mirror of
https://github.com/langgenius/dify-plugin-daemon.git
synced 2026-07-21 17:25:23 -04:00
[local] uv in virtual environment ignores UV_NATIVE_TLS, causing SSL certificate issues behind corporate proxy #50
Closed
opened 2026-02-16 00:19:24 -05:00 by yindo
·
1 comment
No Branch/Tag Specified
main
build/fix-serverless-runtime-error-propagation
gh-pages
build/test-document2
build/test-document
build/onboarding-ui
build/slim-extract
codex/depot-builds
codex/mac-runner-benchmark
feat/storage-path-prefix
feat/multi-db-user
feat/slim-action
deploy/dev
feat/dify-cli
feat/add-e2e
build/pg-bouncer
codex/add-multimodal-rerank-and-embedding-apis
refactor/local-runtime
build/multimodal-embeddings
codex/refactor-routine.submit-label-handling
codex/refactor-service-layer-based-on-provided-plan
feat/trigger-response
feat/trigger
build/trigger
deploy/trigger-dev
codex/remove-claude-code-reviewer-from-github-ci
codex/add-manifest-check-to-upload-endpoint
feat/no-root-dockerfile
fix/json-schema
fix/blocking-anthorized-langgenius
454-bump-cli-template
build/datasource
feat/datasource
bump-cloud-kit
feat/rag-tag
fix/change-session-not-found-to-400
feat/plugin-readme
add-claude-github-actions-1756274550417
docs/comprehensive-development-documentation
chore/remove-json-schema-validation-error
71cef04
fix/missing-parameter-type
fix/sessions-log
fix/template.env
bump/go-git
build/oauth
feat/oauth-refresh-token
feat/plugin-oauth
feat/tool-oauth-cli
build/plugin-oauth
feat/readme-i18n
fix/memory-leak
feat/icon-dark
feat/default-icon
plugin_launch_concurent
feat/collect-active-requests
feat/dark-icon
feat/support-structured-llm-output
feat/dynamic-selector
fix/reduce-logs
feat/decode-plugin-package
feat/db-extras
fix/backwards-invocation-overflow
feat/length-prefixed-chunking
fix/http-request-reader-header
chore/unify-configurations
fix/hardcoded-serverless-runtime-timeout
fix/cmd
fix/signature
refactor/implement-gen-routes
fix/redis-lock
refactor/codegen
feat/add-authorized-category
chore/style
feat/run-plugin-cli
reduce/run-once
feat/reinstall-serverless-runtime
feat/support-setup-process
fix/apply-stdio-buffer-size
chore/add-warning-messages-to-installed-bucket
feat/repo
enhance/stdio
feat/make-buffer-size-configurable
fix/moderation-init
fix/only-validate-profile-on-quick-mode
feat/support-quick-init-plugins
refactor/oauth-parameters
feat/oauth
refactor/simplify-plugin-invocation
test/integration-test-for-plugins
fix/backwards-compatible-to-llm-result-chunk
feat/auto-scale
enhance/reduce-ci-tests
fix/cli-ci
enhance/removes-llm-result-prompt-messages
fix/disable-benchmark-logs
benchmark/local-runtime
chore/remove-useless-benchmark
feat/benchmark
feat/fetch-app-info
fix/windows-remap-assets
fix/skip-hidden-file
feat/stream-tool-blob-message
fix/path-travel
feat/template-add-ci
enhance/version-compare
feat/sign-apple-os-cli
feat/support-minimal-dify-version-required
refactor/stdip
feat/add-serverless-connector-launching-timeout
fix/remove-prompt_messages-from-llm-result-chunk
feat/standardize-plugin-sdk-versions
chore/update-docs-and-refine-wording
update/readme-cli
fix/infinity-environment-setup
fix/cbor-unmarshaling
fix/use-aws-iam-baseendpoint
fix/lost-query-params-in-endpoint
fix/tiktoken
cohre/update-readme
fix/redis-tests
