Skip to content

fix(distribution): allow proxied Docker Hub tokens without local DNS - #1081

Draft
doringeman wants to merge 1 commit into
docker:mainfrom
doringeman:fix/csesc-1921-docker-token-proxy-dns
Draft

doringeman wants to merge 1 commit into
docker:mainfrom
doringeman:fix/csesc-1921-docker-token-proxy-dns

Conversation

@doringeman

@doringeman doringeman commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

On proxy-only networks, Docker Hub model pulls fail before the token request reaches the proxy because the realm SSRF guard requires local DNS resolution of auth.docker.io.

Allow Docker Hub's trusted https://auth.docker.io/token endpoint (default HTTPS port or explicit 443) through the supplied proxy transport without local DNS validation. Scope the exception to Docker Hub registry names and apply it to both containerd authentication and Exchange() preflight validation. Preserve the supplied proxy dialer, TLS certificate verification, direct-connection IP validation and pinning, and the existing checks for all other endpoints, including redirects.

Regression tests cover unavailable local DNS with a working CONNECT proxy and verified TLS, token exchange, exact endpoint matching, unrelated registries, direct connections, and redirects to metadata endpoints.

Validation: make validate-all passed in an isolated checkout containing this change, including module tidiness, full lint, all tests with race detection, ShellCheck, and version validation.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant