做技术的难免需要经常从github或者gitlab等等国外的代码托管平台上拉取和下载远程的仓库内容,但由于github配置的托管仓库的服务器地址在国内速度堪称龟速,不是小水龙头般的下载速度就是出现unable to access '...' Couldn't resolve host '...'等错误,为此,git提供了相关代理的功能:

举个栗子

当使用https方式,如:

$ git clone https://github.com/kubernetes/kubernetes.git

使用ssh+git方式:

$ git clone git@github.com:kubernetes/kubernetes.git

根据自身习惯可以选择配置针对其中一种的代理方式,也可以两者皆可,但要注意,当使用config等非临时的写入配置文件的代理配置方式,这是全局的配置方式;需要更多用于控制代理与个性化的参数请自行查阅官方git文档。

Git ssh+git

ssh代理设置

注意:实际上,当我们使用ssh+git方式的时候,我们完全不必在~/.gitconfig中配置任何代理地址或者运行git config --global http.proxy ...与其他相似的命令。

在~/.ssh/config中配置ProxyCommand,git在拉取的时候就会开始使用此代理。

socks代理

当代理服务端开启socks服务时,我们可以使用nc命令,使用ssh的ProxyCommand配合nc可以让ssh通过设置的代理访问服务器

$ vim ~/.ssh/config

然后写入一些命令:

Host *
ProxyCommand nc -X 5 -x 127.0.0.1:1080 %h %p

nc命令上述涉及的参数:-X是指定协议参数:4即为socks4协议,5即为socks5协议

-x是指定代理服务器及端口 [代理服务器:端口]

非socks代理

没有socks代理的时候,可以使用corkscrew让ssh使用HTTP代理,Corkscrew是一个HTTP隧道代理ssh的工具

如果你的系统没有安装corkscrew,你可以通过以下方式安装:

对于mac用户:

$ brew install corkscrew

对于linux用户:

$ sudo apt-get install corkscrew

对于windows用户有更方便的管理ssh的工具,如PuTTY等,都可对ssh直接设置代理, 当然mac端也有termius这样的图形界面工具,根据自身喜好决定配置思路

使用查询路径的命令查询corkscrew的执行文件路径如:

$ which corkscrew

假设此处查到的路径为%corkscrew_path%,向~/.ssh/config文件中添加如下内容:

1
2
3
4
5
Host github.com
Hostname github.com
ServerAliveInterval 55
ForwardAgent yes
ProxyCommand %corkscrew_path% 127.0.0.1 7580 %h %p

127.0.0.1:7580即代理服务端地址及端口,其中可以只添加最后一句,前面的语句都是用于控制一些参数和作用域名,关于如何详细配置git的参数可参阅:git-config

Git http

HTTP代理配置

使用~/.gitconfig文件全局的配置代理,使用--global参数切换,或者在.git/config文件中设置对某个仓库的局部代理

设置一个全局代理

配置一个全局代理当你想使用它访问所有的远程仓库:

配置HTTP代理:

$ git config --global http.proxy http://proxyUsername:proxyPassword@proxy.server.com:port

配置HTTPS代理:Git并没有https.proxy这个配置项,上面的http.proxy对http://和https://开头的远程仓库都会生效,无需另外配置。

配置socks5代理:

$ git config --global http.proxy socks5://proxyUsername:proxyPassword@proxy.server.com:port

用户名和密码为缺省状态:

$ git config --global http.proxy http://proxy.server.com:port
$ git config --global http.proxy socks5://proxy.server.com:port

注意:git config配置的代理会写入配置文件(--global即写入~/.gitconfig),效果与直接修改配置文件相同,是永久生效的,关闭终端也不会失效,需要用后文的--unset取消;配置后对之后执行的git命令立即生效,无需重启。如果只想临时使用代理,可以用git -c http.proxy=... clone ...只对单条命令生效。

配置针对特定URL代理

当希望能够指定代理应该用于那些被http.<url>.key所指定的URL:

$ git config --global http.https://domain.com.proxy http://proxyUsername:proxyPassword@proxy.server.com:port

其中https://domain.com是要匹配的远程仓库URL,https://开头的仓库同样使用http.开头的配置项,不存在https.<url>.proxy这种写法。

同理,同样的命令在~/.gitconfig文件中可以添加为:

1
2
3
[http]
[http "https://domain.com"]
proxy = http://proxyUsername:proxyPassword@proxy.server.com:port

处理后续SSL报错

如果在配置代理之后还是会遇到unable to access 'https://...': Unknown SSL protocol error in connection to ...:443,或许你可以使用-c http.sslVerify=false参数来手动关闭SSL验证,譬如:

$ git -c http.sslVerify=false clone https://domain.com/path/to/git

注意:http.sslVerify=false会关闭TLS证书校验,此时无法识别中间人攻击,建议只作为临时排查手段,并尽量只对单个仓库或特定URL关闭,用完及时恢复。

可以选择在拉取下来的项目中配置.git/config,在该项目文件夹打开终端:

$ git config http.sslVerify false

当仅仅想针对特定URL使用http.<url>.sslVerify设置而其他仍然使用全局配置时:

$ git config --global http.https://domain.com.proxy http://proxyUsername:proxyPassword@proxy.server.com:port
$ git config --global http.https://domain.com.sslVerify false

在~/.gitconfig文件根据同样的要求配置的结果:

1
2
3
4
[http]
[http "https://domain.com"]
proxy = http://proxyUsername:proxyPassword@proxy.server.com:port
sslVerify = false

显示当前设置

显示当前所有http部分当前配置:

$ git config --global --get-regexp 'http.*'

Git没有https部分的配置,如果之前误设过https.proxy之类的配置项(它们不会生效),可以这样检查并删除:

$ git config --global --get-regexp '^https\.'
$ git config --global --unset https.proxy

如果远程项目已经被拉取到本地了,进入项目目录,丢弃--global参数同样能查询当前所有配置

$ git config --get-regexp 'http.*'

取消代理或SSL验证的配置

在终端中使用git config配置的代理会写入配置文件,关闭终端后依然有效,不再需要时要手动取消。

使用--unset参数来取消这些特定的代理配置,比如http.proxy或http.<url>.proxy代理移除:

1
2
3
4
5
$ git config --global --unset http.proxy
$ git config --global --unset http.https://domain.com.proxy

$ git config --global --unset http.sslVerify
$ git config --global --unset http.https://domain.com.sslVerify

查看配置信息:

$ git config -l --global

执行查看代理:

$ git config -l