAR_HTTP_PROXY,
PILLAR_HTTPS_PROXY, PILLAR_PROXY_USERNAME, PILLAR_PROXY_PASSWORD,
PILLAR_NO_PROXY). It never reads HTTP_PROXY, HTTPS_PROXY or NO_PROXY.
import { installEgressProxyFromEnv, nodeAgentFor, pinoEgressLogger } from '@bluealba/pillar-egress';
installEgressProxyFromEnv(pinoEgressLogger(logger.pino)); // first line of the process
nodeAgentFor('https://s3.eu-west-1.amazonaws.com'); // agent for a node:http client, or undefinedinstallEgressProxysets the global undici dispatcher, so nativefetchuses the proxy.egressDispatcher(agentOptions)returns a dispatcher for clients that take one (@fastify/reply-from).nodeAgentFor(url)returns anode:httpproxy agent, orundefinedwhen the call must go direct.egressProxyFor(url)returns the proxy and credentials for clients with their own proxy settings.setCatalogRoutes({ proxy, direct })replaces thehost:portroutes that every client above consults. Build the keys withegressRouteKey(host, port, protocol).
A proxy route always uses the proxy, a direct route always goes direct, and PILLAR_NO_PROXY decides the rest.
Hosts in PILLAR_NO_PROXY go direct. The list accepts hosts, suffixes, IPs, IPv4 CIDR
ranges and host:port. When the proxy is off, nothing changes.
A failed connection to the proxy is logged once per 30 seconds and reason, with
component: "egress-proxy":
Egress proxy connection failed (proxy=host:port, target=host, reason=auth-rejected (407))
Reasons are auth-rejected, proxy-rejected, unreachable and timeout. The original error
is not changed. The password is never logged.