fix/friendly-identity
fix/marshal-any-map
chore/upgrade-ants
fix/graceful-precompile
enhance/tiktoken
feat/graceful-shutdown
fix/close-serverless-response
fix/correct-cli-guide
fix/plugin-active-log
fix/remove-proxy-args-from-uv
fix/endpoint-hook-url
fix/ci-credentials
feat/disable-gevent
fix/add-gcc
fix/hardcoded-endpoint-timeout
fix/bump-cli-sdk-version
fix/deadloop-when-redis-disconnect
fix/enhence/speed-up-environment-setup
enhance/introduce-uv
fix/change-default-db
fix/deadlock
readme
chore/env.example
feat/add-action-in-url
fix/add-more-pip-args
fix/optimize-local-heartbeat
optimize/db-init
fix/optimize-internal-server-error
fix/increase-default-plugin-max-execution-timeout
fix/force-patch-older-version
enhance/increase-installing-process
LICENSE
fix/set-user-id-to-unrequired
fix/max-launching-concurrent
improve/error-handing-in-serverless
refactor/json-unmarshaler-enhancement
fix/add-pip-mirror-url
enhance/serverless-connector
0.6.5
0.6.4
0.6.3
0.6.2
0.6.1
0.6.0
0.5.9
0.5.8
0.5.7
0.5.6
0.5.5
0.5.4
0.5.3
0.5.2
0.5.1
0.5.0
0.4.1
0.4.0
0.3.3
0.3.2
0.3.1
0.3.0
0.3.0b1
0.2.0
0.1.3
0.1.2
0.1.1
0.1.0
0.0.10
0.0.9
0.0.8
0.0.7
0.0.6
0.0.5
0.0.4
0.0.3
0.0.2
0.0.1
0.0.1-beta.23
0.0.1-beta.22
0.0.1-beta.21
0.0.1-beta.20
0.0.1-beta.19
0.0.1-beta.18
0.0.1-beta.17
0.0.1-beta.16
0.0.1-beta.15
0.0.1-beta.14
0.0.1-beta.13
0.0.1-beta.12
0.0.1-beta.11
0.0.1-beta.10
0.0.1-beta.9
0.0.1-beta.8
0.0.1-beta.7
0.0.1-beta.6
0.0.1-beta.5
0.0.1-beta.4
0.0.1-beta.3
0.0.1-beta.2
0.0.1-beta.1
No Label
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: langgenius/dify-plugin-daemon#50
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @zolgear on GitHub (Mar 19, 2025).
We are self-hosting inside a corporate proxy where SSL inspection rewrites certificates.
To accommodate this, we mounted our custom root certificate and configured
SSL_CERT_FILEaccordingly.Here’s an excerpt from our
docker-compose.override.yaml:We have added our corporate root certificate to
ex_ca.pem, ensuring that system-wide and Python SSL inspection configurations are correctly handled.However, the following error occurs when running this code in
internal/core/plugin_manager/local_runtime/environment_python.go:Error in
InitPythonEnvironment()The error occurs when installing plugin dependencies using
uv.According to the
uvdocumentation, we addedUV_NATIVE_TLS: trueandUV_INSECURE_HOST: "*".Running
uvinside the Docker container shell works fine.However, when
uvis executed within the virtual environment created by the following code, it does not respect the environment variables and instead uses the virtual environment's certificate settings:[Relevant code in dify-plugin-daemon](https://github.com/langgenius/dify-plugin-daemon/blob/84edb2682d569dca2011564d4d1c13f0a42fdc9f/internal/core/plugin_manager/local_runtime/environment_python.go#L121-L126)
As a workaround, adding
--native-tlsto the arguments allows successful installation:Question:
Are environment variables restricted when executing commands in Go for security reasons?
If so, would it be possible to add support for
UV_NATIVE_TLSto address this issue?@zolgear commented on GitHub (Mar 19, 2025):
I found
PIP_EXTRA_ARGS.By adding
PIP_EXTRA_ARGS="--native-tls"to the environment variables, the issue was resolved.