# How to Configure a Network Proxy in Agent Reach for Restricted Environments via CLI

> Easily configure Agent Reach network proxy in restricted environments using the CLI. Learn how to set up proxy settings via flags or commands for seamless external tool integration, even in restricted networks.

- Repository: [Pnant/Agent-Reach](https://github.com/Panniantong/Agent-Reach)
- Tags: how-to-guide
- Published: 2026-07-09

---

**Agent Reach stores proxy settings in `~/.agent-reach/config.yaml` and exposes them through the `--proxy` flag during installation or the `configure proxy` sub-command, which downstream agents export as `HTTP_PROXY`/`HTTPS_PROXY` environment variables for external tools.**

Agent Reach is an open-source automation framework that orchestrates interactions with external platforms like YouTube, Twitter, and Reddit. When deploying agents inside corporate firewalls or restricted networks, you must configure a network proxy in Agent Reach for restricted environments via CLI to ensure agents can route traffic through your corporate gateway.

## Where Agent Reach Stores Proxy Configuration

Agent Reach persists runtime settings in a per-user YAML file located at `~/.agent‑reach/config.yaml`. The **Config** class in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py) manages this file, providing generic `set(key, value)` and `get(key)` methods that update an in-memory dictionary and flush changes to disk via `Config.save()`.

When you configure a proxy, the CLI writes the supplied string to two keys: `proxy` and the legacy `bili_proxy`. This dual-key approach maintains backward compatibility while ensuring modern agents read the correct value.

## CLI Methods for Configuring a Proxy

The [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) module provides two distinct entry points for supplying a proxy value, depending on whether you are performing initial setup or modifying an existing installation.

### Option 1: Set Proxy During Installation (--proxy flag)

During the one-shot installation process, pass the `--proxy` flag to write the proxy URL directly into the configuration file. According to the source code at lines 68‑71 and lines 36‑44 in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py), the installer extracts the flag value and invokes `Config.set("proxy", value)` and `Config.set("bili_proxy", value)` before saving.

```bash
agent-reach install --proxy "http://user:pass@proxy.example.com:8080"

```

This approach is ideal for automated deployment scripts that provision Agent Reach in restricted environments without requiring interactive configuration steps.

### Option 2: Update Proxy After Installation (configure sub-command)

If you need to rotate credentials or change endpoints post-installation, use the `configure` sub-command. The handler defined at lines 62‑70 in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py) maps the `proxy` argument directly to the configuration store, overwriting any existing values.

```bash
agent-reach configure proxy "http://newuser:newpass@proxy.example.com:8080"

```

Both commands ultimately trigger the same persistence logic, ensuring the YAML file remains the single source of truth for network settings.

## How Agents Consume the Proxy Configuration

Agent Reach treats the proxy string as opaque configuration; the core library does not perform any network validation or proxy handshakes. Instead, agents retrieve the value via `Config.get("proxy")` and export it as standard environment variables `HTTP_PROXY` and `HTTPS_PROXY` before invoking upstream utilities.

This design keeps the framework lightweight while allowing external tools—such as those handling `youtube`, `twitter`, and `reddit` channels—to respect the corporate proxy transparently. The environment variable injection happens automatically during agent initialization, requiring no additional code changes in your automation scripts.

## Verifying Your Proxy Configuration

To confirm that your settings persisted correctly, inspect the configuration file directly:

```bash
cat ~/.agent-reach/config.yaml

```

You should see output similar to:

```yaml
proxy: http://user:pass@proxy.example.com:8080
bili_proxy: http://user:pass@proxy.example.com:8080

```

The presence of both keys indicates that the CLI stored the value successfully and that agents will have access to the proxy endpoint when executing network requests.

## Summary

- **Configuration location**: Runtime settings live in `~/.agent-reach/config.yaml`, managed by the `Config` class in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py).
- **Installation-time setup**: Use `agent-reach install --proxy <url>` (lines 36‑44 and 68‑71 in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py)) to write the proxy during initial setup.
- **Post-installation updates**: Use `agent-reach configure proxy <url>` (lines 62‑70 in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py)) to modify or add a proxy later.
- **Dual-key storage**: Values are stored under both `proxy` and `bili_proxy` keys for backward compatibility.
- **Environment export**: Agents automatically export the stored value as `HTTP_PROXY` and `HTTPS_PROXY` for external tools.

## Frequently Asked Questions

### Does Agent Reach validate the proxy URL before saving it?

No. According to the implementation in [`agent_reach/cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/cli.py), the CLI treats the proxy string as opaque data. It passes the value directly to `Config.set()` without performing connectivity checks or URL validation. Verification occurs only when downstream agents attempt to route traffic through the proxy.

### Can I configure different proxies for different channels like YouTube and Twitter?

Currently, Agent Reach uses a single global proxy setting stored under the `proxy` key. The source code in [`agent_reach/config.py`](https://github.com/Panniantong/Agent-Reach/blob/main/agent_reach/config.py) does not implement per-channel proxy overrides; all agents retrieve the same value via `Config.get("proxy")` and apply it uniformly across `youtube`, `twitter`, and `reddit` channels.

### What happens if I run `configure proxy` with an empty value?

Running `agent-reach configure proxy ""` will store an empty string in both the `proxy` and `bili_proxy` keys, effectively clearing the configuration. Because agents export this value directly to `HTTP_PROXY`, an empty string typically results in no proxy being used, falling back to direct connections unless system-wide environment variables are set.

### Where are the proxy configuration tests located?

The test suite asserting proxy flag acceptance and storage logic resides in [`tests/test_cli.py`](https://github.com/Panniantong/Agent-Reach/blob/main/tests/test_cli.py), specifically around lines 158 and 174. These tests verify that the `install` command parser recognizes the `--proxy` argument and that the `configure` sub-command correctly invokes the configuration setter.