When you set a proxy through environment variables, every request from curl, Python, Go, Node and many other tools goes through it. NO_PROXY is the exception list:
export HTTPS_PROXY=http://USERNAME:PASSWORD@HOST:PORT
export HTTP_PROXY=$HTTPS_PROXY
export NO_PROXY=localhost,127.0.0.1,.internal.example.com
Hosts on the list are contacted directly. A leading dot, or a bare domain in most tools, matches its subdomains.
Why it matters
- Cost. Calls to your own database, queue or metadata service should not travel through a paid proxy, and on a per-GB plan they would be billed.
- Breakage. Internal hostnames do not resolve from the proxy's side of the internet, so requests to them fail.
- Leaks. Every entry sends traffic from your real IP. A pattern broader than you meant, such as a whole domain instead of one host, quietly takes scraping traffic off the proxy.
No standard, so test
There is no specification for NO_PROXY, and tools disagree. Whether uppercase or lowercase wins, whether * means "everything", whether a leading dot is required, and whether CIDR ranges like 10.0.0.0/8 work all vary by tool and version. GitLab's engineers surveyed the differences. Set both NO_PROXY and no_proxy, and check with the tool you run:
curl -s "https://api.ipify.org?format=json"
If the address printed is your server's own, that request bypassed the proxy.
Common confusion
NO_PROXY does not block anything; it routes around the proxy. Desktop operating systems have their own bypass list in the proxy settings, covered in the Windows guide, and browsers can use a PAC file for per-URL rules.