October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk6 min

Build a Go Proxy for HTTP, CONNECT, and SOCKS5

Build an inbound Go proxy with separate HTTP, HTTPS CONNECT, and SOCKS5 handlers, shared policy and relay components, careful logging, and Prometheus metrics.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Build this as three protocol-specific entry points—a conventional HTTP forwarder, an HTTPS CONNECT tunnel, and a SOCKS5 TCP CONNECT handler—over shared dialing, destination policy, logging, metrics, and shutdown code. Go’s net/http proxy support is for clients making outbound requests; configuring a Transport to use a proxy does not create an inbound proxy server.

Decide what the proxy will support

Keep each protocol’s wire handling separate. HTTP forwarding sends an HTTP request through the proxy to an origin. HTTPS proxying normally begins with CONNECT, then relays a tunnel. SOCKS5 negotiates a method and then receives a command and destination. They can share policy and connection-relay components, but they are not interchangeable request paths.

As an Amazon Associate I earn from qualifying purchases.

Go’s net/http documentation describes outbound proxy support for HTTP, HTTPS, and SOCKS5 proxy schemes. That is client behavior, not a complete inbound HTTP-and-SOCKS5 server. Treat the handlers below as an implementation design, not a feature supplied by net/http or a tested library recipe.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set an explicit support boundary

  • HTTP: accept and forward ordinary HTTP proxy requests.
  • HTTPS: support CONNECT tunneling without terminating the client’s TLS session.
  • SOCKS5: a basic TCP proxy can implement CONNECT and reject unsupported commands. That is not full SOCKS5 command coverage.
  • Authentication: state which methods are accepted. SOCKS5 username/password authentication is separately specified by RFC 1929 and does not encrypt those credentials.
  • Address handling: decide whether IPv4, domain names, and IPv6 are supported, and whether names are resolved by the proxy or elsewhere.

How do I build an HTTP proxy in Go?

Parse, authorize, dial, and forward

For a conventional HTTP proxy request, validate the requested destination before opening a connection. Apply destination and port policy, dial with a context and explicit timeouts, forward the request and response, and close resources on every path. Preserve the request semantics expected by the origin; do not treat arbitrary client-supplied destinations as trusted input.

#1 Best Overall
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
  • Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM)
  • Includes 128GB Micro SD Card pre-loaded with 64-bit Raspberry Pi OS, USB MicroSD Card Reader
  • CanaKit Turbine Black Case for the Raspberry Pi 5
  • CanaKit Low Noise Bearing System Fan
  • Mega Heat Sink - Black Anodized

A maintainable layout keeps protocol handlers separate from common services. For example, HTTP and SOCKS5 handlers can both call a destination-policy function and a context-aware dialer, while the HTTP handler remains responsible for parsing and forwarding HTTP messages.

type Destination struct {
    Host string
    Port string
}

type Policy interface {
    Allow(ctx context.Context, protocol string, dst Destination) error
}

type Dialer interface {
    DialContext(ctx context.Context, network, address string) (net.Conn, error)
}

This is an architectural sketch, not a complete proxy. In particular, it leaves request parsing, response handling, authentication, and policy rules to the implementation. Reject malformed authorities and disallowed destinations before dialing; return errors without exposing credentials or other secrets.

Protect the proxy from becoming an open relay

Decide which clients may connect and which destinations and ports they may reach. Require appropriate access controls for untrusted networks; an unauthenticated proxy reachable by arbitrary clients can be abused. Apply connection and request timeouts, cap resource use, and make shutdown close listeners and active connections in a controlled way. These are operational design recommendations, not a complete policy prescribed by Go’s documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
CanaKit Raspberry Pi 4 4GB Starter PRO Kit - 4GB RAM
  • Includes Raspberry Pi 4 4GB Model B with 1.5GHz 64-bit quad-core CPU (4GB RAM)
  • Includes Pre-Loaded 32GB EVO+ Micro SD Card (Class 10), USB MicroSD Card Reader
  • CanaKit Premium High-Gloss Raspberry Pi 4 Case with Integrated Fan Mount, CanaKit Low Noise Bearing System Fan
  • CanaKit 3.5A USB-C Raspberry Pi 4 Power Supply (US Plug) with Noise Filter, Set of Heat Sinks, Display Cable - 6 foot (Supports up to 4K60p)
  • CanaKit USB-C PiSwitch (On/Off Power Switch for Raspberry Pi 4)

How do I support HTTPS CONNECT in a Go proxy?

Treat CONNECT as a tunnel

A client asks the proxy to connect to an authority such as example.com:443. Validate that authority and its port, apply destination policy, and establish the upstream connection. Only after the connection succeeds should the proxy report success to the client. Then relay bytes in both directions until either side closes or the request is cancelled.

After a successful tunnel is established, the client’s TLS session is with the destination, not the proxy. The proxy relays encrypted bytes and cannot inspect encrypted application content merely because it supports HTTPS proxying. Inspecting that content would require a separate TLS-interception design, which is outside this tunnel implementation.

