惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

A
Arctic Wolf
博客园 - 聂微东
F
Fortinet All Blogs
云风的 BLOG
云风的 BLOG
小众软件
小众软件
V
Visual Studio Blog
博客园 - 三生石上(FineUI控件)
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Apple Machine Learning Research
Apple Machine Learning Research
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
The Cloudflare Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The GitHub Blog
The GitHub Blog
Y
Y Combinator Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园_首页
L
LangChain Blog
A
About on SuperTechFans
阮一峰的网络日志
阮一峰的网络日志
I
Intezer
T
The Blog of Author Tim Ferriss
Security Latest
Security Latest
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
Simon Willison's Weblog
Simon Willison's Weblog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
P
Palo Alto Networks Blog
Scott Helme
Scott Helme
S
Secure Thoughts
Spread Privacy
Spread Privacy
T
Threat Research - Cisco Blogs
Attack and Defense Labs
Attack and Defense Labs
P
Privacy & Cybersecurity Law Blog
O
OpenAI News
H
Heimdal Security Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Help Net Security
Help Net Security
C
Cyber Attacks, Cyber Crime and Cyber Security
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
G
Google Developers Blog
博客园 - Franky
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
K
Kaspersky official blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
T
Tor Project blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
T
Tenable Blog
Google Online Security Blog
Google Online Security Blog
PCI Perspectives
PCI Perspectives

hsfzxjy 的博客

解决 VSCode + CMake + MSVC 编译器信息乱码的问题 使用 3090 部署 1.58bit 动态量化版 DeepSeek R1 671b 如何在跳板机背后的服务器上使用 VS Code Remote - Containers Cohesive Digests for Ints and Floats Rust 中的隐匿概念 —— Place(位置) 美术馆 一尺之槌,日取其半,1075日而竭 老生常谈:使用 Cloudflare 自选 IP 加速站点访问 辩义 State、Nation 与 Country 将 Base64 编码的数据快速转换为 Uint8Array 折腾 NPU·第1章 —— 搭建 Level Zero 开发环境 折腾 NPU·第0章 —— Intel NPU 概述与 Level-Zero 新增域名 monad.run CSS 中为特定字符设置不同字体 Arbitary Lifetime Transmutation via Rust Unsoundness Dijkstra 算法的延伸 Manacher 回文计数算法 硬卧 Go Fact: Zero-sized Field at the Rear of a Struct Has Non-zero Size Display *big.Rat Losslessly and Smartly in Golang 代码的仪式 Building Electron From Scratch 中式亲属称谓研究之一:构建半群 Some Notes on Kotlin Coroutines Git sparse-checkout and partial clones for Mega-Repos 辩义“封建” Diving from the CUDA Error 804 into a bug of libnvidia-container Modern Cryptography, GPG and Integration with Git(hub) Move the Root Partition of Ubuntu A New Programmer Kicks a Roadblock Git-based Dependencies in Dart and Go Reversy Naming 人类一败涂地 Invalid Golang Pointers Can Bite You Even If You Don't Dereference Side Project(副业) A Flaw of Promoting Complex Trait Bounds in Rust Initialize Process Pool Worker with Individual Value Rust - Python FFI From Scratch [Extending Hexo For My Site] Part 1 [Extending Hexo For My Site] Part 0 Debug a 'torch.tensor(1).cuda()' hanging 不自由的互联网 Retrieve Contents over HTTP without curl or wget [Unravelling mocona] Part 1 - Verbosity or Anti-Pattern [Unravelling mocona] Part 0 - Preface Understanding pickle in Python Rough Notes on Deploying Vaultwarden & NextCloud Bookmarks 语言狂热者与实用主义者 Demystify the randomness in CUDA kernels Performant Bulk Mutations in IndexedDB Auto Rebuild .pyx Files with pyximport Cython and Threads Obtain a Random Available TCP Port with Bash Information Theory: KL Divergence Information Theory: Entropy and Mutual Information 铁板烧 西郊线 Proof of the Gumbel Max Trick Option::as_ref Rc, RefCell and Interior Mutability Visualizing Correlation 三月十日杂感 三月一日杂感 二月十一日杂感 一月二十六日杂感 SS Configuration 一月七日杂感 四月·病 Haskell 笔记:State Monad Haskell 笔记:Monad 引论 Haskell 笔记:Applicative Haskell 笔记:Category Theory and Functor Haskell 笔记:data, type, newtype Haskell 笔记:folds 使用 Aria2 在 Ubuntu 中下载百度云资源 从伪并行的 Python 多线程说起 一个 Reentrant Error 引发的对 Python 信号机制的探索和思考 Linux 文件权限 HSFZMUN 4.0 部署小记 午后雨·科大 最后的雨夜·广州 揭秘·变态的平方根倒数算法 神坑·Python 装饰类无限递归 Python“黑魔法”之 Encoding & Decoding Ubuntu 重新映射键盘布局 为什么我要翻墙 Python“黑魔法”之 Generator Coroutines 数学美 之 判断线段相交的最简方法 除夕杂感 17 行代码实现的简易 Javascript 字符串模板 Python“黑魔法”之 Meta Classes 诗集 生活,需要被“发现” 家书·十八岁成人礼 炫技?还是需求? 【译】响应式图片的现状 【译】“为什么有这么多的编程语言?” Wisecity 商赛总结——也谈前端自动化测试 记一次 DoS 诈骗网站的经历 那一年,我们望向星空
如何在 VS Code DevContainer 中配置 HTTP 代理
2025-01-21 · via hsfzxjy 的博客

