Dify cannot recall test in knowlege base, though I have already built a knowlge base using embedding model. #21065

Closed
opened 2026-02-21 20:10:31 -05:00 by yindo · 5 comments
Owner

Originally created by @Guofu1149 on GitHub (Dec 15, 2025).

Self Checks

  • I have read the Contributing Guide and Language Policy.
  • This is only for bug report, if you would like to ask a question, please head to Discussions.
  • I have searched for existing issues search for existing issues, including closed ones.
  • I confirm that I am using English to submit this report, otherwise it will be closed.
  • 【中文用户 & Non English User】请使用英语提交,否则会被关闭 :)
  • Please do not modify this template :) and fill in all the required fields.

Dify version

1.10.1.fix.1

Cloud or Self Hosted

Self Hosted (Docker)

Steps to reproduce

Query call with protocol GRPC search failed with message The request to Weaviate failed after 5 retries. Details: <_InactiveRpcError of RPC that terminated with: status = StatusCode.UNAVAILABLE details = "failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403" debug_error_string = "UNKNOWN:Error received from peer {grpc_message:"failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403", grpc_status:14}" >.

docker compose logs -t --tail=120 2>&1 | grep -i -E "error"
weaviate-1 | 2025-12-16T02:13:29.125737146Z {"action":"startup","build_git_commit":"6c571ff","build_go_version":"go1.22.8","build_image_tag":"","build_wv_version":"","level":"error","msg":"telemetry failed to start: push: failed to send request: Post "https://telemetry.weaviate.io/weaviate-telemetry": dial tcp 34.149.252.24:443: i/o timeout","time":"2025-12-16T02:13:29Z"}
nginx-1 | 2025-12-16T02:20:33.011949491Z 53.217.177.253 - - [16/Dec/2025:02:20:33 +0000] "GET /console/api/datasets/5fcecd41-2afe-4560-aa20-0d3131e606aa/error-docs HTTP/1.1" 200 22 "http://53.89.35.151/datasets/5fcecd41-2afe-4560-aa20-0d3131e606aa/documents" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36" "53.88.202.69"
plugin_daemon-1 | 2025-12-16T02:19:42.552241231Z 2025/12/16 02:19:42 setup_python_environment.go:357: [INFO]pre-compiling langgenius/minimax:0.0.9 - Compiling './.venv/lib/python3.12/site-packages/gevent/tests/test__socket_errors.py'......
api-1 | 2025-12-16T02:20:55.465842257Z 2025-12-16 02:20:55.465 INFO [ThreadPoolExecutor-1_0] [retry.py:55] - Searching in collection Vector_index_5fcecd41_2afe_4560_aa20_0d3131e606aa_Node received exception: <_InactiveRpcError of RPC that terminated with:
api-1 | 2025-12-16T02:20:55.465872056Z details = "failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403"
api-1 | 2025-12-16T02:20:55.465875380Z debug_error_string = "UNKNOWN:Error received from peer {grpc_message:"failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403", grpc_status:14}"
api-1 | 2025-12-16T02:20:56.468544512Z 2025-12-16 02:20:56.467 INFO [ThreadPoolExecutor-1_0] [retry.py:55] - Searching in collection Vector_index_5fcecd41_2afe_4560_aa20_0d3131e606aa_Node received exception: <_InactiveRpcError of RPC that terminated with:
api-1 | 2025-12-16T02:20:56.468580818Z details = "failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403"
api-1 | 2025-12-16T02:20:56.468584069Z debug_error_string = "UNKNOWN:Error received from peer {grpc_message:"failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403", grpc_status:14}"
api-1 | 2025-12-16T02:20:58.471302418Z 2025-12-16 02:20:58.470 INFO [ThreadPoolExecutor-1_0] [retry.py:55] - Searching in collection Vector_index_5fcecd41_2afe_4560_aa20_0d3131e606aa_Node received exception: <_InactiveRpcError of RPC that terminated with:
api-1 | 2025-12-16T02:20:58.471369717Z details = "failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403"
api-1 | 2025-12-16T02:20:58.471379436Z debug_error_string = "UNKNOWN:Error received from peer {grpc_message:"failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403", grpc_status:14}"
api-1 | 2025-12-16T02:21:02.473406659Z 2025-12-16 02:21:02.472 INFO [ThreadPoolExecutor-1_0] [retry.py:55] - Searching in collection Vector_index_5fcecd41_2afe_4560_aa20_0d3131e606aa_Node received exception: <_InactiveRpcError of RPC that terminated with:
api-1 | 2025-12-16T02:21:02.473439749Z details = "failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403"
api-1 | 2025-12-16T02:21:02.473442909Z debug_error_string = "UNKNOWN:Error received from peer {grpc_message:"failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403", grpc_status:14}"
api-1 | 2025-12-16T02:21:10.475613022Z 2025-12-16 02:21:10.475 INFO [ThreadPoolExecutor-1_0] [retry.py:55] - Searching in collection Vector_index_5fcecd41_2afe_4560_aa20_0d3131e606aa_Node received exception: <_InactiveRpcError of RPC that terminated with:
api-1 | 2025-12-16T02:21:10.475657873Z details = "failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403"
api-1 | 2025-12-16T02:21:10.475661324Z debug_error_string = "UNKNOWN:Error received from peer {grpc_message:"failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403", grpc_status:14}"
api-1 | 2025-12-16T02:21:26.477759598Z 2025-12-16 02:21:26.477 INFO [ThreadPoolExecutor-1_0] [retry.py:55] - Searching in collection Vector_index_5fcecd41_2afe_4560_aa20_0d3131e606aa_Node received exception: <_InactiveRpcError of RPC that terminated with:
api-1 | 2025-12-16T02:21:26.477797431Z details = "failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403"
api-1 | 2025-12-16T02:21:26.477800601Z debug_error_string = "UNKNOWN:Error received from peer {grpc_message:"failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403", grpc_status:14}"

