The CI pain point
When build agents sit behind cross-border links, downloading dependencies, fetching sources and pulling binary tools can all stretch pipeline duration — or fail on timeouts. Routing GitHub-bound steps through the accelerated address is usually the simplest fix.
Option 1: replace download URLs
In Dockerfiles or build scripts, prefix the accelerated domain when downloading Release binaries or archives:
# Dockerfile snippet: download a release binary
RUN curl -fL -o /usr/local/bin/tool \
"https://ghclone.com/https://github.com/owner/repo/releases/download/v1.0/tool-linux-amd64" \
&& chmod +x /usr/local/bin/tool
Option 2: clone acceleration
When the pipeline clones sources, use the accelerated address; for build-only scenarios combine it with a shallow clone:
git clone --depth=1 https://ghclone.com/https://github.com/owner/repo.git
For projects with submodules, rewrite the prefix locally after cloning:
git config --local url."https://ghclone.com/https://github.com/".insteadOf "https://github.com/" git submodule update --init --recursive
Option 3: caching and artifact repositories
For frequently used dependencies, do not re-download across borders every build: use the CI cache directories, or push pinned archives into an internal artifact repository. The principle: crossing the border is a one-time cost; afterwards, use the cache or the local network.
Reliability checklist
- Pin versions (tags or commits) before downloading so builds stay reproducible
- Verify checksums after download; fail fast so bad artifacts never flow downstream
- Wrap downloads with retries (
--retryor a shell loop) against link jitter - With multiple lines available, script a fallback to the next line on failure
# shell retry wrapper example
fetch() {
curl -C - -fL --retry 3 --retry-delay 2 -o "$2" "$1" && return 0
echo "download failed: $1" >&2
return 1
}
fetch "https://ghclone.com/https://github.com/owner/repo/releases/download/v1.0/tool.tar.gz" tool.tar.gz
A note on GitHub Actions
GitHub-hosted runners already sit inside GitHub’s network, so pulling official resources usually needs no acceleration; self-hosted runners (especially behind cross-border links) and third-party CI platforms are where this guide applies. Also: never put credentials in URLs — the gateway strips credential headers anyway, and write operations are always rejected.