上回 我们讲了如何在跳板机背后的服务器上使用 VS Code Remote - Containers。DevContainer 中还有个棘手的问题是网络代理,本文将聊聊在 VS Code 中配置代理的问题,以及我目前的解决方案。

LOCALREMOTE SERVERHTTP://192.168.9.100:11451DOCKERVS CODE (CONTAINER)?
LOCALHTTP://127.0.0.1:1081VS CODE (LOCAL)

网络拓扑

上图描述了我目前使用 DevContainer 在远端开发时的环境,以及其与本地环境的对比。

  • 本地环境 在本地正常开发时,我会在本地启动一个代理服务,地址为 http://127.0.0.1:1081。通过在 VS Code 中设置 http.proxy 为该地址,即可让 VS Code 的所有网络请求经由该代理。
  • Remote 环境 在 Remote 使用 DevContainer 时,代理的地址变为了 http://192.168.9.100:11451 —— 这是集群内部提供的一个代理。此时该如何应对呢?

那么,在 VS Code 中能否为不同环境设置不同的代理地址呢?

尝试一:为不同环境设置不同 http.proxy 值(失败)

VS Code 的配置是层叠式的。打开设置页可以看到如下图所示的多层作用域:UserRemoteWorkspaceUser 下的设置会对所有环境生效,Remote 下的设置则只对 DevContainer 生效。作用域小的设置会覆盖作用域大的设置。Remote 中更改的某项设置会覆盖 User 中的原有项,以便用户对特定环境作更精准的配置。

如此一来,一个很自然的想法便是:保持 User 下的 http.proxy 为本地的 http://127.0.0.1:1081,再将 Remote 下的设置为 http://192.168.100:11451,以期在不同环境下使用不同的代理。

然而这样配置并没有达到预期效果。VS Code 会把所有网络请求都发往 http://192.168.100:11451,而不是根据当前环境选择代理。这其中包括了 DevContainer 内部的网络请求,也包括了本地与 DevContainer 间的通信——后者显然是不合理的。

LOCALHTTP://192.168.9.100:11451(BAD)REMOTE SERVERHTTP://192.168.9.100:11451DOCKERVS CODE (CONTAINER)?

既然如此,我们必须保持 http.proxy 始终为 http://127.0.0.1:1081,从而需要在 DevContainer 内部另架设一个转发代理,网络拓扑如下

LOCALREMOTE SERVERHTTP://192.168.9.100:11451DOCKERVS CODE(CONTAINER)HTTP://127.0.0.1:1081

尝试二:在 DevContainer 内部架设转发代理

该方法后来被证明不是完全有效,因为 squid 会在请求转发前作 DNS 查询,且该行为似乎无法关闭。若遇上被墙的域名,squid 在 DNS 失败后会直接返回 503。正确解法见尝试三。

我们选择 squid 作为 DevContainer 内部的转发代理。

安装 squid

首先在 Dockerfile 中安装 squid,并写入配置文件:


RUN apt-get install -y squid
RUN printf 'http_port 127.0.0.1:1082\ncache_peer 192.168.9.100 parent 11451 0 no-query proxy-only tls-flags=DONT_VERIFY_PEER\ncache deny all\nssl_bump peek all\nssl_bump bump all\nsslproxy_cert_error allow all\ntls_outgoing_options flags=DONT_VERIFY_PEER' >> /etc/squid/squid.conf

第二行的配置文件内容如下:

http_port 127.0.0.1:1081
cache_peer 192.168.9.100 parent 11451 0 no-query proxy-only tls-flags=DONT_VERIFY_PEER
cache deny all

ssl_bump peek all
ssl_bump bump all
sslproxy_cert_error allow all
tls_outgoing_options flags=DONT_VERIFY_PEER

其中前两行配置了 squid 的监听端口和上级代理。后面的 ssl_* 部分则开启了 SSL Bump 功能——这是必要的,否则 HTTPS 请求经由 squid 时会报 503 直接拒绝,困扰了我许久。

设置 squid 自启动

为了使 squid 服务在容器启动时自动启动,我们需要在 devcontainer.json 中添加如下配置:

{

"postStartCommand": "service squid restart"
}

尝试三:在 DevContainer 内使用 socat 转发代理

这种方法的的出发点与 squid 类似,但是过程更简单,只需起一个 socat 进程作为 TCP 转发的中介即可。

安装 socat

首先在 Dockerfile 中安装 socat:


RUN apt-get install -y socat

与尝试二相比,甚至不需要写入配置文件。

设置 socat 进程自启动

我们需要在 devcontainer.json 中添加如下配置:

{

"postStartCommand": "nohup bash -c 'socat -d TCP-LISTEN:1081,fork TCP:192.168.9.100:11451 > /tmp/proxy.log &'"
}

读者可根据实际情况更改监听端口以及上游地址。

如此一来,即使在 DevContainer 内也可以经由 http://127.0.0.1:1081 地址访问代理,与本地环境保持一致。Copilot 等工具也可以正常使用了。


作者:hsfzxjy
链接:
许可:CC BY-NC-ND 4.0.
著作权归作者所有。本文不允许被用作商业用途,非商业转载请注明出处。