✔️ Expected Behavior

successful

Actual Behavior

error

Originally created by @Guofu1149 on GitHub (Dec 15, 2025). ### Self Checks - [x] I have read the [Contributing Guide](https://github.com/langgenius/dify/blob/main/CONTRIBUTING.md) and [Language Policy](https://github.com/langgenius/dify/issues/1542). - [x] This is only for bug report, if you would like to ask a question, please head to [Discussions](https://github.com/langgenius/dify/discussions/categories/general). - [x] I have searched for existing issues [search for existing issues](https://github.com/langgenius/dify/issues), including closed ones. - [x] I confirm that I am using English to submit this report, otherwise it will be closed. - [x] 【中文用户 & Non English User】请使用英语提交,否则会被关闭 :) - [x] Please do not modify this template :) and fill in all the required fields. ### Dify version 1.10.1.fix.1 ### Cloud or Self Hosted Self Hosted (Docker) ### Steps to reproduce Query call with protocol GRPC search failed with message The request to Weaviate failed after 5 retries. Details: <_InactiveRpcError of RPC that terminated with: status = StatusCode.UNAVAILABLE details = "failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403" debug_error_string = "UNKNOWN:Error received from peer {grpc_message:"failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403", grpc_status:14}" >. docker compose logs -t --tail=120 2>&1 | grep -i -E "error" weaviate-1 | 2025-12-16T02:13:29.125737146Z {"action":"startup","build_git_commit":"6c571ff","build_go_version":"go1.22.8","build_image_tag":"","build_wv_version":"","level":"error","msg":"telemetry failed to start: push: failed to send request: Post \"https://telemetry.weaviate.io/weaviate-telemetry\": dial tcp 34.149.252.24:443: i/o timeout","time":"2025-12-16T02:13:29Z"} nginx-1 | 2025-12-16T02:20:33.011949491Z 53.217.177.253 - - [16/Dec/2025:02:20:33 +0000] "GET /console/api/datasets/5fcecd41-2afe-4560-aa20-0d3131e606aa/error-docs HTTP/1.1" 200 22 "http://53.89.35.151/datasets/5fcecd41-2afe-4560-aa20-0d3131e606aa/documents" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36" "53.88.202.69" plugin_daemon-1 | 2025-12-16T02:19:42.552241231Z 2025/12/16 02:19:42 setup_python_environment.go:357: [INFO]pre-compiling langgenius/minimax:0.0.9 - Compiling './.venv/lib/python3.12/site-packages/gevent/tests/test__socket_errors.py'...... api-1 | 2025-12-16T02:20:55.465842257Z 2025-12-16 02:20:55.465 INFO [ThreadPoolExecutor-1_0] [retry.py:55] - Searching in collection Vector_index_5fcecd41_2afe_4560_aa20_0d3131e606aa_Node received exception: <_InactiveRpcError of RPC that terminated with: api-1 | 2025-12-16T02:20:55.465872056Z details = "failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403" api-1 | 2025-12-16T02:20:55.465875380Z debug_error_string = "UNKNOWN:Error received from peer {grpc_message:"failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403", grpc_status:14}" api-1 | 2025-12-16T02:20:56.468544512Z 2025-12-16 02:20:56.467 INFO [ThreadPoolExecutor-1_0] [retry.py:55] - Searching in collection Vector_index_5fcecd41_2afe_4560_aa20_0d3131e606aa_Node received exception: <_InactiveRpcError of RPC that terminated with: api-1 | 2025-12-16T02:20:56.468580818Z details = "failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403" api-1 | 2025-12-16T02:20:56.468584069Z debug_error_string = "UNKNOWN:Error received from peer {grpc_message:"failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403", grpc_status:14}" api-1 | 2025-12-16T02:20:58.471302418Z 2025-12-16 02:20:58.470 INFO [ThreadPoolExecutor-1_0] [retry.py:55] - Searching in collection Vector_index_5fcecd41_2afe_4560_aa20_0d3131e606aa_Node received exception: <_InactiveRpcError of RPC that terminated with: api-1 | 2025-12-16T02:20:58.471369717Z details = "failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403" api-1 | 2025-12-16T02:20:58.471379436Z debug_error_string = "UNKNOWN:Error received from peer {grpc_message:"failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403", grpc_status:14}" api-1 | 2025-12-16T02:21:02.473406659Z 2025-12-16 02:21:02.472 INFO [ThreadPoolExecutor-1_0] [retry.py:55] - Searching in collection Vector_index_5fcecd41_2afe_4560_aa20_0d3131e606aa_Node received exception: <_InactiveRpcError of RPC that terminated with: api-1 | 2025-12-16T02:21:02.473439749Z details = "failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403" api-1 | 2025-12-16T02:21:02.473442909Z debug_error_string = "UNKNOWN:Error received from peer {grpc_message:"failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403", grpc_status:14}" api-1 | 2025-12-16T02:21:10.475613022Z 2025-12-16 02:21:10.475 INFO [ThreadPoolExecutor-1_0] [retry.py:55] - Searching in collection Vector_index_5fcecd41_2afe_4560_aa20_0d3131e606aa_Node received exception: <_InactiveRpcError of RPC that terminated with: api-1 | 2025-12-16T02:21:10.475657873Z details = "failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403" api-1 | 2025-12-16T02:21:10.475661324Z debug_error_string = "UNKNOWN:Error received from peer {grpc_message:"failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403", grpc_status:14}" api-1 | 2025-12-16T02:21:26.477759598Z 2025-12-16 02:21:26.477 INFO [ThreadPoolExecutor-1_0] [retry.py:55] - Searching in collection Vector_index_5fcecd41_2afe_4560_aa20_0d3131e606aa_Node received exception: <_InactiveRpcError of RPC that terminated with: api-1 | 2025-12-16T02:21:26.477797431Z details = "failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403" api-1 | 2025-12-16T02:21:26.477800601Z debug_error_string = "UNKNOWN:Error received from peer {grpc_message:"failed to connect to all addresses; last error: UNKNOWN: ipv4:53.89.34.207:3128: HTTP proxy returned response code 403", grpc_status:14}" ### ✔️ Expected Behavior successful ### ❌ Actual Behavior error
yindo added the 👻 feat:rag label 2026-02-21 20:10:31 -05:00
yindo closed this issue 2026-02-21 20:10:31 -05:00
Author
Owner

@dosubot[bot] commented on GitHub (Dec 15, 2025):

Your gRPC connection to Weaviate is failing with an HTTP proxy 403 error, which means Dify can't reach the vector database to recall knowledge base entries. This is almost always caused by Docker networking or port mapping issues, or by a firewall/proxy blocking the gRPC port.

Here's how to fix it:

  1. Make sure your docker-compose.yaml for Weaviate exposes both ports:

    ports:
      - "8080:8080"
      - "50051:50051"
    

    The Weaviate image should be at least semitechnologies/weaviate:1.27.0 for Dify 1.10.1 compatibility.
    Reference

  2. In your .env file, set:

    VECTOR_STORE=weaviate
    WEAVIATE_ENDPOINT=http://weaviate:8080
    WEAVIATE_GRPC_ENDPOINT=grpc://weaviate:50051
    WEAVIATE_API_KEY=<your_api_key>
    

    (Replace <your_api_key> with your actual key, matching the Weaviate config.)

