fix(docker): scope package proxy env (#5991)

* Revert "Add NO_PROXY defaults to Docker proxy setup"

This reverts commit 109be58abe.

* fix(docker): scope package proxy env
This commit is contained in:
InfinityPacer
2026-06-23 20:47:43 +08:00
committed by GitHub
parent 109be58abe
commit 724b4a59d5
4 changed files with 91 additions and 178 deletions

View File

@@ -35,43 +35,15 @@ function apply_package_cache_env() {
mkdir -p "${PIP_CACHE_DIR}" "${UV_CACHE_DIR}"
}
function apply_no_proxy_env() {
local default_no_proxy="localhost,127.0.0.1,::1,0.0.0.0,10.0.0.0/8,100.64.0.0/10,169.254.0.0/16,172.16.0.0/12,192.168.0.0/16,fc00::/7,fe80::/10,host.docker.internal,host.containers.internal,gateway.docker.internal,.local,.lan,.internal,.home.arpa,.localdomain"
local merged="${NO_PROXY:-}"
local source_value item old_ifs
local -a no_proxy_items
# Docker 内常见本机、局域网和内网服务必须直连,避免 PROXY_HOST 被映射到
# HTTP_PROXY 后拦截 Telegram 回调、下载器、媒体服务器等本地请求。
for source_value in "${no_proxy:-}" "${default_no_proxy}"; do
old_ifs="${IFS}"
IFS=','
read -ra no_proxy_items <<< "${source_value}"
IFS="${old_ifs}"
for item in "${no_proxy_items[@]}"; do
item="${item#"${item%%[![:space:]]*}"}"
item="${item%"${item##*[![:space:]]}"}"
if [ -z "${item}" ]; then
continue
fi
case ",${merged}," in
*",${item},"*) ;;
*) merged="${merged:+${merged},}${item}" ;;
esac
done
done
export NO_PROXY="${merged}"
export no_proxy="${merged}"
}
function apply_package_proxy_env() {
if [ -n "${PROXY_HOST:-}" ]; then
export HTTP_PROXY="${PROXY_HOST}"
export HTTPS_PROXY="${PROXY_HOST}"
export http_proxy="${PROXY_HOST}"
export https_proxy="${PROXY_HOST}"
apply_no_proxy_env
function run_package_command() {
if [ -n "${PROXY_HOST}" ]; then
HTTP_PROXY="${PROXY_HOST}" \
HTTPS_PROXY="${PROXY_HOST}" \
http_proxy="${PROXY_HOST}" \
https_proxy="${PROXY_HOST}" \
"$@"
else
"$@"
fi
}
@@ -198,9 +170,6 @@ function load_config_from_app_env() {
done
shopt -u extglob
if [ -n "${PROXY_HOST:-}${HTTP_PROXY:-}${HTTPS_PROXY:-}${http_proxy:-}${https_proxy:-}" ]; then
apply_no_proxy_env
fi
INFO "配置加载流程执行完毕。"
}
@@ -328,13 +297,12 @@ function ensure_backend_runtime_dependencies() {
fi
WARN "→ 检测到后端核心依赖异常,开始尝试恢复主程序依赖..."
apply_package_proxy_env
local -a pip_cmd=("${VENV_PATH}/bin/pip" "install" "-r" "/app/requirements.txt")
if [ -n "${PIP_PROXY}" ]; then
pip_cmd+=("-i" "${PIP_PROXY}")
fi
if ! "${pip_cmd[@]}" > /dev/stdout 2> /dev/stderr; then
if ! run_package_command "${pip_cmd[@]}" > /dev/stdout 2> /dev/stderr; then
ERROR "→ 自动恢复主程序依赖失败,后端无法启动。"
diagnostic_keepalive 1
fi

View File

@@ -36,42 +36,17 @@ function apply_package_cache_env() {
apply_package_cache_env
function apply_no_proxy_env() {
local default_no_proxy="localhost,127.0.0.1,::1,0.0.0.0,10.0.0.0/8,100.64.0.0/10,169.254.0.0/16,172.16.0.0/12,192.168.0.0/16,fc00::/7,fe80::/10,host.docker.internal,host.containers.internal,gateway.docker.internal,.local,.lan,.internal,.home.arpa,.localdomain"
local merged="${NO_PROXY:-}"
local source_value item old_ifs
local -a no_proxy_items
PIP_ENV=()
# 代理仅用于外网依赖下载,容器访问本机、局域网和内网服务时应保持直连。
for source_value in "${no_proxy:-}" "${default_no_proxy}"; do
old_ifs="${IFS}"
IFS=','
read -ra no_proxy_items <<< "${source_value}"
IFS="${old_ifs}"
for item in "${no_proxy_items[@]}"; do
item="${item#"${item%%[![:space:]]*}"}"
item="${item%"${item##*[![:space:]]}"}"
if [[ -z "${item}" ]]; then
continue
fi
case ",${merged}," in
*",${item},"*) ;;
*) merged="${merged:+${merged},}${item}" ;;
esac
done
done
export NO_PROXY="${merged}"
export no_proxy="${merged}"
}
function apply_package_proxy_env() {
if [[ -n "${PROXY_HOST:-}" ]]; then
export HTTP_PROXY="${PROXY_HOST}"
export HTTPS_PROXY="${PROXY_HOST}"
export http_proxy="${PROXY_HOST}"
export https_proxy="${PROXY_HOST}"
apply_no_proxy_env
function set_package_proxy_env() {
PIP_ENV=()
if [[ -n "${PROXY_HOST}" ]]; then
PIP_ENV=(
"HTTP_PROXY=${PROXY_HOST}"
"HTTPS_PROXY=${PROXY_HOST}"
"http_proxy=${PROXY_HOST}"
"https_proxy=${PROXY_HOST}"
)
fi
}
@@ -120,13 +95,13 @@ function install_backend_and_download_resources() {
# 复制新的requirements.in
cp "${TMP_PATH}/App/requirements.in" /app/requirements.in
# 重新编译依赖
if ! ${VENV_PATH}/bin/pip-compile /app/requirements.in -o /app/requirements.txt; then
if ! env "${PIP_ENV[@]}" ${VENV_PATH}/bin/pip-compile /app/requirements.in -o /app/requirements.txt; then
ERROR "依赖编译失败,恢复原依赖"
cp /tmp/requirements.txt.backup /app/requirements.txt
return 1
fi
# 安装新依赖
if ! ${VENV_PATH}/bin/pip install ${PIP_OPTIONS} -r /app/requirements.txt; then
if ! env "${PIP_ENV[@]}" ${VENV_PATH}/bin/pip install ${PIP_OPTIONS} -r /app/requirements.txt; then
ERROR "依赖安装失败,恢复原依赖"
cp /tmp/requirements.txt.backup /app/requirements.txt
return 1
@@ -236,7 +211,7 @@ function test_connectivity_pip() {
if [[ $? -eq 0 ]]; then
PIP_OPTIONS="-i ${PIP_PROXY}"
PIP_LOG="镜像代理模式"
apply_package_proxy_env
set_package_proxy_env
return 0
fi
fi
@@ -248,13 +223,14 @@ function test_connectivity_pip() {
${VENV_PATH}/bin/pip install pip-hello-world > /dev/null 2>&1; then
PIP_OPTIONS=""
PIP_LOG="全局代理模式"
apply_package_proxy_env
set_package_proxy_env
return 0
fi
fi
return 1
;;
2)
PIP_ENV=()
PIP_OPTIONS=""
PIP_LOG="不使用代理"
return 0