Your CI can't fetch a private module from github.com/acme/secret. Walk through GOPROXY, GOPRIVATE, GONOPROXY, GONOSUMDB and GOINSECURE.
Question 417HardGo 1.22 to 1.25
By default GOPROXY=https://proxy.golang.org,direct and GOSUMDB=sum.golang.org. The public proxy cannot see private repos, and the checksum database would reject, or at least leak the existence of, module paths it cannot verify.
- GOPRIVATE: glob list of path prefixes that are private. It is the default for both of the next two variables.
- GONOPROXY: these paths skip the proxy and are fetched directly from VCS.
- GONOSUMDB: these paths are not checked against sum.golang.org (go.sum still protects them locally).
- GOINSECURE: allows plain HTTP or unverified TLS. Avoid it.
GOSUMDB=offdisables checksum verification for every module, which is a bad idea. Scope it with GONOSUMDB instead.
go env -w GOPRIVATE='github.com/acme/*,gitlab.corp.io'
# credentials for direct git fetch in CI:
git config --global url."https://${GH_TOKEN}@github.com/".insteadOf "https://github.com/"
# or ~/.netrc: machine github.com login x-access-token password $GH_TOKEN
# corporate proxy that also serves private modules:
GOPROXY=https://goproxy.corp.io,https://proxy.golang.org,direct
GONOSUMDB=github.com/acme/*
# Go 1.24+: GOAUTH controls how credentials are obtained for module fetches
GOAUTH='netrc;git ~/src' # default is netrc
Gotchas: the comma in GOPROXY falls through only on 404/410, while a pipe (|) falls through on any error. Docker build stages need the token too (use BuildKit secrets, never bake it into a layer). Interviewers want the relationship "GOPRIVATE sets both defaults" plus a secure way to pass credentials.
More on Modules, Packages & Tooling
- Q415How does vendoring work in module mode, and when is it still worth using?
- Q416How do internal packages work? Give an example of an allowed and a forbidden import.
- Q418How does the Go checksum database protect the supply chain? What does go mod verify actually check?
- Q419What do the go and toolchain directives mean since Go 1.21, and how does GOTOOLCHAIN behave?
- Q420What does this print? (Hint: consider the go line in go.mod.)
- Q421What does the Go 1.24 tool directive replace, and how do you use it?