  3. Start the Weaviate container if it's not running:

    docker compose --profile weaviate up -d weaviate
    

    Reference

  4. Restart all containers to apply changes:

    docker compose down
    docker compose up -d
    
  5. Test connectivity:

    • From your host: curl http://localhost:8080/v1/meta
    • Check gRPC: netstat -tulpn | grep 50051 (should show Weaviate listening)
    • If you have grpcurl, try: grpcurl -plaintext localhost:50051 list
  6. If you use a firewall (e.g., CentOS 9), open the ports:

    sudo firewall-cmd --add-port=8080/tcp --permanent
    sudo firewall-cmd --add-port=50051/tcp --permanent
    sudo firewall-cmd --reload
    

    If SELinux is enforcing, try sudo setenforce 0 as a test.

  7. If you changed VECTOR_STORE after creating your dataset, recall tests may still try to use the old backend. In that case, delete and recreate the dataset after fixing the config.

If you still see 403 errors, check if your Docker or server environment is forcing traffic through an HTTP proxy that blocks gRPC. Dify does not add proxy logic for Weaviate; all proxying must be handled at the OS or Docker level.

For more details and troubleshooting, see the Weaviate migration guide and this issue.

To reply, just mention @dosu.


How did I do? Good | Irrelevant | Incorrect | Verbose | Hallucination | Report 🐛 | Other

