Repository navigation
fix(distribution): allow proxied Docker Hub tokens without local DNS - #1081
Draft
doringeman wants to merge 1 commit into
Draft
doringeman wants to merge 1 commit into
doringeman wants to merge 1 commit into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
On proxy-only networks, Docker Hub model pulls fail before the token request reaches the proxy because the realm SSRF guard requires local DNS resolution of
auth.docker.io.Allow Docker Hub's trusted
https://auth.docker.io/tokenendpoint (default HTTPS port or explicit443) through the supplied proxy transport without local DNS validation. Scope the exception to Docker Hub registry names and apply it to both containerd authentication andExchange()preflight validation. Preserve the supplied proxy dialer, TLS certificate verification, direct-connection IP validation and pinning, and the existing checks for all other endpoints, including redirects.Regression tests cover unavailable local DNS with a working CONNECT proxy and verified TLS, token exchange, exact endpoint matching, unrelated registries, direct connections, and redirects to metadata endpoints.
Validation:
make validate-allpassed in an isolated checkout containing this change, including module tidiness, full lint, all tests with race detection, ShellCheck, and version validation.