Red Hat's public registry blocked by the enforced proxy egress allowlist
Hosted Dependabot docker version updates for Red Hat Universal Base Images (UBI) from
registry.access.redhat.com have failed since proxy-egress-enforce was enabled for the job. The
updater reports private_source_authentication_failure, but the proxy's egress allowlist returns the
403 and the request never reaches Red Hat.
Reproduction and observed evidence
Hosted run in a private repository, 2026-09-29 07:02 UTC. There is no registries: configuration, and
the job's only credential is git_source for github.com.
- Dockerfile:
FROM registry.access.redhat.com/ubi9/ubi-minimal:9.8-1790074235
dependabot.yml: package-ecosystem: docker, schedule.interval: daily
Proxy image: ghcr.io/dependabot/proxy:v2.0.20260929055832@sha256:45fa12e4fdbeb668d70389b231fe60ce9ef755949f52c64828b9ecbc14f2305f,
created 2026-09-29T05:59Z, after #276 was merged.
proxy | [014] GET https://registry.access.redhat.com:443/v2/ubi9/ubi-minimal/tags/list
proxy | [014] * egress not allowlisted registry.access.redhat.com
[014] 403 https://registry.access.redhat.com:443/v2/ubi9/ubi-minimal/tags/list
[014] Remote response: Forbidden
updater | Handled error whilst updating ubi9/ubi-minimal: private_source_authentication_failure {source: "registry.access.redhat.com"}
The same job succeeded on 2026-09-25, when its experiments had proxy-egress-observe but not
proxy-egress-enforce. That run logged * egress not allowlisted registry.access.redhat.com for each
request, and Red Hat answered each with HTTP 200. Apart from Dependabot's job API, the proxy saw requests
only to github.com and registry.access.redhat.com, with no redirects:
GET /v2/ubi9/ubi-minimal/tags/list, plus 27 paginated ?last= pages
HEAD /v2/ubi9/ubi-minimal/manifests/<ref> (2 requests)
Independent checks on 2026-09-29 confirmed anonymous access. GET https://registry.access.redhat.com/v2/
returns HTTP 200 with no WWW-Authenticate challenge, and tags/list returns 200, so there is no token
service to allowlist. Blob downloads from this registry 302-redirect to cdn01.quay.io, but the
version-update job made no blob requests.
Expected behavior
Hosted Dependabot should be able to discover updates for public UBI images without private registry
credentials. Please add registry.access.redhat.com to the built-in Docker allowlist, for example in the
"Vendor-operated public OCI registries that allow anonymous pulls" block added in #276. Otherwise, please
document a supported credential-free docker-registry configuration for this host. Keep egress
enforcement enabled.
This request covers only the anonymous registry. It does not cover registry.redhat.io, Red Hat's
authenticated registry, which returns 401 without a Red Hat login.
Relevant source
|
func NewEgressAllowlistHandler(cfg *config.Config, env config.ProxyEnvSettings, metricSender MetricSender) *EgressAllowlistHandler { |
|
allowed := append([]string(nil), githubInfraDomains...) |
|
allowed = append(allowed, sharedRegistryDomains...) |
|
allowed = append(allowed, allEcosystemDomains...) |
|
|
|
return &EgressAllowlistHandler{ |
|
observe: cfg.Experiments.Enabled(egressObserveExperiment), |
|
enforce: cfg.Experiments.Enabled(egressEnforceExperiment), |
|
allowed: allowed, |
|
dynamicHosts: dynamicHosts(cfg.Credentials), |
|
metrics: metricSender, |
|
} |
|
} |
|
docker: &docker_registries |
|
- registry-1.docker.io |
|
- auth.docker.io |
|
- index.docker.io |
|
- registry.hub.docker.com |
|
- hub.docker.com |
|
- production.cloudflare.docker.com |
|
- production.cloudfront.docker.com |
|
- ghcr.io |
|
- mcr.microsoft.com |
|
- quay.io |
|
- public.ecr.aws |
|
- lscr.io |
|
- .gcr.io |
|
- .pkg.dev |
|
# Vendor-operated public OCI registries that allow anonymous pulls. |
|
# docker.getcollate.io fronts Docker Hub via Scarf, so its token service is |
|
# auth.docker.io above and its blobs land on the Docker Hub CDN hosts above. |
|
- docker.getcollate.io |
|
# Elastic's registry, its anonymous token service, and the R2 bucket its |
|
# blob downloads 307-redirect to. The bucket host embeds Elastic's own |
|
# Cloudflare account hash, so it is exact only: a glob over |
|
# *.r2.cloudflarestorage.com would match every Cloudflare tenant. |
|
- docker.elastic.co |
|
- docker-auth.elastic.co |
|
- docker-registry-production.d24a988e385e0074d717b6bdaea58f0d.r2.cloudflarestorage.com |
|
docker_compose: *docker_registries |
The handler accepts built-in domains plus exact dynamic hosts from configured credentials. At this
revision, which includes #276, the built-in Docker list doesn't contain registry.access.redhat.com.