Chat with Dosu Open in Cursor Join Discord Share on X

@dosubot[bot] commented on GitHub (Dec 15, 2025): <!-- Answer --> Your gRPC connection to Weaviate is failing with an HTTP proxy 403 error, which means Dify can't reach the vector database to recall knowledge base entries. This is almost always caused by Docker networking or port mapping issues, or by a firewall/proxy blocking the gRPC port. Here's how to fix it: 1. Make sure your `docker-compose.yaml` for Weaviate exposes both ports: ```yaml ports: - "8080:8080" - "50051:50051" ``` The Weaviate image should be at least `semitechnologies/weaviate:1.27.0` for Dify 1.10.1 compatibility. [Reference](https://github.com/langgenius/dify/issues/29386) 2. In your `.env` file, set: ``` VECTOR_STORE=weaviate WEAVIATE_ENDPOINT=http://weaviate:8080 WEAVIATE_GRPC_ENDPOINT=grpc://weaviate:50051 WEAVIATE_API_KEY=<your_api_key> ``` (Replace `<your_api_key>` with your actual key, matching the Weaviate config.) 3. Start the Weaviate container if it's not running: ``` docker compose --profile weaviate up -d weaviate ``` [Reference](https://github.com/langgenius/dify/issues/29406) 4. Restart all containers to apply changes: ``` docker compose down docker compose up -d ``` 5. Test connectivity: - From your host: `curl http://localhost:8080/v1/meta` - Check gRPC: `netstat -tulpn | grep 50051` (should show Weaviate listening) - If you have `grpcurl`, try: `grpcurl -plaintext localhost:50051 list` 6. If you use a firewall (e.g., CentOS 9), open the ports: ``` sudo firewall-cmd --add-port=8080/tcp --permanent sudo firewall-cmd --add-port=50051/tcp --permanent sudo firewall-cmd --reload ``` If SELinux is enforcing, try `sudo setenforce 0` as a test. 7. If you changed VECTOR_STORE after creating your dataset, recall tests may still try to use the old backend. In that case, delete and recreate the dataset after fixing the config. If you still see 403 errors, check if your Docker or server environment is forcing traffic through an HTTP proxy that blocks gRPC. Dify does not add proxy logic for Weaviate; all proxying must be handled at the OS or Docker level. For more details and troubleshooting, see the [Weaviate migration guide](https://github.com/langgenius/dify/blob/main/docs/weaviate/WEAVIATE_MIGRATION_GUIDE/README.md) and [this issue](https://github.com/langgenius/dify/issues/29386). <!-- Dosu Comment Footer --> *To reply, just mention [@dosu](https://go.dosu.dev/dosubot).* --- <sup>How did I do? [Good](https://app.dosu.dev/response-feedback/e0c5681d-79f1-47d7-a3b8-54a7f578abd3?feedback_type=great_response) | [Irrelevant](https://app.dosu.dev/response-feedback/e0c5681d-79f1-47d7-a3b8-54a7f578abd3?feedback_type=irrelevant_answer) | [Incorrect](https://app.dosu.dev/response-feedback/e0c5681d-79f1-47d7-a3b8-54a7f578abd3?feedback_type=incorrect_sources) | [Verbose](https://app.dosu.dev/response-feedback/e0c5681d-79f1-47d7-a3b8-54a7f578abd3?feedback_type=too_verbose) | [Hallucination](https://app.dosu.dev/response-feedback/e0c5681d-79f1-47d7-a3b8-54a7f578abd3?feedback_type=hallucination) | [Report 🐛](https://app.dosu.dev/response-feedback/e0c5681d-79f1-47d7-a3b8-54a7f578abd3?feedback_type=bug_report) | [Other](https://app.dosu.dev/response-feedback/e0c5681d-79f1-47d7-a3b8-54a7f578abd3?feedback_type=other)</sup> [![Chat with Dosu](https://dosu.dev/dosu-chat-badge.svg)](https://app.dosu.dev/6088a4f4-073a-43f3-b3d4-4f06fb0c05a0/ask?utm_source=github)&nbsp;[![Open in Cursor](https://dosu.dev/dosu-in-cursor.svg)](https://cursor.com/link/prompt?text=Your%20gRPC%20connection%20to%20Weaviate%20is%20failing%20with%20an%20HTTP%20proxy%20403%20error%2C%20which%20means%20Dify%20can%27t%20reach%20the%20vector%20database%20to%20recall%20knowledge%20base%20entries.