Go

Your CI can't fetch a private module from github.com/acme/secret. Walk through GOPROXY, GOPRIVATE, GONOPROXY, GONOSUMDB and GOINSECURE.

Question 417HardGo 1.22 to 1.25

By default GOPROXY=https://proxy.golang.org,direct and GOSUMDB=sum.golang.org. The public proxy cannot see private repos, and the checksum database would reject, or at least leak the existence of, module paths it cannot verify.

  • GOPRIVATE: glob list of path prefixes that are private. It is the default for both of the next two variables.
  • GONOPROXY: these paths skip the proxy and are fetched directly from VCS.
  • GONOSUMDB: these paths are not checked against sum.golang.org (go.sum still protects them locally).
  • GOINSECURE: allows plain HTTP or unverified TLS. Avoid it.
  • GOSUMDB=off disables checksum verification for every module, which is a bad idea. Scope it with GONOSUMDB instead.
go env -w GOPRIVATE='github.com/acme/*,gitlab.corp.io'
# credentials for direct git fetch in CI:
git config --global url."https://${GH_TOKEN}@github.com/".insteadOf "https://github.com/"
# or ~/.netrc:  machine github.com login x-access-token password $GH_TOKEN

# corporate proxy that also serves private modules:
GOPROXY=https://goproxy.corp.io,https://proxy.golang.org,direct
GONOSUMDB=github.com/acme/*

# Go 1.24+: GOAUTH controls how credentials are obtained for module fetches
GOAUTH='netrc;git ~/src'   # default is netrc

Gotchas: the comma in GOPROXY falls through only on 404/410, while a pipe (|) falls through on any error. Docker build stages need the token too (use BuildKit secrets, never bake it into a layer). Interviewers want the relationship "GOPRIVATE sets both defaults" plus a secure way to pass credentials.

More on Modules, Packages & Tooling

All 36 Modules, Packages & Tooling questions