Construct for Docker
- Last UpdatedAug 19, 2026
- 1 minute read
Set proxy variables on the container and use NO_PROXY to list hosts that must bypass
the proxy (local databases, brokers, internal APIs, etc.).
You can trust a corporate proxy CA using either of the following methods:
-
Mount a trusted CA bundle from the host into the container, or
-
Bake the CA into a custom image
Code example
Download the file here.
Notes
Add your proxy CA to Ubuntu (host)
place proxy-root.crt in /usr/local/share/ca-certificates/ and run sudo update-ca-certificates. This updates /etc/ssl/certs/ca-certificates.crt, which the container mounts.
Local services in Compose
Add each service name you connect to (for example, db, mosquitto, influxdb) to NO_PROXY.
Docker host from Linux containers
if you call services on the Docker host, include host.docker.internal (on Linux you may need to add extra_hosts: - "host.docker.internal:host-gateway" and Docker 20.10+).
