How to Configure Proxy Settings for actions/checkout
You can configure proxy settings for actions/checkout by setting standard environment variables such as HTTPS_PROXY, HTTP_PROXY, and NO_PROXY in your workflow or on the runner machine.
The actions/checkout action automatically respects standard proxy environment variables used by the underlying @actions/http-client library. When the action executes, it detects these variables in the compiled runtime code and routes HTTP requests through the specified proxy without requiring additional input parameters.
How Proxy Configuration Works in actions/checkout
The action does not expose dedicated proxy inputs in action.yml. Instead, it relies on the standard Node.js HTTP client proxy detection mechanism implemented in the compiled distribution file.
According to the source code in dist/index.js (lines 759–771), the action checks for proxy variables in the following priority order:
// Compiled proxy detection logic from dist/index.js
const proxyVar = (() => {
return process.env['https_proxy'] || process.env['HTTPS_PROXY'];
})() ?? (() => {
return process.env['http_proxy'] || process.env['HTTP_PROXY'];
})();
if (proxyVar) {
// Normalizes URL by adding scheme if missing
const proxyUrl = new DecodedURL(proxyVar.startsWith('http') ? proxyVar : `http://${proxyVar}`);
}
Once a proxy URL is identified, the action creates an undici.ProxyAgent (lines 634–648 in dist/index.js) and injects it into the HTTP request pipeline used for GitHub API calls.
Supported Proxy Environment Variables
The action recognizes the following environment variables, checking both lowercase and uppercase variants:
https_proxy/HTTPS_PROXY: Proxy URL for secure HTTPS traffichttp_proxy/HTTP_PROXY: Proxy URL for plain HTTP trafficno_proxy/NO_PROXY: Comma-separated list of hostnames to bypass the proxy
Implementation Details
Proxy Detection Logic
In dist/index.js (lines 759–771), the compiled TypeScript first checks for https_proxy or HTTPS_PROXY, falling back to http_proxy or HTTP_PROXY if not found. The logic prioritizes HTTPS-specific variables for secure connections.
ProxyAgent Creation
After resolving the proxy URL, the action instantiates an undici.ProxyAgent (lines 634–648 in dist/index.js). This agent handles all HTTP requests made by the action, including the GitHub API calls required to fetch repository metadata.
No-Proxy Handling
The exclusion logic for bypassing the proxy resides in dist/index.js (lines 788–808). When the target hostname matches an entry in the NO_PROXY list, the action routes the request directly, skipping the proxy agent.
Configuring Proxy Settings in Your Workflow
You can set proxy environment variables at three different scopes depending on your security and reuse requirements.
Job-Level Configuration
Define variables in the env block at the job level to apply proxy settings to all steps, including the checkout action:
jobs:
build:
runs-on: ubuntu-latest
env:
HTTPS_PROXY: http://proxy.mycompany.com:3128
NO_PROXY: github.mycompany.com
steps:
- name: Checkout repository
uses: actions/checkout@v7
Step-Level Configuration
Apply proxy settings only to the checkout step by using the env keyword on the specific step:
steps:
- name: Checkout with proxy
uses: actions/checkout@v7
env:
HTTP_PROXY: http://proxy.mycompany.com:3128
NO_PROXY: internal.example.com,10.0.0.0/8
Runner-Level Configuration
For self-hosted runners, export the variables in the runner's startup script or system environment. The action automatically inherits these values without workflow modifications:
export HTTPS_PROXY="http://proxy.mycompany.com:3128"
export NO_PROXY="github.mycompany.com"
./svc.sh install
./svc.sh start
Summary
- actions/checkout respects standard proxy environment variables (
HTTPS_PROXY,HTTP_PROXY,NO_PROXY) rather than exposing dedicated action inputs. - The proxy detection logic compiles into
dist/index.js(lines 759–771) and creates anundici.ProxyAgent(lines 634–648) for routing requests. - Configure proxies at the job level, step level, or runner level depending on your network architecture.
- Use
NO_PROXYto bypass the proxy for internal GitHub Enterprise Server instances or specific subnets.
Frequently Asked Questions
Does actions/checkout have a dedicated proxy input parameter?
No, the action does not define proxy inputs in action.yml. Instead, it relies entirely on standard environment variables detected by the underlying @actions/http-client library at runtime.
Which proxy environment variables does actions/checkout support?
The action supports https_proxy/HTTPS_PROXY for secure traffic, http_proxy/HTTP_PROXY for plain HTTP, and no_proxy/NO_PROXY for exclusion lists. It checks both lowercase and uppercase variants, prioritizing HTTPS variables when available.
How does actions/checkout handle the NO_PROXY variable?
The action evaluates NO_PROXY as a comma-separated list of hostnames, IP addresses, or CIDR ranges to bypass. This logic is implemented in dist/index.js (lines 788–808), where matching targets route directly instead of through the undici.ProxyAgent.
Can I configure proxy settings for self-hosted runners?
Yes, self-hosted runners inherit proxy settings from the system environment. Export HTTPS_PROXY and NO_PROXY in the runner's startup script or shell profile before starting the runner service, and actions/checkout will automatically apply these settings to all HTTP requests.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →