# \[Feature Request\] Proxy auto-configuration (PAC) support

**URL:** https://hub.mender.io/t/feature-request-proxy-auto-configuration-pac-support/3518
**Category:** General Discussions
**Created:** [April 15, 2021, 8:34pm UTC](https://hub.mender.io/t/feature-request-proxy-auto-configuration-pac-support/3518 "2021-04-15T20:34:35Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![nowls](https://avatars.discourse-cdn.com/v4/letter/n/919ad9/32.png) [@nowls](https://hub.mender.io/u/nowls)
#### Post date: [April 15, 2021, 8:34pm UTC](https://hub.mender.io/t/feature-request-proxy-auto-configuration-pac-support/3518/1 "2021-04-15T20:34:35Z")

</div>

We run devices on customers’ corporate networks. We’ve recently had a request to support proxy auto-configuration for our devices’ connections to REST APIs, including the Mender client’s connection to [hosted.mender.io](http://hosted.mender.io). Currently we’re using a workaround by supplying a fixed proxy server address through the HTTPS\_PROXY environment variable. The customer would prefer the client to download a PAC file in order to resolve the proxy server address (or list of addresses to try in order).

Would you consider pulling in optional support for PAC file processing? I don’t have any Golang programming experience but I did come across a PAC parsing library and an example of a transport client that uses it:

> **[jackwakefield/gopac](https://github.com/jackwakefield/gopac)**
>
> A go package for using proxy auto-config (PAC) files

> <https://github.com/jackwakefield/transpac/blob/master/proxy.go>

Could this somehow be integrated into the Mender client’s HTTP transport?

> <https://github.com/mendersoftware/mender/blob/master/client/client.go>

---

<div class="post-metadata">

### Author: ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)
#### Post date: [April 16, 2021, 1:32pm UTC](https://hub.mender.io/t/feature-request-proxy-auto-configuration-pac-support/3518/2 "2021-04-16T13:32:43Z")

</div>

@eystein thoughts?

---

<div class="post-metadata">

### Author: ![nowls](https://avatars.discourse-cdn.com/v4/letter/n/919ad9/32.png) [@nowls](https://hub.mender.io/u/nowls)
#### Post date: [April 16, 2021, 4:59pm UTC](https://hub.mender.io/t/feature-request-proxy-auto-configuration-pac-support/3518/3 "2021-04-16T16:59:40Z")

</div>

Upon further consideration, I could see how adding direct support might be awkward. The historical design of needing a JavaScript parsing engine to process PAC files is burdensome for standalone clients, but seemed natural to browser developers who already have one loaded.

It looks like [libproxy](https://github.com/libproxy/libproxy) is one way to get this support (at least for a C/C++ application, not sure about Golang bindings).

Perhaps more interesting is querying proxy info over D-Bus using [pacrunner](https://git.kernel.org/pub/scm/network/connman/pacrunner.git/). I’m not sure if that fits your model or not.

Unfortunately, it seems like PAC file processing and proxy configuration is a messy problem in general with all kinds of hacks in the real world to make it work.

---

<div class="post-metadata">

### Author: ![eystein](https://avatars.discourse-cdn.com/v4/letter/e/e5b9ba/32.png) [@eystein](https://hub.mender.io/u/eystein)
#### Post date: [April 16, 2021, 9:13pm UTC](https://hub.mender.io/t/feature-request-proxy-auto-configuration-pac-support/3518/4 "2021-04-16T21:13:35Z")

</div>

Thanks for the ideas.

I am not too familiar with this area unfortunately, but as I understand it you only want to auto-configure the URI the Mender client uses? This is indeed a quite interesting problem.

We did look a bit into service discovery like avahi, is that something you have considered? We’d need to solve a general problem in a standard way if we are to include it in the client…

---

<div class="post-metadata">

### Author: ![nowls](https://avatars.discourse-cdn.com/v4/letter/n/919ad9/32.png) [@nowls](https://hub.mender.io/u/nowls)
#### Post date: [April 16, 2021, 10:01pm UTC](https://hub.mender.io/t/feature-request-proxy-auto-configuration-pac-support/3518/5 "2021-04-16T22:01:26Z")

</div>

I want to be able to resolve URLs for HTTP proxy servers dynamically by downloading and processing a [PAC file](https://developer.mozilla.org/en-US/docs/Web/HTTP/Proxy_servers_and_tunneling/Proxy_Auto-Configuration_PAC_file), whose purpose is to tell an HTTP client which proxy server URL(s) to use for connections. Currently the Mender client only allows setting a static proxy URL using the HTTP\_PROXY or HTTPS\_PROXY environment variable.

A workaround I am considering is to use a stand-alone script or program that will download and process a PAC file and write the corresponding proxy server URL list to a file. Then I’d make a systemd timer that periodically runs that script and restarts Mender client with a new value for HTTPS\_PROXY.