Because the job has no registry credentials, it gets no dynamic host for it either.
Red Hat's public registry blocked by the enforced proxy egress allowlist
Hosted Dependabot
dockerversion updates for Red Hat Universal Base Images (UBI) fromregistry.access.redhat.comhave failed sinceproxy-egress-enforcewas enabled for the job. Theupdater reports
private_source_authentication_failure, but the proxy's egress allowlist returns the403 and the request never reaches Red Hat.
Reproduction and observed evidence
Hosted run in a private repository, 2026-09-29 07:02 UTC. There is no
registries:configuration, andthe job's only credential is
git_sourceforgithub.com.FROM registry.access.redhat.com/ubi9/ubi-minimal:9.8-1790074235dependabot.yml:package-ecosystem: docker,schedule.interval: dailyProxy image:
ghcr.io/dependabot/proxy:v2.0.20260929055832@sha256:45fa12e4fdbeb668d70389b231fe60ce9ef755949f52c64828b9ecbc14f2305f,created 2026-09-29T05:59Z, after #276 was merged.
The same job succeeded on 2026-09-25, when its experiments had
proxy-egress-observebut notproxy-egress-enforce. That run logged* egress not allowlisted registry.access.redhat.comfor eachrequest, and Red Hat answered each with HTTP 200. Apart from Dependabot's job API, the proxy saw requests
only to
github.comandregistry.access.redhat.com, with no redirects:GET /v2/ubi9/ubi-minimal/tags/list, plus 27 paginated?last=pagesHEAD /v2/ubi9/ubi-minimal/manifests/<ref>(2 requests)Independent checks on 2026-09-29 confirmed anonymous access.
GET https://registry.access.redhat.com/v2/returns HTTP 200 with no
WWW-Authenticatechallenge, andtags/listreturns 200, so there is no tokenservice to allowlist. Blob downloads from this registry 302-redirect to
cdn01.quay.io, but theversion-update job made no blob requests.
Expected behavior
Hosted Dependabot should be able to discover updates for public UBI images without private registry
credentials. Please add
registry.access.redhat.comto the built-in Docker allowlist, for example in the"Vendor-operated public OCI registries that allow anonymous pulls" block added in #276. Otherwise, please
document a supported credential-free
docker-registryconfiguration for this host. Keep egressenforcement enabled.
This request covers only the anonymous registry. It does not cover
registry.redhat.io, Red Hat'sauthenticated registry, which returns 401 without a Red Hat login.
Relevant source
proxy/internal/handlers/egress_allowlist.go
Lines 64 to 76 in 90ee7d2
proxy/internal/handlers/egress_allowlist_defaults.yaml
Lines 311 to 337 in 90ee7d2
The handler accepts built-in domains plus exact dynamic hosts from configured credentials. At this
revision, which includes #276, the built-in Docker list doesn't contain
registry.access.redhat.com.Because the job has no registry credentials, it gets no dynamic host for it either.