Keep tunnel lifecycle handling explicit

  • Handle CONNECT separately from ordinary HTTP forwarding; it changes the connection from request/response handling to a bidirectional byte stream.
  • Use bounded dialing and a cancellation-aware lifecycle so a stalled upstream cannot hold resources indefinitely.
  • Close both sides when relay ends, and account for errors from either direction.
  • Test failed upstream dials, disallowed destinations, client disconnects, and shutdown while tunnels are active.

Go’s transport documentation describes the client-side use of CONNECT for HTTPS targets. It does not provide an inbound tunnel server implementation.

Rank #3
ELECROW CrowPi Case Kit for Raspberry Pi 5, 9-Inch Display
  • Not including the Raspberry Pi 5 (8GB), the Crowpi advanced version comes with the Raspberry Pi 5
  • ELECROW Black Case for the Raspberry Pi 5, CrowPi is equipped with a 9-inch HD touchscreen along with a camera; All the regular components used in DIY electronics are packed into the CrowPi development board, such as LCD, LED matrix, buzzer, light sensor, PIR sensor, ultrasonic sensor, IR sensor, etc
  • Raspberry Pi Sensors: The Crowpi raspberry pi 5 programming kit is jam-packed with lots of buttons such as 19 different sensors in a tidy easy to use package; You don't have to wait and wire things
  • Build Quality: Solid ABS shell and well made components in one place make it strong and convenient to travel
  • Programming Lessons: This raspberry pi 5 learning kit ships with step by step instructions and provides 21 lessons to take you through identifying components reading code and running it in the terminal

How do I add SOCKS5 support to a Go proxy?

Implement negotiation before relaying

RFC 1928 defines SOCKS Version 5 method negotiation, a request containing a command and destination, and a reply with a status and bound-address information. Its address forms include IPv4, a domain name, and IPv6; its commands include CONNECT, BIND, and UDP ASSOCIATE.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Read and validate the client’s SOCKS version and offered authentication methods.
  2. Select a method the server actually supports, or reject the negotiation if none is acceptable.
  3. Read the request, including its command and address type; reject malformed or unsupported values with protocol-appropriate replies.
  4. For supported TCP CONNECT, apply destination policy and dial the destination.
  5. Send the appropriate success or failure reply, then relay the TCP stream only after a successful connection.

If the implementation supports only TCP CONNECT, reject BIND and UDP ASSOCIATE; do not claim complete SOCKS5 command coverage. Be equally explicit about supported address types and where domain-name resolution occurs. RFC 1928 is the protocol authority; RFC 1929 separately describes username/password authentication.

How should HTTP and SOCKS5 share code?

Share the parts that have the same job, not the protocol parsing. A useful boundary is to have each handler produce a validated destination and protocol identity, then call shared policy, dialing, connection accounting, and lifecycle code. HTTP forwarding still needs HTTP message handling; CONNECT and SOCKS5 each need their own negotiation or tunnel setup.

Rank #4
CanaKit Raspberry Pi 5 Desktop PC with SSD (Fully Assembled) (256 GB SSD)
  • Fully assembled for plug-and-play operation
  • Includes Raspberry Pi 5 with 8GB RAM
  • 256 GB PCIe Pi NVMe SSD (Pre-loaded with Pi 64-Bit OS)
  • M.2 HAT+
  • CanaKit Turbine Black Case for the Pi 5
  • Protocol handlers: parse and validate the HTTP request, CONNECT authority, or SOCKS5 negotiation and command.
  • Destination policy: apply client authorization and permitted-host and port rules consistently.
  • Dialing: use context-aware connection attempts with explicit timeouts.
  • Relay and cleanup: centralize bidirectional copying and ensure both connections are closed on completion, cancellation, or error.
  • Observability: emit protocol-neutral lifecycle events with protocol-specific outcomes.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How do I add logging and Prometheus metrics?

Log lifecycle events without secrets

Use structured events for connection or request start and finish, protocol, outcome, duration, and a safely normalized destination when policy allows. Do not log authorization headers, SOCKS credentials, or payload data. If destinations can contain sensitive information, redact or omit them and document that behavior. The sources do not prescribe a required Go logging package.

Instrument bounded metrics

The Prometheus Go guide documents an official Go client library, custom application metrics, a /metrics endpoint using promhttp, and scrape configuration. It states: “Prometheus has an official Go client library that you can use to instrument Go applications.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Useful starting metrics include accepted connections, failed connections, and duration observations. Keep labels bounded—for example, protocol and a small set of result classes. Do not use arbitrary hostnames, client IPs, or other high-cardinality values as labels.

Best Value
RasTech Raspberry Pi 5 8GB Kit with Active Cooler and Pi5 Case
  • 【What you Get】You will get 1*Pi 5 8GB Single Board,1*RasTech Case,1*Active Cooler,1*Screwdriver,1*Installation instructions,12-month free warranty, lifetime service, 24-hour prompt and friendly response.
  • 【More Connectors】There are two USB 3.0 ports(5Gbps simultaneously) and two USB 2.0 ports, which triple total bandwidth ,support any combination of up to two cameras or displays. Peak SD card performance is doubled through support for the SDR104 high-speed mode. It provides a smooth desktop experience for you. Offer Gigabit Ethernet and a PCIe interface, along with dual-band Wi-Fi and Bluetooth 5.0/BLE wireless capability. The RasTech Pi 5 Kit use the new 27W 5.1V 5A USB-C power connector.
  • 【 Support Dual 4Kp60 Display 】Each of the two microHDMI sockets can control a 4K display at 60 Hertz, now support HDR, offering super HD video for media streaming projects. RPi 5 is the first RPi model that comes with a PCI Express port (PCIe 2.0 x1 with 500 MB/s) to attach SSDs (requires separate M.2 HAT).
  • 【 Excellent Chips And Applications】Pi 5 is a full-size Pi computer using silicon built in-house at Pi. The RP1 “southbridge” provides the bulk of the I/O capabilities for Pi 5. Pi 5 is more friendly and convenient in the development of Internet of Things, Web development, machine identification, automatic control and other electronic equipment applications and network.
  • 【 Faster CPU, Better GPU 】 Pi 5 features a Broadcom BCM2712 64-bit quad-core Arm Cortex-A76 processor running at 2.4GHz, it delivers a 2–3× increase in CPU performance relative to RaspberryPi 4. The 800MHz VideoCore VII GPU is compatible to OpenGL ES 3.1 and Vulkan 1.2, substantial uplift in graphics performance. Pi 5 Offers lightning-fast CPU speed, a PCI Express interface, a Real Time Clock (RTC) and a power button and runs significantly cooler than Pi 4.
requests := prometheus.NewCounterVec(
    prometheus.CounterOpts{
        Name: "proxy_connections_total",
        Help: "Proxy connections by protocol and result class.",
    },
    []string{"protocol", "result"},
)

// Register the collector with the Prometheus registry used by the server.
// Serve the registered metrics handler on the metrics listener.

Keep the metrics listener’s access policy deliberate: exposing operational metrics to every proxy client may reveal information about service activity. Configure Prometheus to scrape the metrics endpoint using the target address and job configuration appropriate to your deployment.

How do I run a Go proxy in Docker?

A safe container recipe depends on the chosen build, runtime, user, capabilities, health check, and exposed ports. The available source material does not establish current Docker guidance for those choices, so a prescriptive Dockerfile or production command would be unjustified here.

Before deploying a container, verify those choices against current official Docker documentation. Configure and document separately which listener accepts proxy traffic and which serves metrics; do not assume the two should be reachable by the same clients. Also carry the proxy’s destination policy, authentication, timeouts, and graceful-shutdown behavior into the runtime configuration. A container does not make an exposed or unauthenticated proxy safe by itself.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Bestseller No. 1
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
CanaKit Raspberry Pi 5 Starter Kit PRO - Turbine Black (128GB Edition) (8GB RAM)
Includes Raspberry Pi 5 with 2.4Ghz 64-bit quad-core CPU (8GB RAM); CanaKit Turbine Black Case for the Raspberry Pi 5
$259.95
Bestseller No. 2
CanaKit Raspberry Pi 4 4GB Starter PRO Kit - 4GB RAM
CanaKit Raspberry Pi 4 4GB Starter PRO Kit - 4GB RAM
Includes Raspberry Pi 4 4GB Model B with 1.5GHz 64-bit quad-core CPU (4GB RAM); Includes Pre-Loaded 32GB EVO+ Micro SD Card (Class 10), USB MicroSD Card Reader
$159.99
Bestseller No. 4
CanaKit Raspberry Pi 5 Desktop PC with SSD (Fully Assembled) (256 GB SSD)
CanaKit Raspberry Pi 5 Desktop PC with SSD (Fully Assembled) (256 GB SSD)
Fully assembled for plug-and-play operation; Includes Raspberry Pi 5 with 8GB RAM; 256 GB PCIe Pi NVMe SSD (Pre-loaded with Pi 64-Bit OS)
$339.97

What to test before exposing the proxy

  • HTTP requests to allowed destinations succeed, while malformed requests and prohibited destinations are rejected.
  • CONNECT establishes a tunnel only after a successful upstream dial, and the proxy does not claim to inspect end-to-end TLS traffic.
  • SOCKS5 negotiation rejects unsupported authentication methods, commands, and address types correctly.
  • Client disconnects, upstream failures, timeouts, and shutdown close connections and produce useful outcome logs.
  • Metrics distinguish protocols and result classes without labels that grow with arbitrary hosts or client addresses.
  • Container listeners and access controls match the intended network exposure after Docker settings have been checked against current official documentation.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.