{"record":{"id":"bec2ebf8a6ed439d","repo":"grpc/grpc-go","slug":"delegating-resolver-failed-to-determine-proxy-url","errorCode":null,"errorMessage":"delegating_resolver: failed to determine proxy URL for target %q: %v","messagePattern":"delegating_resolver: failed to determine proxy URL for target %q: (.+?)","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/resolver/delegatingresolver/delegatingresolver.go","lineNumber":125,"sourceCode":"\tr := &delegatingResolver{\n\t\ttarget:         target,\n\t\tcc:             cc,\n\t\tproxyResolver:  nopResolver{},\n\t\ttargetResolver: nopResolver{},\n\t}\n\n\taddr := target.Endpoint()\n\tvar err error\n\tif target.URL.Scheme == \"dns\" && !targetResolutionEnabled && envconfig.EnableDefaultPortForProxyTarget {\n\t\taddr, err = parseTarget(addr)\n\t\tif err != nil {\n\t\t\treturn nil, fmt.Errorf(\"delegating_resolver: invalid target address %q: %v\", target.Endpoint(), err)\n\t\t}\n\t}\n\n\tr.proxyURL, err = proxyURLForTarget(addr)\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"delegating_resolver: failed to determine proxy URL for target %q: %v\", target, err)\n\t}\n\n\t// proxy is not configured or proxy address excluded using `NO_PROXY` env\n\t// var, so only target resolver is used.\n\tif r.proxyURL == nil {\n\t\treturn targetResolverBuilder.Build(target, cc, opts)\n\t}\n\n\tif logger.V(2) {\n\t\tlogger.Infof(\"Proxy URL detected : %s\", r.proxyURL)\n\t}\n\n\t// Resolver updates from one child may trigger calls into the other. Block\n\t// updates until the children are initialized.\n\tr.childMu.Lock()\n\tdefer r.childMu.Unlock()\n\t// When the scheme is 'dns' and target resolution on client is not enabled,\n\t// resolution should be handled by the proxy, not the client. Therefore, we","sourceCodeStart":107,"sourceCodeEnd":143,"githubUrl":"https://github.com/grpc/grpc-go/blob/0c51461d27177d997e14c642fe18c11668fc09a3/internal/resolver/delegatingresolver/delegatingresolver.go#L107-L143","documentation":"Before building child resolvers, the delegating resolver determines whether a proxy applies by calling proxyURLForTarget(addr) which internally invokes http.ProxyFromEnvironment (delegatingresolver.go:86-92, 123-126). If that function returns a non-nil error (malformed HTTPS_PROXY/HTTP_PROXY URL), New() aborts with this wrapped error. A nil proxy URL with nil error simply means 'no proxy'.","triggerScenarios":"Triggered when the HTTPS_PROXY (or HTTP_PROXY) environment variable is set to a value that cannot be parsed as a URL by net/url (e.g. missing scheme, embedded illegal characters), or http.ProxyFromEnvironment otherwise errors for the target address.","commonSituations":"Misconfigured proxy env vars in a container/systemd unit, a value like 'proxy.corp:3128' missing the 'http://' scheme, a typo or trailing space in HTTPS_PROXY, or a CI runner injecting a broken proxy URL.","solutions":["Inspect the wrapped %v which usually comes from url.Parse and names the malformed component.","Fix the HTTPS_PROXY/HTTP_PROXY value to be a fully-qualified URL, e.g. 'http://proxy.corp:3128'.","If no proxy is intended, unset HTTPS_PROXY/HTTP_PROXY or add the target host to NO_PROXY.","Restart the process after correcting env vars."],"exampleFix":"# before\nexport HTTPS_PROXY='proxy.corp:3128'   # missing scheme\n\n# after\nexport HTTPS_PROXY='http://proxy.corp:3128'","handlingStrategy":"validation","validationCode":"package main\n\nimport (\n\t\"fmt\"\n\t\"net/http\"\n\t\"net/url\"\n\t\"os\"\n)\n\nfunc validateProxyEnv() error {\n\tfor _, kv := range os.Environ() {\n\t\t// Inspect keys only, never print secret values.\n\t\tname := kv\n\t\tif i := indexOf(kv, '='); i >= 0 {\n\t\t\tname = kv[:i]\n\t\t}\n\t\tif name != \"HTTPS_PROXY\" && name != \"HTTP_PROXY\" {\n\t\t\tcontinue\n\t\t}\n\t}\n\treq := &http.Request{URL: &url.URL{Scheme: \"https\", Host: \"example.com\"}}\n\tif _, err := http.ProxyFromEnvironment(req); err != nil {\n\t\treturn fmt.Errorf(\"proxy env invalid: %w\", err)\n\t}\n\treturn nil\n}\n\nfunc indexOf(s, sub string) int {\n\tfor i := 0; i+len(sub) <= len(s); i++ {\n\t\tif s[i:i+len(sub)] == sub {\n\t\t\treturn i\n\t\t}\n\t}\n\treturn -1\n}\n\n// func main() { _ = validateProxyEnv }","typeGuard":null,"tryCatchPattern":"// Dial fails synchronously with this wrapped error.\n//\n//   conn, err := grpc.Dial(target, opts)\n//   if err != nil && strings.Contains(err.Error(), \"failed to determine proxy URL\") {\n//       // fix HTTPS_PROXY, then retry Dial\n//   }","preventionTips":["Always include the scheme in HTTPS_PROXY/HTTP_PROXY (e.g. http://host:port).","Validate proxy env at process start with http.ProxyFromEnvironment against a sample URL.","Document required proxy env format in deployment manifests."],"tags":["resolver","delegating-resolver","proxy","environment","configuration","grpc"],"backgroundTag":null,"analyzedSha":"0c51461d27177d997e14c642fe18c11668fc09a3","analyzedAt":"2026-08-11T14:49:15.055Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}