Volume XXII, number 280Wednesday, October 7, 2026Latest message 35 minutes ago

The Git List

News and archive of git@vger.kernel.org, since April 2005

Untrusted Caching Proxy

1 messages between Mar 9, 2026 and Mar 9, 2026, from Skye Soss.

Plain Markdown or JSON for tools and agents.

Skye SossMar 9, 2026, 15:28 UTC on lore
Git can use http or ssh proxies to access remotes. This can be useful for companies that have their own private repository mirrors. But because this form of proxy rewrites the url, the client must completely trust the proxy.
I propose a configuration that would work differently: a client would still connect to the real remote for metadata, but before downloading data would attempt to query a read-only cache. Any downloaded data will be validated to prevent spoofing, and if the cache does not make the data available the client will fall-back to the remote.
The intended use case is for a simple per-site cache, similar to apt’s DNS-SD caching (but opt-in). This is to easily enable “good internet citizenship” by allowing networks to cache cloned repositories without needing the trust model of remote rewriting. While git was never designed to be used as a CDN it unfortunately is very common.
Is this a feasible feature for git? Or are there aspects of the git internals that make this complicated.

Back to recent threads

Untrusted Caching Proxy | The Git List