%20This%20is%20almost%20always%20caused%20by%20Docker%20networking%20or%20port%20mapping%20issues%2C%20or%20by%20a%20firewall/proxy%20blocking%20the%20gRPC%20port.%0A%0AHere%27s%20how%20to%20fix%20it%3A%0A%0A1.%20Make%20sure%20your%20%60docker-compose.yaml%60%20for%20Weaviate%20exposes%20both%20ports%3A%0A%20%20%20%60%60%60yaml%0A%20%20%20ports%3A%0A%20%20%20%20%20-%20%228080%3A8080%22%0A%20%20%20%20%20-%20%2250051%3A50051%22%0A%20%20%20%60%60%60%0A%20%20%20The%20Weaviate%20image%20should%20be%20at%20least%20%60semitechnologies/weaviate%3A1.27.0%60%20for%20Dify%201.10.1%20compatibility.%20%20%0A%20%20%20%5BReference%5D%28https%3A//github.com/langgenius/dify/issues/29386%29%0A%0A2.%20In%20your%20%60.env%60%20file%2C%20set%3A%0A%20%20%20%60%60%60%0A%20%20%20VECTOR_STORE%3Dweaviate%0A%20%20%20WEAVIATE_ENDPOINT%3Dhttp%3A//weaviate%3A8080%0A%20%20%20WEAVIATE_GRPC_ENDPOINT%3Dgrpc%3A//weaviate%3A50051%0A%20%20%20WEAVIATE_API_KEY%3D%3Cyour_api_key%3E%0A%20%20%20%60%60%60%0A%20%20%20%28Replace%20%60%3Cyour_api_key%3E%60%20with%20your%20actual%20key%2C%20matching%20the%20Weaviate%20config.%29%0A%0A3.%20Start%20the%20Weaviate%20container%20if%20it%27s%20not%20running%3A%0A%20%20%20%60%60%60%0A%20%20%20docker%20compose%20--profile%20weaviate%20up%20-d%20weaviate%0A%20%20%20%60%60%60%0A%20%20%20%5BReference%5D%28https%3A//github.com/langgenius/dify/issues/29406%29%0A%0A4.%20Restart%20all%20containers%20to%20apply%20changes%3A%0A%20%20%20%60%60%60%0A%20%20%20docker%20compose%20down%0A%20%20%20docker%20compose%20up%20-d%0A%20%20%20%60%60%60%0A%0A5.%20Test%20connectivity%3A%0A%20%20%20-%20From%20your%20host%3A%20%60curl%20http%3A//localhost%3A8080/v1/meta%60%0A%20%20%20-%20Check%20gRPC%3A%20%60netstat%20-tulpn%20%7C%20grep%2050051%60%20%28should%20show%20Weaviate%20listening%29%0A%20%20%20-%20If%20you%20have%20%60grpcurl%60%2C%20try%3A%20%60grpcurl%20-plaintext%20localhost%3A50051%20list%60%0A%0A6.%20If%20you%20use%20a%20firewall%20%28e.g.%2C%20CentOS%209%29%2C%20open%20the%20ports%3A%0A%20%20%20%60%60%60%0A%20%20%20sudo%20firewall-cmd%20--add-port%3D8080/tcp%20--permanent%0A%20%20%20sudo%20firewall-cmd%20--add-port%3D50051/tcp%20--permanent%0A%20%20%20sudo%20firewall-cmd%20--reload%0A%20%20%20%60%60%60%0A%20%20%20If%20SELinux%20is%20enforcing%2C%20try%20%60sudo%20setenforce%200%60%20as%20a%20test.%0A%0A7.%20If%20you%20changed%20VECTOR_STORE%20after%20creating%20your%20dataset%2C%20recall%20tests%20may%20still%20try%20to%20use%20the%20old%20backend.%20In%20that%20case%2C%20delete%20and%20recreate%20the%20dataset%20after%20fixing%20the%20config.%0A%0AIf%20you%20still%20see%20403%20errors%2C%20check%20if%20your%20Docker%20or%20server%20environment%20is%20forcing%20traffic%20through%20an%20HTTP%20proxy%20that%20blocks%20gRPC.%20Dify%20does%20not%20add%20proxy%20logic%20for%20Weaviate%3B%20all%20proxying%20must%20be%20handled%20at%20the%20OS%20or%20Docker%20level.%0A%0AFor%20more%20details%20and%20troubleshooting%2C%20see%20the%20%5BWeaviate%20migration%20guide%5D%28https%3A//github.com/langgenius/dify/blob/main/docs/weaviate/WEAVIATE_MIGRATION_GUIDE/README.md%29%20and%20%5Bthis%20issue%5D%28https%3A//github.com/langgenius/dify/issues/29386%29.)&nbsp;[![Join Discord](https://img.shields.io/badge/join-5865F2?logo=discord&logoColor=white&label=)](https://go.dosu.dev/discord-bot)&nbsp;[![Share on X](https://img.shields.io/badge/X-share-black)](https://twitter.com/intent/tweet?text=%40dosu_ai%20helped%20me%20solve%20this%20issue!&url=https%3A//github.com/langgenius/dify/issues/29698)
Author
Owner

@Guofu1149 commented on GitHub (Dec 15, 2025):

how to add no_proxy in docker-compose.yaml?
my proxy server is http://s1333333355a.corpintra.net:3128

@Guofu1149 commented on GitHub (Dec 15, 2025): how to add no_proxy in docker-compose.yaml? my proxy server is http://s1333333355a.corpintra.net:3128
Author
Owner

@Guofu1149 commented on GitHub (Dec 15, 2025):

how to add no_proxy in docker-compose.yaml?
my proxy server is http://s1333333355a.corpintra.net:3128/

@dosu

@Guofu1149 commented on GitHub (Dec 15, 2025): how to add no_proxy in docker-compose.yaml? my proxy server is http://s1333333355a.corpintra.net:3128/ @dosu
Author
Owner

@Guofu1149 commented on GitHub (Dec 15, 2025):

how to add no_proxy in docker-compose.yaml?
my proxy server is http://s1333333355a.corpintra.net:3128
@dosu.

@Guofu1149 commented on GitHub (Dec 15, 2025): how to add no_proxy in docker-compose.yaml? my proxy server is http://s1333333355a.corpintra.net:3128 [@dosu](https://go.dosu.dev/dosubot).
Author
Owner

@dosubot[bot] commented on GitHub (Dec 15, 2025):

To bypass your corporate proxy for internal Docker service communication, set the NO_PROXY (and no_proxy) environment variable in both your .env file and in the environment: section of each relevant service in your docker-compose.yaml. This ensures requests between containers (like Dify and Weaviate) aren't routed through the proxy, preventing 403 errors.

Example .env:

HTTP_PROXY=http://s1333333355a.corpintra.net:3128/
HTTPS_PROXY=http://s1333333355a.corpintra.net:3128/
http_proxy=http://s1333333355a.corpintra.net:3128/
https_proxy=http://s1333333355a.corpintra.net:3128/
NO_PROXY=localhost,127.0.0.1,weaviate,api,db,redis,plugin_daemon,web,worker,sandbox,ssrf_proxy
no_proxy=localhost,127.0.0.1,weaviate,api,db,redis,plugin_daemon,web,worker,sandbox,ssrf_proxy

Adjust the service names to match your actual docker-compose.yaml.

Example docker-compose.yaml service section:

services:
  api:
    environment:
      HTTP_PROXY: ${HTTP_PROXY}
      HTTPS_PROXY: ${HTTPS_PROXY}
      http_proxy: ${http_proxy}
      https_proxy: ${https_proxy}
      NO_PROXY: ${NO_PROXY}
      no_proxy: ${no_proxy}
  weaviate:
    environment:
      HTTP_PROXY: ${HTTP_PROXY}
      HTTPS_PROXY: ${HTTPS_PROXY}
      http_proxy: ${http_proxy}
      https_proxy: ${https_proxy}
      NO_PROXY: ${NO_PROXY}
      no_proxy: ${no_proxy}

After updating these files, restart your containers with:

docker-compose down && docker-compose up -d

This setup is the standard way to configure proxy bypass for Docker Compose deployments in Dify. For more details and examples, see this issue and this discussion.

To reply, just mention @dosu.


How did I do? Good | Irrelevant | Incorrect | Verbose | Hallucination | Report 🐛 | Other

Chat with Dosu Open in Cursor Join Discord Share on X

@dosubot[bot] commented on GitHub (Dec 15, 2025): <!-- Answer --> To bypass your corporate proxy for internal Docker service communication, set the `NO_PROXY` (and `no_proxy`) environment variable in both your `.env` file and in the `environment:` section of each relevant service in your `docker-compose.yaml`. This ensures requests between containers (like Dify and Weaviate) aren't routed through the proxy, preventing 403 errors. **Example `.env`:** ```env HTTP_PROXY=http://s1333333355a.corpintra.net:3128/ HTTPS_PROXY=http://s1333333355a.corpintra.net:3128/ http_proxy=http://s1333333355a.corpintra.net:3128/ https_proxy=http://s1333333355a.corpintra.net:3128/ NO_PROXY=localhost,127.0.0.1,weaviate,api,db,redis,plugin_daemon,web,worker,sandbox,ssrf_proxy no_proxy=localhost,127.0.0.1,weaviate,api,db,redis,plugin_daemon,web,worker,sandbox,ssrf_proxy ``` Adjust the service names to match your actual docker-compose.yaml. **Example `docker-compose.yaml` service section:** ```yaml services: api: environment: HTTP_PROXY: ${HTTP_PROXY} HTTPS_PROXY: ${HTTPS_PROXY} http_proxy: ${http_proxy} https_proxy: ${https_proxy} NO_PROXY: ${NO_PROXY} no_proxy: ${no_proxy} weaviate: environment: HTTP_PROXY: ${HTTP_PROXY} HTTPS_PROXY: ${HTTPS_PROXY} http_proxy: ${http_proxy} https_proxy: ${https_proxy} NO_PROXY: ${NO_PROXY} no_proxy: ${no_proxy} ``` After updating these files, restart your containers with: ``` docker-compose down && docker-compose up -d ``` This setup is the standard way to configure proxy bypass for Docker Compose deployments in Dify. For more details and examples, see [this issue](https://github.com/langgenius/dify/issues/26177) and [this discussion](https://github.com/langgenius/dify/issues/21330). <!-- Dosu Comment Footer --> *To reply, just mention [@dosu](https://go.dosu.dev/dosubot).* --- <sup>How did I do? [Good](https://app.dosu.dev/response-feedback/c0096ce0-bf4f-4205-b741-335ac329ee18?feedback_type=great_response) | [Irrelevant](https://app.dosu.dev/response-feedback/c0096ce0-bf4f-4205-b741-335ac329ee18?feedback_type=irrelevant_answer) | [Incorrect](https://app.dosu.dev/response-feedback/c0096ce0-bf4f-4205-b741-335ac329ee18?feedback_type=incorrect_sources) | [Verbose](https://app.dosu.dev/response-feedback/c0096ce0-bf4f-4205-b741-335ac329ee18?feedback_type=too_verbose) | [Hallucination](https://app.dosu.dev/response-feedback/c0096ce0-bf4f-4205-b741-335ac329ee18?feedback_type=hallucination) | [Report 🐛](https://app.dosu.dev/response-feedback/c0096ce0-bf4f-4205-b741-335ac329ee18?feedback_type=bug_report) | [Other](https://app.dosu.dev/response-feedback/c0096ce0-bf4f-4205-b741-335ac329ee18?feedback_type=other)</sup> [![Chat with Dosu](https://dosu.dev/dosu-chat-badge.svg)](https://app.dosu.dev/6088a4f4-073a-43f3-b3d4-4f06fb0c05a0/ask?utm_source=github)&nbsp;[![Open in Cursor](https://dosu.dev/dosu-in-cursor.svg)](https://cursor.com/link/prompt?text=To%20bypass%20your%20corporate%20proxy%20for%20internal%20Docker%20service%20communication%2C%20set%20the%20%60NO_PROXY%60%20%28and%20%60no_proxy%60%29%20environment%20variable%20in%20both%20your%20%60.env%60%20file%20and%20in%20the%20%60environment%3A%60%20section%20of%20each%20relevant%20service%20in%20your%20%60docker-compose.yaml%60.%20This%20ensures%20requests%20between%20containers%20%28like%20Dify%20and%20Weaviate%29%20aren%27t%20routed%20through%20the%20proxy%2C%20preventing%20403%20errors.%0A%0A%2A%2AExample%20%60.env%60%3A%2A%2A%0A%60%60%60env%0AHTTP_PROXY%3Dhttp%3A//s1333333355a.corpintra.net%3A3128/%0AHTTPS_PROXY%3Dhttp%3A//s1333333355a.corpintra.net%3A3128/%0Ahttp_proxy%3Dhttp%3A//s1333333355a.corpintra.net%3A3128/%0Ahttps_proxy%3Dhttp%3A//s1333333355a.corpintra.net%3A3128/%0ANO_PROXY%3Dlocalhost%2C127.0.0.1%2Cweaviate%2Capi%2Cdb%2Credis%2Cplugin_daemon%2Cweb%2Cworker%2Csandbox%2Cssrf_proxy%0Ano_proxy%3Dlocalhost%2C127.0.0.1%2Cweaviate%2Capi%2Cdb%2Credis%2Cplugin_daemon%2Cweb%2Cworker%2Csandbox%2Cssrf_proxy%0A%60%60%60%0AAdjust%20the%20service%20names%20to%20match%20your%20actual%20docker-compose.yaml.%0A%0A%2A%2AExample%20%60docker-compose.yaml%60%20service%20section%3A%2A%2A%0A%60%60%60yaml%0Aservices%3A%0A%20%20api%3A%0A%20%20%20%20environment%3A%0A%20%20%20%20%20%20HTTP_PROXY%3A%20%24%7BHTTP_PROXY%7D%0A%20%20%20%20%20%20HTTPS_PROXY%3A%20%24%7BHTTPS_PROXY%7D%0A%20%20%20%20%20%20http_proxy%3A%20%24%7Bhttp_proxy%7D%0A%20%20%20%20%20%20https_proxy%3A%20%24%7Bhttps_proxy%7D%0A%20%20%20%20%20%20NO_PROXY%3A%20%24%7BNO_PROXY%7D%0A%20%20%20%20%20%20no_proxy%3A%20%24%7Bno_proxy%7D%0A%20%20weaviate%3A%0A%20%20%20%20environment%3A%0A%20%20%20%20%20%20HTTP_PROXY%3A%20%24%7BHTTP_PROXY%7D%0A%20%20%20%20%20%20HTTPS_PROXY%3A%20%24%7BHTTPS_PROXY%7D%0A%20%20%20%20%20%20http_proxy%3A%20%24%7Bhttp_proxy%7D%0A%20%20%20%20%20%20https_proxy%3A%20%24%7Bhttps_proxy%7D%0A%20%20%20%20%20%20NO_PROXY%3A%20%24%7BNO_PROXY%7D%0A%20%20%20%20%20%20no_proxy%3A%20%24%7Bno_proxy%7D%0A%60%60%60%0AAfter%20updating%20these%20files%2C%20restart%20your%20containers%20with%3A%0A%60%60%60%0Adocker-compose%20down%20%26%26%20docker-compose%20up%20-d%0A%60%60%60%0AThis%20setup%20is%20the%20standard%20way%20to%20configure%20proxy%20bypass%20for%20Docker%20Compose%20deployments%20in%20Dify.%20For%20more%20details%20and%20examples%2C%20see%20%5Bthis%20issue%5D%28https%3A//github.com/langgenius/dify/issues/26177%29%20and%20%5Bthis%20discussion%5D%28https%3A//github.com/langgenius/dify/issues/21330%29.)&nbsp;[![Join Discord](https://img.shields.io/badge/join-5865F2?logo=discord&logoColor=white&label=)](https://go.dosu.dev/discord-bot)&nbsp;[![Share on X](https://img.shields.io/badge/X-share-black)](https://twitter.com/intent/tweet?text=%40dosu_ai%20helped%20me%20solve%20this%20issue!&url=https%3A//github.com/langgenius/dify/issues/29698)
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#21065